Privacy Policy

Effective date: 28 July 2026 · Last updated: 28 July 2026

How Unblunt Solutions Pvt. Ltd. collects, uses, discloses and protects personal data in connection with the Metriqual platform, its APIs, dashboards, website and related services.

At a glance

Model training
We do not use your prompts, inputs or outputs to train our own or any third party’s foundation models, and we do not sell Customer Data.
Provider Keys
Encrypted in transit and at rest, used solely to authenticate and route your requests. You can revoke or rotate them at any time.
Failover context
Recent conversation context is held only long enough to replay a failed request to another provider, then deleted or de-identified.
Your rights
Access, correct, delete, restrict, object, port your data, or withdraw consent by emailing privacy@metriqual.com.
Grievance Officer
Gopal Singh, reachable at grievance@metriqual.com under the IT Act, 2000 and the DPDP Act, 2023.

Preamble

This Privacy Policy explains how Unblunt Solutions Pvt. Ltd., a company incorporated under the Companies Act, 2013, having its registered office at Jaipur, Rajasthan, India ("Company", "Metriqual", "we", "us", "our"), collects, uses, discloses, and protects personal data in connection with the Metriqual platform, its application programming interfaces, dashboards, website, and related services (collectively, the "Service").

This Policy applies to visitors, account holders, and customers of the Service. Please read it together with our Terms and Conditions. By using the Service, you acknowledge that you have read and understood this Policy.

We are committed to handling personal data in accordance with applicable data protection laws, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and rules thereunder (India), the General Data Protection Regulation (EU) 2016/679 ("GDPR") where applicable, and the California Consumer Privacy Act as amended ("CCPA/CPRA") where applicable.

1. Who we are

Unblunt Solutions Pvt. Ltd. is the entity responsible for the Service. For personal data that we determine the purposes and means of processing, we act as a data controller (or "Data Fiduciary" under Indian law). For personal data contained in Customer Data that our customers submit and control, we generally act as a data processor (or "Data Processor") on behalf of that customer, in which case the customer is the controller and this Policy is supplemented by any applicable Data Processing Agreement.

2. Scope

2.1. This Policy covers personal data we process in three broad contexts:

  • Website and marketing data. Information collected when you visit our website or interact with our marketing.
  • Account and billing data. Information we collect to create and manage your Account and to bill you.
  • Customer Data processed through the Service. Prompts, inputs, outputs, conversation history, and other content routed through the gateway, which may contain personal data controlled by you.

2.2. This Policy does not cover the practices of Third-Party Providers or other third-party services you connect to through the Service. Their handling of your data is governed by their own privacy policies.

3. Information we collect

3.1 Information you provide to us

  • Account information: name, email address, company name, job role, username, and password.
  • Billing information: billing name, billing address, tax identifiers, and payment details (payment card data is processed by our payment processors and not stored by us in full).
  • Provider Keys: API keys, tokens, or credentials for Third-Party Providers that you supply under the Bring Your Own Key (BYOK) model. These are credentials, and we treat them as sensitive.
  • Communications: information you provide when you contact support, respond to surveys, or communicate with us.

3.2 Customer Data routed through the Service

  • Prompts, inputs, and outputs: the content you or your end users send to and receive from Third-Party Providers through the gateway, which may include text, images, audio, or other multimodal content.
  • Conversation history: to enable features such as conversation-history-preserving failover, the Service may temporarily hold recent conversation context so that it can be replayed to an alternative Third-Party Provider if the primary provider fails.

3.3 Information we collect automatically

  • Usage and log data: request metadata, timestamps, endpoints called, Third-Party Providers routed to, token counts, latency, error and failover events, and status codes.
  • Device and technical data: IP address, browser type, operating system, device identifiers, and referring URLs.
  • Cookies and similar technologies: as described in Section 9.

3.4 Information from third parties

We may receive information from payment processors, identity or fraud-prevention providers, analytics providers, and business partners, which we combine with information we already hold.

4. How we use personal data

We use personal data for the following purposes:

  • to create, authenticate, and manage your Account;
  • to provide, operate, maintain, and secure the Service, including routing requests to Third-Party Providers, load balancing, and failover;
  • to process payments, invoicing, and manage your Subscription;
  • to monitor, analyse, and improve the performance, reliability, and features of the Service;
  • to detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms;
  • to communicate with you about the Service, including service announcements, technical notices, and support;
  • to send marketing communications where permitted by law, from which you may opt out at any time;
  • to comply with legal obligations, respond to lawful requests, and enforce our agreements; and
  • to establish, exercise, or defend legal claims.

We do not use Customer Data (including prompts, inputs, or outputs routed through the gateway) to train our own or any third party's foundation models, and we do not sell Customer Data.

5. Legal bases for processing (GDPR)

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract. To provide the Service you have requested and to administer your Account.
  • Legitimate interests. To secure, improve, and market the Service, provided such interests are not overridden by your rights. You may object to processing based on legitimate interests.
  • Consent. Where required, for example for certain marketing communications or non-essential cookies. You may withdraw consent at any time.
  • Legal obligation. To comply with applicable laws, including tax, accounting, and regulatory requirements.

Where we process personal data contained in Customer Data as a processor, we do so on the documented instructions of our customer, who is responsible for establishing the legal basis for that processing.

6. Provider Keys and Customer Data handling

6.1. Provider Keys supplied under the BYOK model are encrypted in transit and at rest and are used solely to authenticate and route your requests to the relevant Third-Party Providers. We do not use Provider Keys for any purpose other than providing the Service to you. You may revoke or rotate Provider Keys at any time; you remain responsible for managing the scope and lifecycle of your keys with each Third-Party Provider.

