Privacy Policy
Last updated: July 20, 2026 — Version 1.0
Zero Headache is an AI Start-up operated by Alap Putatunda, from India. Zero Headache ("Zero Headache," "we," "us") operates the website zeroheadache.co and provides an AI-native, managed lead-capture, qualification, and booking service (the "Service"). This Privacy Policy explains how we handle personal information.
Two roles — please read.
We handle personal information in two distinct capacities:
- As a controller — for information about our clients and website visitors (the businesses and people who buy from or contact us).
- As a processor (service provider) — for information about our clients' end customers (the leads who call, text, or message our clients). For that data, our client is the controller and we act on their documented instructions under our Data Processing Agreement. If you are an end customer and want your data accessed or deleted, contact the business you were trying to reach; we will assist them.
1. Information we collect
- You provide: name, business name, email, phone, billing details, and anything you submit via forms, checkout, or calls with us.
- End-customer data we process for clients: caller/messager name and contact details, message and call content, call audio and transcripts, appointment details, and lead source — collected across connected channels (phone, SMS, web, WhatsApp, Messenger DMs, Instagram DMs, email, third-party platforms).
- Automatically: device/browser data, IP, and usage analytics via cookies (see Cookie Policy).
2. How we use information
We use information to operate the Service, process leads on our clients' instructions, process payments, and meet legal obligations. We do not sell personal information.
- Legal basis (GDPR): We process client data on the basis of contract (Art 6(1)(b)) and legitimate interests (Art 6(1)(f)); we process end-customer data on the basis of the client's instructions and, where applicable, the end-customer's consent.
- Automated decision-making: The Service uses automated processing to qualify leads and book appointments. This does not produce legal or similarly significant effects on you. You may contact the business you reached for human review.
3. Calls and messages
The Service places and receives calls and messages and may record and transcribe them. Where required by law, callers are notified at the start of the interaction. See the Call Recording & Consent Policy and AI Disclosure Statement.
4. Sharing
We share information with our sub-processors (telephony, speech, AI, scheduling, hosting, payments, integrations), with our clients (for their own leads), and where required by law or to protect rights. Each sub-processor is bound by data-protection terms.
5. Retention
We keep personal information only as long as needed. Default retention for call recordings and transcripts is 6 months unless the client instructs otherwise (see Security and Data Protection). Lead and appointment records are retained for the term of the service plus 3 months. Usage logs are retained for at least one year as required by the DPDP Rules. Billing records are retained for 7 years. Clients control retention of their end-customer data and may request deletion at any time.
6. Security & Breaches
We use encryption in transit and at rest, access controls, and region-appropriate hosting. No method is 100% secure. A Data Protection Impact Assessment has been conducted and is available to clients on reasonable request.
In the event of a personal data breach, we notify affected clients without undue delay (and in any event within 72 hours of becoming aware, consistent with GDPR Article 33), and we notify the relevant supervisory authority or Data Protection Board where required. Where the breach is likely to result in a high risk to individuals, we also notify affected individuals.
7. International transfers
We may process data in the United States and European Union. Where data crosses borders, we rely on appropriate safeguards (e.g., Standard Contractual Clauses).
8. Your rights
Depending on your location, you have specific rights regarding your data:
- GDPR/UK GDPR: You have the right to access, correct, delete, port, or restrict your data, and to opt out of certain processing. You may complain to your local authority.
- India DPDP Act 2023: You have the right to access, correct, or erase your personal data, and to seek grievance redressal. Our Grievance Officer is Alap Putatunda, contactable at
legal@zeroheadache.co. - California CCPA/CPRA: You have the right to know the categories of personal information collected, sources, business purposes, and third-party disclosures (as detailed in Sections 1-4). You have the right to limit the use of sensitive personal information and opt out of automated decision-making. We do not sell or share personal information for cross-context behavioral advertising. We respond to verified requests within 45 days.
Exercise your rights at legal@zeroheadache.co. We honor browser opt-out signals where required.
9. Children
The Service is not directed to children. We do not knowingly collect data from children under 16 (or under 13 in the United States under COPPA). Because the Service handles inbound messages on social platforms where age is not verified, we may inadvertently process information from a minor. If you believe we have processed data belonging to a child under this age, contact us and we will delete it. Clients are responsible for handling any age-related requirements in their end-customer relationships.
10. Government and law enforcement
We disclose personal data to government or law-enforcement agencies only where required by valid legal process. We notify affected clients unless we are legally prohibited from doing so. We publish a transparency report on request.
11. Changes & contact
We may update this policy; material changes will be posted with a new effective date.
legal@zeroheadache.co












