How SISLCloudWorx Pvt. Ltd. collects, uses, shares and protects personal data in connection with NeuroRoute. It covers both the data we hold about you directly and the customer content your applications route through the platform.
SISLCloudWorx Pvt. Ltd. ("SISLCloudWorx", "we", "us") operates NeuroRoute, an AI model routing platform available at neuroroute.sislcloudworx.ai. Our registered office is A-10/11, Mohan Cooperative Industrial Estate, Mathura Road, New Delhi – 110 044, India.
This policy distinguishes two very different roles, because your rights differ depending on which applies:
| Category | Examples | Where it comes from |
|---|---|---|
| Account data | Name, work email, organisation, role, authentication identifiers | You, or your organisation admin, at sign-up / Google sign-in |
| Sales enquiry data | First and last name, company, designation, work email, mobile number, chosen solution, free-text message | The enquiry form on our website |
| Usage metadata | Timestamps, model selected, token counts, latency, cost, request and organisation identifiers, routing decisions | Generated automatically when you call the API |
| Customer content | Prompts, conversation history and model responses | Sent by your application. Stored only where your retention mode permits — see section 3 |
| Billing data | Plan tier, invoices, consumption records | Generated by the platform |
| Technical data | IP address, browser and device information, security and audit events | Your browser and our infrastructure logs |
We do not use customer content to train any model, ours or a third party's, and we do not sell personal information.
Retention of customer content is a per-organisation setting, not a single policy, and every API response states which mode served it in the X-Data-Retention header so you can verify it from your own logs rather than take our word for it.
| Mode | What is stored |
|---|---|
| zero-strict | Nothing. Response caches are bypassed on read and write, conversation memory is refused, and provider-side prompt caching is disabled. |
| zero | Nothing is persisted by NeuroRoute. Provider-side prompt caching may apply. |
| retain | Conversations and cache entries are stored for the number of days the organisation configures (1–365), encrypted at rest, then deleted by an automated sweeper. |
| Purpose | Basis (GDPR/UK GDPR) | Basis (India DPDP Act, 2023) |
|---|---|---|
| Providing the platform to an account holder | Performance of a contract (Art. 6(1)(b)) | Performance of a contract / legitimate use |
| Responding to a sales enquiry you submitted | Steps prior to a contract at your request (Art. 6(1)(b)) | Consent, given when you submit the form |
| Billing, fraud prevention, security, abuse limits | Legitimate interests (Art. 6(1)(f)) | Legitimate use |
| Verifying your email by one-time code | Performance of a contract / legitimate interests | Consent |
| Marketing communications | Consent (Art. 6(1)(a)), withdrawable at any time | Consent, withdrawable at any time |
| Meeting statutory and tax obligations | Legal obligation (Art. 6(1)(c)) | Legal obligation |
Where we rely on consent you may withdraw it at any time; withdrawal does not affect processing already carried out.
Routing a request means sending it to an AI provider. This is the most important disclosure in this policy: the content of your prompt leaves our infrastructure and is processed by the provider that serves it, under that provider's own terms.
The following sub-processors are engaged in production today:
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Google Cloud Platform | Hosting, database, cache, object storage, key management | India (asia-south1, Mumbai) |
| Google Cloud Vertex AI | AI model inference; text embeddings for optional semantic cache | India / global endpoints |
| Anthropic | AI model inference (Claude models) | United States |
| DeepInfra | AI model inference (open-weight model catalogue) | United States |
| Microsoft (Graph) | Transactional email delivery only — no customer prompt content | European Union / global |
The NeuroRoute platform is hosted in India (Google Cloud asia-south1, Mumbai) and customer content stored under "retain" mode stays there.
Inference is different. Some AI providers listed above process requests in the United States or on multi-region endpoints, so a prompt may be transferred outside your country at the moment it is routed. For transfers of personal data out of the EEA or the UK we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, and on the transfer terms in each provider's data processing agreement.
If you need inference confined to a specific jurisdiction, use a per-key model allowlist or a self-hosted model endpoint, or contact us before you send regulated data.
| Data | Retention |
|---|---|
| Customer content | Per your retention mode — nothing at all, or 1–365 days as configured (section 3) |
| Usage and billing metadata | Retained for the life of the account and then as required for tax and accounting law |
| Account data | For the life of the account; anonymised on erasure |
| Sales enquiry data | Up to 24 months from last contact, unless you ask us to delete it sooner |
| One-time verification codes | 5 minutes, stored only as a hash |
| Security and audit events | Retained to evidence access to the platform |
Subject to the law that applies to you, you have rights of access, correction, erasure, restriction, objection, and portability, and the right not to be subject to a decision based solely on automated processing that produces legal effects. NeuroRoute's routing decisions select a model; they do not make decisions about people.
Several of these are self-service rather than a support ticket:
We respond within 30 days (GDPR/UK GDPR) or 45 days (CCPA/CPRA, acknowledged within 10 business days), extendable where the law permits and we tell you why. There is no charge unless a request is manifestly unfounded or excessive.
If you are an end user whose data reached us through a customer's application, we will refer your request to that customer, who is your controller.
No system is perfectly secure. We do not claim a certification we do not hold; if you need our current security documentation for a vendor review, ask at legal@sislcloudworx.com. Where a personal data breach is likely to result in a risk to individuals we notify the competent supervisory authority within 72 hours of becoming aware, and affected individuals and customers without undue delay.
The NeuroRoute application sets only what it needs to work: a session cookie for authentication and preference storage for your dashboard. We do not run advertising cookies or cross-site trackers on the application.
Where analytics cookies are used on our marketing pages they are set only with your consent, and you can withdraw it at any time through your browser or our cookie controls.
NeuroRoute is a business product and is not directed to children. We do not knowingly collect personal data from anyone under 18. Under the India DPDP Act, processing children's data requires verifiable parental consent, which our sign-up flow is not designed to obtain; if you believe a child has provided us data, contact us and we will delete it.
We may update this policy. Material changes affecting how we handle customer content will be notified to account holders by email or in-product notice before they take effect, and the effective date above will change. Continued use after that date means the updated policy applies.
We aim to acknowledge grievances within 24 hours and resolve them within 15 days, as the IT Rules require. If you are in the EEA or UK you also have the right to complain to your local supervisory authority; if you are in India, to the Data Protection Board.
This policy describes controls the platform actually implements. Where a control is optional or tier-limited it says so.