Data Fabric · Privacy & Consent
Agents act on tokens, never on a member's phone number
Phone, PAN and email are tokenised in a vault. An agent can ask the messaging tool to reach a token; it cannot read the number. Consent is separate per channel, with a timestamp and a source, and no consent means no channel.
Tokenised fields
14
Consent flags tracked
6
voice, WhatsApp, push, email, SMS, marketing
Erasure requests this month
412
all completed with a receipt
Agents with raw PII access
0
Controls
Each one is enforced in the tool layer, not in a policy document
Purpose binding
Each agent's token names its purpose; a retention agent cannot read KYC documents even though it can read KYC status.
Field-level masking
Phone, PAN and email are tokenised. Agents act on tokens; only the messaging tool resolves them, inside the vault.
Consent ledger
Voice, WhatsApp and marketing consent are separate flags with timestamps and source. No consent, no channel.
Retention windows
Raw audio 30 days, transcripts 12 months, verdicts 7 years. Deletion is a job with a receipt.
Right to erasure
One request fans out across datasets, indexes and caches, and returns a signed completion record.
Data residency
Member data stays in the India region; model calls carry no raw identifiers.
Member privacy lookup
What the OS holds, and what an agent can see
- Member
- SG-4482190
- Phone
- tok_ph_9f21…4b · vault-resolved
- PAN
- tok_pan_c18…2e · masked always
- Voice consent
- granted · 12 Mar, in-app
- WhatsApp consent
- granted · 12 Mar, in-app
- Marketing consent
- withdrawn · 2 Aug
- Raw audio retained
- 0 days remaining of 30
- Transcripts retained
- 9 months remaining of 12
What withdrawn consent actually does
This member withdrew marketing consent in August. The lifecycle agents can still send a transactional renewal notice, because that is contractual, but no campaign, creative test or referral nudge can reach them — the messaging tool refuses the send and the reason is logged against the campaign, not hidden.

