Privacy Policy
Effective date:
Privacy Policy — Reach Far AI
Effective Date: 19 September 2026 Last Updated: 19 September 2026
1. Introduction and Scope
Welcome to Reach Far AI, a product operated by Bibha AI Labs Private Limited (“Bibha AI,” “Reach Far AI,” “we,” “us,” or “our”).
This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you access or use the Reach Far AI website, platform, applications, AI-powered features, and related services available through https://reachfarai.com and associated subdomains or applications (collectively, the “Services”).
This Privacy Policy applies to:
- Visitors to the Reach Far AI website.
- Registered users and customers.
- Individuals who submit information through our forms.
- Individuals who communicate with us.
- Individuals who interact with Reach Far AI-powered services.
- Business representatives and contacts.
- Individuals whose personal information is processed through the Services.
- Other individuals whose personal data we process in connection with the Services.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy.
If you do not agree with the practices described in this Privacy Policy, please discontinue use of the Services.
2. Data Controller Information
The data controller responsible for your personal data is:
Bibha AI Labs Private Limited Bangalore, Karnataka, India Email: info@bibha.ai Website: https://reachfarai.com
Reach Far AI is a product operated and provided by Bibha AI Labs Private Limited.
Where our customers use Reach Far AI to process personal data belonging to their customers, users, employees, prospects, or other individuals, the customer may act as the data controller and Bibha AI Labs Private Limited may act as a data processor on the customer's behalf.
Where applicable, this relationship may be governed by a Data Processing Agreement (“DPA”).
For EU/EEA data subjects, Bibha AI Labs Private Limited may act as the data controller where it determines the purposes and means of processing personal data. Where a customer determines the purposes and means of processing personal data through Reach Far AI, that customer may act as the data controller and Bibha AI Labs Private Limited may act as a processor.
3. Types of Data We Collect
3.1 Personal Data You Provide
Depending on how you use Reach Far AI, we may collect the following categories of information.
Account and Identity Data
- Full name.
- Email address.
- Phone number.
- Company or organization name.
- Job title and professional information.
- Account credentials.
- Billing address.
- Payment and transaction information.
- Information required to create and manage your account.
Business and Service Data
Depending on the features and Services you use, this may include:
- Business information.
- Customer information.
- Contact information.
- Information submitted through forms.
- Documents and files uploaded by users.
- User-created content.
- AI prompts and instructions.
- AI agent configurations.
- Workflow configurations.
- Knowledge-base content.
- Integration configuration.
- Conversation data.
- Other information necessary to provide the Services.
Communication Data
We may collect:
- Emails and messages sent to us.
- Customer support requests.
- Feedback.
- Survey responses.
- Information submitted through contact forms.
- Other communications between you and Reach Far AI.
Payment Information
Where payments are processed through third-party payment processors, we may receive information such as:
- Transaction identifiers.
- Billing information.
- Payment status.
- Subscription information.
We generally do not store complete payment card numbers where payment processing is handled directly by third-party payment processors.
3.2 Usage and Technical Data
We may automatically collect certain technical and usage information when you interact with the Services, including:
- IP address.
- Browser type and version.
- Operating system.
- Device type.
- Device identifiers.
- Pages visited.
- Features used.
- Session information.
- Session duration.
- Timestamps.
- Referring URLs.
- Error logs.
- Performance information.
- API request and usage information.
- Other diagnostic and technical information.
3.3 AI-Generated and AI-Processed Data
Where Reach Far AI provides artificial intelligence features, we may process:
- User prompts and instructions.
- AI-generated text.
- AI-generated audio or other media.
- Conversation transcripts.
- AI-generated summaries.
- Workflow outputs.
- Classifications.
- Recommendations.
- Analytics derived from AI interactions.
- Other information generated or processed through AI-powered features.
The exact information processed depends on the Services and features you use.
3.4 Information From Third Parties
We may receive information from third parties, including:
- Authentication and single sign-on providers.
- Third-party integrations authorized by you.
- CRM and business software integrations.
- Communication platforms.
- Payment processors.
- Service providers.
- Business partners.
- Publicly available sources, where permitted by applicable law.
4. How We Collect Data
4.1 Direct Collection
We collect information directly from you when you:
- Create an account.
- Register for our Services.
- Submit forms.
- Request information or a demonstration.
- Subscribe to our Services.
- Upload files or documents.
- Configure or use AI features.
- Connect third-party integrations.
