Axonwise Private Limited
Privacy Policy

Updated on: July 29, 2026


This Privacy Policy (“Privacy Policy” or “Policy”) applies to your use of our website https://www.sarvam.ai/ and https://platform.sarvam.ai/ (collectively, “Platform”) and products and services offered through the Platform (hereinafter collectively referred to as “Services”) which are owned, controlled and operated by Axonwise Private Limited, a company incorporated under the laws of India, and having its registered office at Sarvam AI, 2nd Floor, 732 Urban Vault, Indiranagar, Bangalore-560038, India (“Company” or “Sarvam”). This Privacy Policy does not apply to content that we process on behalf of customers of our business offerings, such as our enterprise accounts. Our use of that data is governed by our customer agreements covering access to, and use of, those offerings.

For the purposes of this Privacy Policy, “we”, “our” and “us” shall mean the Company and “you” and “your”, shall mean a user of the Services, whether registered or not (“User”).

This Privacy Policy sets out what data we collect and how and why we use it, when you access the Services. You are advised to read the Privacy Policy carefully before accessing any Services. To access any Services, you are required to accept the terms of this Privacy Policy. By accepting this Privacy Policy, you confirm that you have read, understood and agree to be bound by the same. We may update this Privacy Policy from time to time. Material changes will be notified at least 5 days in advance via email or prominent website notice. Continued use after the effective date constitutes acceptance. You may withdraw consent at any time if you disagree with changes. To this end, we request you to go through this Policy every time you access or use the Services.

Data Fiduciary Information

Axonwise Private Limited (doing business as Sarvam AI) is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDPA”) and is responsible for determining the purposes and means of processing your personal data.

  • Our Commitments:
    • Process personal data only with your informed, specific, and freely given consent or under legitimate uses specified in DPDPA
    • Implement appropriate technical and organizational measures to protect your data
    • Maintain transparency about our data practices
    • Facilitate exercise of your rights as Data Principal under DPDPA
  • Compliance Certifications:
    • ISO 27001:2022 (Information Security Management)
    • SOC 2 Type II (Security, Availability, Confidentiality)
    • Significant Data Fiduciary as notified under DPDPA Section 10

Registered Office:

Sarvam AI, 2nd Floor, 732 Urban Vault, Indiranagar

Bangalore 560038, Karnataka, India

Email: [email protected]

Collection & Processing of Personal Data & Legal Bases

  • We collect personal data of the User, as detailed further in this clause, and as expressly set forth in this Privacy Policy. While some User data has to be mandatorily provided, for your use of the Services, others are optional; Sarvam will let the User know all of the foregoing categories of data. Additional data may be gathered during subsequent or continued use of our Services.
  • In order to access/use the Services, upon expressly consenting, you may be required, from time to time, at the request of Sarvam, to provide certain personal data, such as your first and last names, location (unless disabled by accessing the Device settings, in which case we may not be able offer/effectively offer our Services), email address, residential and/or work place address, mobile number, postal code, etc. The foregoing is an inclusive but not an exhaustive list, and such other personal data as may be required from time to time, may be collected and appropriately used after obtaining express consent of the User.
  • When you use our Product, we collect the information provided by you which includes your inputs, file uploads, outputs generated by the Product.
  • We may also automatically receive, collect, store and process certain anonymous data sourced by your usage of the Services, such as standard usage logs, through the web server, cookies, standard web log data, traffic to and from our Services, tracking within the same, and any other available data from:
    • an IP address, assigned to the Device used by the User;
    • type of browser used by the User;
    • the domain server through which the User accesses the Services and the functions and features therein;
    • queries, comments, or feedback as submitted by the User, including any correspondence you have made with us; and
    • the type/model/make of device used by the User (“Device”).
  • In order to enhance our ability to provide a valuable experience to the Users while accessing/using the Services, we may seek and receive one time or continuous access to: (i) automatically receive, collect and analyze your location data which may be accessed through a variety of methods including, inter alia, GPS, Internet Protocol address, and cell tower/Device location; (ii) collect data pertaining to your Device and your usage thereof, including, inter alia, data about your Device, and data about your use of features or functions on your Device; (iii) camera access to scan/capture/upload documents and/or photographs; (iv) microphone permissions; (v) any other files and media. A user may, at any time, revoke access to the aforesaid data through the Device settings.
  • Sources of personal data: We may collect the personal data through various sources, such as those:
    • Submitted by yourself, through our Services or by contacting/emailing our official contact
    • Shared with or by any of our employees and affiliates;
    • Our sales or marketing representatives (including third party representatives), vendors, suppliers and service provided
    • Sourced from public websites and social media, including but not limited to your publicly accessible profiles, etc.; and
    • Sourced via cookies and similar tracking technologies as deployed on our Services
  • It is clarified we do not collect or store any contact (or related) data that may be present on a Device.
  • Sensitive Personal Data: We do NOT knowingly collect sensitive personal data as defined under DPDPA (financial data, health data, sexual orientation, biometric data, genetic data, transgender status, intersex status, caste, religious belief) nor do our Services need any sensitive personal data except:

