Privacy Policy

Effective Date: 28 September 2026

Walkover Web Solutions Pvt. Ltd. (“Walkover,” “we,” “our,” or “us”) respects your privacy and is committed to protecting the Personal Data you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you and your organization use Liliphant (the “Platform”) — a meeting intelligence service that joins your scheduled meetings, records and transcribes them, and produces a summary, the key topics and the action items afterwards.

Note: Liliphant is designed for business-to-business (B2B) use. Where your organization deploys the Platform for its workforce, your employer acts as the Data Controller and determines which meetings are recorded and what data are processed. We act as a Data Processor and handle data only under your organization’s instructions.

1. Scope

This Policy applies to information processed through the Platform, our related websites, desktop application, dashboards, APIs, and any associated services (collectively, the “Services”). It does not apply to:

  • Third-party sites or services that integrate with the Platform, including your calendar provider and the meeting platform a call is held on.
  • Data your organization collects or processes outside the Platform.

2. Information We Collect

2.1 Data You or Your Organization Provide

CategoryExamples
Account & Profile DataBusiness email, name, job title, company, phone number, authentication credentials.
Meeting ContentAudio and video recordings of meetings the Platform is asked to join, transcripts, speaker labels, meeting titles, invitee and participant lists, and the notes you write against a meeting.
Connections & ConfigurationCalendar and scheduling authorizations, which calendars or event types are watched, meeting links, and the teams and members your organization sets up.
Support & FeedbackChat transcripts, bug reports, survey responses.

2.2 Data We Collect Automatically

  • Usage Data: Log files, timestamps, feature interaction, error reports.
  • Device & Connection Data: IP address, browser type, operating system, device identifiers.
  • Telemetry: Performance metrics, API call metadata (method, latency, status code), and processing records for each meeting — when a bot was booked, whether it joined, how long transcription took and what it cost.

2.3 Data from Integrations

When you connect a calendar or scheduling account — Google Calendar, Calendly or Cal ID — we read the events it holds so we know which meetings to join. That includes each event’s title, description, time, organizer, invitee list and conferencing link. We read only the calendars or event types you choose to watch, and only within the scopes you authorize.

2.4 Information About Meeting Participants

A meeting usually includes people who have no Liliphant account and may not be part of your organization — clients, candidates, vendors, guests. When the Platform joins such a meeting it necessarily processes their voice, image, name and spoken words as part of the recording and transcript.

We process this information solely as a Data Processor, on the instructions of the organization that asked us to join. That organization is responsible for having a lawful basis to record, and for giving the notice described in Section 4.

3. How We Use Information

We process data to:

  1. Provide the Platform and its core functions — reading your calendar to find meetings, sending a bot to join them, recording and transcribing the conversation, and generating the summary, key topics and action items.
  2. Secure and maintain the Services (fraud prevention, debugging, backup, disaster recovery).
  3. Improve and develop features and user experience (aggregated analytics, A/B testing).
  4. Support you (respond to inquiries, provide documentation, onboarding, and training).
  5. Comply with legal obligations (tax, accounting, export controls, data-protection laws).

We do not use your recordings, transcripts or any other meeting content to train publicly available AI models. Where we improve our underlying systems, we use only aggregated and anonymized data, or data with your organization’s written consent.

Recording a conversation is the one thing the Platform does that other people in the room can feel, so we are specific about it.

  • The bot is visible. It joins as a named participant, appears in the participant list like anyone else, and can be removed from the call by any participant with the ability to do so.
  • It announces itself. On joining, it posts a message in the meeting chat stating that it is recording and that a summary, key topics and action items will be shared afterwards.
  • Consent is the customer’s responsibility. Recording laws differ by jurisdiction, and some require the consent of every participant rather than only the organizer. The organization that connects a calendar decides which meetings are recorded, and is responsible for obtaining whatever consent its jurisdiction and its participants’ jurisdictions require. The in-meeting notice above is a courtesy and a signal — it is not, by itself, legal consent.
  • Meetings can be excluded. Your administrator controls which calendars and event types are watched, and can stop a meeting from being joined or delete a recording afterwards.

