Please read this privacy policy carefully before using our services.
Last Updated : 20th April 2026
Thank you for choosing to be part of our company i.e. Runo by Rutakshi Technologies Private Limited (“company”, “we”, “us”, or “our”). We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about our policy, or our practices with regards to your personal information, please contact us at Quadrant 1, Cyber Towers, Hitech City, Madhapur, Hyderabad, Telangana, India or send us email to care@runo.ai
When you visit our website www.runo.in or application at Google play store or Apple App Store and use our services, you trust us with your personal information. We take your privacy very seriously. In this privacy notice, we describe our privacy policy. We seek to explain to you in the clearest way possible what information we collect, how we use it and what rights you have in relation to it. We hope you take some time to read through it carefully, as it is important.
The mobile application or the website platform or software can be used in following manner.
The Product RUNO is available only in the application format and can be accessed through Google “play store” and Apple “App store”. The application requires login and the data is stored on the device of the user as well as our cloud storage hosted on AWS. The application also allows user to save notes and status in the application, with the data being stored in the customer device. The user can use the short messaging service or message through apps like WhatsApp or email for sending any communication with the customer. The application uses device storage to read media information such as Call Recordings and Call Logs and this information is sent to our Cloud servers.
The applicant creates a login to start using our service. The service is free for 10 (Ten) days and chargeable thereafter based on the tariff shown at the time of payment.
This privacy policy applies to all information collected through our website or mobile application (such as www.runo.in, Android or IOS Application) ("Apps"), and/or any related services, sales, marketing or events (we refer to them collectively in this privacy policy as the "Sites").
Please read this privacy policy carefully as it will help you make informed decisions about sharing your personal information with us.
In Short: We collect personal information that you provide to us such as name, address, contact information, passwords and security data and payment information (if applicable) data.
We collect personal information that you voluntarily provide to us when registering at the Sites or Apps, expressing an interest in obtaining information about us or our products and services, when participating in activities on the Sites such as posting messages in our online forums or entering competitions, contests or giveaways or otherwise contacting us.
The personal information that we collect depends on the context of your interactions with us and the Sites, the choices you make and the products and features you use. The personal information we COLLECT can include the following:
As per details on www.runo.in or the application installed
All personal information that you provide to us must be true, complete and accurate, and you must notify us of any changes to such personal information.
In Short: Some information – such as IP address and/or browser and device characteristics – is collected automatically when you visit our websites.
We automatically collect certain information when you visit, use or navigate the Sites. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Site and other technical information. This information is primarily needed to maintain the security and operation of our Sites, and for our internal analytics and reporting purposes.
Like many businesses, we also collect information through cookies and similar technologies. You can find out more about this in our Cookie Policy
In Short: We may collect information regarding your geo-location, mobile device, and push notifications when you use our apps.
If you use our Apps, we may also collect the following information:
In Short: We may collect limited data from public databases, marketing partners, social media platforms, and other outside sources.
We may obtain information about you from other sources, such as public databases, joint marketing partners, social media platforms (such as Facebook), as well as from other third parties. Examples of the information we receive from other sources include: social media profile information (your name, gender, birthday, email, current city, state and country, user identification numbers for your contacts, profile picture URL and any other information that you choose to make public); marketing leads and search results and links, including paid listings (such as sponsored links).
In Short: We process your information for purposes based on legitimate business interests, the fulfilment of our contract with you, compliance with our legal obligations, and/or your consent.
We use personal information collected via our Sites for a variety of business purposes described below. We process your personal information for these purposes in reliance on our legitimate business interests, in order to enter into or perform a contract with you, with your consent, and/or for compliance with our legal obligations. We indicate the specific processing grounds we rely on next to each purpose listed below.
We use the information we collect or receive:
In Short: We only share information with your consent, to comply with laws, to protect your rights, or to fulfil business obligations. We only share and disclose your information in the following situations:
In Short: We may use cookies and other tracking technologies to collect and store your information.
We may use cookies and similar tracking technologies (like web beacons and pixels) to access or store information.
Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Policy.
In Short: Yes, we use Google Maps for the purpose of providing better service.
This website or mobile application uses Google Maps APIs. You may find the Google Maps APIs Terms of Service here. To better understand Google’s Privacy Policy, please refer to this link.
By using our Maps API Implementation, you agree to be bound by Google’s Terms of Service. By using our implementation of the Google Maps APIs, you agree to allow us to gain access to information about you including personally identifiable information (such as usernames) and non-personally identifiable information (such as location).