- Voice biometric data for Content Studio (with explicit consent and additional safeguards);

- Financial transaction data (processed by certified payment gateways, not stored by us).

If you inadvertently provide sensitive personal data through Your Content or inputs, you consent to its processing solely for the purpose of delivering the requested Service.

  • It is further clarified that we do not sell your data to any third party under any circumstance as the purpose of collecting data under this Privacy Policy is to deliver Services / enhance a quality User experience or improve our Services in a manner we deem fit and necessary.

Grounds for Processing Personal Data

We process your personal data under the following grounds as specified in DPDPA 2023:

  • Consent: For most processing activities, we rely on your free, specific, informed, unconditional, and unambiguous consent obtained through clear affirmative action. You may withdraw consent at any time through your account settings or by contacting our Data Protection Officer.
  • Legitimate Use: We may process personal data without consent for:
    • Performance of contract: To provide Services you have requested or subscribed to.
    • Compliance with law: To comply with legal obligations under Indian or applicable foreign law.
    • Medical emergency: To provide medical treatment or health services during emergencies.
    • Employment/safeguards: For recruitment, employment, or similar purposes where appropriate safeguards exist.
    • Reasonable purposes: As may be prescribed by the Central Government.
  • Purpose Limitation: We will process personal data only for the specific purposes for which consent was obtained or as permitted under legitimate uses. We will not use your data for secondary purposes without obtaining fresh consent.
Type of Data Purpose Grounds for Processing
Identifiers for an Indus account, or to receive information on our Services upon sign-up:
name,
email address,
phone number,
payment/ billing information
Account creation, administration and billing purposes Consent
Certain billing/tax records may also rest on the legitimate use of compliance with law
Account & subscription data:
Account identifiers
API subscription key/credentials
To provide, maintain and facilitate any products and services offered to you with respect to your Indus account, which are governed by our Terms of Service Consent
Service input content:
text prompts,
audio/voice recordings,
documents and images submitted to the APIs (text-to-speech, speech-to-text, translation, transliteration, chat completion, document digitization), and
resulting outputs
To process your requests and generate outputs (transcription, synthesized speech, translations, digitized documents); to operate and deliver the Services you invoke Consent
Feedback on your use of our Services: We appreciate feedback, including ideas and suggestions for improvement or rating an Output in response to an Input (“Feedback”). If you rate an Output in response to an Input,for example, by using the thumbs up/thumbs down icon,we may store the entire related conversation as part of your Feedback. Improving our Services Consent
Voice / biometric samples for consent-based voice cloning:
The 30-60 second speech sample and derived voice model
To create a custom cloned voice at your request, if the User chooses to use the Content Agents/ voice cloning functionality of Indus Consent
Model training / service improvement:
inputs and outputs, where applicable
To train and improve Sarvam AI models and conduct research Consent
Usage, technical & log data:
IP address,
device/browser information,
API call logs,
usage metrics,
cookies
To monitor, secure and maintain the platform, prevent abuse and fraud, enforce rate limits, troubleshoot and improve reliability Legitimate uses: security, prevention of fraud, and compliance with law; consent for non-essential cookies
Communication & support data:
name,
contact details, and
contents of messages you send us
To respond to enquiries and provide support, and to investigate and resolve disputes Consent
Legitimate use of responding to the data principal

