Frosty AgentFrostyAgent
Why FrostyFeaturesDesign / Widget GalleryChannelsIntegrationsDevelopersAPI DocsSecurity
Capture & Qualify
Lead Generation & CaptureCampaign AttributionCRM & Lead IntelligenceLead VerificationMeta CAPI / Conversion Reporting
Convert
AI QuotationsAppointment BookingConversational AIAI ReceptionistAI Email Agent
Support & Retain
After-Sales & Order StatusFollow-Up & Re-engagementHuman Handoff
Foundation
Multilingual (24 languages, 95+ countries)Voice NotesRAG / Knowledge-GroundedNo-Code Setup
What Frosty Does — All 18 Solutions
Global Industries
HealthcareClinics & Medical
Real EstateAgents & Brokers
Home ServicesHVAC, Plumbing, Electrical & Handyman
Manufacturing & B2BIndustrial, Equipment & Distribution
Auto DealershipsNew, Used & Service Centers
View all 50+ industries
Learn
WhatsApp Business API GuideCTWA AttributionMeta Pricing ChangesDPDP and AI Chatbots
Free Tools
Unanswered Enquiries CalcWhatsApp API Pricing CalcCTWA ROAS Calculator
More
BlogComparisonsCase StudiesTemplatesGlossaryHelp Centre
Pricing
Log inStart free trial
PRIVACY POLICY24 Sections
011. Introduction & Operating RolesAPart A — Merchants (Controller)022. What We Collect from Merchants033. Lawful Basis & No Model Training044. Merchant Data Retention Schedule055. Merchant Rights & Consent WithdrawalBPart B — Visitors (Processor)066. What is Processed in Conversations6b6b. Ad Measurement & Meta Conversions API077. AI Transparency & Profiling Safeguards088. Browser Local Storage & Cookies099. Purpose & Retention Ceilings1010. Visitor Rights & RoutingCPart C — General (Applies to Everyone)1111. Data Request Handling & SLAs1212. Sub-processors & Third Parties1313. Data Residency & International Transfers1414. Security Architecture & RLS1515. Breach Notification Timelines1616. United States — California (CCPA/CPRA)1717. Other International Countries1818. Children & Minor Data Protection1919. Contact & Grievance Officer2020. Governing Law & Regulators
Version 1.0 · Frostrek LLP · Gurugram, IndiaOfficial Policy

Frostrek LLP (“Frostrek”, “we”, “us”, “our”) provides Frosty Agent, an AI sales and support agent that businesses deploy on their own website and messaging channels. This policy covers frostyagent.com, the Frosty Agent dashboards, the chat widget, and the agent itself wherever it operates.

01

1. Introduction & Operating Roles

1.1. Frostrek LLP (“Frostrek”, “we”, “us”, “our”) provides Frosty Agent, an AI sales and support agent that businesses deploy on their own website and messaging channels. This policy explains what we do with personal data.

1.2. This policy covers frostyagent.com, the Frosty Agent dashboards, the chat widget, and the agent itself wherever it operates.

1.3. We act in two different roles, and which one applies determines your rights and who you contact:

If you areOur roleWho decides how your data is used
A merchant using Frosty AgentControllerUs
A visitor talking to a merchant’s agentProcessorThe merchant

1.4. If you spoke to an AI agent on a company’s website or on WhatsApp, that company decides how your data is used and is the first place to go with a question or a request. We process it on their instructions. We also have obligations of our own — to keep your data secure, to tell them promptly if there is a breach, and to act only on their lawful instructions — and you can hold us to those. If you cannot reach the company, write to privacy@frostyagent.com and we will route your request to them and help them answer it.

1.5. One qualification to the table above. For most visitor data we act only on the merchant’s instructions. For a few things we decide ourselves — which sub-processors we use, where we store data, what technical data we need to keep the Service secure and working, and the maximum period we will hold anything for. To that limited extent we act as a Data Fiduciary (controller) in our own right, and this policy tells you what we do. It does not change who is responsible for the conversation itself: that is the merchant.

