Skip to content
AuraBook my call

Legal

Privacy policy

What we collect, why, who it goes to, and what you can make us do about it.

Effective
25 September 2026
Last updated
8 August 2026

1. There are two different relationships here

This matters more than anything else in the document, so it is first.

If you are visiting this website or filling in our enquiry form, we decide why and how your personal data is used. Under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) we are the Data Fiduciary. Part A applies to you.

If your employer uses Aura, and Aura is processing recordings of calls between your company and its customers, then your company decides why and how that data is used. Your company is the Data Fiduciary; we act only on its instructions and are the Data Processor. Part B applies, and it is deliberately narrow: we do not decide what happens to your call data, and we cannot grant requests about it that your company has not authorised.

If you are an individual who was recorded on a call with a business that uses Aura, your rights are against that business, not against us. We will tell you who they are and forward your request to them. See §10.

2. Who we are

Mohamed Riyaz, proprietor, trading as Sirah Digital, operating as Aura.

Part A: if you visit this site or contact us

3. What we collect, and why

There is no chat widget on this site, and our fonts are served from our own servers rather than Google’s.

We use the Meta (Facebook) advertising pixel, Google Tag Manager and Microsoft Clarity, and none of them wait for your consent. They load on every page view, for every visitor, as soon as the page is interactive. We do not ask first, and there is no control on this site to opt out.

Lawful basis: legitimate interest, as the site owner, in measuring advertising performance and understanding how the site is used. We are not relying on your consent for these three.

The Meta pixel and Google Tag Manager tell Meta and Google that a browser visited a page here, and separately when someone books a call. They receive your IP address and a cookie identifier, and Meta may link those to a Facebook or Instagram account it already holds. Microsoft Clarity records how visitors use this site - page views, clicks and scrolling - as session recordings and heatmaps, and receives your IP address, browser and device details. Clarity masks form input by default; we do not configure it to record what you type into the enquiry form. We do not send any of the three your name, email address or phone number. Their own controls are at facebook.com/adpreferences and clarity.microsoft.com.

Beyond that, we collect personal data only when you give it to us.

3.1 When you fill in our enquiry form

WhatWhy we need it
Your nameTo address you correctly when we reply
Your email addressTo reply to your enquiry
Your phone numberTo call you back, because most of our enquirers prefer a call
Your WhatsApp number, if differentTo reply on the channel you chose
Your countryTo interpret your phone number correctly
The type of business you runTo judge whether Aura actually suits you
How many people make callsThe same
Your monthly budget rangeTo tell you honestly and early if we are not a fit
Where you are in your decisionTo pitch the conversation at the right level
Whether you use a CRM, and which oneTo tell you whether we already connect to it
Whether you want a CRM built for youTo route you to the right person
The exact consent wording you agreed to, and whenTo prove what you agreed to, if it is ever questioned
Campaign parameters in the link you arrived throughTo know which of our efforts brought you here

Lawful basis (DPDP Act §6): your consent, given by ticking the unticked consent box on the form. We do not pre-tick it. If you do not tick it, the form does not submit.

We record the exact text of the consent you agreed to and the timestamp, so that if you ever ask us what you agreed to we can show you the actual sentence rather than our current wording.

3.2 To stop the form being abused

We limit how many times the same person or connection can submit the form. To do that we store a salted, one-way cryptographic hash of your IP address, and never the address itself. The hash cannot be reversed to recover your IP, and we do not retain the IP anywhere else in this system.

3.3 What we do not collect on this website

  • We do not buy contact data about you from anyone.
  • We do not sell, rent, or share your details with any third party for their own marketing. Not now, and this is not a policy we intend to change quietly. If it ever changed we would have to ask you again.

4. Cookies

One cookie of our own.

NamePurposeLifetime
aura_funnel_sidRemembers, between step 1 and step 2 of the enquiry form, which submission is yours2 hours

It is cryptographically signed so it cannot be forged, marked httpOnly so no JavaScript on the page can read it, and marked SameSite=Lax so another website cannot use it. It contains an internal reference number and a timestamp. It contains no personal data and is not used to track you.

We do not use it for analytics or advertising. It is strictly necessary for the form to work, which is why you are not asked to consent to it separately. The Meta pixel, Google Tag Manager and Microsoft Clarity described in §3 set their own cookies, which are not ours and are not covered by that exemption.

This is the cookie count for this marketing website. If you are a signed-in user of the console, see §9, which covers the cookies the console itself sets.

5. How long we keep your enquiry

We keep what you send through the enquiry form for 365 days, after which it is deleted. If you become a customer, your enquiry becomes part of the contractual record and is kept for as long as the account, plus the period in §13.

You can ask us to delete your enquiry at any time before then. See §10.

Part B: if your company uses Aura

6. Our role, stated narrowly

When your company uses Aura, we process the following on its instructions and for no other purpose:

  • audio recordings of calls made or received on enrolled handsets, and the transcripts generated from them;
  • the fields extracted from those transcripts: quantities, prices, locations, commitments, and whatever other fields your company has configured;
  • leads and contacts, and the records your team creates about them in the CRM: notes, tasks, stage and pipeline data;
  • conversations from messaging channels your organisation connects, such as WhatsApp, including message content and the phone numbers involved;
  • mail, calendar and spreadsheet data from any mailbox, calendar or Google Sheet a member of your team chooses to connect, limited to the access they grant when connecting it;
  • the phone numbers and names of the people on your calls, conversations and leads;
  • records of which of your staff handled which call, conversation or lead.