5. Google User Data and Limited Use

Liliphant’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: we request read access to your calendar only, we use the events we read only to identify and join the meetings you have asked us to join, we do not transfer Google user data to third parties except as needed to provide the Service or as required by law, we do not use Google user data for advertising, and no human reads it except with your explicit permission, for security purposes, or where the law requires it. Revoking our access in your Google account, or disconnecting the account in Liliphant, stops this immediately.

If the EU/UK GDPR applies, our lawful bases are:

  • Contractual Necessity (Art. 6(1)(b)) — to provide Services to your organization.
  • Legitimate Interests (Art. 6(1)(f)) — to safeguard, improve, and market the Services (we balance these interests against your rights).
  • Legal Obligation (Art. 6(1)(c)).
  • Consent (Art. 6(1)(a)) for optional features or marketing where required, and for recording where your organization relies on consent as its basis.

7. Cookies & Similar Technologies

We use session cookies, local storage, and similar technologies for authentication, security, and analytics. You can control cookies through your browser settings, but disabling them may affect functionality — including staying signed in.

8. Sharing & Disclosure

We share data only as necessary:

  • Within Walkover (affiliated entities under common ownership, bound by this Policy). Identity and sign-in are handled by MSG91, and integrations are brokered by viaSocket — both Walkover services.
  • Service Providers & Sub-Processors under strict data-processing agreements. Meeting content reaches a small, fixed set of them: Recall.ai supplies and hosts the meeting bot and the recording it captures; AssemblyAI produces the transcript; and our AI gateway, GTWY, runs the transcript through a language model to produce the summary, key topics and action items. Cloud hosting, database and message-queue providers hold the resulting records.
  • Third-Party Integrations you enable (per scopes granted).
  • Corporate Transactions (merger, acquisition — subject to confidentiality).
  • Legal Requirements (court orders, lawful requests). We will notify you of legal requests where legally permissible.

We do not sell or rent Personal Data, and we do not share meeting content between companies. Each company on the Platform is a separate environment: a meeting filed to one is not visible from another.

9. International Data Transfers

We are based in India, with servers and partners in multiple regions. When transferring Personal Data across borders, we rely on:

  • Standard Contractual Clauses (SCCs) or equivalent safeguards for EEA/UK data.
  • Adequacy decisions or explicit consent where applicable.
  • Digital Personal Data Protection Act, 2023 (India) compliance.

10. Data Security

We implement administrative, technical, and physical safeguards such as:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access controls (RBAC) & Multi-Factor Authentication (MFA).
  • Separation of each company’s data, enforced on every query rather than by convention.
  • Network segmentation & firewalling.
  • Regular penetration testing & code reviews.
  • 24×7 infrastructure monitoring.

11. Data Retention

We retain Personal Data only for as long as necessary to fulfill the purposes outlined in this Policy, including legal, accounting, or reporting requirements. Recordings, transcripts and the summaries derived from them are retained for the term of your organization’s contract, and can be deleted earlier at your administrator’s request.

Upon contract termination, your organization may request deletion or export of data; backups are overwritten within 30 days.

12. Your Rights

Depending on your location, you may have rights to:

  • Access, correct, or delete Personal Data.
  • Object to or restrict processing.
  • Port data to another service.
  • Withdraw consent.
  • Lodge a complaint with a supervisory authority.

Please contact your organization’s administrator or email us at privacy@walkover.in to exercise these rights. We will cooperate with your organization to fulfil requests.

If you took part in a recorded meeting but are not a customer of ours, write to the same address and we will route your request to the organization that recorded it — they are the Data Controller and the deletion is theirs to instruct.

13. Children's Privacy

The Services are not directed to children under 18. We do not knowingly collect Personal Data from children.

14. Changes to This Policy

We may update this Policy periodically. Material changes will be notified via email or an in-app banner at least 14 days before the new version takes effect. Continued use after the effective date constitutes acceptance.

15. Contact Us

Walkover Web Solutions Pvt. Ltd.

5th Floor, Wing B, LIC Tower, 28-29-30, PU-03, Scheme No. 54
Indore – 452011, Madhya Pradesh, India
Email: privacy@walkover.in
Phone: +91 731 2560056

If you have questions about this Policy or our privacy practices, please contact us using the details above.

Last updated: 28 September 2026