Privacy Policy
Last updated: July 17, 2026
This Privacy Policy explains how Abidott Solutions OPC Pvt Ltd ("Zedutt", "we", "us") collects, uses, and protects information when you use our CRM application and website (the "Service"). By using the Service you agree to this policy.
1. Who we are
The data controller is Abidott Solutions OPC Pvt Ltd, Kerala, India. For privacy questions, contact support@zedutt.com.
2. Information we collect
- Account data — your name, email, phone number, and workspace/business details you enter when you register. We use email-and-password sign-in; we do not use Google Sign-In.
- Workspace data — the leads, clients, campaigns, meetings, tasks, messages, and notes you create in the CRM.
- Lead/contact data — information about your customers' leads that you or your integrations add (name, email, phone, etc.).
- Usage & technical data — log data, IP address, and device/browser information for security and analytics.
3. How we use information
- To provide, operate, and secure the Service.
- To send transactional email/messages you configure (auto-replies, sequences, reminders, reports).
- To authenticate you and prevent abuse.
- To provide support and communicate service updates.
4. Sub-processors & third parties
We share data with vendors only as needed to run the Service:
- Google — optional Calendar, Gmail send, Drive (Sheets sync), and Ads connections, only if you connect them.
- Anthropic — powers Zedutt's AI sales agent on your workspace conversations. Google Workspace data is never sent to it (see section 5).
- Resend — outbound email delivery.
- Meta (WhatsApp Business Platform) — WhatsApp messaging, where you connect a number.
- Stripe — subscription billing (we do not store card numbers).
- Google Cloud (Cloud Run) / Neon (PostgreSQL) — hosting and database.
We do not sell your personal information.
5. Google user data (Calendar & Gmail)
Connecting your Google account is optional. When you do, Zedutt requests only the minimum scopes needed for the feature you turn on:
- Google Calendar (
.../auth/calendar.events) — to create, update, and cancel calendar events for meetings you book in Zedutt, including generating Google Meet links. We only manage events created through Zedutt. - Gmail send (
.../auth/gmail.send) — to send emails to your leads from your own address when you choose to send. We do not read, search, or store the contents of your mailbox. - Google Drive (per-file) (
.../auth/drive.file) — to create one spreadsheet named “Zedutt” in your Drive and append rows to it when CRM events happen (new lead, deal won, meeting booked). This scope only grants access to files Zedutt itself creates — we cannot see the rest of your Drive. - Google Ads (
.../auth/adwords) — to read your campaign spend so your dashboard can show cost-per-lead. Read-only in practice; we never create or edit ads.
To keep these connections working we securely store the OAuth refresh token Google issues. You can disconnect anytime in Settings → Connections, or revoke access at myaccount.google.com/permissions.
Zedutt's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising and do not sell it or transfer it to third parties except to provide the features you requested, to comply with law, or as part of a merger or acquisition.
AI/ML:Google user data is never used to develop, improve, or train AI or machine-learning models — neither ours nor anyone else's — and is never transferred to third-party AI services. Zedutt's AI sales agent operates only on the WhatsApp/email conversations and business facts inside your Zedutt workspace; data obtained through Google Workspace APIs (Calendar, Gmail, Drive) is not sent to any AI model. Our only third-party AI provider is Anthropic (Claude, paid commercial API tier), whose terms confirm that customer data submitted through the API is not used to train their models. The use of raw or derived user data received from Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements.
Protection, retention & deletion of Google data: OAuth refresh tokens are encrypted at rest (AES-256-GCM) and all transfers use TLS/HTTPS. Access inside your workspace is limited to what you grant your team. When you disconnect a Google integration (Settings) or revoke access from your Google account, we delete the stored token immediately; on account closure all Google-derived data is deleted with the rest of your workspace within 30 days.
6. Data retention
We retain workspace data while your account is active. You may delete records in-app at any time; on account closure we delete or anonymize your data within 30 days, except where we must retain it to meet legal obligations.
7. Your rights (GDPR / PDPL / similar)
Depending on your location you may have the right to access, correct, export, or delete your personal data, and to object to or restrict processing. To exercise these rights, contact support@zedutt.com. The Service includes consent tracking and unsubscribe handling to help you honor your own contacts' rights.
8. Security
We use encryption in transit, scoped access controls, and reputable infrastructure providers. No method of transmission is 100% secure, but we work to protect your data and notify you of material breaches as required by law.
9. International transfers
Your data may be processed in countries other than your own. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers.
10. Changes to this policy
We may update this policy from time to time. Material changes will be posted here with an updated date.
11. Contact
Abidott Solutions OPC Pvt Ltd, Kerala, India — support@zedutt.com.