Method and Manner of Use of Data

  • We may use your personal data for the following purposes:
    • to provide a meaningful user experience, better usability, troubleshooting and maintenance of our Services;
    • to develop and improve our existing Services and such other aspects we deem necessary;
    • to develop new products, user experience, services, etc.;
    • for compliance and undertaking of the purchase orders/contract for our products, items or services;
    • to understand when and which parts of our Services are most visited and its frequency;
    • to identify a User;
    • to communicate with a User, including contacting and responding to queries or requests and such other communication as may be required;
    • to communicate special offers and general information about our products, services and events which we may offer that may be similar to those that you have already purchased or enquired about unless the User has opted not to receive such communication/data;
    • to offer tailored content based on Users’ preferences;
    • to enhance and optimize our company operations, systems, security and processes;
    • to enable marketing and sales related communications and related purposes;
    • to protect and defend the rights or property of Sarvam;
    • to protect the personal safety of Users of our Services and/or the general public;
    • to protect against or defend any legal liability; and
    • in order to be compliant with applicable law or to honour back-to-back obligations we may have with any other third party in relation to our Services.
  • You acknowledge that if we determine that any data you have provided or uploaded violates the terms of this Privacy Policy, we have the right, in our absolute discretion, to delete or destroy such data without incurring any liability to you.
  • . By providing such data, you automatically agree, or promise that the owner of such data has expressly agreed to allow or license, as the case may be, us to use the data in the manner set out in this Privacy Policy. We may, to the extent permitted by law, also use, license, reproduce, distribute disclose, and aggregate, non-personally identifiable data that is derived through your use of our Services and you hereby provide consent for the same.
  • For the avoidance of any doubt, it is hereby clarified that any User data collected from you and eventually stored by us will be used only for the purposes enumerated above.

Sharing of Data

  • We will not use User data for any purpose other than in connection with Services. You understand that we may share the User data with required third parties in connection with our Services as may be required and you explicitly agree to such User data being shared.
  • We may use third party vendors, service providers, including logistic service providers payment gateway service providers, maintenance service providers, etc. to help us better provide our Services to you (for payments and troubleshooting of our Services), to whom we may have to disclose your personal data. Where we use third-party tools, these third parties will have access to some of your personal data, including analytics tools. As may be necessary for managing partnerships, we may also provide deidentified data to our partners relating to the usage of products and services provided by our partners.
  • When accessing/using the Services, in the event you are directed to a third party website or application, and if you choose to access them (or avail what such websites have to offer), we will not be responsible for any such third-party websites or applications. Please note that in case you share any data with such third parties, you will be bound their respective privacy policies and/or terms of use/service. Sarvam will not disclose any of the User's personally identifiable data to third parties, save when required under applicable law.
  • If all or some of the business, stock or assets of Sarvam are acquired or merged with another business entity, we may share all or some of your data with the acquiring/merged entity.

Your Rights & Preferences as a Data Subject

  • This Privacy Policy is governed by your rights as per applicable law within the territory from where you access our Services.
  • You shall also be provided with an option to provide or deny consent for use of the data collected for the purposes mentioned in this Privacy Policy, restrict disclosure to third parties, data retention, data rectification, revoke consent already granted to collect data and if required, make us delete/anonymize the data collected by us. However, in the event of the foregoing, please note that we may not be able to provide all our Services efficiently to you.
  • To the extent applicable under applicable law, you can exercise your rights by submitting a request to the Grievance Officer.

