In short
- A business that uses CellAssist, such as your clinic, controls its assistant and decides what it keeps about you. For those calls and messages we act on that business's instructions, so please contact the business first. We will help it respond.
- Calls handled by CellAssist are processed by AI and are recorded and transcribed.
- We do not sell personal data, and we do not use call recordings, transcripts or contact lists to train general-purpose AI models.
- You can reach our Grievance Officer at care@cellassist.ai. We acknowledge complaints within 24 hours and aim to resolve them within 15 days.
This summary helps you read the policy. The full text below is what applies.
About this policy
This Privacy Policy explains how CellStrat Information Systems Private Limited ("CellStrat", "we", "us") collects, uses, shares and protects personal data when you visit cellassist.ai, sign up for or use CellAssist (the "Service"), or speak or exchange messages with a business that uses CellAssist.
We are based in India. This policy is written first for the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, the "DPDP Act"), and for the Information Technology Act, 2000 and the rules made under it, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules"). If you are outside India, section 13 sets out the additional rights you may have, including under the EU and UK General Data Protection Regulation ("GDPR") and US state privacy laws.
1. Who we are and our role
CellAssist is a product of CellStrat Information Systems Private Limited, a company incorporated in India (CIN U62099KA2023FTC174951), with its registered office at Vaishnavi Signature, Marathahalli-Sarjapur Outer Ring Road, Bellandur, Bengaluru, Karnataka 560103, India.
We play two different roles, and which one applies decides who you should contact first.
| Whose data | Our role | Who decides how it is used |
|---|---|---|
| Website visitors, people who contact us or book a demo, people who sign up, and the team members they invite ("Members") | Data Fiduciary (under GDPR, controller) | CellStrat |
| People a business talks to through CellAssist: its callers, the people it calls, the people who message it on WhatsApp, and its patients and customers ("End Users") | Data Processor (under GDPR, processor), acting on the business's instructions | The business using CellAssist (our "Customer"), which is the Data Fiduciary |
For End User data, this policy describes how we handle it on the Customer's behalf. The Customer's own privacy notice governs why it collects that data and what it does with it. Our commitments to Customers are in our Terms and Conditions, including the Data Processing Terms in Schedule 1.
2. If you called, or were called by, a business using CellAssist
- You were speaking with an AI assistant that the business set up and controls. The business decides what the assistant says and asks, what it saves about you in its contact list, whether it books an appointment, and whether you are sent a WhatsApp message or an email afterwards.
- Calls are recorded and transcribed so that the business can review them, and an AI summary of the call may be created for the business.
- To access, correct or delete this information, or to withdraw your consent, contact the business directly. If you cannot reach it, or you do not know which business called you, write to our Grievance Officer at care@cellassist.ai with the phone number involved and the date and time of the call. We will pass your request to the business, help it respond, and act on anything that is our own responsibility.
- If you do not want further calls, tell the business. For promotional calls in India you can also register your preferences with the National Customer Preference Register by calling or sending an SMS to 1909 from your mobile number.
3. Personal data we collect
Information you give us
- Enquiries, demos and newsletters: your name, email address, phone number, company and message.
- Sign-up and onboarding: your name, email address, phone number, company name, industry, how you heard about us and your expected daily call volume.
- Your account: the names, email addresses and roles of your Members and invitations; your organisation's settings, such as its time zone; and everything you enter to set up an assistant, including its instructions, welcome message, vocabulary, business details and the names, specialties and schedules of the people or resources you make bookable.
- Support: what you tell us when you write to us, and our replies.
- Billing, if you buy a paid plan: billing contact, billing address, GST number and payment records. Card details are handled by our payment processor, and we do not store full card numbers.
Information collected automatically
- Sign-in and device data: IP address, browser and device type, time zone and session identifiers, collected by our authentication provider when you sign in.
- Usage and logs: the features you use, the changes you make and who made them, errors, and requests to our servers.
- Usage metering: the number and length of calls and other actions, and the credits they use.
- Website cookies: described in section 7.
