Legal
Security
Effective Date: April 11, 2026
Security is part of how Dona AI is built, not an afterthought bolted on later. This page explains, at a high level, how we protect the call data and analysis that pass through the platform.
1. Data in Transit and at Rest
All traffic to and from Dona AI is encrypted using TLS. Call recordings, transcripts, and analysis results are encrypted at rest in our database and storage layers.
2. Access Control
Access to customer data is role-based and limited to what a person's job requires. Internal access to production systems is logged and reviewed periodically.
3. Data Retention
Call recordings and derived data are retained according to a configurable retention policy per organization. Customers can request deletion of their data at any time.
4. Webhook and Integration Security
Data sent into Dona AI over webhooks is authenticated per organization. API keys can be rotated or revoked at any time from your workspace settings.
5. Infrastructure
Dona AI runs on reputable cloud infrastructure with network isolation between tenants and regular security patching of underlying systems.
6. Incident Response
If we become aware of a security incident affecting customer data, we will notify affected organizations without undue delay and take steps to contain and remediate the issue.
7. Responsible Disclosure
If you believe you've found a security vulnerability in Dona AI, please report it to us — we take these reports seriously and will respond promptly.
8. Contact Us
For security questions or to report a vulnerability, contact us at:
- Email: admin@dona.ai.in
- WhatsApp: +91 74835 76065
This page describes our current security practices and may be updated as the product evolves. It is not a certification or compliance attestation.