AI Model Training & Your Data

Default Policy: Opt-In

  • We use Your content (including inputs, uploads, prompts, or generated outputs) to train, fine-tune, and/ or improve our AI models unless you explicitly opt-out through your account settings or by writing to [email protected].
  • What We May Use for Model Improvement:
    • De-identified usage patterns and aggregate statistics
    • Error logs and performance metrics (with identifiers removed)
    • Explicitly labeled training data you choose to contribute
    • Your Rights: You may review your current communication preferences and opt-in/opt-out status in your Account Settings. You may withdraw your consent at any time. Such withdrawal will apply prospectively and will not affect the lawfulness of processing carried out before the withdrawal. You may also request deletion of your personal data, subject to our legal obligations to retain certain information, applicable exemptions under the Digital Personal Data Protection Act, 2023, and other applicable laws. Where immediate deletion from backup or archival systems is not technically practicable, we will securely delete or anonymise such data in accordance with our retention practices.
  • Automated Decision-Making & Profiling: Our Services use AI models that may generate outputs based on statistical patterns and automated processing. We do NOT use automated decision-making for decisions that produce legal or similarly significant effects concerning you without human review.
  • Voice Cloning & Synthetic Media (Content Studio)
    • Voice samples are processed solely to provide voice cloning services you requested.
    • We maintain audit logs of voice cloning consent for 3 years post-deletion.
    • You must obtain consent from any individual whose voice you clone using our Service. You represent that such individual consent has been obtained by you.
    • We implement automated filters to detect potential misuse (deepfakes, impersonation).
    • You retain all rights to your cloned voice models; we claim no ownership.
    • All voice outputs generated by Content Studio are tagged with metadata indicating AI synthesis (where technically feasible). You are responsible for disclosing AI-generated content when distributing it publicly.
  • Algorithmic Transparency
    • Our Services use large language models, speech synthesis models, and voice encoders.
    • Models are trained on diverse datasets (publicly available text, licensed corpora, voice datasets).
    • Outputs are probabilistic and may contain inaccuracies or biases
    • We continuously monitor model performance and implement bias mitigation measures.
  • Limitations:
    • AI-generated outputs may be inaccurate, misleading, or inappropriate.
    • Outputs may not be unique; other users may receive similar responses.
    • You must evaluate accuracy and suitability for your use case (human review recommended).

Metadata & Provenance for Synthetically Generated Content (SGI)

  • Where we provide tools that generate, modify, host, publish, or distribute synthetically generated information (including AI‑generated or AI‑modified audio, images, video, or other media), we may process and attach technical metadata and provenance information to such content for compliance, safety, and traceability purposes.
  • What metadata we may process/embed (where technically feasible): (a) an indicator/label that content is synthetically generated; (b) a persistent unique identifier; (c) identifiers of the computer resource, account, or tool/workflow used to generate or materially modify the content; (d) timestamps, file/asset identifiers, and integrity signals (e.g., cryptographic hashes or watermark/provenance tags); and (e) limited distribution and processing logs necessary to demonstrate compliance and investigate abuse.
  • We process such metadata to (i) comply with applicable law and intermediary due‑diligence obligations; (ii) help users identify AI‑generated/synthetic content; (iii) prevent, detect, investigate, and respond to abuse (including impersonation and deceptive synthetic media); (iv) maintain security, auditability, and integrity of our Services; and (v) support user reports, grievance handling, and lawful requests.
  • Anti‑tampering: We do not knowingly enable removal, suppression, or alteration of SGI labels, unique identifiers, or embedded provenance metadata applied by us where technically feasible, and we may restrict functionality or take enforcement actions if we detect attempts to tamper with such measures.
  • Retention: SGI metadata and related integrity/audit logs are retained for the periods described in the Data Retention & Deletion section (including security incident logs and usage/technical logs), unless longer retention is required by law or necessary to address fraud, security incidents, or legal claims.
  • User control and transparency: Where our product provides settings for exporting or deleting content, those settings may not remove compliance labels/identifiers that must remain persistent for legal, safety, or integrity reasons, to the extent required/allowed by law.

Your Rights as Data Principal

Under the Digital Personal Data Protection Act, 2023, you have the following rights:

  • Right to Access: You may request-
    • Confirmation of whether we are processing your personal data.
    • Summary of personal data being processed.
    • Details of data fiduciaries and processors with whom data has been shared. Other information prescribed in DPDP Rules 2025.
  • Right to Correction & Erasure
    • Correction of inaccurate, incomplete, or out-of-date personal data.
    • Erasure of personal data where retention is no longer necessary for specified purpose.
  • Right to Grievance Redressal

You may lodge complaints about data processing activities with our Data Protection Officer (contact below) or/and Data Protection Board of India (if unsatisfied with our response).