We do not use any of it for our own purposes. Specifically: we do not use your call recordings, transcripts, messages, connected mailbox data or any other Customer Data to train, fine-tune or evaluate any machine learning model of ours, we do not use it to build any product feature for another customer, and we do not analyse it in aggregate across customers.

Your company decides what is recorded and connected, who may access it, how long it is kept, and when it is deleted. We give them the controls; they make the decisions.

Where you connect an email, calendar or spreadsheet account, or a messaging channel such as WhatsApp, that connection runs on your own account with that provider. If your organisation has not registered its own app with Google or Microsoft, the connection uses Aura’s own registered app to complete the sign-in; either way, it is your organisation’s account, and only the access it grants, that gets used - not ours. Messages sent or received over WhatsApp necessarily also pass through WhatsApp’s own network, operated by Meta, the same as they would if you used WhatsApp directly; if your organisation routes its WhatsApp connection through a WhatsApp Business Solution Provider of its own choosing, that provider processes the same traffic under its own agreement with your organisation, not with us.

7. Your company’s obligations, not ours

Recording a phone call engages the law. The business operating the handset is responsible for telling the people on the call that it is being recorded and obtaining whatever consent applies, for having a lawful basis for the recording, and for responding to requests from the individuals recorded.

We publish guidance on this at /consent, but guidance is not advice and we are not your lawyer. If you are a customer and you have not addressed this, address it before you enrol a handset.

8. Sub-processors

We use the following providers to run the service. Each one is bound by contract to process data only on our instructions.

Sub-processorWhat it doesWhere it runs
Sarvam AIIndic speech recognition and call analysisIndia
Google (Gemini)Call analysis where Sarvam is not the configured providerGoogle’s infrastructure for the Gemini API
HostingerThe application and worker servers, the Postgres database, and the object storage holding call recording audio - we run our own database rather than using a managed provider, so this is the only infrastructure sub-processor for everything except AI analysisMumbai, India

Your data moved: Seoul to Mumbai, September 2026.

Until 24 September 2026, the database behind Aura ran on managed infrastructure in Seoul, South Korea. It now runs on our own servers in Mumbai, India, alongside the rest of the application. We are telling you here, rather than only updating the table above, because a customer who checked this page before that date deserves to know it changed and did not just get a quieter footnote.

We will give 30 days’ notice before adding or replacing a sub-processor, so that you have the opportunity to object.

9. How the data is protected

These are mechanisms, not adjectives. We have deliberately not used the phrases “bank-grade”, “military-grade” or “enterprise-grade” anywhere, and we hold no certification we have not named.

  • Separation between customers is enforced by the database, not by our code. Every table holding customer data carries a Postgres row-level security policy keyed to the organisation, set to force, so it applies even to the table’s owner. The application connects using a database role created explicitly without the privilege to bypass it. An automated check runs over the schema and fails if any table carrying an organisation identifier is missing that protection.
  • In transit, recordings are uploaded over TLS.
  • Deletion cascades. When a call is erased, the stored audio object, the lead, the transcript, the model outputs, the extracted facts, the CRM dispatch log and the call record itself are all removed, and a cryptographically signed receipt is written to the audit log.
  • Every privileged action is logged with the organisation, who did it, what they did, what they did it to, the originating IP and the time.
  • The marketing database is separate. The enquiry form connects using a database role that has access to the marketing schema and to nothing else. It cannot reach any customer’s call data, by construction and not by convention.
  • The console sets its own cookies once you sign in, separate from the one described in §4: to keep you signed in, to remember which organisation you are currently working in, and to remember interface preferences such as your theme. These are strictly necessary for the console to work and are not used for analytics or advertising.

On-device encryption is off by default.

Encrypting a recording on the handset before it is uploaded is an available setting, and it is not enabled unless the customer enables it. We state it here because a customer should not discover a default like that from us later.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If we suffer a personal data breach we will notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act, and affected customers without undue delay and in any event within 72 hours of becoming aware. Security issues can be reported to support@sirahdigital.in.

Part C: applies to everyone

10. Your rights

Under the DPDP Act you may:

  • ask what we hold about you, and why;
  • have it corrected if it is wrong, incomplete or out of date;
  • have it erased, where we no longer need it for the purpose you gave it for;
  • withdraw your consent at any time, as easily as you gave it;
  • nominate someone to exercise these rights on your behalf if you die or become incapacitated;
  • complain to us first, and then to the Data Protection Board of India.

To exercise any of these, write to support@sirahdigital.in. We will respond within 15 days.

If your request is about a call recording, we will almost certainly have to refer you to the business that made the recording, because the data is theirs and not ours. We will tell you who they are and pass your request on within 7 days.

Withdrawing consent does not undo anything we lawfully did before you withdrew it.

11. Grievance officer

The DPDP Act and the IT Rules require us to name a person you can escalate to. That person is:

  • Name: Mohamed Riyaz
  • Designation: Proprietor
  • Email: support@sirahdigital.in
  • Postal address: SY NO 203/10B, Innov8, Featherlite The Address, 200 Feet Radial Rd, Raja Joseph Colony, Pallavaram, Tambaram, Chennai, Tamil Nadu
  • Telephone: +91 73054 26819

If we do not resolve your complaint to your satisfaction, you may escalate to the Data Protection Board of India.

12. Children

Aura is a business product, sold to businesses, and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child’s data has reached us, write to support@sirahdigital.in and we will delete it.

13. Changes to this policy

If we change this policy in a way that materially affects you, we will post the change here and update the date at the top, and if you are a customer we will email you 30 days before it takes effect. We will not quietly broaden what we do with data you have already given us; that would require asking you again.

14. Contact