Atithya is currently sold as a managed service. Customer setup, source approval, preview review, and publish decisions are reviewed before an agent goes live.
Policy Center
Practical policies for managed AI website agents.
These policies define how managed Atithya pilots handle approved data, exclusions, retention, deletion, support, and incident review before broader rollout.
Agents answer from approved website context and route unsupported, private, or sensitive requests to a human-owned follow-up path.
Allowed domains, pause controls, answer limits, incident review, and deletion workflows are treated as product requirements from day one.
Data handling
What Atithya may handle during a pilot.
- customer account and workspace details
- approved website source manifest
- widget settings and brand copy
- safe conversation summaries and transcripts when enabled
- lead submissions and export status
- analytics events, categories, source gaps, and incident notes
Hard exclusions
What should stay outside unless explicitly integrated.
- payment card data
- private customer order records without a verified integration
- unnecessary sensitive personal data
- sensitive connection setup details in visitor-facing flows
- unsupported medical, legal, financial, or compliance advice
Visitor disclosure
Visitors should understand what the agent can and cannot do.
The agent can answer approved brand, product, pricing context, policy, and category questions. If a visitor asks for private account, order, payment, health, legal, or unsupported details, the agent should answer what is safe and route the request to the team.
Retention defaults
Keep what helps the customer. Remove what is no longer needed.
Deletion workflow
Deletion should be calm, traceable, and customer-owned.
- Pause the agent if requested.
- Export leads or transcripts before deletion when the customer asks for a copy.
- Delete selected leads, transcripts, source snapshots, widget settings, and domain settings.
- Keep only the minimum audit record needed to show that deletion was completed.
Support and billing
Managed-first, clear, and without surprise automation.
Refunds, cancellations, and paused pilots are reviewed based on work already delivered, unused service period, active setup scope, and whether the agent has gone live.
Domain and abuse controls
Agents should answer only where they are approved to run.
Each workspace uses allowed production domains, preview domains, and per-domain usage review. Unknown domains, suspicious usage, or repeated out-of-scope abuse can trigger pause and review before the visitor experience is restored.
Acceptable use
Clear boundaries keep genuine visitors moving.
Incident handling
When something breaks, the first job is to protect the visitor experience.
- Pause the affected answer path or full agent when risk is serious.
- Notify the internal owner and customer when the incident is customer-facing.
- Preserve safe diagnostic notes without exposing private technical details.
- Fix source, guardrail, configuration, or interface cause.
- Re-run QA before republishing and send a short incident note.
Before paid scale
Final legal review comes before broad product scale.
These policies make the managed pilot safer and clearer today. Before broad product rollout, Atithya will need finalized legal terms, privacy notice, payment terms, tax process, and region-specific disclosures.