Legal

Privacy Policy

How we handle personal data across intellowork.com, the IntelloWork assistant, and the IntelloWork application — and how to tell us what you want done with yours.

Last updated

1. Who we are

IntelloWork is a product of Exuverse Private Limited (“Exuverse”, “we”, “us”). IntelloWork turns the content an organisation already has — documents, websites, indexes and APIs — into cited answers delivered through a web chat widget and messaging channels.

This policy explains what personal data we handle, why, and what you can ask us to do about it. It covers intellowork.com, the IntelloWork assistant on that site, and the IntelloWork admin application.

2. The two roles we play

Our obligations depend on whose data is involved, so we keep the two cases separate throughout this policy:

  • As a Data Fiduciary (controller). For visitors to our website, people who talk to our assistant, and holders of an IntelloWork account, we decide why and how the data is processed. Sections 3–9 apply.
  • As a Data Processor. When a customer indexes their own content into IntelloWork and their end users converse with their assistant, that customer decides why and how the data is used. We process it on their documented instructions. Section 10 applies, and the customer’s own privacy notice governs the relationship with their users.

If you reached a chat assistant on a company’s own website and want to know how your conversation is used, contact that company first — they are the responsible party. We will support them in answering you.

3. What we collect

Information you give us. When you request a demo, ask to be contacted, or sign up, we collect the details you submit — typically your name, work email address, phone number and company name, together with what you told us you are interested in. When you create an account we also hold your workspace and role.

Conversations with our assistant. Messages you send to the IntelloWork assistant are stored so the conversation has context, so we can improve the product, and so we can respond if you asked us to. Please do not paste passwords, payment card numbers, government identifiers or health information into the chat — it is not the right channel for them.

Technical data. We record IP address, browser and device information, pages viewed, and timestamps. We use this for security, abuse prevention, debugging and aggregate analytics. We do not run IP addresses through third-party geolocation services to infer your physical location.

Local storage, not advertising cookies. The chat widget stores a conversation identifier and your recent messages in your browser’s local storage so your conversation survives a page refresh. The admin application stores a session token the same way. We do not use third-party advertising or cross-site tracking cookies. You can clear this at any time through your browser’s site-data controls, or by starting a new chat.

4. Why we use it, and on what basis

  • To respond to you — answering a demo request or enquiry you submitted. Basis: the consent you gave when you submitted the form, and our legitimate interest in replying.
  • To provide the service — authenticating you, showing your workspace, keeping the assistant working. Basis: performance of our contract with you or your employer.
  • To keep it safe and working — security monitoring, rate limiting, fault diagnosis, audit logs. Basis: legitimate interest and legal obligation.
  • To improve the product — aggregate usage patterns and quality review. Basis: legitimate interest.
  • To send you relevant updates — only where you asked, or where permitted for existing business contacts. You can opt out at any time.

We do not sell personal data, and we do not share it with advertising networks.

5. AI processing

Answers are generated by large language models. To produce an answer, the relevant excerpt of indexed content and the conversation so far are sent to a model provider over an encrypted connection and processed under that provider’s enterprise API terms. Depending on configuration, the provider may be Amazon Bedrock, Anthropic, OpenAI, Google, or a model run on infrastructure the customer controls.

We do not use your content or conversations to train our own models, and we select providers whose API terms exclude API-submitted content from training their models by default. Customers who need a specific provider, region, or a signed data processing agreement can configure their own provider keys.

Generated answers can be wrong. They are grounded in the indexed source material and shown with citations so they can be checked, but they are not professional advice and should not be relied on as the sole basis for a decision.

6. Who we share it with

We share personal data only with service providers who need it to run IntelloWork, each bound by contract to protect it and use it only for the service they provide to us:

  • Cloud hosting and databases — Microsoft Azure and Amazon Web Services.
  • AI model providers — as described in section 5.
  • Communication and scheduling — email delivery, and Calendly when you book a meeting with us.
  • Messaging channels — where a customer enables them: WhatsApp (Meta), Slack, Microsoft Teams.
  • Our own CRM — leads submitted through the assistant are stored in a lead management system operated by Exuverse.

We may also disclose data where legally required, or to establish or defend legal claims. If Exuverse is involved in a merger or acquisition, data may transfer to the successor entity under the terms of this policy.

7. Where your data is processed

Exuverse Private Limited is incorporated in India. Depending on the deployment, IntelloWork infrastructure runs in Indian and United States cloud regions, which means personal data may be transferred outside your country of residence.

Where such a transfer happens, we rely on contractual safeguards with our providers. Customers with data residency requirements should raise them before onboarding — the hosting region is a deployment decision and can be agreed in the contract rather than left to chance.

8. How long we keep it

We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires:

  • Enquiries and demo requests — for as long as we are in contact with you about it, and afterwards for our legitimate business records unless you ask us to erase it.
  • Account data — for the life of the account, and for a limited period afterwards to meet legal, tax and audit obligations.
  • Conversations and indexed content held for a customer — per that customer’s configured retention, and deleted on their instruction or at the end of their contract.
  • Security and audit logs — for a limited period appropriate to their security purpose.

You can ask us to erase your data sooner — see section 9.

9. Your rights

Subject to the law that applies to you — including India’s Digital Personal Data Protection Act, 2023, and the GDPR where relevant — you can ask us to:

  • confirm what personal data of yours we hold, and give you a copy;
  • correct data that is inaccurate, incomplete or out of date;
  • erase your personal data where we have no continuing basis to keep it;
  • withdraw a consent you previously gave, without affecting what we did beforehand;
  • nominate someone to exercise your rights if you die or become incapacitated; and
  • complain to us, and then to your data protection authority if we do not resolve it.

Write to privacy@intellowork.com. We will verify your identity before acting, and respond within the period the applicable law allows. There is no charge for a reasonable request.

If your data was given to a company using IntelloWork as their assistant, send your request to that company — see section 2.

10. Customer content we process on instruction

Where a customer uses IntelloWork to index their own material and serve their own users, the customer is the Data Fiduciary and we act on their documented instructions. In that role we:

  • keep each workspace’s content logically isolated from every other workspace;
  • carry the source system’s access permissions into the search index, so a reader cannot retrieve content their role would not let them open at source;
  • encrypt data in transit and at rest;
  • maintain an audit log of configuration changes and access;
  • act on the customer’s instruction to export, correct or delete their data; and
  • enter into a data processing agreement on request.

11. Security

We protect personal data with encryption in transit and at rest, role-based access control, tenant isolation, audit logging, and change management on production systems. Access to production data is limited to personnel who need it.

No system is perfectly secure, and we will not pretend otherwise. If a personal data breach occurs that affects you, we will notify you and the relevant authority as the applicable law requires.

12. Children

IntelloWork is a business product and is not directed at children. We do not knowingly collect personal data of a child. If you believe a child has given us personal data, write to privacy@intellowork.com and we will delete it.

13. Changes to this policy

We update this policy when our practices change. The date at the top always reflects the current version. If a change materially affects your rights, we will give notice through the product or by email rather than relying on you to re-read this page.

14. Contact us

For any privacy question, or to exercise a right under section 9:

Exuverse Private Limited
Privacy enquiries: privacy@intellowork.com
General enquiries: hello@intellowork.com

Under India’s Digital Personal Data Protection Act, 2023, you may address a grievance to our Grievance Officer at the same address. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.