Privacy Policy

Privacy Policy

Last updated: July 29, 2026

This Privacy Policy explains how Enquiry Desk collects, uses, shares, stores, protects, and deletes personal data through its website, public demo, communications, and authorised service workflows. It is intended to provide clear notice of the data collected, the purposes of processing, and the choices available to individuals.

01

Who operates Enquiry Desk

Enquiry Desk is a service and brand operated by Archivist Vault, which is legally operated by Mira Ghosh, a SOLE PROPRIETORSHIP, with its business or correspondence address at BAGDOGRA, DARJEELING, WB ("Enquiry Desk", "Archivist Vault", "we", "us", or "our").


This Privacy Policy applies to 'enquirydesk.tech', its demo forms, website chatbot, demo WhatsApp workflows where enabled, email communications, and related service enquiries. It does not automatically govern a client's own website, WhatsApp account, CRM, or production deployment; those deployments are also subject to the client's privacy notice and the applicable service agreement or data processing terms.

02

Our role in processing personal data

For this website, demo requests, sales enquiries, service administration, security, and our own business records, Enquiry Desk generally determines why and how personal data is processed and acts as the relevant data fiduciary or controller.


For a client production deployment, the client generally decides the business purpose, approved content, lead fields, follow-up rules, retention requirements, and persons who may access the records. In that context, Enquiry Desk may process data on the client's documented instructions as a data processor or service provider. Enquiry Desk may remain an independent data fiduciary for limited purposes such as account administration, billing, legal compliance, fraud prevention, and security.

03

Personal data we may collect

Information you provide directly may include your name, business name, job role, phone number, email address, industry, preferred communication channel, package or service interest, enquiry details, callback preference, and any information you voluntarily include in a form, chat, WhatsApp message, email, or call.


Conversation and workflow data may include chat text, selected prompts, conversation summaries, source channel, timestamps, lead status, routing status, intent category, human-handoff status, CRM record identifiers, and failed-event or troubleshooting information.


Technical data may include IP address or approximate network location, browser and device type, operating system, referral source, page activity, cookie identifiers, session identifiers, and security or error logs, depending on the website and analytics configuration.


For client deployments, the fields collected are determined by the client and the approved implementation scope. We instruct users not to submit passwords, OTPs, payment-card details, bank credentials, government identification numbers, medical records, diagnosis reports, legal case files, trade secrets, or other highly sensitive information unless a separately documented and lawful deployment expressly requires it.

04

Why we use personal data

We process personal data only for specified and legitimate purposes, including: responding to an enquiry; preparing and presenting a relevant demo; arranging a callback or meeting; understanding business requirements; creating proposals; configuring, testing, supporting, and troubleshooting authorised workflows; routing enquiries for human follow-up; preventing duplicate or fraudulent records; maintaining CRM and operational records; securing the website and connected systems; complying with legal obligations; resolving disputes; and improving service reliability.


We use contact details for promotional messages only where you have requested them, consented to them, or where another lawful basis permits the communication. Service, security, transactional, and requested follow-up messages are treated separately from optional marketing.

05

Why we use personal data

We process personal data only for specified and legitimate purposes, including: responding to an enquiry; preparing and presenting a relevant demo; arranging a callback or meeting; understanding business requirements; creating proposals; configuring, testing, supporting, and troubleshooting authorised workflows; routing enquiries for human follow-up; preventing duplicate or fraudulent records; maintaining CRM and operational records; securing the website and connected systems; complying with legal obligations; resolving disputes; and improving service reliability.


We use contact details for promotional messages only where you have requested them, consented to them, or where another lawful basis permits the communication. Service, security, transactional, and requested follow-up messages are treated separately from optional marketing.

06

Consent and required information

Where processing depends on consent, the consent request should identify the personal data requested and the purpose for which it will be used. You may refuse optional information or optional marketing consent. If you do not provide a working contact method or information necessary to understand your request, we may be unable to respond or prepare the requested demo.


You may withdraw consent for future consent-based processing by contacting us or using an available unsubscribe or opt-out method. Withdrawal does not affect processing already completed lawfully, and we may retain limited records where required for legal, security, accounting, or dispute-resolution purposes.

07

AI and automated processing

The website assistant uses automated conversation and AI technologies to understand questions, retrieve approved information, generate or select a response, collect enquiry details, and prepare a summary for human follow-up. Messages may therefore be processed by configured chatbot, AI, automation, and infrastructure providers.


The public demo is not intended to make legal, medical, financial, employment, credit, insurance, admission, scholarship, refund, eligibility, or other decisions that produce legal or similarly significant effects. Important or sensitive decisions must be reviewed and made by an authorised human. AI-generated or automated outputs may be incomplete, inaccurate, delayed, or affected by outdated source information, so users should verify important information with the relevant business.

08

Service providers and connected platforms

We use service providers to operate the website and workflows. Depending on the environment and client deployment, these may include Framer for website hosting and forms; Voiceflow for chatbot and conversation orchestration; FlowBridge and Meta/WhatsApp services for WhatsApp message transport; Make for webhook and workflow automation; Zoho Bigin for CRM; Google Workspace or Google Sheets for authorised reporting, quality assurance, or mirror records; and email, notification, analytics, hosting, security, or support providers.


These providers process data only for the functions for which they are configured, subject to our account settings, contracts, their service terms, and applicable law. The provider list may change as systems are replaced or improved. Material changes that affect privacy practices will be reflected in this Policy or a separate service-provider notice.