  • Right to Nominate

You may nominate another individual to exercise your rights in case of death or incapacity. Nomination can be made through Account Settings or written notice to [email protected]

  • Right to Consent Withdrawal

You may withdraw consent at any time with the same ease as giving consent. Withdrawal does not affect lawfulness of processing prior to withdrawal. Withdrawing consent for essential processing may prevent us from providing Services. We will inform you of consequences before processing withdrawal.

Consent Management & Withdrawal

  • Before processing personal data, we provide a clear, standalone notice in plain language containing:
    • Itemized list of personal data to be collected
    • Specific purposes for each category of data
    • Manner of exercising rights (access, correction, erasure, withdrawal)
    • Contact details of Data Protection Officer
  • Consent is obtained through:

Clear affirmative action (clicking “I Agree,” toggling opt-in switches)

Unbundled consents for different purposes (not pre-ticked boxes)

Multilingual notices (English, Hindi, and regional languages as applicable)

  • Consent Manager Integration

We support integration with registered Consent Managers. You may:

Use a Consent Manager to grant, review, and withdraw consents across multiple data fiduciaries.

Access your consent dashboard for Sarvam.AI through supported Consent Manager platforms.

Revoke consent through Consent Manager, which we will honor within 7 days.

  • Effect of Withdrawal:

We will cease processing personal data for the specified purpose

Data will be deleted or anonymized within 30 days unless retention is legally required

Withdrawal does not affect past processing conducted under valid consent

You may lose access to Services dependent on withdrawn consent

Data Retention & Deletion

  • We retain personal data only as long as necessary for specified purposes or as required by law.
  • Retention Periods Table (By Category):
Data Category Retention Period Ground for Processing
Account & Profile Data Duration of account + 90 days post-termination unless early deletion is requested in writing Contract performance
Usage Logs & Technical Data 1 year from collection and such additional period as may be prescribed DPDP Rules 2025, Rule 6 (mandatory minimum)
Your Content (Inputs/Outputs) User-configurable (default: 30 days after last access) User consent
Voice Samples & Models Until consent withdrawal + 30 days Income Tax Act, 1961; GST Act, 2017
Support Communications 2 years from last interaction Legitimate business interest
Consent Records 3 years from consent withdrawal DPDP Rules 2025 compliance
Security Incident Logs 7 years from incident Cybersecurity requirements
  • Deletion Upon Request:
    • You may request deletion of your personal data at any time via:

Account Settings

Email: [email protected] with subject “Data Deletion Request”

  • Timeline: We will delete data within 30 days of request verification, except where:

- Retention is required by law (e.g., tax records, legal holds)

- Data is necessary for ongoing legal proceedings

- Technical limitations prevent deletion (we will anonymize instead)

  • Automatic Deletion
    • Inactive accounts: Accounts inactive for 3+ years are flagged for deletion (with 60-day notice).
    • Temporary data: Cached data, session data, and temporary files are auto-deleted per system policies.
  • Anonymization & De-identification: Where deletion is not feasible, we irreversibly anonymize data such that it can no longer identify you. Anonymized data may be retained indefinitely for analytics, research, and model improvement (with opt-in).

Data Security

  • The data provided by the User is stored in access controlled facilities with restricted access. User data transmitted over the internet is protected through the use of encryption, using the secure socket layer (SSL) or equivalent protocols.
  • We shall use generally accepted industry standards to protect the User data submitted to us, both during transmission and upon receipt. However, please be advised that, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, even though we strive to use commercially acceptable means to protect User data, we cannot guarantee its absolute security and your use of our Services is at your sole risk and discretion. We also cannot warrant that such User data may not be misused in the event our safeguards and protocols are breached maliciously. Further, we are not liable to, nor can we fully control the actions of other users with whom you may choose to share your data.
  • The collection, usage, and sharing of User data by us shall be in compliance with applicable laws.
  • If any security breach comes to our knowledge, then we may take all steps required to protect misuse of such data and may attempt to notify you electronically so that you can take the appropriate steps.