6.2. Prompts, inputs, and outputs are transmitted to and from Third-Party Providers to fulfil your requests. The handling of your data by Third-Party Providers is governed by their respective privacy policies and terms.

6.3. Conversation-history-preserving failover requires the Service to retain recent conversation context for a limited period so that, if a primary provider fails, the request can be re-routed to an alternative provider without loss of context. We retain this context only as long as necessary to provide the failover feature and to operate the Service, after which it is deleted or de-identified in accordance with our retention practices.

6.4. We apply administrative, technical, and organisational safeguards to Customer Data as described in Section 8.

7. How we share personal data

We do not sell personal data. We share personal data only in the following circumstances:

  • Third-Party Providers. We route your requests, including prompts and inputs, to the Third-Party Providers you have configured, using your Provider Keys under the BYOK model.
  • Service providers and sub-processors. We engage trusted vendors to provide hosting, cloud infrastructure, payment processing, analytics, communications, and security services. These providers are bound by contractual obligations to protect personal data and process it only on our instructions.
  • Legal and compliance. We may disclose personal data where required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of the Company, our users, or others.
  • Business transfers. In connection with a merger, acquisition, financing, reorganisation, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy.
  • With your consent or at your direction. Where you have asked us to share your information.

A current list of sub-processors is available on request by contacting privacy@metriqual.com.

8. Data security

8.1. We implement reasonable administrative, technical, and physical safeguards designed to protect personal data against unauthorised access, disclosure, alteration, and destruction. These measures include encryption of data in transit and at rest, access controls, network security, and monitoring.

8.2. No method of transmission or storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security, and you provide your personal data and Provider Keys at your own risk.

8.3. In the event of a personal data breach that is likely to result in risk to affected individuals, we will notify the relevant authorities and affected individuals as required by applicable law.

9. Cookies and similar technologies

9.1. We use cookies and similar technologies to operate our website, remember your preferences, authenticate sessions, analyse traffic, and improve the Service.

9.2. Essential cookies are necessary for the Service to function. Non-essential cookies, including analytics and preference cookies, are used where permitted and, where required by law, with your consent.

9.3. You can manage cookies through your browser settings and, where offered, through our cookie preferences tool. Disabling certain cookies may affect the functionality of the Service.

10. International data transfers

10.1. We are based in India and may process and store personal data in India and in other countries where we or our sub-processors operate. These countries may have data protection laws that differ from those in your jurisdiction.

10.2. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country not recognised as providing an adequate level of protection, we implement appropriate safeguards, such as the European Commission's Standard Contractual Clauses, together with any required supplementary measures.

11. Data retention

11.1. We retain personal data for as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements.

11.2. Account and billing data are retained for the duration of your Account and for a reasonable period thereafter as required for legal, tax, and accounting purposes.

11.3. Customer Data, including conversation context held for failover, is retained only for as long as necessary to provide the relevant feature and operate the Service, after which it is deleted or de-identified. Where we act as a processor, retention and deletion of Customer Data are governed by our customer's instructions and any applicable Data Processing Agreement.

11.4. Log and usage data are retained for operational, security, and analytical purposes for a limited period consistent with those purposes.

12. Your rights

Depending on your location and applicable law, you may have some or all of the following rights in relation to your personal data:

  • Access. To request confirmation of whether we process your personal data and to obtain a copy.
  • Correction. To request correction of inaccurate or incomplete personal data.
  • Erasure. To request deletion of your personal data in certain circumstances.
  • Restriction and objection. To restrict or object to certain processing, including processing based on legitimate interests and processing for direct marketing.
  • Data portability. To receive certain personal data in a structured, commonly used, machine-readable format.
  • Withdrawal of consent. To withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing.
  • Nomination (India). To nominate another individual to exercise your rights in the event of death or incapacity.
  • Non-discrimination (CCPA/CPRA). Not to receive discriminatory treatment for exercising your privacy rights. We do not sell or "share" personal information for cross-context behavioural advertising within the meaning of the CCPA/CPRA.

To exercise your rights, contact us at privacy@metriqual.com. We will respond within the timeframes required by applicable law. We may need to verify your identity before acting on your request. Where we process personal data on behalf of a customer as a processor, we will refer your request to that customer.

If you are in the EEA, UK, or Switzerland, you also have the right to lodge a complaint with your local data protection authority. If you are in India, you may raise a complaint with the Data Protection Board of India after first contacting our Grievance Officer.

13. Children's privacy

The Service is intended for businesses and users who are at least eighteen (18) years of age. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete it.

14. Third-party links and services

The Service and our website may contain links to, or integrations with, third-party websites, Third-Party Providers, and services. We are not responsible for the privacy practices of these third parties, and we encourage you to review their privacy policies.

15. Marketing communications

Where we send marketing communications, we do so in accordance with applicable law. You may opt out at any time by using the unsubscribe link in our emails or by contacting privacy@metriqual.com. You will continue to receive non-promotional, service-related communications.

16. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will post the updated Policy with a revised effective date and, where appropriate, notify you by email or through the Service. Your continued use of the Service after the updated Policy takes effect constitutes acceptance of the changes.

17. Grievance Officer and contact

In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the contact details of our Grievance Officer are set out below. You may contact the Grievance Officer with any complaints or concerns regarding the processing of your personal data.

  • Grievance Officer: Gopal Singh
  • Company: Unblunt Solutions Pvt. Ltd. (operating as Metriqual)
  • Address: Jaipur, Rajasthan, India
  • Email: grievance@metriqual.com

For general privacy enquiries

We will acknowledge and address grievances within the timeframes prescribed by applicable law.