Privacy Policy

Last updated 20 August 2026

This policy explains what we collect, why, how long we keep it, how we protect it and what you can ask us to do about it. It covers two different groups of people and the difference matters, so that is set out first.

1. Who this covers

Character XYZ is operated by Charky Labs Pvt Ltd, a company registered in India. Under the Digital Personal Data Protection Act, 2023 we are a Data Fiduciary for the personal data described here.

Customers are the businesses that license the platform: venues, brands and their staff. They hold accounts, they agree to our Terms, and they decide what their character says and what knowledge it draws on.

Guests are the people who walk up to a character in a venue and talk to it. Guests never sign anything with us. That is precisely why the sections below limit what is collected about them and how long any of it survives.

Where a customer decides what is collected through their character and why, that customer is the Data Fiduciary for those interactions and we act as their Data Processor, on their instructions and under our Terms.

2. What the character captures

Our characters can see, hear and speak. Sight and sound are processed live, in the moment, so the character can respond. We do not retain audio recordings and we do not retain camera images or video of guests.

What is retained is the transcript: the text of what was asked and what the character answered, the time it happened, and which venue and instance it happened at.

We do not ask guests for their name, phone number, email address or any identity document, and the character is not built to collect them. We do not knowingly collect biometric identifiers, and our Terms prohibit a customer from configuring a character to solicit sensitive personal data from guests.

3. What we collect from customers

  • Account data: name, work email, phone number and role of the people who use the platform.
  • Billing data: company name, registered address, tax identifiers and invoice history. Card details are handled by our payment provider and are never stored by us.
  • Content you upload: your knowledge base, brand assets, conversation flows and configuration.
  • Technical logs: IP address, browser type and timestamps, used to keep the service secure and working.

4. We do not train AI models on your conversations

Guest conversations are never used to train, fine-tune or improve any AI model, ours or anyone else's. Customer content uploaded to the platform is never used to train models either.

Conversations are used to answer the guest in the moment, and to produce the analytics the venue is paying for. That is all.

5. Why we are allowed to process this

For guests, the basis is consent: a guest chooses to start and continue a conversation, having been told what happens, through the notice displayed at the unit.

For customers, the basis is performance of our contract with you, and our legitimate interest in keeping the service secure, billing correctly and meeting our own legal obligations under Indian tax and company law.

6. Consent, the notice at the unit, and withdrawal

For consent to mean anything, a guest has to know what is happening before they speak. Our Terms require every venue to display a notice, which we supply, at or beside the unit: that they are speaking to an automated character, that a text record of the conversation is kept, and where to find this policy. A venue that does not display it is in breach of its agreement with us.

A guest may withdraw consent at any time by writing to privacy@character.xyz. Withdrawal is as easy as giving consent was. We will delete the transcripts we can identify as theirs, and withdrawal does not affect processing already carried out.

If you spoke to one of our characters and there was no such notice, tell us at privacy@character.xyz. We will remove the record and take it up with the venue.

7. Children

Children talk to characters in malls, theme parks and family venues. We do not keep their conversations.

Where an interaction appears to involve a child, the transcript is used only to answer in the moment and is then discarded rather than stored. It is never retained, never included in analytics, and never used to build recommendations, profiles or any form of behavioural targeting. This reflects the Digital Personal Data Protection Act, 2023, which prohibits tracking, behavioural monitoring and targeted advertising directed at children.

If you are a parent or guardian and believe a record of your child exists, write to privacy@character.xyz and we will find and delete it.

8. What we do with transcripts

Transcripts let a venue see what guests actually asked, which questions the character could not answer, when guests came, and how the character is performing. That is the core of what the product is for.

They are also used to improve what the character can answer, by showing the venue what to add to its knowledge base. The venue makes that change. Nothing happens automatically.

Where a venue chooses to, transcripts inform recommendations the character makes from that venue's own offerings, such as suggesting a dish or a screening. Recommendations are never built from a child's interaction. We do not sell personal data to anyone, and we do not use it for third-party advertising.

9. Automated decisions

A character generates its replies automatically, and may suggest items from the venue's own offerings. It does not make decisions that produce legal effects for a guest or anything similarly significant: it cannot approve credit, deny service, set a price for an individual, or record anything against a person's name.

10. What the venue can see

The venue that operates the character can see the conversations held with it, including full transcripts, alongside the analytics built from them. Guests should assume that what they say to a character can be read by the business running it, in the same way as speaking to a member of staff.