1.6. Binding Commitment: We do not sell personal data. We do not use your data, or your visitors’ conversations, to train foundation models. This is a contractual commitment, not only a statement of policy.

1.7. We may update this policy. We will post changes on this page and, for material changes, notify merchants by email at least 30 days in advance. The version each update replaces stays available at https://frostyagent.com/legal/privacy/archive, with its version number and the dates it was in force, so you can see exactly what changed.

A
Scope 1

Part A — Merchants (we are the controller)

This Part explains how Frostrek handles personal data belonging to merchants who register for, configure, and use the Frosty Agent platform.

02

2. What we collect from merchants

  • 2.1. Account data — name, business email, phone number, company name, role, and a hashed password.
  • 2.2. Business data — GSTIN, billing address, plan, invoices and payment references. We never see or store your card number. Razorpay handles payment details.
  • 2.3. Configuration — your knowledge base, catalogue, agent settings and branding.
  • 2.4. Usage data — logins, actions taken in the dashboard, audit logs, IP address, device and browser.
  • 2.5. Support communications — messages you send us and our replies.
03

3. Why we process it, and our lawful basis

3.1. Where the EU or UK General Data Protection Regulation applies, we rely on the following bases:

PurposeBasis — India (DPDP Act, 2023)Basis — EU/UK (GDPR)
Creating and operating your account, and providing the ServiceConsent (Section 6)Article 6(1)(b) — contract
Billing, invoicing and taxCertain legitimate use (Section 7(d) — Income-tax Act, CGST Act, LLP Act)Article 6(1)(b) and Article 6(1)(c)
Service emails — outages, security, changesConsent (Section 6)Article 6(1)(b)
Security, fraud prevention, abuse investigation and incident responseConsent (Section 6); and Section 7(d) where a law requires it, including CERT-In DirectionsArticle 6(1)(f) — legitimate interests. Object under Article 21
Marketing emailsConsent (Section 6) — withdraw at any timeArticle 6(1)(a) — consent
Improving the Service — aggregate analytics on dashboard useConsent (Section 6). Optional separate consent at signupArticle 6(1)(f) — aggregated and de-identified data

3.2. India does not have a “legitimate interests” basis. The Digital Personal Data Protection Act allows processing on consent or on one of the eleven certain legitimate uses in section 7, and nothing else. The table above states which applies for each purpose.

3.3. We do not process personal data for any purpose other than those listed. We never use your content, your configuration or your visitors’ conversations to train or fine-tune any AI model — clause 12.4 of our Terms of Service makes that a contractual commitment.

04

4. How long we keep merchant data

DataRetention
Account and configurationFor the life of the account, then 30 days
Invoices and tax records8 years, as required by law
Audit logs365 days
Backups30 days
05

5. Merchant rights

5.1. Under India’s Digital Personal Data Protection Act, 2023 you may: obtain a summary of the personal data we hold about you and of our processing of it, and the identities of every other Data Fiduciary and Data Processor we have shared it with, with a description of what was shared (Section 11); have it corrected, completed, updated or erased (Section 12); nominate another person to exercise your rights if you die or become incapable (Section 14); and raise a grievance (Section 13).

5.2. Withdrawing consent. Where we rely on your consent you may withdraw it at any time, as easily as you gave it, at privacy@frostyagent.com. Withdrawal does not affect anything we did lawfully beforehand. When you withdraw consent we erase your personal data within 30 days and require our processors to do the same, except where a law requires us to keep it — in particular tax and LLP records, which we must keep for eight years. Withdrawing consent to the core processing closes your account.

5.3. Consent Managers. You may give, manage, review or withdraw consent through a Consent Manager registered with the Data Protection Board of India under section 6(7). We accept instructions from a registered Consent Manager as if you had given them to us directly.

5.4. In addition, wherever you are, we voluntarily offer access, correction, deletion, a portable copy in a structured, commonly used, machine-readable format, restriction of processing, and objection to processing based on our legitimate interests. Where the GDPR applies, these are your rights under Articles 15 to 21.