- Communicate with us by email, chat, phone, or other channels.
- Submit feedback or surveys.
- Subscribe to marketing communications.
4.2 Automatic Collection
We automatically collect certain technical and usage information through:
- Cookies.
- Web beacons.
- Pixels.
- Local storage.
- Server logs.
- Browser technologies.
- Similar tracking technologies.
We may also collect location information inferred from an IP address where necessary for security, analytics, localization, or other legitimate purposes.
4.3 Third-Party Sources
We may receive information from:
- Authentication providers.
- Third-party integrations activated by users.
- Payment and billing providers.
- Business partners.
- Publicly available databases and directories.
5. Legal Bases for Processing
Where applicable under the General Data Protection Regulation (“GDPR”) and other applicable privacy laws, we process personal data on the following legal bases:
Contractual Necessity
We process information when necessary to:
- Create and manage accounts.
- Provide the Services.
- Process subscriptions and payments.
- Provide customer support.
- Perform our contractual obligations.
Legitimate Interests
We may process personal information where necessary for our legitimate interests, including:
- Improving our Services.
- Maintaining service reliability.
- Product analytics.
- Security monitoring.
- Fraud and abuse prevention.
- Troubleshooting.
- Protecting our legal rights.
- Communicating with existing customers about relevant Services.
Where required, we assess whether our legitimate interests are balanced against your rights and freedoms.
Consent
We may rely on consent for processing activities such as:
- Certain marketing communications.
- Optional cookies and tracking technologies.
- Other activities for which applicable law requires consent.
You may withdraw consent where applicable.
Legal Obligation
We may process personal information where necessary to:
- Comply with applicable laws.
- Respond to lawful governmental requests.
- Comply with court orders or legal processes.
- Fulfill regulatory obligations.
- Maintain legally required records.
6. Purpose of Data Processing
We process personal information for the following purposes.
Service Delivery
We may use personal information to:
- Provide and operate Reach Far AI.
- Authenticate users.
- Provide AI-powered functionality.
- Process user requests.
- Execute workflows.
- Process customer-provided information.
- Provide customer support.
- Maintain and monitor service performance.
Account Management
We may use personal information to:
- Create and manage accounts.
- Process subscriptions.
- Process payments.
- Generate invoices.
- Provide customer support.
- Send service-related communications.
Product Improvement
We may use information to:
- Analyze usage patterns.
- Improve features and user experience.
- Conduct product research.
- Test new functionality.
- Debug and troubleshoot issues.
- Optimize performance.
- Improve service reliability.
Where appropriate, we may use aggregated, de-identified, or anonymized information for analytics and product improvement.
We will not use customer content to train general-purpose AI models unless such use is expressly disclosed and permitted under the applicable agreement, settings, or consent.
Communication
We may use personal information to send:
- Account notifications.
- Security alerts.
- Billing notifications.
- Service updates.
- Support communications.
- Product-related communications.
- Marketing communications where permitted by applicable law.
You may opt out of marketing communications at any time.
Security and Compliance
We may process information to:
- Detect and prevent fraud.
- Detect and prevent abuse.
- Investigate security incidents.
- Protect our Services.
- Enforce our Terms of Use.
- Protect our legal rights.
- Comply with applicable laws and legal processes.
7. Data Sharing and Third-Party Disclosures
We do not sell your personal data.
We may share personal information with the following categories of recipients where reasonably necessary to provide and operate the Services.
7.1 Service Providers and Sub-Processors
We may engage trusted third-party service providers for:
- Cloud infrastructure and hosting.
- Database and storage services.
- Payment processing.
- Email and communications.
- Authentication.
- Analytics.
- AI and machine-learning infrastructure.
- Customer support.
- Security monitoring.
- Other infrastructure required to provide the Services.
Our third-party service providers may process personal information on our behalf and are expected to maintain appropriate security and confidentiality measures.
A current list of material subprocessors may be requested by contacting:
7.2 Customer-Directed Sharing
Personal information may be shared with third-party services where:
- You authorize an integration.
- You configure a workflow that requires the sharing.
- The sharing is necessary to provide a requested feature.
- Your organization instructs us to share the information.
7.3 Legal and Regulatory Disclosures
We may disclose personal information when reasonably necessary to:
- Comply with applicable law.
- Respond to court orders or subpoenas.
- Respond to lawful governmental requests.
- Protect our rights, property, or safety.
- Protect users or other individuals.