09

When personal data may be shared

We do not sell personal data. We may share personal data with: authorised personnel and contractors who need it to perform their duties; the client business responsible for a requested follow-up; configured service providers; professional advisers such as accountants, auditors, insurers, or lawyers; and public authorities or other persons where disclosure is required or permitted by law, necessary to protect rights or security, or needed to investigate fraud or misuse.


If a business reorganisation, merger, acquisition, financing, or transfer occurs, relevant records may be transferred subject to appropriate confidentiality and legal safeguards.

10

International processing

Some service providers or their subprocessors may store or process personal data outside India. Where international processing occurs, we use the service in accordance with applicable law, contractual protections, provider security arrangements, and any restrictions or directions issued by competent authorities. A client contract may impose additional location or transfer requirements.

11

Retention and deletion

We retain personal data only for as long as reasonably necessary for the stated purpose, contractual obligations, security, legal compliance, or dispute resolution. Unless a different period is required by law or a client agreement, our intended retention schedule is:


  • Website and demo enquiries that do not become an active commercial relationship: up to 12 months after the last substantive interaction.

  • Public demo chat transcripts not linked to an active lead: normally up to 90 days.

  • Lead, proposal, client, implementation, and support records: for the active relationship and a reasonable period afterwards for contract, support, tax, accounting, and dispute purposes.

  • Technical, access, security, and failed-event logs: normally up to 12 months, or longer where required by law, security investigation, or contract.

  • Client production data: according to the client's documented instructions and the applicable service agreement; deletion or return is handled at termination, subject to backups and legal retention.

  • Backups: retained for limited rolling periods and deleted or overwritten in the ordinary backup cycle.


When data is no longer required, we delete, anonymise, aggregate, or restrict it. A deletion request may be refused or partially fulfilled where retention is required by law, necessary for a legal claim, needed to prevent fraud, or technically retained in a protected backup until the normal deletion cycle.

12

Security

We use reasonable technical and organisational measures appropriate to the nature of the service and the data, which may include access controls, restricted administrator access, encrypted transmission, credential protection, logging, monitoring, backups, vendor controls, testing, and incident-response procedures.


No internet, messaging, chatbot, cloud, CRM, or automation system is completely secure. Do not use the website or demo assistant to transmit secrets, credentials, highly confidential records, or emergency information.

13

Cookies and analytics

The website may use essential cookies or similar technologies required for site operation, security, form submission, session continuity, and chatbot functionality. Optional analytics or campaign technologies should be activated only in accordance with the available consent and preference controls.


You can use browser settings to block or delete cookies, but some website or chatbot functions may not work correctly. Where a cookie preference tool is displayed, your selections will apply to the categories described in that tool.

14

Children and minors

This website and public demo are intended for business enquiries and are not directed to persons under 18. A person under 18 should not submit personal data directly. A parent, lawful guardian, or an authorised adult may make an enquiry on the minor's behalf.


Because some client deployments may serve coaching or education businesses, any production workflow that processes a minor's personal data must be separately designed with the client, limited to necessary information, and supported by the notices, consent, age or guardian checks, and safeguards required by applicable law. Contact us if you believe a minor's data has been submitted improperly.

15

Your rights and choices

Subject to applicable law and verification of your identity, you may request: information about personal data we process about you; access to or a summary of the data; correction or completion of inaccurate data; erasure of data that is no longer required; withdrawal of consent for future processing; cessation of optional marketing; grievance redressal; and, where applicable, nomination of another individual to exercise rights in the event of death or incapacity.


To make a request, email speak@enquirydesk.tech with the subject line “Privacy Request” and state the email address or phone number used, the nature of the request, and enough information for us to locate the record. We may request proportionate verification and will not ask for passwords, OTPs, or unnecessary identity documents.

16

Privacy and grievance process

Email: speak@enquirydesk.tech.


We will acknowledge a privacy grievance or rights request as soon as reasonably practicable and aim to provide a substantive response within 30 days. Complex or legally restricted requests may require additional time, in which case we will communicate the reason and expected next step. You may also have the right to approach the competent data-protection or other regulatory authority after using the available grievance process, where required by applicable law.

17

Personal data breaches

If we become aware of a personal data breach affecting information for which we are responsible, we will investigate, contain, document, and remediate the incident. We will notify affected individuals, clients, service providers, the Data Protection Board of India, CERT-In, or another authority where and when notification is required by applicable law or contract.


Any notice may describe the nature of the incident, likely consequences, mitigation steps, and contact details for questions.

18

Third-party websites and client channels

The website may link to third-party websites, calendars, messaging services, or client channels. Their privacy practices are governed by their own notices. When you communicate with a client through a client deployment, that client is responsible for its own notices, lawful processing, and follow-up practices, except to the extent Enquiry Desk has expressly accepted responsibility in writing.

19

Changes to this Policy

We may update this Policy to reflect legal, technical, operational, or service changes. The revised version will show a new “Last updated” date. If a change materially alters the purpose of consent-based processing, we will provide a new or supplemental notice and obtain fresh consent where required; merely continuing to browse the website will not be treated as consent to a materially different processing purpose.

Privacy controls

Your cookie choices

We use necessary cookies and similar technologies to keep this website secure, support forms and session continuity, and operate the live assistant. With your permission, we may also use analytics to understand website usage and improve the experience.