5.5. Direct marketing — an absolute right to object. Tell us at any time to stop sending you marketing and we will stop. No balancing, no exception. Use the unsubscribe link in any marketing email or write to privacy@frostyagent.com. We will still send service notices about outages, security and changes, because those are part of providing the Service.

5.6. How to exercise any of these: privacy@frostyagent.com. You may appoint an authorised agent; we will ask for written proof of their authority and may ask you to confirm it. Clause 11 sets out how we handle requests.

5.7. If you are not satisfied, raise a grievance with our Grievance Officer (clause 19). Section 13(3) of the Act requires you to use our grievance mechanism before approaching the Data Protection Board of India.

B
Scope 2

Part B — Visitors (the merchant is the controller; we are the processor)

This Part applies to end-users and visitors interacting with a merchant’s AI agent deployed via chat widget, WhatsApp, or API.

06

6. What is processed when you talk to an agent

  • 6.1. What you type or say, and the agent’s replies — the full conversation transcript.
  • 6.2. Contact details you provide — name, email address, phone number.
  • 6.3. Voice, if you send a voice note: an audio recording and its transcript.
  • 6.4. Channel identifiers — your WhatsApp number, or a website session identifier.
  • 6.5. Meeting and quotation details you agree with the agent.
  • 6.6. Technical data — IP address, approximate location derived from it at city level, browser and device.
  • 6.7. Sensitive information — please do not send it. Some of what you tell the agent may be sensitive personal data or information under Rule 3 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, or a special category of personal data under Article 9 of the GDPR. Please do not send the agent health information, payment card or bank details, government identity numbers such as Aadhaar or PAN, or details of your religion, caste, political views or sexual orientation. The agent does not need them, and merchants are contractually required to configure their agent so that it does not ask for them.
  • 6.8. Advertising click identifiers and campaign attribution — where you arrive via an ad or marketing link (such as WhatsApp Click-to-WhatsApp ads or web campaigns with UTM parameters, Google Click ID gclid, or Meta Click ID fbclid), the widget reads these transient URL parameters on load. They are stored on the conversation record solely to provide campaign attribution reporting to the merchant and, where configured by the merchant, to report conversion events via the Meta Conversions API (CAPI) (see Section 6b).
6b

6b. Ad Measurement & Meta Conversions API

Purpose. When a visitor arrives from a Meta / WhatsApp ad (or another ad with a click ID), the merchant may use Frosty to measure which ads led to outcomes such as a qualified lead, a booked meeting, or an accepted quote. That measurement may include sending conversion events to Meta's Conversions API (CAPI) so the merchant can optimise ads.

Roles. The merchant is the controller for end-customer data and is responsible for notices and, where required, consent for ad measurement. Frostrek acts as a processor on the merchant's instructions. Frostrek does not collect a separate consent prompt inside the chat for this purpose.

  • What may be sent (when CAPI is enabled by the merchant and platform gates allow): event name, event time, a deduplicating event ID, action_source=business_messaging, messaging_channel=whatsapp, and the Click-to-WhatsApp click ID (ctwa_clid). Events without a valid ctwa_clid, or outside a 7-day click window, are not sent.
  • Defaults: live CAPI sending is off (merchant toggle + platform control). Merchants can suppress individual contacts from CAPI in the CRM.
  • Cross-border: Meta may process conversion payloads outside India under Meta's terms.
Enabling live CAPI for a workspace additionally requires Frostrek's contractual package (updated DPA warrant and, where applicable, the 30-day notice under Section 12.1a of this Privacy Policy) to be completed. Until then, conversion attempts are recorded only for debugging and are not posted to Meta.
07

7. You are talking to an AI

7.1. The agent is automated software, not a human being. Where the merchant has enabled human handoff, it may hand you over to a human member of the merchant’s team. If you ask whether you are speaking to a person or an AI, it will tell you.

