By accessing or using OWNTHUM AI services, you trust us with your data. We take that responsibility with absolute gravity.
This Privacy Policy outlines how OWNTHUM AI (referred to as "Company", "We", "Us", or "Our") collects, uses, stores, discloses, and protects information when you visit our website, use our platform, integrate our APIs, or deploy autonomous AI agents. We are committed to maintaining the confidentiality, security, and privacy of all enterprise data, user credentials, and operational workflows processed through our infrastructure in accordance with global data protection frameworks including GDPR, CCPA/CPRA, and the India Digital Personal Data Protection Act, 2023 (DPDPA).
Introduction & Core Principles
At OWNTHUM AI, privacy is built into our core architecture. As a provider of autonomous enterprise AI agents, Retrieval-Augmented Generation (RAG) knowledge bases, and automated workflow pipelines, we understand that enterprise data is your most valuable asset.
Our operational privacy architecture is guided by three foundational principles:
- Complete Data Isolation: Customer data and operational knowledge bases are strictly partitioned and isolated per tenant. Your data is never combined or cross-contaminated with other organizations.
- Zero Unsanctioned AI Training: We never use your proprietary inputs, Customer Data, documents, or AI agent outputs to train or fine-tune public foundation AI models without your explicit written agreement.
- Transparent Sovereignty: You retain complete ownership and governance over your data at all times, including the right to inspect, export, or permanently purge your data upon request.
Information We Collect
We collect several categories of information to provide, secure, and optimize our autonomous AI services:
- Account & Contact Information: Name, work email address, phone number, job title, company name, billing address, and account credentials when you register or communicate with us.
- Billing & Payment Data: Payment card details, billing history, tax identification numbers, and transaction metadata. Payment card processing is handled securely by PCI-DSS certified processors (Stripe/Razorpay); we do not store full credit card numbers on our servers.
- Customer Data & Content: Text, prompt logs, uploaded PDF/Word documents, CRM data, vector embeddings, customer support tickets, email communications, and API payloads ingested into or generated by AI agents configured by you.
- System & Usage Telemetry: IP addresses, browser type, operating system, device identifiers, system response times, API usage rates, agent task execution logs, error tracebacks, and interaction metrics with our web interface.
- Integration Credentials: OAuth tokens, API keys, and webhook secrets provided by you to connect OWNTHUM AI to third-party tools (such as Slack, Shopify, HubSpot, or Google Cloud). All tokens are stored using AES-256 vault encryption.
How We Collect Data
We collect information through various direct and automated mechanisms:
- Direct Inputs: Information provided by you when completing account registration, submitting enquiry forms (such as strategy call requests sent to help@owntum.com), configuring AI agent workflows, or contacting support.
- API & Webhook Ingestion: Data programmatically transmitted to our endpoints by your connected software systems, databases, CRMs, or server webhooks.
- Automated Platform Monitoring: Telemetry, error logs, and session statistics collected automatically via cookies, web beacons, and server logs as you navigate our dashboard.
- Third-Party Authentication: Profile details obtained when you log in via single-sign-on (SSO) providers such as Google Workspace or Microsoft Azure AD.
Legal Basis for Processing
Under international privacy laws (including GDPR and India DPDPA 2023), OWNTHUM AI processes personal data under the following lawful bases:
- Performance of Contract: Processing necessary to fulfill our service agreement with you, deploy configured AI workflows, bill subscriptions, and deliver technical support.
- Legitimate Interests: Processing necessary for our legitimate business interests, including platform security, fraud prevention, service reliability monitoring, and product performance optimization, provided these interests are not overridden by your fundamental privacy rights.
- Legal Compliance: Processing required to comply with statutory legal obligations, tax filings, law enforcement warrants, or regulatory mandates.
- Explicit Consent: Processing based on your specific consent, such as subscribing to product updates or participating in opt-in beta testing programs. You may withdraw consent at any time.
How We Use Your Information
We utilize the collected information strictly for the following business purposes:
- To operate, maintain, provision, and enhance the OWNTHUM AI autonomous agent platform and dashboard interface.
- To execute user-configured AI workflows, agent reasoning tasks, RAG document retrievals, and automated API actions.
- To process billing transactions, send tax invoices, manage renewals, and handle payment inquiries.
- To communicate critical service updates, security advisories, system status alerts, and technical support responses.
- To monitor infrastructure performance, prevent denial-of-service (DoS) attacks, detect malicious agent behavior, and enforce our Acceptable Use Policy.
- To conduct anonymized, aggregated analytics on platform utilization trends without identifying individual customers or users.
