Atithya AIAccess

Policy Center

Practical policies for managed AI website agents.

These policies define how managed Atithya pilots handle approved data, exclusions, retention, deletion, support, and incident review before broader rollout.

Managed pilot first

Atithya is currently sold as a managed service. Customer setup, source approval, preview review, and publish decisions are reviewed before an agent goes live.

Visitor-safe answers

Agents answer from approved website context and route unsupported, private, or sensitive requests to a human-owned follow-up path.

Control before scale

Allowed domains, pause controls, answer limits, incident review, and deletion workflows are treated as product requirements from day one.

Data handling

What Atithya may handle during a pilot.

  • customer account and workspace details
  • approved website source manifest
  • widget settings and brand copy
  • safe conversation summaries and transcripts when enabled
  • lead submissions and export status
  • analytics events, categories, source gaps, and incident notes

Hard exclusions

What should stay outside unless explicitly integrated.

  • payment card data
  • private customer order records without a verified integration
  • unnecessary sensitive personal data
  • sensitive connection setup details in visitor-facing flows
  • unsupported medical, legal, financial, or compliance advice

Visitor disclosure

Visitors should understand what the agent can and cannot do.

The agent can answer approved brand, product, pricing context, policy, and category questions. If a visitor asks for private account, order, payment, health, legal, or unsupported details, the agent should answer what is safe and route the request to the team.

Retention defaults

Keep what helps the customer. Remove what is no longer needed.

Analytics summariesUp to 12 months
Conversation transcripts90 days by default on Free and Pro
LeadsUntil export, deletion, or customer request
Source snapshotsLatest approved version plus one previous version
Incident notesUp to 12 months
Deleted customer dataPurge target within 30 days where technically possible

Deletion workflow

Deletion should be calm, traceable, and customer-owned.

  1. Pause the agent if requested.
  2. Export leads or transcripts before deletion when the customer asks for a copy.
  3. Delete selected leads, transcripts, source snapshots, widget settings, and domain settings.
  4. Keep only the minimum audit record needed to show that deletion was completed.

Support and billing

Managed-first, clear, and without surprise automation.

Standard support24 to 48 business hours for managed pilot questions
Launch blockersPrioritized during preview approval and install handoff
Agent pauseAvailable from the workspace when visitor experience needs to stop
Payment and invoice questionsHandled through a managed payment path before automation is enabled

Refunds, cancellations, and paused pilots are reviewed based on work already delivered, unused service period, active setup scope, and whether the agent has gone live.

Domain and abuse controls

Agents should answer only where they are approved to run.

Each workspace uses allowed production domains, preview domains, and per-domain usage review. Unknown domains, suspicious usage, or repeated out-of-scope abuse can trigger pause and review before the visitor experience is restored.

Acceptable use

Clear boundaries keep genuine visitors moving.

Allowed visitor questionsAtithya can support brand, product, pricing context, policy, setup, fit, security, and competitor or industry questions inside approved source scope.
Misuse that can trigger reviewRepeated unrelated trivia, abusive volume, unapproved-domain use, automated scraping, or attempts to expose hidden instructions and private configuration can trigger review.
Customer responsibilitiesCustomers should approve source pages, keep public policies current, avoid unnecessary sensitive data collection, and review lead disclosures before launch.
Free tier abuse controlsFree workspaces use one production domain, lower answer allowance, stricter request limits, and automatic pause when abuse patterns repeat.

Incident handling

When something breaks, the first job is to protect the visitor experience.

  1. Pause the affected answer path or full agent when risk is serious.
  2. Notify the internal owner and customer when the incident is customer-facing.
  3. Preserve safe diagnostic notes without exposing private technical details.
  4. Fix source, guardrail, configuration, or interface cause.
  5. Re-run QA before republishing and send a short incident note.

Before paid scale

Final legal review comes before broad product scale.

These policies make the managed pilot safer and clearer today. Before broad product rollout, Atithya will need finalized legal terms, privacy notice, payment terms, tax process, and region-specific disclosures.

Contact policy owner