7.2. The agent is automated, and it profiles you. It generates its replies automatically. It also scores your enquiry — estimating, from what you have said, how interested and how urgent you appear — so the merchant’s team can decide which enquiries to follow up first. This is profiling within the meaning of Article 4(4) of the GDPR.

7.3. What the score is based on, and what it does. It is derived from the content of your messages, the topics you asked about, whether you gave contact details, and whether you asked to speak to a person or book a meeting. It draws on no data about you from outside your conversation with this merchant. Its only consequence is the order in which the merchant’s staff see your enquiry. It does not decide what price you are offered, whether you may buy, or whether you reach a human. Where the merchant has enabled human handoff, you can ask to speak to a person and the agent will pass you on; where human handoff is not enabled or available, the agent will invite you to leave your message or contact details so the merchant’s team can follow up directly.

7.4. Decisions with legal or significant effects. Frosty Agent is not designed to make them, and section 1 of our Acceptable Use Policy prohibits merchants from configuring it to make automated decisions with legal or similarly significant effects on an individual — including credit, employment, insurance and housing decisions — without human review. If you believe a decision about you was made solely by automated means, contact the merchant and tell us at privacy@frostyagent.com; we will investigate the merchant’s configuration.

7.5. Quotations. Where a merchant has configured the agent to prepare quotations, a quotation generated in your conversation is indicative unless the merchant has approved it. It is not a binding offer until they confirm it.

08

8. Storage in your browser

8.1. The chat widget stores functional state (such as visitor session tokens and conversation identifiers) in your browser’s first-party local storage on the merchant’s website, so your conversation stays open if you navigate away or return. It uses no persistent third-party advertising cookies and performs no cross-site tracking of its own. As disclosed in Section 6.8, URL-based advertising click identifiers (e.g. ctwa_clid, and web click IDs like gclid and fbclid) present in the page address when you arrive are captured for conversation attribution and optional Meta Conversions API reporting on the merchant's instructions. You can clear local storage in your browser settings at any time.

8.2. Cookies used on frostyagent.com itself are described in our Cookie Policy at https://frostyagent.com/legal/cookies.

09

9. Why it is processed, and for how long

9.1. Visitor data is processed on the merchant’s instructions — to answer your questions, capture your enquiry, book meetings, prepare quotations, and (where configured) pass you to a human. The merchant chooses the purpose and the lawful basis.

9.2. Retention is determined by the merchant, within the ceilings below. We delete conversation data when the merchant deletes it, or within 30 days of the merchant closing their account.

9.3. Our maximum retention periods. Whatever a merchant chooses, we apply these ceilings and delete on expiry. A merchant may choose shorter, never longer:

Visitor dataOur maximum
Conversation transcripts and the agent’s replies24 months from the last message
Voice recordings7 days from receipt — we transcribe, then delete the audio. Only the transcript is kept
Contact details captured as a lead24 months from last contact, or until the merchant deletes the lead
Meeting and quotation records8 years where a quotation forms part of the merchant’s tax records; otherwise 24 months
Technical data — IP address, derived location, browser, device90 days
Channel identifiersWith the conversation they belong to

9.4. Deletion and backups. Deleted data is removed from our live systems immediately. Encrypted backups are overwritten within a further 30 days, so complete deletion takes up to 60 days. During that window backups are used only to restore the system after a failure.

10

10. Visitor rights

10.1. Contact the merchant you were talking to. They are the controller and they decide.

10.2. If you cannot reach them, write to privacy@frostyagent.com. We will route your request to the merchant and support them in answering it, and we will tell you that we have done so.

C
Scope 3

Part C — Applies to everyone

This Part sets out cross-cutting governance standards, sub-processors, security architecture, and regulatory compliance.

11

11. How we handle a data request

11.1. Verifying who you are. Before we act on a request we take reasonable steps to confirm your identity, proportionate to the sensitivity of the data. We will not ask for more documentation than is necessary. If we cannot verify you, we will say so and explain why.