- Investigate fraud, abuse, security incidents, or unlawful activity.
7.4 Business Transfers
If Bibha AI Labs Private Limited is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar corporate transaction, personal information may be transferred as part of that transaction.
Where required by applicable law, we will provide appropriate notice regarding such changes.
8. International Data Transfers
Bibha AI Labs Private Limited is headquartered in India and may provide Services to users and customers located in different countries.
Your personal information may therefore be transferred to, stored in, or processed in countries other than your country of residence.
Where required by applicable law, we use appropriate safeguards for international transfers, which may include:
- Standard Contractual Clauses approved by the European Commission.
- Data Processing Agreements.
- UK International Data Transfer Agreements.
- UK Addenda to EU Standard Contractual Clauses.
- Other legally recognized transfer mechanisms.
You may contact us at privacy@bibha.ai to request additional information about applicable international transfer safeguards.
9. Data Retention
We retain personal information only for as long as reasonably necessary to:
- Provide the Services.
- Fulfill the purposes for which it was collected.
- Maintain business records.
- Resolve disputes.
- Enforce agreements.
- Comply with legal obligations.
- Protect our legitimate business interests.
Different categories of information may be retained for different periods.
Where applicable, the following retention periods may apply:
| Data Category | Retention Period |
|---|---|
| Account data | Duration of account plus applicable legal/business retention period |
| Customer/service data | Duration of customer relationship, subject to contractual requirements |
| AI configurations | Duration of account plus applicable deletion period |
| Conversation data | As configured by the customer or as necessary to provide the Services |
| Voice or media recordings | Where applicable, according to product configuration or applicable contractual requirements |
| Usage and analytics data | As reasonably necessary for analytics, security, and product improvement |
| Payment and billing records | As required by applicable tax and financial laws |
| Marketing consent records | As required to demonstrate compliance with applicable law |
| Security and audit logs | As reasonably necessary for security, compliance, and incident investigation |
When personal information is no longer required, we may securely delete, anonymize, or aggregate it.
Customers may request deletion of customer-controlled data subject to applicable contractual and legal requirements.
10. Cookies and Tracking Technologies
We use cookies and similar technologies to operate and improve our website and Services.
These technologies may be used for:
- Authentication.
- Security.
- Session management.
- Analytics.
- Performance monitoring.
- User preferences.
- Website functionality.
- Marketing measurement where applicable.
Strictly Necessary Cookies
These cookies are required for essential functionality, security, authentication, and other necessary operations.
Analytics Cookies
These cookies help us understand how visitors use our website and Services.
Functional Cookies
These cookies may enable enhanced functionality and remember preferences.
Marketing Cookies
Where used and permitted by applicable law, marketing cookies may be used to measure campaigns and support relevant communications.
Where required by law, we will obtain consent before placing non-essential cookies.
You may also manage cookies through your browser settings.
11. Your Rights Under GDPR
If you are located in the European Economic Area (“EEA”), United Kingdom, or Switzerland, you may have rights under applicable data protection laws, including:
- Right of Access — Request access to personal data we hold about you.
- Right to Rectification — Request correction of inaccurate or incomplete information.
- Right to Erasure — Request deletion of personal information, subject to applicable exceptions.
- Right to Restriction — Request restriction of processing in certain circumstances.
- Right to Data Portability — Request your information in a structured, commonly used, machine-readable format.
- Right to Object — Object to certain processing activities, including processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent — Withdraw consent where processing is based on consent.
- Rights Regarding Automated Decision-Making — Request applicable safeguards where decisions are made solely by automated means and have legal or similarly significant effects.
To exercise these rights, contact:
We may verify your identity before processing your request.
Where required by applicable law, we will respond within the applicable statutory period.
You may also have the right to lodge a complaint with your relevant data protection authority.
12. Your Rights Under California Privacy Laws
If you are a California resident, applicable California privacy laws, including the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”), may provide additional rights.
Depending on the circumstances, these may include:
- Right to know what personal information is collected.
- Right to know the purposes for which personal information is used.
- Right to know the categories of sources from which information is collected.
- Right to know the categories of third parties with whom information is disclosed.
- Right to request deletion.
- Right to request correction.
- Right to opt out of certain sales or sharing of personal information.
- Right to limit certain uses of sensitive personal information.
- Right to non-discrimination for exercising privacy rights.
Reach Far AI does not sell personal information.
To submit a California privacy request, contact:
We may verify your identity before processing your request.