For a full list of what we use information for, please see the previous sections. You agree to allow us to obtain or cache your location. You may revoke your consent at anytime. We use information about location in conjunction with data from other data providers.
If you choose to connect your Google account to RUNO, our system will request access to read email metadata and send emails on your behalf (gmail.readonly and gmail.send scopes).
In Short: We use regional data hosting based on the customer’s primary business or service location.
Our regional data-hosting arrangements are as follows:
Production data, databases, call recordings, application data, backups and replicas are maintained within the customer’s applicable hosting region, unless a different arrangement is expressly agreed with the customer in writing.
Rutakshi Technologies Private Limited is based in India. Authorised RUNO personnel located in India may have limited remote access to data hosted in the European Economic Area or the United Kingdom where access is necessary to provide technical support, maintain the Services, investigate security incidents or meet our legal and contractual obligations.
Such access is limited according to role and business need and is protected through appropriate access controls, authentication, access logging, confidentiality obligations and other technical and organisational safeguards. Remote access from India does not change the customer’s designated hosting location, but it may constitute an international transfer under applicable data-protection law.
For transfers of personal data from the European Economic Area to India or another country not covered by an adequacy decision, we use an applicable lawful transfer mechanism. This may include the European Commission’s Standard Contractual Clauses, a transfer impact assessment and supplementary technical, contractual and organisational safeguards.
For transfers of personal data from the United Kingdom to India or another country not covered by UK adequacy regulations, we use an applicable lawful transfer mechanism. This may include the UK International Data Transfer Agreement, the UK Addendum to the European Commission’s Standard Contractual Clauses, a data protection test and supplementary safeguards.
Some third-party service providers may process personal data in other countries. We assess relevant providers and require appropriate contractual, confidentiality and security protections.
Further information about our hosting locations and international-transfer safeguards may be requested from our Data Protection Officer.
In Short: We keep your information for as long as necessary to fulfil the purposes outlined in this privacy policy unless otherwise required by law.
We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy policy, unless a longer retention period is required or permitted by law (such as tax, accounting or other legal requirements). No purpose in this policy will require us keeping your personal information for longer than 1 year past the termination of your account
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
For users located in the European Economic Area or the United Kingdom, we delete or anonymise personal data within one month following termination of the Services where contractually agreed or requested by the relevant controller, unless a longer retention period is required or permitted by applicable law. Where information remains in protected backups, it will be isolated from further processing and deleted in accordance with the applicable backup-retention schedule.
In Short: We aim to protect your personal information through a system of organizational and technical security measures.
We have implemented appropriate technical and organizational security measures designed to protect the security of any personal information we process. However, please also remember that we cannot guarantee that the internet itself is 100% secure. Although we will do our best to protect your personal information, transmission of personal information to and from our Sites is at your own risk. You should only access the services within a secure environment.
In Short: We do not knowingly collect data from or market to children under 18 years of age.
We do not knowingly solicit data from or market to children under 18 years of age. By using the Sites, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the Site and App. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we have collected from children under age 18, please contact us at care@runo.ai
Our product is only accessible to employees of client companies who are expected to be over 18. In rare cases involving minors, we collect data only with verified parental consent.
In short: We have appointed a Data Protection Officer (DPO) to oversee all data protection activities and ensure legal compliance. You may contact our DPO using the details below:
Name: Vamsi P
Email: vamsi@runo.in
Phone: 94915 58725
DPO Roles and Responsibilities:
In Short: Depending on your location, you may have rights that allow you to access and control your personal data.
If you are located in the European Economic Area or the United Kingdom, your rights under applicable data-protection law may include the right to:
These rights may be subject to conditions and exemptions under applicable law. To exercise a right, contact us using the details provided in this Privacy Policy. We may need to verify your identity before completing your request.
Withdrawing consent will not affect the lawfulness of processing carried out before consent was withdrawn.
If you are located in the European Economic Area, you may complain to the data-protection authority in the country where you live, work or believe an infringement occurred.
If you are located in the United Kingdom, you may complain to the Information Commissioner’s Office at https://ico.org.uk. We encourage you to contact us first so that we can try to resolve your concern.
Obtaining Consent: Our privacy policy details transparently the purposes of data processing, the affirmative actions required for consent, and the granularity of choices, ensuring individuals have clear control over their data.
Modification of Consent: Users can conveniently modify consent preferences through accessible settings, with notifications for changes, and comprehensive documentation maintained for all modifications.
Withdrawal of Consent: Clear instructions on withdrawing consent are provided in our privacy policy, ensuring no negative consequences, and a detailed record-keeping process is outlined for transparency and compliance.
