StockGro6

Data Fabric · Privacy & Consent

Agents act on tokens, never on a member's phone number

Phone, PAN and email are tokenised in a vault. An agent can ask the messaging tool to reach a token; it cannot read the number. Consent is separate per channel, with a timestamp and a source, and no consent means no channel.

Tokenised fields

14

Consent flags tracked

6

voice, WhatsApp, push, email, SMS, marketing

Erasure requests this month

412

all completed with a receipt

Agents with raw PII access

0

Controls

Each one is enforced in the tool layer, not in a policy document

Purpose binding

Each agent's token names its purpose; a retention agent cannot read KYC documents even though it can read KYC status.

Field-level masking

Phone, PAN and email are tokenised. Agents act on tokens; only the messaging tool resolves them, inside the vault.

Consent ledger

Voice, WhatsApp and marketing consent are separate flags with timestamps and source. No consent, no channel.

Retention windows

Raw audio 30 days, transcripts 12 months, verdicts 7 years. Deletion is a job with a receipt.

Right to erasure

One request fans out across datasets, indexes and caches, and returns a signed completion record.

Data residency

Member data stays in the India region; model calls carry no raw identifiers.

Member privacy lookup

What the OS holds, and what an agent can see

Member
SG-4482190
Phone
tok_ph_9f21…4b · vault-resolved
PAN
tok_pan_c18…2e · masked always
Voice consent
granted · 12 Mar, in-app
WhatsApp consent
granted · 12 Mar, in-app
Marketing consent
withdrawn · 2 Aug
Raw audio retained
0 days remaining of 30
Transcripts retained
9 months remaining of 12

What withdrawn consent actually does

This member withdrew marketing consent in August. The lifecycle agents can still send a transactional renewal notice, because that is contractual, but no campaign, creative test or referral nudge can reach them — the messaging tool refuses the send and the reason is logged against the campaign, not hidden.