1. Scope
This Privacy Policy applies to Paladin and related Northmann Groupe websites, documentation, dashboards, APIs, billing flows, support channels, and communications. It should be read together with our Terms & Conditions.
This Policy covers personal data relating to account users, website visitors, workspace members, billing contacts, support contacts, business prospects, and individuals whose data is processed through Paladin, such as call recipients, callers, campaign contacts, leads, customers, or other end users of a Customer.
Where a Customer uses Paladin to process personal data about its own call recipients, leads, customers, employees, or users, the Customer is responsible for giving required notices, obtaining consent or another lawful basis, honoring opt-outs, and complying with all applicable privacy, telecom, consumer, employment, sector-specific, and data-protection laws.
2. Privacy Roles
For personal data that we collect to operate Paladin accounts, billing, tax, fraud prevention, authentication, phone verification, support, website analytics, product security, service communications, and our own business administration, Northmann acts as the data fiduciary, controller, or equivalent decision-maker, depending on applicable law.
For Customer Data submitted to Paladin by a Customer or processed by Paladin on a Customer's instructions, including contact lists, campaign rows, prompts, call audio, transcripts, recordings, workflow runs, context variables, knowledge-base files, webhook payloads, and provider credentials, Northmann generally acts as a data processor, service provider, or equivalent processor for the Customer. The Customer remains responsible for deciding the purpose and means of that processing unless a separate written agreement says otherwise.
For Indian users and individuals, we design this Policy with the Digital Personal Data Protection Act, 2023 and related rules in mind. Where laws use different terms, references to controller, processor, data fiduciary, data principal, personal data, and processing should be read in the closest applicable sense.
3. Notice, Acceptance, and Consent Records
Paladin may require users to review and accept the current Terms & Conditions and Privacy Policy before registration, onboarding, phone verification, billing access, or service use. If you do not accept, you may not be able to proceed. We may store the acceptance timestamp, accepted version, accepted URLs, account identifiers, phone verification status, IP address, user agent, and related audit records to prove that notice was provided and that the Terms and Privacy Policy were accepted.
Where processing is based on consent, consent must be free, specific, informed, unconditional, unambiguous, and given by clear affirmative action. Withdrawal of consent may limit or stop access to Paladin where the relevant processing is required to provide, secure, bill, or support the service, and withdrawal does not affect lawful processing already completed before withdrawal.
4. Personal Data We Collect or Process
The categories of personal data we collect or process depend on how Paladin is used. They may include:
- Account and authentication data: name, email address, password hash or authentication identifier, OAuth or Stack Auth identifiers, phone number, phone verification status, login events, session data, selected organization, roles, invitations, terms and privacy acceptance records, and account preferences.
- Profile and workspace data: company name, job title, workspace or organization name, members, roles, permissions, API keys, folder names, workspace settings, configuration choices, and usage preferences.
- Billing, tax, and payment data: billing name, billing email, billing address, country, state, city, postal code, GSTIN or tax details, tax evidence, payment status, Razorpay order/payment/subscription identifiers, invoices, transaction logs, chargeback data, audit events, IP address, user agent, and fraud or risk signals. We do not intentionally store full payment card numbers unless a payment provider makes such data available under its own controlled environment.
- Telephony and call data: caller and recipient phone numbers, call direction, call timing, duration, provider metadata, telephony configuration, call status, call transfer data, inbound or outbound routing data, campaign run data, retry data, recordings, transcripts, call summaries, extracted variables, QA outputs, and usage/cost information.
- AI workflow and content data: prompts, workflow definitions, nodes, tools, templates, model settings, voice settings, context variables, knowledge-base documents, embeddings-related metadata, generated outputs, test runs, production runs, and model responses.
- Campaign and contact-list data: uploaded CSV or structured source data, phone numbers, names, custom fields, scheduled call windows, consent-related fields provided by Customer, retry configuration, campaign logs, and campaign reports.
- Integration and credential data: provider type, API keys, bearer tokens, basic auth values, custom headers, webhook endpoints, MCP endpoints, CRM or automation endpoints, telephony provider credentials, and configuration metadata. We aim to mask secrets in responses and logs, but Customers must avoid sharing secrets unnecessarily.
- Support and security data: support tickets, category, severity, title, description, attachments, comments, ratings, page URL, device and browser metadata, support access requests, access reasons, impersonation or support-session audit logs, IP address, user agent, and troubleshooting logs.
- Website, device, and analytics data: IP address, browser type, device information, approximate location derived from IP, pages visited, timestamps, referrer, clicks, form submissions, cookie identifiers, local storage identifiers, performance data, and telemetry from tools such as analytics, logging, monitoring, and error-reporting providers.
