Privacy Policy
Last updated: March 2026
AGZ Technologies Private Limited ("Macha", "we", "us", "our") operates the getmacha.com website and the Macha AI platform. This privacy policy explains how we collect, use, disclose, and protect personal information when you use our services. Macha provides AI-powered agents that integrate with third-party tools including Zendesk, Slack, Notion, Google Workspace, Shopify, Stripe, and others to help support teams work more efficiently.
By using Macha, you agree to the terms of this policy. If you do not agree, please discontinue use of our services.
Data Controller and Contact
The data controller for personal information collected through Macha is AGZ Technologies Private Limited, registered in India. For privacy questions or to exercise your rights, contact [email protected]. For general support: [email protected].
Information We Collect
We collect the following categories of personal information:
- Account information: Name, email address, phone number, payment details, and identity verification documents.
- Activity and usage data: IP address, device type, browser, operating system, timestamps, referrer URLs, feature usage, and session analytics.
- Integration data: Content accessed through connected third-party services (support tickets, messages, documents, orders, and similar records) as authorised by the user.
- User-generated content: Agent configurations, instructions, prompts, and business information you provide through the platform.
- Client data: Information submitted by your end-users when they interact with customer-facing AI agents you deploy through Macha.
- Demo and enquiry data: Email addresses, company names, and role details submitted through demo booking and contact forms.
- Communications: Records of your correspondence with us, including support tickets, chat transcripts, and email exchanges.
- Inferences: Insights we derive from the above categories to characterise usage patterns and product preferences.
Payment processing occurs through external gateways (Chargebee, Stripe, Razorpay) and follows those providers' own retention policies.
Sources of Personal Information
We obtain personal information from the following sources:
- Directly from you when you create an account, book a demo, contact us, or use our services.
- Automatically from your device and browser when you interact with our website or product.
- From third-party services you connect to Macha, under the scopes and permissions you grant.
- From end-users of your AI agents when they interact with the agents you deploy.
- From publicly available sources or business partners for lead qualification and account enrichment.
How We Use Your Information
We use collected information for the following purposes:
- Providing, maintaining, and improving the Macha platform and its AI agent functionality.
- Account access control, authentication, and personalising your experience.
- Processing payments, billing, and subscription management.
- Administrative communications, service updates, and transactional emails.
- Internal analytics, product research, and performance improvement.
- Marketing and promotional communications, with consent where required by law.
- Security, fraud prevention, abuse detection, and enforcement of our terms.
- Compliance with legal obligations and cooperation with law enforcement.
Legal Bases for Processing (GDPR)
Where the General Data Protection Regulation (GDPR) or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract: To provide the services you have signed up for, process payments, and honour our contractual obligations.
- Legitimate interests: To operate, improve, and secure our services, communicate with you about your account, and pursue lawful commercial activities where those interests are not overridden by your rights and freedoms.
- Consent: For optional cookies, marketing communications, and any processing that requires your explicit opt-in. You may withdraw consent at any time.
- Legal obligations: To comply with applicable tax, accounting, and regulatory requirements, and to respond to lawful government requests.
Third-Party Integrations
Macha connects to third-party services on behalf of users to power AI agent functionality. When you connect an integration, we access only the data necessary to perform the actions you configure. Supported integrations include but are not limited to:
- Support platforms: Zendesk, Freshdesk, Gorgias, Front
- Communication tools: Slack, email
- Knowledge and productivity: Notion, Google Docs, Google Sheets, Airtable, Confluence, Document360
- E-commerce and payments: Shopify, Stripe, Razorpay
- Google Workspace: Gmail, Calendar, Docs, Sheets, and Drive (accessed via OAuth)
Data accessed through integrations is processed by our AI providers (OpenAI, Anthropic, Groq) solely for agent functionality and user-requested actions. OAuth tokens are stored encrypted. Integration content is accessed at request time and is not permanently stored unless you explicitly configure it as a knowledge source. You can disconnect any integration at any time through your account settings.
Third-Party Sharing and Recipients
We share personal information with the following categories of recipients:
- AI and LLM providers (OpenAI, Anthropic, Groq) for processing agent requests. Enterprise providers operate under zero data retention agreements where available.
- Cloud infrastructure providers (DigitalOcean, MongoDB Atlas) for hosting and data storage.
- Payment processors (Chargebee, Stripe, Razorpay) for transaction processing and subscription management.
- Analytics and marketing platforms (Google Analytics, Google Tag Manager, Meta Pixel, Microsoft Clarity, Hotjar, LinkedIn Insight Tag, Twitter Pixel, Google Ads) for website measurement and marketing attribution, subject to your cookie preferences.
- Transactional email providers (Postmark) for account-related email delivery.
