Privacy

Privacy Policy and Trust Center.

Silver Suits AI Private Limited. How we collect, use, store, share and protect personal and transactional information under the DPDP Act, 2023.

23 languages. Translations are reproduced exactly as supplied.

At Silver Suits AI, we design contextual, autonomous AI agents for the Banking, Financial Services and Insurance (BFSI) sectors. We recognise that handling financial data demands the highest standards of security, privacy and regulatory compliance.

This Privacy Policy outlines how we collect, use, store, share and protect personal and transactional information in strict compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable financial regulatory frameworks.

1. Scope and legal roles

This policy governs personal data processed by Silver Suits AI across our workforce and enterprise platforms. Under the DPDP Act, 2023, our legal role depends on the data source:

Employee and contractor data: Silver Suits AI acts as the Data Fiduciary (Controller) for data relating to our team members, contractors and corporate invitees.

Enterprise client and customer data: When our financial AI agents interact with end-users of banking, insurance or financial institutions, Silver Suits AI acts strictly as a Data Processor. The respective financial institution acts as the Data Fiduciary (Controller).

2. Categories of data we process

2.1 Enterprise support and customer data. To execute automated financial workflows, our AI agents process the minimum necessary data, including:

Identifiers: name, mobile number, or account references — typically obtained on demand through secure API integrations with the client.

Interaction content: conversation logs, text transcripts, voice recordings and user selections.

Technical and system metadata: timestamps, agent execution flows, tool-invocation parameters, IP addresses and device signatures.

2.2 Employee and contractor data. For workforce management we collect standard operational identifiers including name, corporate device IDs, tax identifiers, bank details for payroll processing and occupational health configurations.

3. Purpose of processing and legal basis

We process data under valid legal bases including explicit consent, contractual necessity, or specified legitimate uses such as fraud prevention and financial compliance:

Service delivery: executing task workflows through voice or text mechanics — balance enquiries, claim processing, or direct routing.

AI safety and security: monitoring tool-execution parameters to prevent algorithmic bias, prompt-injection risks and unauthorised deviations inside financial model loops.

Compliance and audit: to fulfil statutory accounting, corporate security or tax-related mandates.

4. Your rights as a Data Principal

Under the DPDP Act, 2023, individuals retain robust rights over their personal data.

Note: for end-customer data, rights must be exercised through your primary financial provider (the Data Fiduciary), who will instruct us to action the downstream request.

Right to information and access: request a summary of the personal data being processed and the purpose of that processing.

Right to correction and completion: request immediate correction of inaccurate or outdated financial or personal records used by our execution loops.

Right to erasure: request removal of records from active application databases, LLM context windows and backup archives, subject to regulatory retention mandates.

Right to nominate: nominate an individual to exercise your data rights on your behalf in the event of death or incapacity.

Right to grievance redressal: file immediate complaints regarding data processing discrepancies.

5. Multi-channel grievance redressal

If you wish to exercise any of your rights or raise a privacy concern, you may contact our designated Grievance Officer / Data Protection Officer (DPO) through any of our operational channels:

Online grievance form: submit a structured, trackable request on the Privacy Grievance Portal.

By email: reach our DPO directly at pavan@silversuits.ai.

Physical address: Silver Suits AI Private Limited, 235 Binnamangala, 2nd Floor, C/O PROWORKS 13TH CROSS, HOYASALA NAGAR 02ND STG, Indiranagar (Bangalore), Bangalore North, Bangalore – 560038, Karnataka.

Acknowledgement: all valid grievances are acknowledged officially within 48 hours.

Identity verification: for financial security we verify identity through automated account verification or an out-of-band one-time password (OTP) before disclosing profile logs.

Statutory timeline: valid requests are processed promptly, targeting internal resolution within 30 days and strictly limited to a maximum of 90 days as prescribed by law.

6. Cross-border transfers and local residency

Default framework: data is securely hosted on premium cloud infrastructure. Any cross-border transmission uses Standard Contractual Clauses (SCCs) and encryption mechanisms permitted under the DPDP Act.

Localisation option: for BFSI clients bound by local central banking or insurance directives, Silver Suits AI offers dedicated local-region deployment, guaranteeing that backups and metadata do not leave Indian soil.

7. Technical and organisational security measures (TOMs)

Advanced encryption: AES-256 for data at rest and TLS 1.3 for data in transit. High-risk PII attributes carry envelope encryption (AES-GCM).

System isolation and access controls: identity access management operates on single sign-on (SSO), mandatory multi-factor authentication (MFA) and strict role-based isolation (RBAC).

Breach protocol: in the event of any unforeseen data vulnerability, Silver Suits AI maintains structured playbooks to notify the Data Protection Board of India (DPBI) and affected entities immediately, as legally required.

8. Data retention

Customer interaction logs: maintained strictly for the duration of the enterprise contract, or configured according to the specific client’s data lifecycle directives.

Security audit logs: operational access logs are retained for 12 months; forensic legal holds may extend to 7 years.

Workforce records: retained for 7 years post-termination to fulfil statutory labour and tax frameworks.

On expiry of the retention window, data is automatically purged or subjected to irreversible anonymisation.

Talk to us

Tell us about your funnel — the quickest way to reach us is WhatsApp.

WhatsApp only · +91 738 173 2333