Last updated 6 October 2026
Privacy policy
What we collect, why we collect it, who else handles it, and exactly how long we keep it. If anything here is unclear, write to support@resono.co.in and a person will answer.
1Who we are
Resono is provided by Sameer, sole proprietor, trading as Resono, Rohini, Sector 4, Delhi, India. For the personal data this policy describes as ours, we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023.
2Whom this covers
- people who visit this website or ask us for access;
- people who use Resono at the businesses we serve;
- people who receive a call from, or make a call to, one of those businesses through Resono. For you, the business is the Data Fiduciary and we process your data on its behalf. Your first contact for questions about the call is the business that called you. If you cannot reach them, write to us and we will help.
3What we collect
- When you ask for access: your name, work email, company, phone number, and what you tell us you would use Resono for.
- When you have an account: your name, email address, a securely hashed password, your role, and a record of sign-ins with the IP address and device they came from.
- When you accept our terms and this policy: which version you accepted, the exact words you agreed to, when, and the IP address and browser you used. You are asked when you create your account, and again if either document changes.
- When a call is made through Resono: the audio recording of the whole call, a written transcript, and a log of how the agent handled it, including the instructions and context given to the AI model. Every call is recorded. For a campaign, the people in the list the business gave, from a file it uploaded or a Google Sheet it chose.
- When a business connects a Google account: only what it chooses to let Resono reach. Clause 12 says exactly what that is.
- What the business gives its agent: its instructions and documents, which can contain personal data the business chose to include.
We do not buy personal data, and we do not collect more than the service needs.
4Why we use it
- to provide Resono: to place and answer calls, and to keep the record of each one;
- to reply to access requests, and to send you emails about your account, such as password-reset codes and invitations;
- to keep the service and its users secure, and to investigate misuse;
- to work out what each call cost, and to bill for it;
- to keep a record of what you agreed to and when, so that either of us can show it later;
- to meet our legal obligations.
We use it with your consent, or for the uses the law allows without separate consent, such as providing a service you asked for. We do not sell personal data, we do not use it for advertising, and we do not use it to train AI models.
5Cookies
We use one cookie, and only to keep you signed in to Resono. We do not use advertising or tracking cookies. If that changes, this page will say so first.
6Who else handles it
A phone call through Resono passes through these companies, each of which handles only what it needs to do its part:
| Company | What it does | Where |
|---|---|---|
| Amazon Web Services | Hosting, storage of recordings and data, and our email | India (Mumbai) |
| LiveKit | Carrying the live audio of a call | May be outside India |
| Vobiz | Placing and receiving phone calls on the telephone network | India |
| Deepgram | Turning speech into text, and some voices | May be outside India |
| ElevenLabs | Voices: turning the agent's text into speech | May be outside India |
| Rumik AI | Voices: turning the agent's text into speech | May be outside India |
| Smallest AI | Voices: turning the agent's text into speech | India or the USA |
| The AI model that writes the agent's replies, and some voices | May be outside India |
We will disclose data to authorities only when the law requires it. If the business that runs Resono were ever sold or merged, the data would pass on under this policy.
7Where it is stored
Our servers, databases, recordings and backups are in Mumbai, India. Some of the providers above process parts of a call outside India while it is happening, as Indian law permits.
8How long we keep it
Each kind of data is deleted automatically when its period ends. A business can ask us to delete its data sooner.
| What | Kept for |
|---|---|
| Call recordings | 90 days |
| Recordings of test calls made in the console | 14 days |
| Call transcripts | 90 days |
| Call logs, which include the conversation as the AI model saw it, and the instructions and context it was given | 1 year: 90 days in our database, then in a compressed archive |
| A campaign's list as the business gave it, from a file or a Google Sheet, and the details of anyone it never called | Until the campaign ends |
| For each person a campaign called: the details that call used, and its result | 1 year after the campaign ends |
| A connected Google account's access, stored encrypted | Until the business disconnects it |
| Access requests from this website | 90 days |
| Sign-in records (email address, IP address, device) | 1 year |
| Server access logs (IP address, time, page requested, browser) | 180 days, as the law requires |
| The record of your acceptance of the terms and this policy (email address, the words you agreed to, the time, IP address, browser) | While your account exists, and 3 years after it closes |
| Database backups | 30 days |
Account details are kept while the account is open. When a recording is deleted, we keep a note that it existed and when it was removed, without the audio.
If you need to keep a copy of your recordings or transcripts, write to support@resono.co.in at least 7 days before they are due to be deleted, and we will send you one. We do not extend the period itself: once data is deleted, it cannot be recovered. If a law that applies to your business requires you to keep call records for longer, keeping those copies is yours to do.
The periods above are the longest we keep each kind of data, with one exception: where the law requires us to keep something longer, such as under an order of a court or an authority, or to establish or defend a legal claim, we keep only what is required, for only as long as it is required, and then delete it.
9How we protect it
- every connection to Resono is encrypted;
- passwords are stored only as secure hashes, and stored credentials are encrypted;
- each business’s data is kept apart from every other’s by the database itself, not only by the application;
- only the few people who run the service can reach production systems.
No system is perfectly secure. If a breach affects your data, we will tell you and the authorities as the law requires.
10Your rights
Under the Digital Personal Data Protection Act, 2023 you can ask us to:
- tell you what personal data of yours we hold, and who we have shared it with;
- correct, complete or update it;
- erase it, where we no longer need it or you withdraw consent;
- hear and resolve a grievance about how we handled it;
- act through a person you nominate, if you die or cannot act yourself.
You can withdraw consent at any time, as easily as you gave it. Write to support@resono.co.in; we will reply within 30 days. Withdrawing consent to our use of your account details means we close your account, except for what the law requires us to keep, such as the record of what you accepted. If you are not satisfied with our answer, you can complain to the Data Protection Board of India.
11Children
Resono is for businesses and is not meant for anyone under 18. Businesses may not use it to call children. If you believe we hold a child’s data, write to us and we will delete it.
12Google accounts a business connects
A business can connect its own Google account to Resono. We reach only what it switches on, for the agents it chooses:
- Google Sheets: only the spreadsheets the business picks. We read the people to call from them, and write each call’s result back into columns of our own. We cannot see any other file in the account.
- Google Calendar: when the calendar is busy, not what the events are, so that an agent can offer a free time; and the events its agents book, which we add to the business’s own calendar with invitations sent from its own address.
- the account’s email address, to show which account is connected.
The access Google gives us is stored encrypted and used only by our servers. It never reaches a browser, and we never share it.
Limited Use. Resono’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use that information only to provide the features the business switched on; we do not sell it, use it for advertising, or use it to train AI models; and no person at Resono reads it, except with the business’s permission, to investigate a security problem or misuse, or where the law requires.
Google appears in clause 6 for its AI models; a connected account is different. It is the business’s own, and we reach it only on the business’s instruction. A business can disconnect at any time from the Connectors page in Resono, which ends our access at Google and deletes the stored access; it can also remove Resono under third-party access in its Google Account’s security settings. What a call used from a spreadsheet stays with that call, for the periods in clause 8.
13Changes to this policy
If we change this policy, we will update the date at the top of this page. If the change is material, we will email account holders before it takes effect, and ask you to accept the new version before you continue to use Resono.
14Grievance officer
Sameer, founder, Rohini, Sector 4, Delhi, India. Email support@resono.co.in. See also our terms of service.