11.2. How long we take:

Your locationWe acknowledgeWe respond
India (DPDP Act)PromptlyWithin 30 days
EU / UK (GDPR)PromptlyWithin 1 month, extendable by 2 months for complex requests
California (CCPA/CPRA)Within 10 business daysWithin 45 days, extendable by a further 45

11.3. When we may not be able to fulfil a request. We may decline, in whole or in part, where the law requires us to keep the data (for example tax records), where it is needed to establish or defend a legal claim, where the data is subject to a legal hold, or where fulfilling it would adversely affect another person’s rights. If we decline, we will tell you why, and you may complain to your regulator.

12

12. Who else receives data

12.1. We use the following categories of provider. The current list is maintained at https://frostyagent.com/legal/sub-processors.

ProviderWhat they doWhere they process
SupabaseDatabase, authentication, file storageIndia (Mumbai)
GoogleAI models and Google Calendar connectionOutside India
MetaWhatsApp message delivery, and advertising measurement / Conversions API (when enabled by merchant)Outside India
RazorpayPayment processingIndia
ResendEmail deliverySee sub-processors page
UpstashCaching and rate limitingSee sub-processors page

12.1a. We give 30 days’ notice before adding a new sub-processor or materially changing an existing one, so that a merchant can object.

12.2. We may also disclose personal data to our professional advisers, insurers and auditors where reasonably necessary; where we are required to do so by law or in connection with legal proceedings; to establish, exercise or defend legal rights; and to a purchaser or prospective purchaser of our business, subject to equivalent confidentiality obligations.

12.3. Except as described in this policy, we do not provide personal data to third parties.

13

13. Where data is stored, and international transfers

13.1. Primary data is stored in India (Mumbai region).

13.2. Some providers process data outside India — in particular Google for AI model inference and Meta for WhatsApp delivery.

13.3. India — the DPDP Act. We transfer personal data outside India only where section 16 of the Digital Personal Data Protection Act, 2023 and Rule 15 of the DPDP Rules, 2025 permit. We do not transfer personal data to any country the Central Government has notified as restricted, and we will stop any transfer that becomes restricted. We impose contractual obligations on each recipient that are no less protective than those we owe you. Where a sectoral law imposes stricter localisation — for example the Reserve Bank of India’s requirements for payment data — that prevails, and payment data is handled entirely by Razorpay within India.

13.4. EEA and UK. Frostrek LLP is established in India, which the European Commission has not found to provide an adequate level of protection. Transfers from the EEA to us are therefore made under the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), and transfers from the UK under the International Data Transfer Addendum issued by the Information Commissioner, in each case supported by a transfer risk assessment and by supplementary measures including encryption in transit and at rest, application-layer encryption of credentials, and tenant isolation enforced at the database.

13.5. Get a copy. Ask at privacy@frostyagent.com and we will send you the clauses that apply to you, with commercially confidential terms redacted.

13.6. Data protection laws in other countries may not be equivalent to those in India, the EEA or the United Kingdom.

14

14. Security

14.1. Encryption. Data is encrypted in transit using TLS 1.2 or above and at rest using AES-256. Credentials, API keys and third-party tokens are additionally encrypted at the application layer, with keys held separately from the data.

14.2. Tenant isolation. Every merchant’s data is separated by row-level security enforced in the database itself and by role-based access control in the application. These controls are designed so that one merchant cannot read another merchant’s data, and we test them as part of our release process.

14.3. Access control. Access to production systems and personal data is restricted to the people who need it for their role, granted least-privilege, reviewed quarterly, and protected by multi-factor authentication. Everyone with access is bound by a written confidentiality obligation that survives the end of their engagement with us.

14.4. Logging. We keep audit logs of privileged actions and of access to personal data. We retain security logs for at least one year, as Rule 6 of the DPDP Rules, 2025 requires, and retain the logs specified in the CERT-In Directions of 28 April 2022 for 180 days within India.

14.5. Testing. We review and test our technical and organisational measures at least annually and after any significant infrastructure change.

14.6. Certifications — our position, stated plainly. We do not hold a SOC 2 report or ISO/IEC 27001 certification. We have built to those controls and intend to certify as we grow. We will not describe ourselves as certified, audited to a standard, or compliant with one until we are.