You may at any time review or change the information in your account by:
Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, some information may be retained in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our Terms of Use and/or comply with legal requirements.
Cookies and similar technologies: Most Web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove cookies and to reject cookies. If you choose to remove cookies or reject cookies, this could affect certain features or services of our Sites.
In Short: Yes, if you are a resident of California, you are granted specific rights regarding access to your personal information.
California Civil Code Section 1798.83, also known as the “Shine The Light” law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided below.
If you are under 18 years of age, reside in California, and have a registered account with the Sites/ Mobile Application, you have the right to request removal of unwanted data that you publicly post on the Sites/ Mobile Application. To request removal of such data, please contact us using the contact information provided below, and include the email address associated with your account and a statement that you reside in California. We will make sure the data is not publicly displayed on the Sites/ Mobile Application, but please be aware that the data may not be completely or comprehensively removed from our systems.
In Short: Yes, we will update this policy as necessary to stay compliant with relevant laws.
We may update this privacy policy from time to time. The updated version will be indicated by an updated “Revised” date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy policy, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy policy frequently to be informed of how we are protecting your information.
We agree to abide by and maintain adequate data security measures, consistent with industry standards and technology best practices, to protect your Data from unauthorized disclosure or acquisition by an unauthorized person and is protected by HTTPS SSL and Firewall.
We intend to appraise that the currently application is running on AWS EC2 instances. Your data is stored in MongoDB also on AWS EC2 instances. There is an added layer of data security through this vendor in addition to our own data security layer.
Purpose:
The purpose of this Data Breach policy is to establish the goals and the vision for the breach response process.
Scope:
This policy applies to all employees and customers of our organisation who have been onboarded to the platform.
Policy:
As soon as a theft, data breach, or exposure containing Our Organisation’s Sensitive information or protected data is identified, the process of removing all access to that resource will begin.
The CEO/CTO of Our Organization will chair an incident response team to handle the breach or exposure. The team includes:
The CEO/CTO of Our Organisation will be contacted about the theft, breach, or exposure. The IT team will examine the breach or exposure to determine the root cause.
Any Our Organisation employee found in violation of this policy will be subjected to disciplinary action, up to and including termination of employment. Any third-party client/partner organization found in violation will have their contractual work terminated if any are active.
Identify a Personal Data Breach/Suspected Personal Data Breach:
There are several reasons why there can be a breach of personal data. For example:
Reporting an Incident:
It is vital that as soon as a Personal Data Breach is identified or suspected it is immediately reported to the IT Security team. To improve our understanding of the risks to data and address them before breaches occur, we would also encourage individuals to report ‘near misses’ (i.e. situations where a data breach would have occurred but for a miracle or "luck"). Near misses should be reported in the same way as a real breach, with the distinction that it was a near miss made very apparent.
All employees and contractors must report an actual or suspected personal data breach to RUNO’s Information Security Team at care@runo.ai as soon as possible and, where practicable, within 12 hours of discovery. This is RUNO’s internal reporting requirement.
Where RUNO is responsible for notifying a data-protection supervisory authority, a notifiable personal data breach will be reported without undue delay and, where feasible, within 72 hours after the controller becomes aware of it, as required under the EU GDPR and UK GDPR.
Where RUNO acts as a processor, RUNO will notify the relevant customer or controller without undue delay after becoming aware of a personal data breach affecting customer-controlled personal data.
Where a breach is likely to result in a high risk to individuals’ rights and freedoms, affected individuals will also be notified without undue delay where required by applicable law.
Investigating an Incident:
Depending on the type and severity of the incident, their team will analyse the form, update the Personal Data Breach Log, and determine whether any immediate corrective, containment, or escalation Officer along with his team will assess whether a full investigation into the breach is required. Where required the Data Information Security Officer along with his team will appoint an appropriate investigation team who will complete a full breach report.
Incident Investigation Policy
Procedures for Investigating Personal Data Breaches
Policy Statement
Upon identification of a personal data breach or a near-miss incident, the following procedures must be adhered to ensure a thorough and consistent response:
Reporting Breach to the CTO or Data Subject:
The IT Security Analyst will coordinate breach reporting to the CTO within a time period of becoming aware of a relevant breach. The ITSA will also evaluate whether the breach is ‘likely to result in a high risk to the rights and freedoms’ of the data subject. If this is found to be the case, the occurrence will also be immediately disclosed to the data subjects. Any such report will be coordinated by the CCO and Team. Assistance will be required from other teams, including Marketing, Sales, Customer Support, Tech, Communications and the Print Room should be made available on demand.
