Privacy Policy
Last updated: July 2026
1.0 Overview
Wemacx ("we", "us", or "the Company") operates an enterprise contact centre platform ("the Service"). This Privacy Policy explains how we collect, process, store, and protect information in connection with our platform. It applies to enterprise clients, their agents and supervisors, and end consumers who interact with contact centres powered by Wemacx.
2.0 Data Collection
We collect information necessary to provide the Service, including: (a) Identity Data — names, email addresses, phone numbers, and biometric data where applicable; (b) Interaction Data — call recordings, chat transcripts, email content, and session metadata; (c) Telemetry Data — platform usage metrics, performance logs, and system diagnostics; (d) Contract Data — billing information, service agreements, and support records. We do not sell personal data to third parties under any circumstances.
3.0 Interaction Fabric Privacy
All customer interaction data processed through the Wemacx platform is governed by our Data Processing Agreement (DPA) with the enterprise client. Wemacx acts as a Data Processor on behalf of the enterprise (the Data Controller). Interaction recordings, transcripts, and analytics remain the property of the enterprise client and are stored according to the retention policies configured by them.
4.0 Data Sovereignty
Wemacx is designed for sovereign deployment. Enterprise clients may deploy the platform entirely within their own infrastructure (On-Premise or Private Cloud), ensuring no interaction data is transmitted to Wemacx or any third-party service. For managed SaaS deployments, data is stored within the geographic region selected by the enterprise client, with encryption at rest (AES-256) and in transit (TLS 1.3).
5.0 GDPR & CCPA Compliance
For clients operating in the European Economic Area or California: (a) We support all data subject rights including access, rectification, erasure, and portability; (b) Our AI systems are designed for GDPR Article 22 compliance — no solely automated decisions are made without human oversight where required; (c) We maintain appropriate Standard Contractual Clauses for international data transfers; (d) A Data Protection Officer (DPO) is available at privacy@wemacx.com.
6.0 SOC2 & Security
Wemacx maintains SOC2 Type II certification, ISO 27001 compliance, and PCI DSS Level 1 certification for payment interaction handling. Security controls include: role-based access control, multi-factor authentication, penetration testing (quarterly), vulnerability management, and 24/7 security monitoring. Full security documentation is available under NDA for enterprise clients.
7.0 Contact Information
For privacy enquiries, data subject requests, or security concerns, contact: sales@wemacx.com · +91 80 3730 7830. Registered address and DPO contact available upon request.