- Communications data: messages sent through forms, email, support, sales, billing, security, product updates, service notices, unsubscribe preferences, and related metadata.
5. Sources of Personal Data
We collect personal data directly from you, from your workspace administrators or invited users, from Customer uploads, from call participants and campaign contacts when Customer uses Paladin, from telephony and AI providers, from payment and tax providers, from authentication providers, from analytics and security tools, from support interactions, from webhooks and integrations, and from public or third-party sources where lawful and relevant.
6. Purposes and Legal Bases
We process personal data for lawful purposes, including:
- creating, authenticating, verifying, securing, and administering accounts and workspaces;
- providing Paladin features such as workflows, calls, campaigns, recordings, transcripts, knowledge-base processing, APIs, webhooks, provider configuration, and support;
- processing Customer instructions and Customer Data for Customer workflows;
- performing phone verification, fraud checks, abuse prevention, rate limiting, risk review, and enforcement of our Terms;
- billing, payment processing, tax/GST verification, invoice generation, accounting, audits, dispute handling, collections, and chargeback management;
- monitoring service health, debugging, logging, crash reporting, security investigation, performance improvement, and prevention of unauthorized access;
- responding to support, sales, privacy, legal, and security requests;
- sending service notices, onboarding messages, billing messages, product updates, security alerts, and legally required notices;
- improving Paladin, documentation, pricing, usability, reliability, safety, and abuse controls using aggregated, de-identified, or limited operational data where appropriate;
- complying with law, court orders, regulator requests, telecom provider requirements, tax obligations, law-enforcement requests, and legal process;
- protecting the rights, property, safety, and legitimate interests of Northmann, Customers, users, call recipients, providers, and the public.
Depending on the context and applicable law, we rely on consent, performance of a contract, compliance with legal obligations, certain legitimate uses, legitimate interests, or Customer instructions as the basis for processing. Where consent is required, you may withdraw consent through the relevant product control, unsubscribe mechanism, or contact channel, subject to legal, contractual, billing, security, and operational consequences.
7. AI, Audio, Recordings, and Customer Content
Paladin may process prompts, call audio, speech, transcripts, recordings, context variables, knowledge-base files, and generated outputs through AI, speech-to-text, text-to-speech, telephony, storage, and workflow systems. This processing may involve third-party providers and Customer-selected providers.
Customers must notify call participants and obtain consent for recording, transcription, AI processing, synthetic or generated voice, automated calling, and commercial communications where required. Customers must not submit personal data to Paladin unless they have a lawful basis and all required rights, consents, registrations, and notices.
We do not knowingly sell Customer Data. We do not use Customer Content to train public foundation models controlled by Northmann unless separately agreed or enabled by the Customer. Third-party AI providers may process Customer Content according to their own terms, data-processing commitments, retention settings, and provider configuration.
8. Sharing and Disclosure
We may share personal data with:
- Customer administrators and workspace users according to workspace roles, permissions, and product functionality;
- service providers and subprocessors that support hosting, cloud storage, authentication, AI models, speech-to-text, text-to-speech, telephony, payments, GST/tax verification, email, analytics, monitoring, logging, support, security, and infrastructure;
- Customer-selected providers and integrations such as telephony providers, AI providers, CRMs, automation tools, webhooks, MCP servers, and external APIs configured by Customer;
- payment, banking, tax, and fraud-prevention providers for checkout, billing, invoicing, GST verification, dispute management, and compliance;
- professional advisers such as lawyers, auditors, accountants, insurers, and consultants under confidentiality obligations;
- authorities, courts, regulators, telecom providers, and law-enforcement agencies where required by law, legal process, provider rules, or to protect rights, safety, security, or prevent misuse;
- business-transfer parties in connection with a merger, acquisition, financing, restructuring, sale of assets, or transfer of all or part of the Paladin business.
We require service providers to process personal data only for authorized purposes and to use appropriate safeguards, subject to the nature of the service and applicable law.
9. International Transfers and US Hosting
Server location: Paladin's primary service infrastructure and storage may be hosted in the United States. Personal data may also be processed in the United States and other jurisdictions by our service providers or by Customer-selected providers.
By using Paladin and accepting this Policy, you understand and authorise that personal data may be transferred to, stored in, accessed from, and processed in countries outside your location, including the United States. These countries may have data-protection laws different from those in India or your jurisdiction. If you cannot lawfully permit this processing or transfer for your use case, you must not use Paladin for that data.
Where applicable law requires transfer safeguards, we use appropriate contractual, organizational, and technical measures. We will also observe applicable Indian cross-border transfer restrictions, if any country, territory, person, or entity is restricted by notification or law. Customers are responsible for ensuring that their own use of Paladin and Customer-selected providers complies with any data-localization, sectoral, contractual, or cross-border transfer obligations applicable to them.
