Encryption, Indian data residency and strict tenant isolation — with the outbound-contact controls this kind of platform actually needs.
BlueAI Chat handles your customers' phone calls, WhatsApp messages and lead lists. This page sets out exactly how that data is protected, where it lives, and what the platform will and will not do.
All customer data — conversations, recordings, knowledge bases, contact lists and analytics — is hosted exclusively in Microsoft Azure's Central India region. Your data does not leave India.
Data in Azure PostgreSQL and Azure Storage is encrypted with AES-256, and backups are encrypted too. Selected sensitive fields — including the credentials for channels you connect — carry a further layer of application-level encryption, so they are unreadable even with database access.
Everything runs over TLS 1.2 or above. The dashboard, the APIs, the chat widget and all webhook traffic are HTTPS-only.
Your AI employee answers from the knowledge you give it. It is configured to decline questions outside that scope rather than improvise, which is what keeps it from inventing a price or a promise.
You can define restricted topics, custom fallback messages, and the conditions that hand a conversation to a human. Every conversation is reviewable in the dashboard.
Your documents, conversations and recordings are never used to train AI models. They stay yours.
The platform defends against jailbreak and prompt-injection attempts so that a caller cannot talk your AI employee out of its instructions.
The platform is built to support your obligations under India's Digital Personal Data Protection Act. People can request access to, correction of, and deletion of their personal data. See the Privacy Policy.
Because the platform can place calls and send messages at scale, it also carries the controls you need to stay on the right side of TRAI's DND and unsolicited-communication rules and Meta's WhatsApp Business policy — per-category message classification, opt-out handling and campaign-level suspension. Your obligations are set out in the Terms of Service.
Payments are processed by Razorpay and Cashfree, both PCI DSS compliant. BlueAI Chat never sees or stores card numbers.
Conversations and analytics are retained while the account is active. After cancellation you have 30 days to export, after which business content and conversation data are deleted.
Email security@blueaichat.com. Please include enough detail to reproduce the issue. We acknowledge reports within 72 hours and will keep you updated until it is resolved. We will not pursue action against researchers who report in good faith and do not access other customers' data.