Cross-Border Data Transfers

  • Personal data may be transferred to and processed in countries outside India, including:
    • United States: Cloud infrastructure (AWS, GCP, Azure), analytics providers
    • European Union: Certain model providers, security vendors
    • Other jurisdictions: As necessary for Service provision
  • Safeguards for International Transfers:
    • Standard Contractual Clauses (SCCs):EU Commission-approved SCCs for GDPR transfers.
    • Adequacy Decisions: Transfers to countries recognized by India/EU as providing adequate protection
    • Contractual Obligations: Data processing agreements with all international vendors
    • Data Localization: Sensitive personal data of Indian users is stored in India where feasible
  • Data Localization (Indian Users):

In compliance with sectoral data localization requirements:

  • Payment data: Stored in India per RBI Payment System Data guidelines
  • Voice biometric data: Stored in India (Content Studio users)
  • Critical personal data: Processed and stored in India if notified by Central Government
  • Your Rights on Cross-Border Transfers:
    • Right to object to transfers to specific countries (we will assess feasibility)
    • Right to information about recipients and transfer mechanisms
    • Right to file complaints with Data Protection Board if transfers are unlawful

Cookies

  • When you are using/accessing our Services, one or more cookies will be sent to the Device being used by you. The cookies are either used to improve the quality of our Services or for storing your preferences as a User, improving the overall User experience. You have the option of disabling cookies via your Device settings. However, if you disable cookies, some parts of our Services may not function in the manner it was designed/intended.
  • If you would like to disable our access to any passive data we receive from the use of various technologies, you may do so by disabling cookies in your web browser/Device, which may affect the complete use of our Services. Please note that Sarvam may still receive data about your usage and also your personal data, such as your email address. If you choose to terminate your engagement with Sarvam, we will store data about you for such period as permitted under applicable law.

Children’s Privacy

  • Age Restriction: Our Services are NOT directed to children under 18 years of age. We do not knowingly collect personal data from children.
  • Strict Prohibition:
    • Children under 18 may NOT create accounts
    • Children under 18 may NOT use AI services without verifiable parental consent
    • Voice cloning features are strictly prohibited for users under 18
  • Verifiable Parental Consent: If a child's personal data is collected inadvertently, we require verifiable consent from parent or legal guardian. Verification methods include Government-issued ID verification, Credit card or payment method verification, Video/audio confirmation call, Signed consent form with identity proof.
  • Parent/Guardian Rights include, access child's data, request correction or deletion, and withdraw consent at any time.
  • Educational Institutions

For Services provided to educational institutions:

  • School/institution acts as lawful guardian
  • Institution must obtain parental consent
  • We process student data only as data processor on institution's behalf
  • Separate Data Processing Agreement governs such processing
  • Discovery of Children's Data

If we discover we have collected personal data from a child without proper consent:

  • We will delete the data within 72 hours
  • We will terminate the child's account
  • We will notify parents/guardians if contact information is available

Contact & Grievance Redressal

  • Data Protection Officer:

For all privacy-related queries, consent management, rights exercise, or complaints:

NAME: Saurabh Kumar Karn

ADDRESS: Sarvam AI, 2nd floor, 732 Urban Vault, CMH Road, Indiranagar, Bangalore - 560025

EMAIL: [email protected]

Business Hours: Monday-Friday, 9:00 AM - 6:00 PM IST

Response Timeline: Acknowledgment: Within 72 hours of receipt. Resolution within 30 days of acknowledgment (may be extended by 30 days with notice for complex requests).

  • Grievance Redressal Process
    • Step 1: Internal Complaint: Submit written complaint to Data Protection Officer via email or postal mail.
    • Step 2: Data Protection Board of India

Write to the address of the DPBI on the website of DPBI

  • Step 3: Legal Remedies: You retain all rights to pursue legal remedies under DPDPA, including compensation for data breaches.
  • European Users: For EEA/UK users, you may also lodge complaints with:
    • Your local Data Protection Authority (DPA)
    • Lead supervisory authority where we have EU establishment (if applicable)
  • California Users (CCPA)

California residents may submit complaints to:

California Attorney General's Office

Website: https://oag.ca.gov/contact/consumer-complaint-against-business-or-company

Phone: 1-800-952-5225

Dispute Resolution

In the event of any dispute, difference or claim arising out of this Privacy Policy the same shall be settled in accordance with the applicable laws in India through regular judicial process and the courts of Bengaluru, India, shall have exclusive jurisdiction.