- Government agencies and legal authorities when required by law, subpoena, or court order.
- Successors in interest in connection with a merger, acquisition, financing, or sale of assets, with notice to affected users.
We do not sell personal information for monetary consideration. Certain cookie-based sharing with advertising and analytics partners may fall within the definition of "sale" or "sharing" under specific state privacy laws (see the California Privacy Rights section below).
A current list of our sub-processors is available in our Data Processing Agreement. We notify customers of material changes to our sub-processor list at least 30 days in advance where feasible.
International Data Transfers
Macha is operated from India, and our AI and infrastructure providers are located primarily in the United States and the European Union. Where we transfer personal information out of your country, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Addendum, the EU-U.S. Data Privacy Framework where applicable, and adequacy decisions where available. A copy of the safeguards we use is available on request from [email protected].
Cookies and Tracking
Our website uses cookies for session management, analytics, and marketing. For details about the categories of cookies we use and how to manage your preferences, see our Cookie Policy. Our website honours the Global Privacy Control (GPC) signal and treats it as a valid request to opt out of the sale or sharing of personal information for cross-context behavioural advertising.
Data Security
We implement industry-standard security measures to protect your data, including TLS encryption in transit, encryption at rest, role-based access controls, secrets management, credential encryption in internal logs, and regular security assessments. We maintain zero data retention arrangements with our AI providers for customer conversation content where available. Staff may access customer accounts only for support, security, or legal purposes, with appropriate authorisation and audit logging. For more detail, see our Security page.
Data Retention
We retain personal information only for as long as necessary for the purposes described in this policy:
- Account and profile data: For the life of your account plus 30 days after account deletion, unless a longer retention is required by law or for legitimate legal defence.
- Conversation data: Chat conversations auto-expire after 45 days of inactivity (configurable per organisation for Enterprise plans).
- Internal AI logs: Auto-expire after 7 days.
- Chat attachments: Auto-expire after 30 days via storage lifecycle rules.
- Billing and transactional records: Retained for the period required by applicable tax and accounting laws (typically up to 7 years).
- Support communications: Retained for up to 2 years for quality and troubleshooting purposes.
- Marketing consent records: Retained while your consent is active and for 3 years thereafter for audit purposes.
When you delete your account, we schedule your data for deletion within 30 days and cascade-remove associated records across our storage systems.
Automated Decision-Making
Macha's core functionality involves automated processing by large language models to generate responses and take actions on your behalf or on behalf of your end-users. This processing does not produce legal effects or similarly significant effects for individuals in the sense of Article 22 of the GDPR. Agents you configure operate under instructions and permissions you control, and confirmation gates are available for high-impact actions. If you believe an automated decision has affected you significantly, you may contact us to request human review at [email protected].
Data Breach Notification
If we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify affected users and, where required, the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 and 34 of the GDPR and analogous obligations under other applicable laws. For customers where Macha acts as a processor, notification timelines and procedures are governed by our Data Processing Agreement.
Children's Privacy
Macha is a business-to-business platform and is not directed to children. We do not knowingly collect personal information from children under the age of 16 (or the applicable minimum age in your jurisdiction). If you become aware that a child has provided personal information to us, please contact [email protected] and we will take steps to delete that information.
Your Rights
Depending on your jurisdiction, you have the following rights with respect to your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request that we correct inaccurate or incomplete data.
- Deletion: Request that we delete your personal information.
- Restriction: Request that we restrict processing of your data in specific circumstances.
- Objection: Object to processing based on our legitimate interests, including for direct marketing.
- Portability: Receive your data in a structured, machine-readable format.
- Withdraw consent: Withdraw consent for processing based on your consent, without affecting the lawfulness of prior processing.
- Opt out of marketing: Opt out of marketing communications at any time.
European Economic Area, UK, and Swiss Users
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have additional rights under the GDPR, UK GDPR, or the Swiss Federal Act on Data Protection, as applicable. You have the right to lodge a complaint with a supervisory authority in your country of residence or work, or where an alleged infringement occurred. A directory of EU supervisory authorities is available at edpb.europa.eu. UK residents may contact the Information Commissioner's Office. Swiss residents may contact the Federal Data Protection and Information Commissioner.
California Privacy Rights (CCPA and CPRA)
This section applies to California residents and describes rights and disclosures required by the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
Categories of Personal Information We Collect
In the past 12 months, we have collected the following categories of personal information about California residents:
- Identifiers: Name, email address, phone number, IP address, account IDs, device identifiers.
- Customer records (Cal. Civ. Code § 1798.80(e)): Contact and billing details.
- Commercial information: Subscription plan, purchase history, credit usage.
