Resources
Privacy Policy
Liulum, a sole proprietorship operated by Rahul Rishi. Version 2026-07-27. Plain-English summary of what we collect, who processes it, and your rights. Not legal advice.
1. Who we are
Liulum (Liulum, a sole proprietorship operated by Rahul Rishi) operates liulum.com and provides revenue-continuity monitoring, automation oversight, governed recovery, reporting, and support for SaaS and commerce systems. Optional AI communication or bespoke services apply only when separately agreed. For the personal data you give us about yourself and your account, we act as a Data Fiduciary / Controller. For personal data we process on your behalf about your customers or staff, we act as a Data Processor under our DPA. Privacy questions: Rahul Rishi at [email protected].
2. What we collect
- Account & contact details — name, email, phone, company, business profile, and messages you submit via get-started, /build, onboarding, or support.
- Care & support conversations — messages you send our Care Bot and support agents, ticket history, and the account context (your sites, incidents, settings) used to help you.
- Optional voice & lead data — when separately enabled, call metadata, transcripts, structured lead fields, urgency flags, and escalation records.
- Payment records — Razorpay confirmation, invoice IDs, and subscription status. We never receive or store full card numbers — Razorpay handles card data as a PCI-DSS provider.
- System telemetry — configured site, API, browser-journey, deployment, webhook, automation, reconciliation, incident, and recovery evidence.
- Usage & security logs — IP address, browser, timestamps, and portal activity for authentication and abuse prevention.
- Historical outbound-research records — previously collected public business contact details are retained only for audit, suppression, and opt-out safety. Liulum no longer runs automated prospecting or outreach.
3. Why we use it (purpose & legal basis)
We process personal data on the lawful bases of performing our contract with you, your consent (which you may withdraw), our legitimate business interests in running and securing the service, and compliance with legal obligations. Specifically we use it to:
- Deliver, configure, and operate monitoring, automation continuity, governed recovery, support, and portal services.
- Send service, billing, onboarding, and alert notifications (email, WhatsApp outbound, Slack where configured).
- Produce reports and ops digests in your client portal.
- Keep the platform secure, prevent abuse and fraud, and meet tax, accounting, and legal obligations.
We do not sell your personal data and we do not show third-party advertising.
4. AI processing & automation
Parts of the Service are AI-assisted. Your messages, and the account context needed to answer them, are sent to AI model providers (our sub-processors) to generate replies, diagnoses, and drafts. We instruct our AI to use only the data provided for your account, never to make binding commitments on your behalf, and to escalate anything sensitive, irreversible, or security-related to a human for approval. AI outputs can be imperfect; a human reviews consequential actions. We do not use your or your customers' personal data to train third-party foundation models, and we contract for zero-retention / no-training handling from our AI providers where available.
5. Care Bot memory & self-destruct
When you chat with our Care Bot, the conversation is stored so it survives a refresh and stays auditable if you later dispute what you were told. When an issue is resolved, we notify you and then delete that chat transcript after a short privacy grace period (the resolved ticket record remains as the durable audit trail) — unless you ask us to keep it. You can also export or delete your Care Bot history at any time from your portal or by emailing us. Deletes are strictly tenant-scoped: no client can ever access or purge another client's data.
6. Who we share it with (sub-processors)
We use sub-processors only as needed to run the service, each under contractual data-protection terms and processing only on our instructions:
- Cloudflare — DNS, TLS delivery, web-application firewall, traffic management, and abuse protection at its global edge; cross-border processing may apply.
- Hetzner — virtual private server and origin infrastructure in Nuremberg, Germany.
- Supabase — managed PostgreSQL database hosting and database operations.
- Razorpay — payment processing and subscriptions (PCI-DSS).
- Resend — transactional and outbound email, including inbound-reply handling.
- Voice provider — only when an optional voice scope is enabled, AI voice calls, transcripts, and agent configuration.
- AI model providers — only when an AI-assisted feature is enabled, the configured provider receives the minimum account context needed for support, diagnosis, or drafting.
- Upstash / QStash — when configured, queues and distributed rate limiting for background jobs.
- Sentry — error monitoring and reliability.
- Background worker — outbound email notifications and maintenance automations.
We may disclose information if required by law or to protect rights, safety, and fraud prevention. A current sub-processor list is available on request; we give notice of material changes where required.
7. International transfers
Some sub-processors are located outside India (for example in the United States). Where personal data is transferred across borders, we rely on a lawful transfer mechanism appropriate to the destination — contractual safeguards such as the EU Standard Contractual Clauses where the GDPR applies, and equivalent protections under India's DPDP Act — together with provider security controls. A copy of the operative clauses is available on request.
8. Retention
We keep personal data only as long as needed for the purpose collected: account and service data for the life of your account; billing and tax records for the period required by Indian law (generally up to 8 years); Care Bot transcripts until the privacy grace period after resolution; security logs for a limited rolling window. When a purpose ends we delete or anonymise the data, keeping only what the law requires.
9. Your rights
Under India's Digital Personal Data Protection Act, 2023 (and similar laws such as the GDPR where it applies), you can request access to, correction of, and erasure of your personal data; withdraw consent for optional processing; nominate someone to exercise your rights; and raise a grievance. Active clients can self-serve export and deletion from /dashboard. For any other request, email [email protected] — we verify your identity and respond within statutory timelines (generally within 30 days). Withdrawing consent does not affect processing already done and may mean we can no longer provide part of the Service.
10. Children
The Services are for businesses and adults. We do not knowingly collect personal data from children below the age of consent in their jurisdiction. If you route data about minors through the Services, you are responsible for obtaining verifiable parental consent as required by law. If we learn we hold a child's data without a lawful basis, we delete it.
11. Cookies
Essential cookies only — to keep you signed in and the portal secure. No advertising or cross-site tracking cookies. See our Cookie Policy.
12. Security
Encryption in transit, access controls, tenant isolation, secret redaction, and reputable infrastructure providers. No system is perfectly secure; we take reasonable steps and will notify you and the Data Protection Board of a material breach affecting your data within the timelines the DPDP Act and other applicable law require.
13. Grievance officer
For complaints or to exercise your rights: Rahul Rishi, Liulum, [email protected]. If you are unsatisfied with our response, you may complain to the Data Protection Board of India. Governing law: India, courts of Chandigarh.
14. Changes
We may update this policy; the current version (2026-07-27) is shown here, and we give notice of material changes. See also Terms · DPA · Acceptable Use · Anti-Spam · Support.