End User data we process for Customers
| Category | What it includes |
|---|---|
| Call audio | Recordings of calls handled by an assistant, including both sides of the conversation |
| Transcripts and AI output | What was said, as text; call summaries; details the Customer asked to be picked out after the call, such as a preferred appointment date; and a record of the actions the assistant took |
| Call details | Phone numbers of both parties, date, time, duration, direction, how the call ended, carrier status codes and any number the call was transferred to |
| Contacts | Name, phone numbers, email address, postal address, notes, custom fields and the history of past calls and messages |
| Appointments | Who the appointment is for, what or whom it is booked with, the time, and any details the Customer asks the assistant to collect, such as date of birth or reason for the visit |
| Message text, photos and other attachments, and delivery and read status | |
| Calling lists | Names, phone numbers and other values a Customer uploads to call a list of people |
| Data from the Customer's systems | Information the assistant looks up in the Customer's own software during a call, through a connection the Customer sets up |
We do not create voiceprints, and we do not use a person's voice to identify who they are.
4. Health information and other sensitive data
Many of our Customers are clinics, hospitals, diagnostic labs and pharmacies, so a caller may share health information: symptoms, test results, medicines, a doctor's name or the reason for a visit. Under the SPDI Rules, information about a person's physical, physiological and mental health condition, and their medical records and history, is sensitive personal data. So are passwords and financial information such as bank account or card details.
- We treat all health information in End User data as sensitive, whichever law applies.
- We process it only to provide the Service to the Customer that collected it, and never for advertising or profiling.
- CellAssist is not a medical device and does not diagnose, treat or give medical advice. The starting instructions we provide to healthcare businesses tell the assistant not to discuss symptoms, reports or treatment, and to direct emergencies to 112. A Customer can change those instructions and is responsible for what its assistant says.
- CellAssist reads a Customer's patient or business records only if the Customer connects it to its own software.
- Our Acceptable Use Policy forbids assistants that ask for OTPs, PINs, passwords, card numbers or Aadhaar numbers. Please never share these on a call.
- United States: CellAssist is not offered as a business associate service under HIPAA. A US covered entity or business associate must not use it to process protected health information unless it has signed a business associate agreement with us.
5. How we use personal data, and our legal grounds
| Purpose | Data used |
|---|---|
| Run the Service: answer and place calls, transcribe them, book appointments, and send the messages and emails a Customer has set up | End User data, on the Customer's instructions; account data |
| Create and manage accounts, and sign you in | Account, sign-in and device data |
| Measure usage, apply plan limits and credits, and bill | Usage metering and billing data |
| Provide support and fix problems a Customer reports | Support messages, account data, and End User data only where a Customer's problem cannot be fixed without it |
| Keep the Service safe: prevent fraud, spam and abuse, review assistant instructions against our Acceptable Use Policy, and suspend calling where needed | Account data, assistant instructions, call details and logs |
| Send service messages, such as security alerts and changes to our terms | Contact details |
| Send news and offers about CellAssist, which you can unsubscribe from at any time | Contact details |
| Improve the Service | Usage data, aggregated or de-identified wherever possible |
| Meet legal obligations, respond to lawful requests from authorities, and enforce our terms | Any of the above, as the law or the request requires |
Our legal grounds in India. We process personal data for our own purposes with your consent, which you give when you sign up, submit a form or accept cookies, and which you can withdraw at any time. We also rely on the legitimate uses the DPDP Act allows, such as using information you have voluntarily given us for the purpose you gave it, meeting a legal obligation, and complying with a court order. For End User data, the Customer is responsible for having a lawful ground and we process the data only on its instructions.
Our legal grounds under GDPR, where it applies. Performance of our contract with you; our legitimate interests in running, securing and improving the Service and in telling business contacts about it; compliance with legal obligations; and your consent, for cookies and certain marketing.
We do not sell personal data, and we do not use End User data for advertising.
6. How CellAssist uses AI
- CellAssist uses speech recognition, large language models and speech synthesis to understand callers and reply in real time. After a call, it uses AI to write a summary and pick out the details a Customer asked for. When a Customer writes an assistant's instructions, AI can suggest wording.