13. Your Rights Under Indian Law
If you are located in India, your personal information may be subject to applicable Indian privacy and data protection laws, including the Information Technology Act, 2000, applicable rules, and the Digital Personal Data Protection Act, 2023 and rules thereunder as applicable and in force.
Depending on applicable law, you may have rights relating to:
- Access to personal information.
- Correction of inaccurate information.
- Withdrawal of consent.
- Deletion of personal information where applicable.
- Grievance redressal.
- Other rights provided under applicable Indian law.
To exercise applicable privacy rights or submit a grievance, contact:
Data Protection Officer / Grievance Officer Name: Prashant Kumar Email: privacy@bibha.ai Address: Bibha AI Labs Private Limited, Bangalore, Karnataka, India
14. Children's Privacy
Our Services are not directed to children where their use would be prohibited by applicable law.
We do not knowingly collect personal information from children without the consent required by applicable law.
If we become aware that we have collected personal information from a child contrary to applicable law, we will take reasonable steps to delete the information.
If you believe that a child has provided personal information to us without appropriate authorization, please contact:
15. Data Security Measures
We implement reasonable technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, destruction, or other unlawful processing.
Depending on the Services and infrastructure involved, our security measures may include:
Technical Measures
- Encryption of data in transit.
- Encryption of data at rest where appropriate.
- Access controls.
- Role-based access controls.
- Authentication and authorization controls.
- Secure API and credential management.
- Network security controls.
- Monitoring and logging.
- Vulnerability management.
- Security incident response procedures.
Organizational Measures
- Least-privilege access principles.
- Security awareness practices.
- Access management procedures.
- Incident response procedures.
- Periodic security reviews.
- Data protection procedures.
No method of transmission or storage is completely secure. Accordingly, we cannot guarantee absolute security of personal information.
If you suspect a security incident involving Reach Far AI, contact:
16. Data Protection Officer / Grievance Officer
Bibha AI Labs Private Limited has appointed a Data Protection Officer / Grievance Officer to oversee applicable data protection and privacy matters.
Data Protection Officer / Grievance Officer: Name: Prashant Kumar Email: privacy@bibha.ai Address: Bibha AI Labs Private Limited, Bangalore, Karnataka, India
You may contact the DPO / Grievance Officer regarding:
- Questions about this Privacy Policy.
- Privacy requests.
- Data protection concerns.
- Complaints.
- Requests to exercise applicable privacy rights.
For EU/EEA data subjects, where an EU representative is required, applicable representative information will be provided as required by law.
17. Policy Updates and Notification
We may update this Privacy Policy from time to time to reflect:
- Changes to our Services.
- Changes to our data processing practices.
- Changes in technology.
- Changes in applicable laws.
- Changes to our business operations.
For material changes, we may provide notice through email, the Services, or a prominent notice on our website where appropriate.
The Last Updated date at the beginning of this Privacy Policy indicates when the policy was most recently revised.
We encourage you to review this Privacy Policy periodically.
Your continued use of the Services after an updated Privacy Policy becomes effective constitutes acknowledgment of the updated policy to the extent permitted by applicable law.
18. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Bibha AI Labs Private Limited Reach Far AI Website: https://reachfarai.com Company Website: https://bibha.ai Email: info@bibha.ai Privacy Email: privacy@bibha.ai Address: Bangalore, Karnataka, India
For privacy-specific requests:
19. Severability
If any provision of this Privacy Policy is determined to be invalid, unlawful, or unenforceable by a court or competent authority, that provision will be modified or interpreted to the minimum extent necessary to make it enforceable.
The remaining provisions of this Privacy Policy will continue in full force and effect.
20. Related Policies
This Privacy Policy should be read together with other applicable legal documents governing your use of Reach Far AI, including:
- Terms of Use — [Insert Reach Far AI Terms of Use URL]
- Cookie Policy — [Insert Reach Far AI Cookie Policy URL]
- Data Processing Agreement — [Insert DPA URL, if applicable]
- Security / Trust Center — [Insert URL, if applicable]
In the event of a conflict between this Privacy Policy and another agreement, the applicable agreement will govern to the extent permitted by applicable law. For data protection matters, this Privacy Policy will apply unless a separate written agreement specifically governs the relevant processing.
© 2026 Bibha AI Labs Private Limited. All rights reserved.
Reach Far AI is a product of Bibha AI Labs Private Limited.