Legal

Privacy Policy

Last updated 24 July 2026

1. Introduction

This Privacy Policy explains how Vyapnova Technologies Private Limited (“Vyapnova”, “we”, “us”), a company incorporated in India with its registered office in Gurugram, Haryana, India, collects, uses, shares, and protects personal data when you visit our websites, join our waitlist, contact us, or use the Vyapnova service — an AI sales and support agent that helps businesses (“merchants”) respond to their customers on Instagram, WhatsApp, and their own websites (the “Service”).

This Policy is written to comply with India's Digital Personal Data Protection Act, 2023(“DPDP Act”) and to meet the expectations of the EU/UK General Data Protection Regulation(“GDPR”) for users outside India. It also describes how we handle data received from Meta Platforms (“Meta”) services, as required by Meta's Platform Terms and Developer Policies.

If you do not agree with this Policy, please do not use the Service. Questions and requests can be sent to hello@vyapnova.com at any time. This Policy is published in English; if you would like help understanding it in another language — including a language listed in the Eighth Schedule to the Constitution of India — contact us and we will assist.

2. Our role: when we decide, and when your merchant does

The Service involves two kinds of people, and our legal role differs for each:

  • Merchants and their team members. When you create a Vyapnova account, join our waitlist, or contact us, Vyapnova is the Data Fiduciary (DPDP Act) / controller (GDPR) of your personal data. We decide how and why it is processed, as described in this Policy.
  • End customers of merchants. When a customer messages a merchant on Instagram, WhatsApp, or the merchant's website and the Service processes that conversation, the merchant is the Data Fiduciary / controller of that customer's data, and Vyapnova acts as a Data Processor on the merchant's documented instructions. End customers should direct privacy requests to the merchant they messaged; we support merchants in fulfilling those requests (see Section 11), and we will pass on any request we receive directly.

3. Data we collect on our websites

Our marketing website is deliberately light on data collection. It sets no advertising cookies and shows no third-party ads. We collect:

  • Waitlist information you submit: email address (required); and optionally your country, WhatsApp number, business type, the channels you want the agent on, your approximate message volume, what you would consider fair to pay (used only as pricing research — never a commitment or a bill), and your website address.
  • Contact form information you submit: name, email, business name, topic of interest, and your message.
  • Technical context submitted with the forms: device type, operating system, browser, timezone, browser language, the page you submitted from, the referring site, and campaign (UTM) parameters kept for the browser session. We use this to understand where interest comes from.
  • Approximate location: when you open a form, your browser calls the geolocation service ipwho.is, which receives your IP address (as any web service you connect to does) and returns an approximate city, region, and country. We store only that derived city/region/country in our records — not your raw IP address.
  • Usage analytics (Microsoft Clarity): how visitors use the site — pages viewed, clicks, scrolls, and pointer movement, including session replays of those interactions. Clarity is configured to mask text you type into forms, so replays do not show your email address or phone number. Microsoft receives the technical data needed to provide the service (including your IP address and the cookies in Section 9) and processes it under its own privacy terms. We use this solely to understand and improve the website — not for advertising. Clarity runs only if you allow it in the cookie choice shown on our site; you can change your mind at any time via “Cookies” in the footer.

Waitlist and contact submissions are stored in Google Sheets on Google Workspace infrastructure (see Section 8). We do not sell this data and do not use it for third-party advertising. We will email you about your waitlist status, your invite, and material product and pricing updates; you can opt out of non-essential emails at any time.

4. Data we process when merchants use the Service

For merchants and their teams:

  • Account data: name, email address, a one-way hash of your password (we never store passwords in plain text), email-verification and password-reset tokens, team membership and role assignments, and notification preferences.
  • Business knowledge you provide: your catalogue (products, services, prices), product photos and media, business policies, FAQs, and business profile — used solely so the agent can answer your customers accurately.
  • Channel connections: when you connect Instagram or WhatsApp, we store the access tokens Meta issues for your account so the Service can operate on your behalf. Connecting uses Meta's own login — we never ask for or store your Instagram or WhatsApp password.
  • Usage and operational data: audit logs of sensitive actions, AI usage metrics, and service events used to operate, secure, and improve the reliability of the Service.

For end customers, processed on the merchant's behalf:

  • Conversation data: message content, timestamps, and conversation state across the merchant's connected channels.
  • Request data: the structured details a customer shares to place an order, booking, appointment, quote, or callback — such as their name, phone number, items or services requested, dates, and delivery details.
  • Order-tracking data: shipment identifiers and courier status, where the merchant uses order tracking.
  • Aggregated demand signals: records of asks the agent could not fulfil (for example, a product not in the catalogue), used to show the merchant what their customers are asking for.