10. Retention
We retain personal data for as long as reasonably necessary for the purposes described in this Policy, including to provide Paladin, maintain accounts, process billing, comply with law, resolve disputes, enforce Terms, prevent fraud, preserve security, maintain audit records, and meet tax, accounting, telecom, and legal obligations.
Retention periods vary by data type. Account and workspace data may be retained while an account is active and for a reasonable period after closure. Billing, tax, invoice, payment, audit, and transaction records may be retained for legally required periods. Security logs, support logs, abuse evidence, and access logs may be retained as needed for security, investigation, audit, or legal defense. Call recordings, transcripts, campaign data, knowledge-base files, workflow runs, and Customer Content may be retained until deleted by Customer, account closure, product retention settings, backup expiry, or longer where required for legal, billing, security, or dispute reasons.
Backups and residual copies may persist for a limited period after deletion. We may retain aggregated, anonymized, or de-identified data that no longer identifies an individual.
11. Data Principal Rights and Choices
Depending on applicable law, you may have rights to access information about processing, request correction or updating, request erasure, withdraw consent, nominate another person to exercise rights after death or incapacity, object or restrict certain processing, unsubscribe from marketing, or raise a grievance.
To exercise rights relating to your Paladin account, billing profile, or direct relationship with Northmann, contact us through https://www.northmanngrp.com/contact or product support channels. We may need to verify your identity and may refuse, limit, or delay requests where permitted by law, including for security, legal, tax, billing, fraud-prevention, free-speech, dispute, or technical reasons.
If you are a call recipient, lead, customer, employee, or end user of a Paladin Customer, you should first contact that Customer because the Customer usually decides why and how your personal data is processed. We will assist Customers with rights requests as required by applicable law and contract.
You can control cookies through browser settings. You can opt out of non-essential marketing communications through unsubscribe links or by contacting us. Service, security, billing, and legal notices may still be sent where necessary.
12. Children
Paladin is not intended for children and may be used only by individuals who are at least 18 years old. Customers must not use Paladin to target children, profile children, track children, or process children's personal data unless they have all legally required parental or guardian consent, authority, safeguards, and approvals. We may suspend or delete accounts or data if we believe Paladin is being used in a way that creates risk to children or violates applicable law.
13. Cookies, Analytics, and Similar Technologies
We may use cookies, local storage, pixels, SDKs, and similar technologies for authentication, session management, preferences, security, fraud prevention, analytics, performance, product improvement, and support. Some technologies are necessary for Paladin to work. Others help us understand usage and improve the website or product.
Third-party analytics, monitoring, and error-reporting providers may collect device, browser, IP, and usage information according to their own terms and privacy notices. Browser settings may let you block or delete cookies, but some features may not work correctly.
14. Security
We use reasonable technical, organizational, and administrative safeguards designed to protect personal data, such as access controls, credential masking, audit logging, encryption where appropriate, secret-handling practices, monitoring, and provider security controls. No system is fully secure. You are responsible for securing your account, API keys, provider credentials, devices, network, workspace roles, and users.
If we become aware of a personal data breach affecting your personal data or Customer Data, we will assess it and provide notices as required by applicable law, provider obligations, and contractual commitments. We may also preserve and produce security logs, audit records, and incident information where required for CERT-In, law-enforcement, regulator, provider, or court processes.
15. Third-Party Links and Providers
Paladin may link to or integrate with third-party websites and services. Their privacy practices are governed by their own policies. We are not responsible for third-party privacy practices, security, retention, model behavior, telecom routing, payment processing, or independent use of data outside our control.
16. Changes to this Policy
We may update this Privacy Policy to reflect product changes, legal requirements, provider changes, security practices, or operational needs. The updated date and effective version will show the current version. If changes are material, we may provide additional notice or request renewed acceptance where appropriate or legally required.
17. Contact and Grievance Requests
Existing Customers should submit Paladin product, account, billing, security, support, privacy, or operational requests through the in-app report issue or support flow wherever available. New users, prospective customers, non-account holders, and corporate contacts may contact Northmann Groupe through https://www.northmanngrp.com/contact. Privacy, data-protection, legal, and grievance requests may also be submitted through the same public contact page where an in-app route is not available. Where applicable Indian law prescribes a specific acknowledgement, response, redressal, preservation, or reporting timeline, we will handle legally valid requests according to those applicable timelines after receiving sufficient information through the correct channel. If no specific statutory timeline applies, we will use commercially reasonable efforts to respond to verified privacy, data-protection, legal, or grievance requests within 30 days after receiving sufficient information through the correct channel.
Please include enough information for us to identify your account, workspace, request type, relevant data, and the country or law applicable to your request. Do not include sensitive data in a contact form unless necessary.