Legal

Privacy Policy

This policy explains how Blisphere Solutions PVT. LTD. ("Blisphere Solutions PVT. LTD.", "we", "us") handles information on the Brilith.

Effective

Introduction

Blisphere Solutions PVT. LTD. operates the Brilith, software that gives a service business an AI receptionist workspace — a way to answer customer questions, book appointments, and manage customers, services, staff, and conversations. Businesses that use the Brilith (we call them “businesses” or “customers” of ours) use it to communicate with and manage their own customers (we call these “end customers”).

Because of how the Brilith works, we act in two different privacy roles depending on the information involved:

  • For information a business enters, or that its end customers send through the business’s AI employee (for example, a customer’s name, phone number, or a message in a chat conversation), we generally act as a service provider acting on the business’s instructions. The business is generally the controller of that information.
  • For information about the business itself and the people who use our platform directly — account details, billing/contact information, support requests, and website usage — we generally act as the controller.

The exact legal classification can depend on your jurisdiction and specific facts, so this description is a plain-language explanation of how we actually operate rather than a jurisdiction-specific legal determination.

Information we collect

We collect the following categories of information, only as they exist in the product today:

Account information

  • Your name and email address, as provided through our authentication provider
  • An authentication identifier tied to your account
  • The business or businesses your account is a member of, and your role on each

Business information

  • Business name, contact details, website, and address
  • Business hours, service area, services, staff, and staff availability
  • Booking and cancellation policies, pricing notes, and FAQs
  • Instructions the business gives its AI employee, and anything the business teaches it (Business Memory)

End-customer information processed on behalf of a business

  • Name, phone number, email address, and address where a business collects one
  • Appointment history and scheduling details
  • Notes, tags, and communication preferences a business records about its own customer

Conversation information

  • Messages sent by an end customer, by the AI, and by business staff
  • Conversation status, escalation, and human-approval records
  • Operational metadata about a conversation, such as its channel and timestamps

Technical information

  • Log and timestamp data generated by normal operation of the service
  • Session and authentication tokens needed to keep you signed in
  • For the website chat widget: the originating domain, and browser/device information the widget receives when a conversation starts
  • Error and security-related information used to keep the service reliable and safe

Support information

  • Anything you send us directly when you contact support

How we collect information

  • Directly, when you create an account or enter information into the platform
  • Directly, when a business configures its profile, services, staff, and Business Memory
  • Automatically, when an end customer sends a message through a business’s installed chat widget
  • Automatically, through the normal operation of the service, including scheduling and AI processing
  • From our authentication provider, when you sign in or create an account
  • Directly, when you contact us for support

How we use information

We use the information described above to:

  • Operate and provide the Brilith
  • Authenticate accounts and maintain sessions
  • Generate AI responses to end-customer messages and questions
  • Check real availability and book appointments according to a business’s rules
  • Apply a business’s configured policies and escalate conversations to a person when needed
  • Send operational notifications, such as alerting a business owner that a conversation needs human review
  • Maintain and improve the reliability of the service, and debug problems
  • Detect, prevent, and investigate abuse, fraud, or security issues
  • Provide support when you contact us
  • Comply with applicable law

We do not use the content of a business’s conversations or Business Memory to train a generalized AI model of our own. We do not sell personal information.

AI processing

The Brilith uses AI to interpret and respond to end-customer messages, and to help with tasks like qualifying a lead or drafting a reply. To do this, we send limited, relevant information to AI service providers as necessary to generate a response or perform a configured task.

AI output can be incomplete or incorrect. Scheduling and booking decisions are governed by deterministic rules the business configures (such as business hours, staff availability, and booking policies), which take priority over anything the AI alone decides. Some actions require a business’s approval before they take effect, and conversations can be escalated to a person. Businesses are responsible for configuring, reviewing, and supervising how their AI employee behaves.

We do not currently have a general commitment from every third-party AI provider that data is never used for their own model training — please refer to that provider’s own terms for specifics. If this changes, we will update this policy.

Sharing and service providers

We share information with the following categories of service providers, only as needed to run the platform:

  • An authentication provider, to manage account sign-in and sessions
  • An AI service provider, to generate AI responses and perform configured AI tasks
  • An email delivery provider, to send operational notifications such as human-review alerts
  • Our database and hosting infrastructure providers, to store and run the platform

We may also share information:

  • As needed to provide the service you’ve requested
  • To comply with law, legal process, or a valid government request
  • In connection with a merger, acquisition, or sale of business assets
  • At your direction, or a business’s direction with respect to its own data

We do not sell personal information, and we do not name service providers here that are not actually part of the platform today.

Data retention

We retain information for as long as an account is active and as needed to provide the service. Records a business archives (such as an archived customer, staff member, or conversation) remain stored rather than immediately deleted, so the business’s history stays intact. We may retain certain information longer where needed for security, legal, or accounting reasons.

We do not currently offer a fully self-service account or data deletion flow within the product. If you would like information deleted or exported, contact us using the details below and we will address the request directly.

Security

We use technical and organizational measures intended to protect information against unauthorized access, use, or disclosure — for example, isolating each business’s data within the platform and restricting access to authenticated accounts. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

International processing

Our service providers may process information in countries other than the one where you or your business are located. Where this happens, we expect appropriate safeguards to be in place under each provider’s own terms. We do not publish specific data-center locations here, as these can change as our infrastructure providers change theirs.

Your rights

Depending on your location, you may have rights to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Request deletion of your information
  • Restrict or object to certain processing
  • Request a portable copy of your information
  • Withdraw consent, where processing is based on consent
  • Lodge a complaint with your local data-protection authority

If you are the end customer of a business that uses the Brilith — for example, someone who messaged a business’s AI employee — that business generally controls its own customer relationship and data. We recommend contacting that business first. We will still assist directly where required.

Children

The Brilith is a business tool intended for use by service businesses and their staff. It is not directed to children, and we do not knowingly collect personal information from children through the platform itself.

Cookies and local storage

We use essential, technology needed to keep you signed in and to keep the website chat widget working — for example, our authentication provider uses cookies to maintain your session, and the chat widget stores a session and visitor identifier in your browser’s local storage so a conversation can continue if you return to the page. We do not currently use analytics or advertising cookies, so we have not added a cookie-consent banner. If that changes, we will update this policy and this section accordingly.

Policy updates

We may update this policy from time to time. When we do, we will revise the effective date at the top of this page. Continued use of the Brilith after an update means you accept the revised policy.

Contact

Blisphere Solutions PVT. LTD. operates the Brilith. If you have questions about this policy, or want to make a request about your information, contact us at contact@blisphere.com.