11. How long we keep it

  • Guest transcripts: twelve months from the conversation, then deleted or irreversibly anonymised so they can no longer be linked to a single interaction.
  • Interactions that appear to involve a child: not retained at all.
  • Customer account data: for as long as the account is open, then ninety days.
  • Billing and tax records: for as long as Indian tax and company law requires, currently eight years.
  • Security logs: twelve months.

12. Where it is stored, and cross-border transfer

Personal data is stored in Amazon Web Services, Mumbai (ap-south-1), India.

Some processing may involve service providers operating outside India, for example a language-model or speech-recognition provider. Where that happens we transfer only what is needed, under contractual terms requiring equivalent protection, and only to countries not restricted by the Central Government under section 16 of the Digital Personal Data Protection Act, 2023.

13. Who else touches it

We use third parties to run the service: cloud hosting and storage, speech recognition, language-model providers, payment processing, email delivery and error monitoring. They act on our instructions, are bound by contract to protect the data, and may only use it to provide their service to us.

We do not name them individually here so that we can change providers without publishing a stale list. Any customer may request the current sub-processor list from privacy@character.xyz, and we will give reasonable notice of a material change.

14. How we protect it

  • Encryption in transit using TLS, and encryption at rest for stored data.
  • Access limited to the people who need it, with individual accounts and multi-factor authentication.
  • Segregation of customer data so one customer cannot reach another's.
  • Logging and monitoring of access to production systems.
  • Contractual security obligations passed down to every processor we use.
  • No security is absolute. We do not claim our systems cannot be breached, and the sections on breach notification and liability set out what happens if they are.

15. If there is a data breach

If a personal data breach occurs, we will notify the Data Protection Board of India without delay and provide a detailed report within seventy-two hours, as required by the Digital Personal Data Protection Act, 2023 and the rules made under it.

We will also notify every affected person directly, describing what happened, what data was involved, what it may mean for them, what we are doing about it and what they can do to protect themselves. Indian law sets no materiality threshold for this: affected individuals are told regardless of how limited the breach was.

Where the breach concerns a customer's guests, we will notify that customer without undue delay so they can meet their own obligations.

16. Cookies and tracking on this website

This website runs no advertising cookies, no analytics cookies and no tracking pixels. There is nothing here from an ad network, and we do not build a profile of you for visiting.

Signed-in users of the application receive one cookie that keeps them signed in. It is strictly necessary for the service to work and is not used to track anyone across other websites.

17. Your rights

  • Access: ask for a summary of the personal data we hold about you and what we do with it.
  • Correction: ask us to correct data that is inaccurate, and to complete data that is incomplete.
  • Erasure: ask us to delete your personal data where we are not required to keep it.
  • Withdraw consent: at any time, as easily as it was given.
  • Nomination: nominate another person to exercise these rights on your behalf in the event of your death or incapacity, as provided by the Digital Personal Data Protection Act, 2023.
  • Grievance: complain to us first, and to the Data Protection Board of India if we do not resolve it.

18. How to make a request

Write to privacy@character.xyz from the email address you want us to act on, or by post to the registered office below. We will respond within thirty days.

If your request concerns a conversation with a character, tell us the venue and roughly when it happened, because that is how the record is found. We may ask for enough information to be satisfied who you are, so that we do not disclose someone else's data to you.

19. Grievance Officer

In accordance with the Information Technology Act, 2000 and the rules made under it, and the Digital Personal Data Protection Act, 2023, the Grievance Officer is Zeno Saviour.

Write to privacy@character.xyz, or by post to Charky Labs Pvt Ltd, 4 Thendral Nagar, Vilankurichi P.O., Coimbatore 641035, Tamil Nadu, India. Complaints are acknowledged within twenty-four hours and resolved within fifteen days.

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

20. Our status

We have not been notified as a Significant Data Fiduciary by the Central Government. If that changes we will appoint a Data Protection Officer, publish their details here and carry out the additional obligations that status brings.

21. Links to other sites

This site links to third parties, including our scheduling provider. Their handling of your data is governed by their own policies, not this one.

22. Changes to this policy

We will update this page when what we do changes, and the date at the top will change with it. Where a change materially affects customers we will tell them directly, in advance where we reasonably can. This version is dated 20 August 2026.

23. Contact

Charky Labs Pvt Ltd, 4 Thendral Nagar, Vilankurichi P.O., Coimbatore 641035, Tamil Nadu, India. Email hello@character.xyz. Telephone +91 72005 80713.