- Internet or other network activity: Browsing history on our website, interactions with our platform, referral URLs.
- Geolocation data: Approximate location derived from IP address (city or region level, not precise).
- Professional or employment information: Company name and job role when voluntarily provided.
- Inferences: Insights about product usage preferences drawn from the above categories.
Where you use Macha to process content on behalf of your end-users (for example, support ticket contents), that content may contain additional categories, including sensitive personal information. In such cases, you act as the business under the CCPA and Macha acts as a service provider.
Sensitive Personal Information
We may process sensitive personal information (as defined by the CPRA) only for the purposes permitted under Cal. Civ. Code § 1798.121(a), including providing the service you requested, ensuring security and preventing fraud, and short-term transient use. We do not use sensitive personal information to infer characteristics about you. You have the right to limit our use of your sensitive personal information as described below.
Sources and Purposes
We collect the categories above from the sources listed in the "Sources of Personal Information" section and use them for the business and commercial purposes listed in the "How We Use Your Information" section.
Sale and Sharing of Personal Information
We do not sell personal information for monetary consideration. We may "share" personal information with third-party advertising and analytics partners for cross-context behavioural advertising, which is treated as "sharing" under the CPRA. This applies to cookie-based identifiers set by our advertising and analytics vendors listed in the "Cookies and Tracking" section.
You have the right to opt out of the sharing of your personal information for cross-context behavioural advertising. To exercise this right, you can:
- Click the "Do Not Sell or Share My Personal Information" link on our website.
- Enable the Global Privacy Control (GPC) signal in a compatible browser, which we honour as a valid opt-out request.
- Adjust your cookie preferences via our cookie banner.
- Email [email protected].
We have not sold or shared personal information about minors under 16 years of age.
Your California Rights
Subject to certain exceptions and verification, you have the following rights:
- Right to know: Request disclosure of the specific pieces and categories of personal information we have collected about you, the sources, the purposes for collection, and the categories of third parties with whom we share it.
- Right to delete: Request deletion of your personal information, subject to legal exceptions.
- Right to correct: Request correction of inaccurate personal information we maintain about you.
- Right to opt out of sale or sharing: Opt out of any sale or sharing of your personal information.
- Right to limit use of sensitive personal information: Direct us to limit our use of sensitive personal information to purposes permitted by law.
- Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA rights.
Retention Periods
See the "Data Retention" section above for retention periods that apply to each category of personal information.
Submitting Requests
To submit a request to know, delete, correct, or opt out, email [email protected] with the subject line "California Privacy Request". You may also use the data export and account deletion tools in your account settings for standard access and deletion requests. We will verify your identity by matching information you provide against our records. You may designate an authorised agent to submit a request on your behalf by providing signed authorisation and proof of the agent's identity. We will respond to verifiable requests within 45 days, with a possible 45-day extension for complex requests.
Metrics
Macha does not meet the threshold that requires publishing annual request metrics (10 million or more California consumers). If this changes, we will publish the required metrics.
How to Exercise Your Rights
To exercise any of the rights described in this policy, contact [email protected]. You can also use the following self-service tools in your account settings: data export (JSON download), account deletion, cookie preferences, and marketing preferences. We respond within the timeframes required by applicable law, typically within 30 days under the GDPR and 45 days under the CCPA. We may extend this period where reasonably necessary and will notify you of any extension.
Changes to This Policy
We may update this privacy policy from time to time. Any material changes will be posted on this page with an updated revision date. For significant changes that affect how we handle your personal information, we will provide additional notice through the platform or by email. We encourage you to review this policy periodically.
Trademark Acknowledgement
Zendesk® is a registered trademark of Zendesk, Inc. Google Workspace™, Gmail™, Google Docs™, Google Sheets™, and Google Drive™ are trademarks of Google LLC. Slack® is a registered trademark of Slack Technologies, LLC. Notion™ is a trademark of Notion Labs, Inc. Shopify® is a registered trademark of Shopify Inc. Stripe® is a registered trademark of Stripe, Inc. All other trademarks are the property of their respective owners. Macha is not affiliated with or endorsed by any of these companies.
Contact
Questions about this privacy policy should be directed to [email protected]. General support enquiries: [email protected]. Postal correspondence: AGZ Technologies Private Limited, M1801 Meghana Shalini Apartments, Banashankari 2nd Stage, Bangalore - 560070, Karnataka, India.
Built For Trust.
Designed For Privacy.
Your data is safe with Macha AI. We meet the highest security standards so you can focus on support without compromise.
GDPR Compliant
Fully aligned with global data protection and security standards.
Zero Data Retention Policy
We never store customer information or your customer conversations.
Shopify
Stripe
Slack
Notion
Google Workspace
Confluence