14.7. GDPR. We are built to GDPR standards. We do not claim certified GDPR compliance, and we have not appointed a representative under Article 27 of the GDPR or the UK GDPR. If you are established in the EEA or the UK, or your visitors are, tell us before you subscribe — we will appoint a representative and agree the additional terms before accepting your subscription.

14.8. No system is perfectly secure. Transmission over the internet carries inherent risk. Report a suspected vulnerability to security@frostyagent.com; we will not pursue legal action against a researcher who reports one in good faith and does not access, alter or exfiltrate other people’s data.

15

15. Breach notification

15.1. Merchant data, where we are the Data Fiduciary. On becoming aware of a personal data breach we will, without delay, tell each affected person the nature, extent and timing of the breach, its likely consequences for them, what we have done about it, what they can do, and our contact details — as Rule 7(a) of the DPDP Rules, 2025 requires. Where the GDPR applies we will also notify the supervisory authority within 72 hours under Article 33 and affected individuals under Article 34 where the risk to them is high.

15.2. Visitor data, where the merchant is the Data Fiduciary and we are the Data Processor. We will notify the merchant without undue delay and in any event within 24 hours of becoming aware, with what they need to meet their own duties. The merchant notifies their visitors and their regulator.

15.3. The Data Protection Board of India. We will inform the Board without delay of every personal data breach affecting data for which we are the Data Fiduciary, and furnish the detailed particulars Rule 7(b) requires within 72 hours. India applies no severity or risk threshold: every personal data breach is reportable.

15.4. CERT-In. We will report reportable cyber incidents to the Indian Computer Emergency Response Team within 6 hours of noticing them or being made aware of them, as the CERT-In Directions of 28 April 2022 require under section 70B(6) of the Information Technology Act, 2000.

15.5. Our notifications are not an admission of fault or liability.

16

16. United States — California (CCPA/CPRA)

16.1. We act as a service provider to merchants under the California Consumer Privacy Act as amended by the CPRA. We do not sell or share personal information, and we receive no consideration for it.

16.2. Where you are a California resident and we are the controller — that is, a merchant account holder — you have the right to know what personal information we collect and how we use it, to delete it, to correct it, to opt out of sale or sharing (we do neither), and to limit the use of sensitive personal information (we do not use it for any purpose that would require that limit).

16.3. We will not discriminate against you for exercising any of these rights — no denial of service, no different pricing, no reduced quality.

16.4. Exercise these rights at privacy@frostyagent.com. If you are a visitor of one of our merchants, contact that merchant.

16.5. Notice at collection. The categories of personal information we collect from merchant account holders:

Category (Cal. Civ. Code Section 1798.140(v))What we collectSold/Shared?Retention
IdentifiersName, business email, phone, account ID, IP addressNoLife of account + 30d; IP 90d
Customer records (Section 1798.80(e))Company name, billing address, GSTIN, payment referencesNo8 years
Commercial informationPlan, subscription and transaction historyNo8 years
Internet or network activityLogins, dashboard actions, audit logs, device, browserNoAudit logs 365 days
Geolocation, approximate (city level)Derived from IP addressNo90 days
Professional informationYour role at your companyNoLife of account + 30 days
Sensitive personal informationCryptographic hash of passwordNoLife of account

We collect this from you directly and from your use of the Service. We do not buy personal information and we do not collect it from data brokers.

16.6. We use sensitive personal information only to authenticate you. We do not use or disclose it to infer characteristics about you.

16.7. Under-16s. We have no actual knowledge that we sell or share the personal information of consumers under 16, and we do not sell or share personal information at all.

16.8. Visitor data. Where we process personal information on a merchant’s behalf we act as a service provider under Section 1798.140(ag), under a written contract that prohibits us from retaining, using or disclosing it other than for the specified business purposes, from selling or sharing it, from using it outside our relationship with the merchant, and from combining it with information from other sources.