AI Model Training & Data Protection Policy
Given the autonomous and generative nature of our services, we maintain explicit contractual and technical boundaries regarding AI model training:
Strict Anti-Training Guarantee: OWNTHUM AI NEVER uses Customer Data, proprietary uploaded files, internal company knowledge, vector databases, or AI agent outputs to train, retrain, or fine-tune public foundation AI models (such as models operated by OpenAI, Anthropic, or Google) or any shared multi-tenant AI models.
Key commitments regarding AI processing:
- API calls sent to third-party LLM vendors are executed using zero-data-retention enterprise API endpoints where vendors do not store or train on input prompts.
- Vector embeddings created for your documents are hosted in isolated vector stores accessible exclusively by your authorized workspace agents.
- Bespoke fine-tuning is conducted exclusively upon explicit written request for enterprise customers, in which case the resulting model checkpoint is owned solely by that customer and kept isolated.
Autonomous Agent Data Processing
When you deploy autonomous AI agents on OWNTHUM AI, agents operate within defined data execution boundaries:
- Agent Memory & State: Short-term agent conversational context and step-by-step execution histories are stored in encrypted transient databases for the duration of the workflow session.
- External API Execution: When an agent triggers third-party integrations (e.g., sending an email via Gmail, creating a ticket in HubSpot, or charging a payment via Stripe), data passed to those integrations is limited to the minimum necessary parameters required to complete the action.
- Audit Logging: All autonomous agent actions, tool calls, and output generations are recorded in your workspace audit log, providing complete transparency and auditability.
Data Sharing & Third-Party Service Providers
We do not sell, rent, or trade your personal data or Customer Data. We share information only with vetted third-party service providers who assist us in operating our platform, subject to strict confidentiality agreements and Data Processing Addendums (DPAs):
- Cloud & Infrastructure Providers: Google Cloud Platform (GCP) and Amazon Web Services (AWS) for secure cloud hosting, database storage, and computing infrastructure.
- AI Inference Sub-processors: OpenAI, Anthropic, Google DeepMind, and Mistral AI for executing LLM inference calls via enterprise zero-retention API contracts.
- Payment Processors: Stripe and Razorpay for secure credit card and UPI billing processing.
- Transactional Email & Support: Web3Forms, SendGrid, and Postmark for sending customer notification emails and processing strategy enquiries.
- Legal & Regulatory Compliance: We may disclose information if required to do so by applicable law, court order, subpoena, or government regulation, or to protect the safety, rights, or property of OWNTHUM AI or our users.
International Data Transfers
OWNTHUM AI operates globally, with primary cloud data centers located in India, the United States, and the European Union. When data is transferred across national borders, we ensure appropriate safeguards are enforced:
- Transfers from the European Economic Area (EEA) or UK to third countries rely on European Commission Standard Contractual Clauses (SCCs).
- Transfers within India comply with the cross-border data transfer rules under the Digital Personal Data Protection Act (DPDPA 2023).
- Enterprise customers can request dedicated regional data residency (e.g., pinning data strictly within India or EU data centers) via custom enterprise contracts.
Data Retention & Deletion Policy
We retain your data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy:
- Active Accounts: Customer Data, vector indexes, and agent logs are retained for the duration of your active subscription.
- Account Termination: Following account closure, Customer Data is maintained in a soft-delete status for 30 days to facilitate emergency account recovery or data export. On the 31st day, all database records, vector indexes, and file stores are permanently purged using secure cryptographic deletion.
- Billing Records: Tax invoices and transactional records are retained for up to 7 years in compliance with statutory financial auditing regulations.
Data Security & Encryption Standards
OWNTHUM AI employs defense-in-depth security architecture to safeguard your data against unauthorized access, disclosure, alteration, or destruction:
- Encryption in Transit: All data transmitted between your device, our platform, and third-party APIs is encrypted using TLS 1.3 with strong cipher suites.
- Encryption at Rest: Database tables, vector stores, prompt logs, and backups are encrypted using AES-256 bits algorithm key standards.
- Access Controls & Authentication: Strict role-based access control (RBAC), multi-factor authentication (MFA), and zero-trust internal network policies limit employee access to data on a strict needle-to-know basis.
- Security Assessments: Regular vulnerability scanning, automated dependency auditing, and periodic third-party penetration testing.
Your Privacy Rights (DSAR)
Depending on your geographic location, you possess specific data subject rights regarding your personal information:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal information.
- Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your personal data when processing is no longer required.
- Right to Restrict Processing: Request temporary restriction of data processing under certain legal conditions.