A risk to people’s freedoms can include physical, material, or non-material damage such as discrimination, identity theft or fraud, financial loss, and damage to reputation. When assessing the likelihood of the risk to people’s rights and freedoms, Our Organization will consider:
When considering the potential risk to individuals’ rights and freedoms, Our Organisation will assess:
Escalation:
The Personal Data Breach Log will be reviewed regularly by the CEO/CTO, who will determine whether any updates to Policy and Procedures are required, and coordinate any training and communications messages from the lessons learned. They may escalate a breach to the Board of Directors if required.
Timescales for Notification to the Supervisory Authority:
Content of Breach Notification to The Supervisory Authority:
Timescales for Notification to Affected Individuals:
Where a notifiable breach has occurred, which is deemed to have a high risk to the rights and freedoms of individuals, Our Organisation will notify the affected individuals themselves, i.e. the people whose information was compromised, in addition to the supervisory authority. This notification will be made without undue delay and may, dependent on the circumstances, be made before the supervisory authority is notified.
A situation with high risk can be one in which identity theft is a serious concern right away or in which certain types of data are made public online.
Content of Breach Notification to The Affected Individuals
When a breach is reported, the following details will be given to the impacted parties:
Record of Breaches
Our Organisation records all personal data breaches regardless of whether they are notifiable or not as part of its general accountability requirement under GDPR. It documents the facts about the breach, its consequences, and the corrective measures implemented.
ENFORCEMENT
We expect all employees to comply with this policy and any related policies, standards, processes, procedures, and guidelines. Failure and/or refusal to abide by this policy may be deemed a violation. Compliance with the policies will be a matter of periodic review by the Information Security Officer / Information Security Team. Any employee found to have violated this policy may be subject to disciplinary action, as deemed appropriate by management and Human Resources policies.
Monitoring: The company employs appropriate technology solutions to monitor policy/ procedure compliance.
Self-Assessment: The CEO/CTO are required to conduct self-assessment within their areas of control to verify compliance with this policy/ procedure.
SPECIAL CIRCUMSTANCES AND EXCEPTIONS
All exceptions to this policy/ procedure will require a waiver explicitly approved by one of Our Organisation's CEO/CTO.
If you have questions or comments about this policy, email us RUTAKSHI TECHNOLOGIES PVT LTD at care@runo.ai or by post to:
RUTAKSHI TECHNOLOGIES PVT LTD
Rajsekhar Patnaik
India
Quadrant 1, Cyber Towers, Hitech City, Madhapur, Hyderabad, Telangana, India - 500081
United Kingdom
10 John Street, London, United Kingdom, WC1N 2EB
If you are a resident in the European Economic Area, the "data controller" of your personal information is RUTAKSHI TECHNOLOGIES PVT LTD. RUTAKSHI TECHNOLOGIES PVT LTD , has appointed Rajsekhar Patnaik to be its representative in the EEA. You can contact them directly regarding the processing of your information by COMPANY, by email at care@runo.ai or by post to:
RUTAKSHI TECHNOLOGIES PVT LTD
Rajsekhar Patnaik
India
Quadrant 1, Cyber Towers, Hitech City, Madhapur, Hyderabad, Telangana, India - 500081
United Kingdom
10 John Street, London, United Kingdom, WC1N 2EB
We expect all employees to comply with this policy and any related policies, standards, processes, procedures, and guidelines. Failure and/or refusal to abide by this policy may be deemed a violation. Compliance with the policies will be a matter of periodic review by the Information security officer / Information Security Team. Any employee found to have violated this policy may be subject to disciplinary action, as deemed appropriate by management and Human Resources policies.
Monitoring: The company employs appropriate technology solutions to monitor policy/ procedure compliance.
Self-Assessment: The CEO/CTO are required to conduct self-assessment within their areas of control to verify compliance with this policy/ procedure.
In short: Exceptions are rare and require approval. Any deviation from this Privacy Policy must be formally approved by the CEO or CTO of Runo. No other waivers will be considered valid.
If you have any further questions or comments about us or our policies, email us at care@runo.ai or by post to:
RUTAKSHI TECHNOLOGIES PVT LTD
Rajsekhar Patnaik
India
Quadrant 1, Cyber Towers, Hitech City, Madhapur, Hyderabad, Telangana, India - 500081
United Kingdom
10 John Street, London, United Kingdom, WC1N 2EB