← Back to Vridhi
VRIDHI

Data Handling

Last updated: June 2025

This document describes how Vridhi AI processes, stores, and secures data across all systems. It is intended for agents, enterprise clients, and anyone evaluating Vridhi's data practices in detail.

Data Architecture Overview

Vridhi runs on a modern, serverless stack. All personal data flows through authenticated server-side functions — no sensitive data ever reaches the browser directly.

Data Stores

Supabase (PostgreSQL + Storage)
Primary database for agents, leads, properties, call logs, and visit records. Row-level security (RLS) ensures agents can only access their own data. File storage holds property images and ad creatives.

Region: EU West (agents may request data residency confirmation). Backups: daily automated backups, 30-day retention.
Voice Calls (Bolna AI)
AI outbound calls are initiated via Bolna AI's API. Call recordings and transcripts are stored by Bolna for up to 90 days. Vridhi stores summary outcomes (intent score, property interest) in Supabase. No raw audio is retained by Vridhi beyond what Bolna holds under their own retention policy.
WhatsApp Messages (Meta Cloud API)
Messages are sent and received via Meta's WhatsApp Business Cloud API. Message content and lead phone numbers are stored in Supabase. Meta retains message metadata per their own policies. Vridhi does not share WhatsApp conversation data with any third party other than Meta (as required for delivery).
AI Inference (Anthropic Claude)
Lead qualification and conversation analysis is performed via Anthropic's API. Data sent to Anthropic is limited to lead messages and agent context required for the task. Anthropic does not train on API inputs by default. Outputs are stored in Supabase as lead score and intent data.
Payments (Razorpay)
Subscription billing is handled by Razorpay, a PCI-DSS Level 1 certified processor. Vridhi stores only Razorpay order IDs and payment status — never card numbers or bank details. Payment records are retained for 7 years per Indian GST requirements.
Meta Ads (Marketing API)
Ad campaigns are created on behalf of agents using their linked Meta Ad Account. Property images are uploaded to Meta using base64 encoding (not fetched from Supabase URLs) to prevent exposure of private storage URLs. Meta retains ad data per Meta Business policies.

Security Controls

Data Deletion Requests

Agents can request full account deletion by emailing admin@vridhiai.in. We will delete all agent and lead records from Supabase within 30 days. Payment records are retained for the legally required 7-year period. Voice recordings held by Bolna AI are subject to their own deletion process.

Data Breach Response

In the event of a data breach affecting personal data, we will notify affected users within 72 hours of becoming aware, consistent with good practice under the Indian DPDP Act 2023 (when applicable). Notifications will be sent to the registered email address.

Sub-Processors

Contact

For data handling questions or deletion requests: admin@vridhiai.in