- Right to Data Portability: Obtain a structured, machine-readable export of your Customer Data (JSON/CSV).
- Right to Object: Object to data processing conducted on the basis of legitimate interest or direct marketing.
To exercise any of these rights, submit a Data Subject Access Request (DSAR) to our privacy team at privacy@owntum.com or help@owntum.com. We will respond within 30 days.
Cookies & Tracking Technologies
OWNTHUM AI uses essential cookies and performance analytics to ensure website security and optimal user experience:
- Essential Cookies: Required for account login sessions, security token validation, and form processing. These cannot be disabled.
- Functional & Preference Cookies: Remember UI preferences such as theme settings, sidebar states, and language selection.
- Analytics Cookies: Anonymized metrics on website visits and feature utilization to help us improve site navigation. We do not use intrusive third-party cross-site advertising trackers.
You can manage cookie preferences directly via your web browser settings. Disabling essential cookies may impair platform functionality.
Third-Party Links & Integrations
Our platform and documentation may contain links to third-party websites or services (such as documentation links, partner tools, or API services). OWNTHUM AI is not responsible for the privacy practices, content, or security of external third-party sites. We encourage you to read the privacy statements of any third-party service you interact with.
Children's Privacy
OWNTHUM AI is an enterprise business software platform and is strictly intended for individuals who are at least 18 years old. We do not knowingly collect or solicit personal information from children under 18 years of age. If we learn that we have inadvertently collected personal data from a minor, we will immediately delete that information from our database. If you suspect a minor has provided us with personal data, please contact us at help@owntum.com.
California Privacy Rights (CCPA / CPRA)
If you are a resident of California, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights:
- Notice of Collection: Right to know the categories of personal information collected and the business purposes for which it is used.
- Right to Opt-Out of Sale / Sharing: OWNTHUM AI DOES NOT sell your personal information or share it for cross-context behavioral advertising.
- Right to Limit Sensitive Data Usage: Right to limit the use and disclosure of sensitive personal information to that necessary to perform our services.
- Non-Discrimination: Right to equal service and pricing without discrimination when exercising your privacy rights.
To submit a CCPA request, email privacy@owntum.com with "California Privacy Request" in the subject line.
India Digital Personal Data Protection Act (DPDPA 2023)
For data subjects located in India, processing is governed by the Digital Personal Data Protection Act, 2023 (DPDPA):
- Consent Manager Integration: Consent for personal data processing is collected via clear, unambiguous notice. You may withdraw consent at any time.
- Data Fiduciary Responsibilities: OWNTHUM AI acts as a Data Processor for Customer Data and a Data Fiduciary for direct user account data.
- Right to Grievance Redressal: Indian residents have the right to readily accessible grievance redressal mechanisms regarding personal data processing. You may contact our designated Data Protection Officer.
Data Breach Notification Protocol
OWNTHUM AI maintains an incident response plan to promptly identify, mitigate, and report security incidents. In the event of a confirmed security incident or data breach affecting your unencrypted Customer Data:
- We will notify affected enterprise account administrators via email without undue delay, and no later than 72 hours after becoming aware of the breach.
- The notification will detail the nature of the incident, estimated scope of data involved, remedial measures taken, and recommendations for user mitigation.
- We will report the incident to relevant regulatory authorities (such as CERT-In or supervisory authorities under GDPR) as mandated by applicable law.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our technology, operational practices, legal requirements, or regulatory guidance. When changes are made:
- We will update the "Last Updated" and "Effective" dates at the top of this Privacy Policy.
- For material updates affecting how we handle Customer Data or privacy rights, we will provide advance notice at least 14 days prior via email or a prominent banner notification inside our platform dashboard.
We encourage you to review this Privacy Policy periodically to stay informed about how we safeguard your information. Your continued use of the Service following the effective date of an updated Privacy Policy constitutes acceptance of the revised terms.
Contact Our Data Protection Officer (DPO)
If you have any questions, concerns, complaints, or requests regarding this Privacy Policy or our privacy practices, please contact our dedicated Privacy & Data Governance team:
- Data Protection Officer (DPO): DPO & Privacy Office
- Primary Privacy Email: privacy@owntum.com
- General Enquiries: help@owntum.com
- Mailing Address: OWNTHUM AI Legal & Compliance, Mumbai, Maharashtra, India
- Response Window: We aim to acknowledge all privacy enquiries within 1 business day and resolve requests within 30 calendar days.
Have questions about your data privacy?
Our security and privacy engineering team is here to answer any compliance questions. Reach out directly and we will assist you within 1 business day.
Contact Privacy Office →