Legal
Privacy Policy
This policy explains how Blisphere Solutions PVT. LTD. ("Blisphere Solutions PVT. LTD.", "we", "us") handles information on the Brilith.
Effective
Introduction
Blisphere Solutions PVT. LTD. operates the Brilith, software that gives a service business an AI receptionist workspace — a way to answer customer questions, book appointments, and manage customers, services, staff, and conversations. Businesses that use the Brilith (we call them “businesses” or “customers” of ours) use it to communicate with and manage their own customers (we call these “end customers”).
Because of how the Brilith works, we act in two different privacy roles depending on the information involved:
- For information a business enters, or that its end customers send through the business’s AI employee (for example, a customer’s name, phone number, or a message in a chat conversation), we generally act as a service provider acting on the business’s instructions. The business is generally the controller of that information.
- For information about the business itself and the people who use our platform directly — account details, billing/contact information, support requests, and website usage — we generally act as the controller.
The exact legal classification can depend on your jurisdiction and specific facts, so this description is a plain-language explanation of how we actually operate rather than a jurisdiction-specific legal determination.
Information we collect
We collect the following categories of information, only as they exist in the product today:
Account information
- Your name and email address, as provided through our authentication provider
- An authentication identifier tied to your account
- The business or businesses your account is a member of, and your role on each
Business information
- Business name, contact details, website, and address
- Business hours, service area, services, staff, and staff availability
- Booking and cancellation policies, pricing notes, and FAQs
- Instructions the business gives its AI employee, and anything the business teaches it (Business Memory)
End-customer information processed on behalf of a business
- Name, phone number, email address, and address where a business collects one
- Appointment history and scheduling details
- Notes, tags, and communication preferences a business records about its own customer
Conversation information
- Messages sent by an end customer, by the AI, and by business staff
- Conversation status, escalation, and human-approval records
- Operational metadata about a conversation, such as its channel and timestamps
Technical information
- Log and timestamp data generated by normal operation of the service
- Session and authentication tokens needed to keep you signed in
- For the website chat widget: the originating domain, and browser/device information the widget receives when a conversation starts
- Error and security-related information used to keep the service reliable and safe
Support information
- Anything you send us directly when you contact support
How we collect information
- Directly, when you create an account or enter information into the platform
- Directly, when a business configures its profile, services, staff, and Business Memory
- Automatically, when an end customer sends a message through a business’s installed chat widget
- Automatically, through the normal operation of the service, including scheduling and AI processing
- From our authentication provider, when you sign in or create an account
- Directly, when you contact us for support
How we use information
We use the information described above to:
- Operate and provide the Brilith
- Authenticate accounts and maintain sessions
- Generate AI responses to end-customer messages and questions
- Check real availability and book appointments according to a business’s rules
- Apply a business’s configured policies and escalate conversations to a person when needed
- Send operational notifications, such as alerting a business owner that a conversation needs human review
- Maintain and improve the reliability of the service, and debug problems
- Detect, prevent, and investigate abuse, fraud, or security issues
- Provide support when you contact us
- Comply with applicable law
We do not use the content of a business’s conversations or Business Memory to train a generalized AI model of our own. We do not sell personal information.
AI processing
The Brilith uses AI to interpret and respond to end-customer messages, and to help with tasks like qualifying a lead or drafting a reply. To do this, we send limited, relevant information to AI service providers as necessary to generate a response or perform a configured task.
AI output can be incomplete or incorrect. Scheduling and booking decisions are governed by deterministic rules the business configures (such as business hours, staff availability, and booking policies), which take priority over anything the AI alone decides. Some actions require a business’s approval before they take effect, and conversations can be escalated to a person. Businesses are responsible for configuring, reviewing, and supervising how their AI employee behaves.
We do not currently have a general commitment from every third-party AI provider that data is never used for their own model training — please refer to that provider’s own terms for specifics. If this changes, we will update this policy.
Legal bases
Where privacy laws such as the GDPR require a legal basis for processing, we generally rely on:
- Contract — to provide the service you or your business signed up for
- Legitimate interests — to operate, secure, and improve the platform
- Consent — where a specific processing activity requires it
- Legal obligation — where we must retain or disclose information by law
We do not claim certification under any specific data-protection framework, and the availability of a given legal basis can depend on your jurisdiction.
Data retention
We retain information for as long as an account is active and as needed to provide the service. Records a business archives (such as an archived customer, staff member, or conversation) remain stored rather than immediately deleted, so the business’s history stays intact. We may retain certain information longer where needed for security, legal, or accounting reasons.
We do not currently offer a fully self-service account or data deletion flow within the product. If you would like information deleted or exported, contact us using the details below and we will address the request directly.
Security
We use technical and organizational measures intended to protect information against unauthorized access, use, or disclosure — for example, isolating each business’s data within the platform and restricting access to authenticated accounts. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
International processing
Our service providers may process information in countries other than the one where you or your business are located. Where this happens, we expect appropriate safeguards to be in place under each provider’s own terms. We do not publish specific data-center locations here, as these can change as our infrastructure providers change theirs.
Your rights
Depending on your location, you may have rights to:
- Access the personal information we hold about you
- Correct inaccurate information
- Request deletion of your information
- Restrict or object to certain processing
- Request a portable copy of your information
- Withdraw consent, where processing is based on consent
- Lodge a complaint with your local data-protection authority
If you are the end customer of a business that uses the Brilith — for example, someone who messaged a business’s AI employee — that business generally controls its own customer relationship and data. We recommend contacting that business first. We will still assist directly where required.
Children
The Brilith is a business tool intended for use by service businesses and their staff. It is not directed to children, and we do not knowingly collect personal information from children through the platform itself.
Policy updates
We may update this policy from time to time. When we do, we will revise the effective date at the top of this page. Continued use of the Brilith after an update means you accept the revised policy.
Contact
Blisphere Solutions PVT. LTD. operates the Brilith. If you have questions about this policy, or want to make a request about your information, contact us at contact@blisphere.com.