- These models are run by the AI providers listed in section 8, which process the data to provide their service to us. We choose provider settings that keep our data out of their model training wherever such settings are offered.
- We do not use End User data or a Customer's content to train general-purpose AI models.
- AI can mishear, misunderstand or be wrong. Customers should check what matters before relying on it.
- CellStrat does not make decisions about you based solely on automated processing that have legal or similarly significant effects. A Customer may use its assistant to offer or book appointments and remains responsible for those decisions.
- Our terms require every assistant to answer truthfully if asked whether it is a machine, and we ask Customers to say at the start of each call that the caller is speaking with an automated assistant.
7. Cookies and analytics
On cellassist.ai, we use Google Analytics to understand how visitors use the site. Analytics and advertising cookies are off by default and are turned on only if you select "Accept all" in our cookie banner (Google Consent Mode). "Necessary only" keeps them off. You can change your choice at any time by clearing this site's stored data in your browser, which brings the banner back.
In the CellAssist dashboard, we use only the cookies needed to sign you in and keep you signed in. They cannot be switched off without stopping sign-in, and we do not use analytics or advertising cookies there.
8. Who we share personal data with
We share personal data only as this policy describes. We use the following service providers ("sub-processors"), each bound by a contract or terms that limit how it may use the data:
| Provider | What it does for us | Where it processes data |
|---|---|---|
| Google Cloud | Hosting the platform and the website; storing call recordings and WhatsApp attachments | India |
| Neon | Managed database for account and End User records | Singapore |
| LiveKit | Real-time audio for calls | India, and other regions where needed to connect a call |
| Exotel | Phone numbers, call connectivity and WhatsApp messaging | India |
| Meta (WhatsApp Business Platform) | Delivering WhatsApp messages | Global |
| Sarvam AI | Speech recognition, speech synthesis and translation for Indian languages | India |
| OpenAI | Language models for conversations, call summaries and writing suggestions | United States |
| Deepgram, ElevenLabs and LiveKit Inference | Speech recognition, speech synthesis or language models, only if a Customer chooses them for its assistant | United States and other regions |
| Clerk | Sign-in and account management | United States |
| Vercel | Hosting the dashboard | Global |
| Amazon Web Services (SES) | Sending emails a Customer sets up after a call, and service emails | Asia Pacific |
| Resend | Sending website and newsletter emails | United States |
| Google Analytics | Website measurement, only with your consent | United States |
We also share personal data:
- With the Customer whose assistant handled your call or message. End User data belongs to that Customer and its Members can see it.
- With the Customer's own systems, when the Customer has set up its assistant to look something up, send data to its software, or email a summary to an address it chooses.
- With authorities, when the law requires it, for example under the Information Technology Act, 2000, a direction of CERT-In, or an order of a court or regulator.
- With professional advisers, such as lawyers and auditors, under a duty of confidentiality.
- In a business transfer, such as a merger or acquisition, where the recipient agrees to protect the data as this policy does. We will tell affected Customers first.
- With your consent, in any other case.
We keep this list current. We will update it here, and tell Customers in advance, before a new sub-processor starts handling End User data.
9. Where your data is stored and transferred
Call recordings and WhatsApp attachments are stored in India. Some of our providers process data outside India, including in Singapore and the United States, as the table in section 8 shows.
The DPDP Act allows personal data to be transferred outside India except to countries the Central Government restricts by notification, and we will follow any such restriction. For personal data from the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.
10. How long we keep personal data
We keep personal data only as long as the purpose needs it, or as long as the law requires.
| Data | How long we keep it |
|---|---|
| Website analytics | No longer than 14 months |
| Enquiries, demo requests and newsletter subscriptions | Until you unsubscribe or ask us to delete them, and no longer than 24 months after our last contact with you |
| Account data | While the account is open, then deleted or anonymised within 90 days after it closes |
| End User data: recordings, transcripts, contacts, appointments and messages | As long as the Customer keeps it in its account, or until the Customer asks us to delete it. Deleted within 90 days after the Customer's account closes |
| WhatsApp photos and attachments | 90 days after they are received |
| Security and system logs | At least 180 days, as CERT-In directions require |
| Billing and tax records | As long as Indian tax and company law requires, usually 8 years |
| Backups | Up to 30 days after the data is deleted from our live systems |
11. How we protect personal data
- Our website, dashboard and servers are reached over TLS, which encrypts data in transit, and our hosting and database providers encrypt stored data at rest.
