AI Responsibility Statement
RevRag AI Technology Private Limited builds In-App and Voice AI agents for enterprises in regulated sectors. We are committed to developing and operating our AI/ML products responsibly, safely, and in line with India's Responsible AI principles. This statement explains how we do that.
Human oversight and accountability
Our AI agents assist and execute defined workflows; they do not make autonomous high-impact decisions. We do not use AI to make credit, lending, or other adverse decisions about individuals. Sensitive or out-of-scope situations are escalated to a human representative. Our Data Protection Officer, Pankaj Gupta, and a designated grievance officer are accountable for our AI and data-protection practices.
Transparency
Our agents identify the organisation on whose behalf they are calling and state the purpose of the interaction at the outset, and do not impersonate a specific named individual.
Fairness and non-discrimination
We test and evaluate our agents to operate consistently and avoid unfair or discriminatory outcomes, and we apply anti-hallucination ("grounding") controls so responses stay accurate and within scope. We design for inclusivity, including multilingual support.
Privacy and data protection
We act as a Data Processor on behalf of our enterprise clients and process personal data only on their documented instructions. Our production infrastructure is hosted in India (AWS Mumbai), and we do not transfer personal data outside India except where a specific sub-processor providing voice or speech-processing capabilities requires it, under a data processing agreement (DPA) consistent with the Digital Personal Data Protection Act, 2023. Personal identifiers such as phone numbers are masked and are never sent to third-party language, speech-to-text, or text-to-speech models; spoken audio processed by such sub-processors is handled under zero or low-retention configuration. We operate under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.
Data minimisation and retention
We collect and process only the data needed for the contracted purpose, and configure zero or minimal data-retention with our AI sub-processors wherever supported. Consistent with our Terms and Conditions and Privacy Policy, we retain Customer Data for 90 days after service termination, after which it is securely deleted, or sooner upon request.
Security and independent assurance
We encrypt data in transit (TLS 1.2/1.3) and at rest (AES-256), enforce role-based access with multi-factor authentication, and maintain ISO/IEC 27001:2022 certification and SOC 2 Type II attestation, with annual penetration testing and an independent data-localization audit.
Continuous monitoring
We review model performance, safety, and our vendors' practices on an ongoing basis, and we update our controls as AI standards and Indian regulatory guidance evolve.
Last updated: 15 September 2026