Last updated: July 19, 2026
This Privacy Policy explains how Olensys Private Limited, a company incorporated in India with its registered office in Ahmedabad, Gujarat, India ("Olensys", "we", "us", "our"), collects, uses, discloses, and protects personal data in connection with TheenkAI — our AI-powered platform for chat, autonomous AI agents, workflows, productivity, and voice agents — and our websites theenk.ai and olensys.com (together, the "Service").
By using the Service, you acknowledge this Privacy Policy. If you do not agree with it, please do not use the Service.
Understanding our role matters, because it determines who is responsible for your data and whom you should contact to exercise your rights.
(a) Olensys as controller / data fiduciary. We decide how and why to process personal data when you visit our websites, create an account, subscribe, contact support, or receive our communications. This Policy fully describes that processing.
(b) Olensys as processor / data processor. When a business customer of ours ("Customer") deploys TheenkAI agents that interact with the Customer's own end users ("End Users") — for example, a chat widget or voice agent on the Customer's website or phone lines — we process End User personal data on behalf of and under the instructions of that Customer. In that context, the Customer is the controller (or data fiduciary) and its privacy policy governs. If you are an End User and want to access, correct, or delete data collected through a Customer's deployment of TheenkAI, please contact that Customer directly. We will assist Customers in responding to such requests as required by law and our Data Processing Agreement ("DPA").
As a controller, we collect:
As a processor on behalf of Customers, we process:
We do not intentionally collect sensitive or special categories of personal data (such as health, biometric, or financial account data) as a controller. Customers are responsible for ensuring they have a lawful basis before submitting any such data through the Service.
We use personal data that we control to:
AI model training: We do not use Customer Content, End User Data, or AI outputs to train or fine-tune generalized AI/ML models, and we require our third-party AI model providers, by contract, not to use data submitted through our API integrations to train their models.
Where the EU or UK GDPR applies and we act as controller, we rely on: contract performance (providing the Service you or your organization signed up for); legitimate interests (securing and improving the Service, preventing fraud, B2B marketing — balanced against your rights); consent (non-essential cookies, certain marketing — withdrawable at any time); and legal obligation (tax, accounting, and regulatory compliance).
We do not sell personal data, and we do not share it for cross-context behavioral advertising. We share personal data only with:
We are based in India and use service providers located in India, the United States, the European Union, and other countries. Where personal data subject to the GDPR/UK GDPR is transferred outside the EEA/UK, we implement appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement), together with supplementary measures where needed. Transfers of data governed by India's Digital Personal Data Protection Act, 2023 ("DPDP Act") are made in accordance with that Act and any countries restricted by the Central Government.
We retain personal data only as long as needed for the purposes described in this Policy: account data for the life of the account and a reasonable period thereafter; billing records as required by tax and company law; Customer Content and End User Data for the duration of the Customer's subscription and up to 30 days after termination (for export), after which it is deleted from our active systems, with backups purged in the ordinary course; support communications and logs for as long as reasonably necessary for security, audit, and legal purposes. When retention ends, we delete or irreversibly anonymize the data.
We implement technical and organizational measures appropriate to the risk, including encryption in transit, access controls, network security, logging and monitoring, and personnel confidentiality obligations. No system is perfectly secure; we cannot guarantee absolute security. If we become aware of a personal data breach, we will notify affected parties and regulators as required by applicable law (including the DPDP Act and, where applicable, the GDPR's 72-hour notification requirement to supervisory authorities).
Depending on where you live, you may have some or all of the following rights regarding personal data we control. We honor requests as required by the law applicable to you.
European Economic Area / United Kingdom (GDPR / UK GDPR). You have the right to access, rectify, and erase your personal data; to restrict or object to processing (including objecting to direct marketing at any time); to data portability; to withdraw consent at any time without affecting prior processing; and to lodge a complaint with your supervisory authority (in the UK, the ICO).
California (CCPA/CPRA) and other US states. You have the right to know/access, correct, and delete personal information; the right to opt out of "sale" or "sharing" of personal information (we do not sell or share personal information as defined by the CCPA/CPRA); the right to limit use of sensitive personal information (we do not use it for purposes requiring this right); and the right not to be discriminated against for exercising your rights. You may use an authorized agent to submit requests. We recognize opt-out preference signals such as Global Privacy Control for the browser you use.
India (DPDP Act, 2023). You have the right to access a summary of your personal data and processing activities; to correction, completion, updating, and erasure; to grievance redressal; to nominate another individual to exercise your rights in case of death or incapacity; and to withdraw consent where processing is based on consent. You also have the right to complain to the Data Protection Board of India if your grievance is not satisfactorily resolved.
Everywhere. You can opt out of marketing emails at any time via the unsubscribe link or by emailing support@theenk.ai.
How to exercise rights. Email support@theenk.ai with your request. We may need to verify your identity before acting. We respond within the timelines required by applicable law. If you are an End User of one of our Customers, we will refer your request to that Customer (see Section 1) and assist them as required.
We use cookies and similar technologies as described in our Cookie Policy, which explains what we use, why, and how to manage your preferences, including consent and withdrawal where required by law.
The Service is a business tool intended for users 18 years of age or older. We do not knowingly collect personal data from children, and the Service is not directed at them. If you believe a child has provided personal data to us, contact support@theenk.ai and we will delete it. Customers must not deploy TheenkAI in ways directed at children without complying with all applicable children's-privacy laws; they bear responsibility for such deployments.
The Service may link to or integrate with third-party websites and services. Their privacy practices are governed by their own policies, and we are not responsible for them. This includes Paddle's checkout (Paddle is an independent controller of checkout data) and any integrations a Customer chooses to connect.
We do not use personal data we control to make automated decisions that produce legal or similarly significant effects on individuals. Customers configure and deploy AI agents; Customers are responsible for ensuring their deployments comply with laws governing automated decision-making and for providing any required human review.
We may update this Privacy Policy from time to time. We will post the updated version with a revised "Last updated" date and, for material changes, provide notice by email or through the Service before the changes take effect. Your continued use of the Service after the effective date constitutes acknowledgment of the updated Policy.
Olensys Private Limited Registered office: Ahmedabad, Gujarat, India Email: support@theenk.ai
Grievance Officer (under the Information Technology Act, 2000 / IT Rules, 2021 and the DPDP Act, 2023): Krishnal Jadav Email: support@theenk.ai
We endeavor to acknowledge and resolve grievances within the timelines prescribed by applicable law. If you are in the EEA/UK and believe we have not addressed your concern, you may contact your local data protection authority; in India, you may approach the Data Protection Board of India.