NeuroRoute NeuroRoute SISL CloudWorx
Login
PRIVACY

Privacy Policy

Effective 27 July 2026 · SISLCloudWorx Pvt. Ltd.

How SISLCloudWorx Pvt. Ltd. collects, uses, shares and protects personal data in connection with NeuroRoute. It covers both the data we hold about you directly and the customer content your applications route through the platform.

1Who we are, and which hat we are wearing

SISLCloudWorx Pvt. Ltd. ("SISLCloudWorx", "we", "us") operates NeuroRoute, an AI model routing platform available at neuroroute.sislcloudworx.ai. Our registered office is A-10/11, Mohan Cooperative Industrial Estate, Mathura Road, New Delhi – 110 044, India.

This policy distinguishes two very different roles, because your rights differ depending on which applies:

2Information we collect

CategoryExamplesWhere it comes from
Account dataName, work email, organisation, role, authentication identifiersYou, or your organisation admin, at sign-up / Google sign-in
Sales enquiry dataFirst and last name, company, designation, work email, mobile number, chosen solution, free-text messageThe enquiry form on our website
Usage metadataTimestamps, model selected, token counts, latency, cost, request and organisation identifiers, routing decisionsGenerated automatically when you call the API
Customer contentPrompts, conversation history and model responsesSent by your application. Stored only where your retention mode permits — see section 3
Billing dataPlan tier, invoices, consumption recordsGenerated by the platform
Technical dataIP address, browser and device information, security and audit eventsYour browser and our infrastructure logs

We do not use customer content to train any model, ours or a third party's, and we do not sell personal information.

3Customer content and retention modes

Retention of customer content is a per-organisation setting, not a single policy, and every API response states which mode served it in the X-Data-Retention header so you can verify it from your own logs rather than take our word for it.

ModeWhat is stored
zero-strictNothing. Response caches are bypassed on read and write, conversation memory is refused, and provider-side prompt caching is disabled.
zeroNothing is persisted by NeuroRoute. Provider-side prompt caching may apply.
retainConversations and cache entries are stored for the number of days the organisation configures (1–365), encrypted at rest, then deleted by an automated sweeper.
New organisations default to "zero". Usage metadata (section 2) is always retained regardless of mode — it is how we bill and how you audit spend — but it never contains prompt or response text.

4Why we process it, and on what legal basis

PurposeBasis (GDPR/UK GDPR)Basis (India DPDP Act, 2023)
Providing the platform to an account holderPerformance of a contract (Art. 6(1)(b))Performance of a contract / legitimate use
Responding to a sales enquiry you submittedSteps prior to a contract at your request (Art. 6(1)(b))Consent, given when you submit the form
Billing, fraud prevention, security, abuse limitsLegitimate interests (Art. 6(1)(f))Legitimate use
Verifying your email by one-time codePerformance of a contract / legitimate interestsConsent
Marketing communicationsConsent (Art. 6(1)(a)), withdrawable at any timeConsent, withdrawable at any time
Meeting statutory and tax obligationsLegal obligation (Art. 6(1)(c))Legal obligation

Where we rely on consent you may withdraw it at any time; withdrawal does not affect processing already carried out.

5Sub-processors and third-party AI providers

Routing a request means sending it to an AI provider. This is the most important disclosure in this policy: the content of your prompt leaves our infrastructure and is processed by the provider that serves it, under that provider's own terms.

The following sub-processors are engaged in production today:

Sub-processorPurposeProcessing location
Google Cloud PlatformHosting, database, cache, object storage, key managementIndia (asia-south1, Mumbai)
Google Cloud Vertex AIAI model inference; text embeddings for optional semantic cacheIndia / global endpoints
AnthropicAI model inference (Claude models)United States
DeepInfraAI model inference (open-weight model catalogue)United States
Microsoft (Graph)Transactional email delivery only — no customer prompt contentEuropean Union / global

6International transfers

The NeuroRoute platform is hosted in India (Google Cloud asia-south1, Mumbai) and customer content stored under "retain" mode stays there.

Inference is different. Some AI providers listed above process requests in the United States or on multi-region endpoints, so a prompt may be transferred outside your country at the moment it is routed. For transfers of personal data out of the EEA or the UK we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, and on the transfer terms in each provider's data processing agreement.

If you need inference confined to a specific jurisdiction, use a per-key model allowlist or a self-hosted model endpoint, or contact us before you send regulated data.

7How long we keep it

DataRetention
Customer contentPer your retention mode — nothing at all, or 1–365 days as configured (section 3)
Usage and billing metadataRetained for the life of the account and then as required for tax and accounting law
Account dataFor the life of the account; anonymised on erasure
Sales enquiry dataUp to 24 months from last contact, unless you ask us to delete it sooner
One-time verification codes5 minutes, stored only as a hash
Security and audit eventsRetained to evidence access to the platform

8Your rights, and how to actually exercise them

Subject to the law that applies to you, you have rights of access, correction, erasure, restriction, objection, and portability, and the right not to be subject to a decision based solely on automated processing that produces legal effects. NeuroRoute's routing decisions select a model; they do not make decisions about people.

Several of these are self-service rather than a support ticket:

We respond within 30 days (GDPR/UK GDPR) or 45 days (CCPA/CPRA, acknowledged within 10 business days), extendable where the law permits and we tell you why. There is no charge unless a request is manifestly unfounded or excessive.

If you are an end user whose data reached us through a customer's application, we will refer your request to that customer, who is your controller.

9Security

No system is perfectly secure. We do not claim a certification we do not hold; if you need our current security documentation for a vendor review, ask at legal@sislcloudworx.com. Where a personal data breach is likely to result in a risk to individuals we notify the competent supervisory authority within 72 hours of becoming aware, and affected individuals and customers without undue delay.

10Cookies

The NeuroRoute application sets only what it needs to work: a session cookie for authentication and preference storage for your dashboard. We do not run advertising cookies or cross-site trackers on the application.

Where analytics cookies are used on our marketing pages they are set only with your consent, and you can withdraw it at any time through your browser or our cookie controls.

11Children

NeuroRoute is a business product and is not directed to children. We do not knowingly collect personal data from anyone under 18. Under the India DPDP Act, processing children's data requires verifiable parental consent, which our sign-up flow is not designed to obtain; if you believe a child has provided us data, contact us and we will delete it.

12Changes to this policy

We may update this policy. Material changes affecting how we handle customer content will be notified to account holders by email or in-product notice before they take effect, and the effective date above will change. Continued use after that date means the updated policy applies.

13Contact and grievance redressal

We aim to acknowledge grievances within 24 hours and resolve them within 15 days, as the IT Rules require. If you are in the EEA or UK you also have the right to complain to your local supervisory authority; if you are in India, to the Data Protection Board.

This policy describes controls the platform actually implements. Where a control is optional or tier-limited it says so.

Questions about this document? legal@sislcloudworx.comBack to home