- A phone call also travels over telephone networks that we do not operate, and parts of that journey may not be encrypted.
- Each Customer's calls, recordings and contacts are kept separate from every other Customer's.
- Access is limited to the Customer's own Members and to the CellStrat staff who need it to provide support, keep the Service secure or meet a legal obligation.
- Sign-in is handled by a dedicated identity provider, and API keys a Customer gives us are masked when shown back.
- We follow reasonable security practices as section 43A of the Information Technology Act, 2000 and the SPDI Rules require, and we review them as the Service changes.
- If a personal data breach affects you, we will inform the affected Customers without undue delay, and we will notify the Data Protection Board of India, CERT-In and the affected individuals as the law requires.
No system is perfectly secure. Please keep your password safe and tell us straight away at care@cellassist.ai if you think your account has been misused.
12. Your rights in India
Under the DPDP Act you have the right to:
- Information: a summary of the personal data we process about you, what we do with it, and who we have shared it with.
- Correction and erasure: to have inaccurate or incomplete data corrected, completed or updated, and data we no longer need erased.
- Withdraw consent at any time, as easily as you gave it. This does not affect processing already done, and may mean we can no longer provide the Service to you.
- Grievance redressal: to have your complaint handled by our Grievance Officer. See our Grievance page.
- Nominate another person to exercise these rights for you in the event of your death or incapacity.
To use any of these rights, write to care@cellassist.ai. We may ask you to confirm your identity first. We acknowledge every request within 24 hours and aim to complete it within 15 days, and in any case within the time the law allows. If your request is about End User data, we will pass it to the Customer concerned and help it respond. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
The DPDP Act also asks you to give accurate information and not to make a false or frivolous complaint.
13. Additional rights outside India
European Economic Area, United Kingdom and Switzerland. You have the right to access, correct and erase your personal data, to restrict or object to its processing (including for direct marketing at any time), to data portability, and to withdraw consent. You may also complain to your local data protection authority.
United States. Depending on your state, including California, you may have the right to know what personal data we collect and how we use and disclose it, and to access, correct and delete it. We do not sell personal data or share it for cross-context behavioural advertising. We will not treat you differently for using your rights, and you may use an authorised agent.
Everywhere else. Write to us at care@cellassist.ai and we will honour the rights your local law gives you.
14. Children
CellAssist is a service for businesses. Members must be at least 18 years old, and we do not knowingly collect personal data from children for our own purposes. Under the DPDP Act, a child is anyone under 18.
End User data can include information about a child, for example when a parent books an appointment for their child. The Customer is responsible for obtaining verifiable consent from a parent or lawful guardian where the law requires it. We process such data only on the Customer's instructions, and never for tracking, behavioural monitoring or targeted advertising.
15. Changes to this policy
We will post any change on this page with a new "Last updated" date. If a change materially affects how we handle your personal data, we will tell account holders by email or in the dashboard at least 30 days before it takes effect, unless the law requires a change sooner. We will also remind users of this policy at least once a year.
This policy is published in English. If you would like it in another language listed in the Eighth Schedule to the Constitution of India, write to care@cellassist.ai.
16. Contact and Grievance Officer
Grievance Officer and Data Protection Officer
Indrajit Singh, Chief Technology Officer
Email: care@cellassist.ai
CellStrat Information Systems Private Limited
Vaishnavi Signature, Marathahalli-Sarjapur Outer Ring Road, Bellandur, Bengaluru, Karnataka 560103, India
How we handle complaints, and where to go if you are not satisfied, is set out on our Grievance page.