17

17. Other countries

17.1. Where we sell. We offer the Service to businesses in India and internationally. If a data protection law of another country applies to you or to your customers — for example Brazil (LGPD), Canada (PIPEDA), Singapore (PDPA), Australia or South Africa (POPIA) — tell us before you subscribe. We will tell you honestly whether we can currently meet that law’s requirements, and where we can we will agree the additional contractual terms needed. We do not represent that the Service is compliant with a law we have not assessed.

18

18. Children & Minor Data Protection

DPDP Section 9 & Rule 10

18.1. Merchant accounts are available only to people aged 18 or over. We do not knowingly create merchant accounts for children.

18.2. Visitors — the merchant’s responsibility. The agent runs on a merchant’s own website and messaging channels. Where a merchant’s audience may include children, the merchant is the Data Fiduciary and must obtain verifiable parental consent under section 9 of the Digital Personal Data Protection Act, 2023 and Rule 10 of the DPDP Rules, 2025 before the agent processes a child’s personal data. Our Acceptable Use Policy prohibits deploying the agent to an audience the merchant knows or ought reasonably to know includes children, unless they have implemented age assurance and parental consent to that standard. Where the GDPR applies, the age of consent for information society services is 13 to 16 depending on the Member State, and the merchant must meet the applicable threshold.

18.3. Product capabilities and children’s data. We do not knowingly process a child’s personal data. Frosty Agent is designed for commercial business interactions and does not provide controls or switches to selectively disable lead capture, enquiry scoring, or conversation persistence. Because the agent inherently performs automated enquiry scoring (profiling as described in Section 7.2) and persists conversation records across interactions, the product cannot be configured into a non-profiling or non-persisting mode for child users. Merchants who configure data retention may reduce the conversation retention period to the platform’s minimum supported duration of 30 days (configurable between 30 and 730 days in merchant settings). We do not conduct cross-site tracking, behavioural monitoring across services, or targeted advertising directed at children in any configuration. If a merchant cannot satisfy statutory requirements for processing children’s data (including age assurance and verifiable parental consent under Section 9 of the DPDP Act), they must not deploy the agent on channels or pages accessible to children.

18.4. If a child’s data reaches us. Tell us at privacy@frostyagent.com. Where we are the Data Fiduciary we will delete it. Where the merchant is, we will notify them within 2 business days, suspend further processing of the affected conversation, and delete the data on their instruction or if they do not respond within 7 days.

19

19. Contact & Grievance Officer

Privacy & Data Requestsprivacy@frostyagent.com
Security Vulnerability Desksecurity@frostyagent.com
Statutory Grievance Officer (DPDP Act, 2023)Anurag Tripathi
SLA: 48h Ack / 30d Resolution

Email: grievance@frostyagent.com
Frostrek LLP, 4th Floor, 422, Success Tower, Golf Course Extension Road, Gurugram, Haryana 122002, India

20

20. Governing law & Severability

20.1. This policy is published under the laws of India. It is a notice, not a contract, and it does not restrict any right you have under the law of the place where you live.

20.2. You may always complain to your own regulator. In India, to the Data Protection Board of India — after first raising a grievance with our Grievance Officer, as section 13(3) of the DPDP Act requires. In the EEA or the UK, to your local supervisory authority. In California, to the California Privacy Protection Agency or the Attorney General.

20.3. If any provision of this policy is found to be unenforceable, it will be limited or removed to the minimum extent necessary and the rest remains in force.

Frosty AgentFrostyAgent
Powered by Frostrek
GDPR-ready
ISO 27001 Certified
ISO 9001:2015 Certified
GmailWhatsAppLinkedinInstagram

Solutions

  • Campaign Attribution
  • AI Quotations
  • Lead Re-engagement
  • Voice Notes

Company

  • About Us
  • Live Demo
  • FAQ
  • Contact

Location

Map
JMD Empire, Sec 62, Gurugram
© 2026 Frostrek. All rights reserved.
Privacy Policy·Data Deletion·Terms of Service·Acceptable Use Policy