5. Data received from Meta platforms (Platform Data)

The Service connects to Instagram via the Instagram Messaging API and, as it rolls out, to WhatsApp via the WhatsApp Business Platform— Meta's official interfaces. Through them we receive, on the merchant's behalf:

  • the customer's platform identifiers (such as an Instagram-scoped ID, or the WhatsApp number used to message the merchant) and profile name;
  • the content of messages exchanged with the merchant's connected account, including media, delivered to us by Meta's webhooks;
  • merchant channel data: the connected account's identifiers and the access tokens Meta issues for it.

We use Platform Data solely to provide the Service to the merchant whose account it relates to:

  • generating and sending the replies the merchant's agent is configured to give;
  • capturing requests (orders, bookings, appointments, quotes, callbacks) for the merchant;
  • showing the merchant their own conversations and enabling human takeover;
  • security, abuse prevention, and compliance with law and Meta's policies.

We do not sell Platform Data, do not use it for advertising, do not use it to build profiles unrelated to the Service, and do not share it with third parties other than the sub-processors listed in Section 8 acting on our instructions. We honour Meta's Platform Terms and Developer Policies, including deletion obligations: when a merchant disconnects a channel or deletes their account, or when deletion is otherwise required, associated Platform Data is deleted as described in Sections 10 and 11. This includes acting on deletion and deauthorisation notifications we receive from Meta — for example, when someone removes the connection or asks Meta to delete their data. To request deletion of your data, see Section 11 — Data deletion instructions.

6. How AI processing works

Vyapnova generates replies using large language models operated by third-party AI providers. To produce a reply, the relevant parts of a conversation and of the merchant's knowledge base are sent to one of our AI sub-processors — Google (Gemini), OpenAI, or Anthropic (Claude) — with automatic fallback between them for reliability. Voyage AI processes product images to enable image-based catalogue search.

  • We use these providers' business/API services, under terms which provide that API data is not used to train their models.
  • We do not use your customers' conversations to train models of our own, and we do not permit our AI sub-processors to use them for training.
  • Automated replies are generated from the merchant's own knowledge base. The Service is designed to escalate to a human for sensitive or unclear situations, and merchants can take over any conversation at any time. AI output can nonetheless contain errors — see our Terms of Service for the merchant's responsibilities.

7. Purposes and legal bases

We process personal data for the following purposes and, for users in jurisdictions that require a legal basis (such as the GDPR), on the bases shown:

  • Providing and operating the Service (accounts, conversations, requests, knowledge bases) — performance of a contract.
  • Managing the waitlist and invites, and responding to contact requests — steps taken at your request prior to a contract, and our legitimate interest in launching the Service.
  • Pricing and product research from information you volunteer (such as willingness-to-pay) — legitimate interest; never used to charge you.
  • Understanding how our websites are used (usage analytics, Section 3) — your consent, given through the cookie choice on our site and withdrawable at any time (Section 9).
  • Security, abuse prevention, moderation, and audit — legitimate interest and legal obligation.
  • Service communications (invites, material changes, security notices) — contract and legitimate interest. Marketing communications — consent, withdrawable at any time.
  • Compliance with law and enforcement of our terms — legal obligation and legitimate interest.

8. Sharing and sub-processors

We do not sell personal data — including as “sell” or “share” are defined in US state privacy laws such as the California Consumer Privacy Act. We share it only with service providers (sub-processors) who process it on our instructions under contractual safeguards, with the platforms you connect, or where the law requires. Our current sub-processors:

  • Amazon Web Services — cloud infrastructure and media storage (product photos and conversation media).
  • Google (Gemini API), OpenAI, and Anthropic — AI reply generation (Section 6). Voyage AI — image embeddings for catalogue search.
  • Google Workspace (Sheets) — storage of website waitlist and contact submissions.
  • ipwho.is— IP-based approximate geolocation on our website forms (receives the visitor's IP address; we store only the derived city/region/country).
  • Microsoft (Clarity) — usage analytics on our marketing website (interaction events, session replays, device context, and IP address, processed to provide the analytics service).
  • Sentry — error monitoring for service reliability, where enabled.

Meta Platforms(Instagram, WhatsApp) is not our sub-processor: it is the platform through which merchants and their customers communicate. Data exchanged on those platforms is also governed by Meta's own terms and privacy policy. We may additionally disclose data to comply with law, to enforce our terms, or in connection with a corporate transaction — in which case this Policy will continue to apply to data collected under it and we will notify you of material changes.

We update this list as providers change; material changes are announced per Section 17.

9. Cookies and similar technologies

  • Marketing website: no advertising cookies. With your consent — asked once and changeable any time via “Cookies” in the footer — our usage-analytics tool Microsoft Clarity sets its own cookies (such as _clck and _clsk) to recognise a returning browser and stitch a visit into one session. If you decline, Clarity does not load and these cookies are not set; declining loses no site functionality. We also use the browser's sessionStorage to remember, for the current session only, which campaign or referrer brought you here, so a waitlist submission can record its source.
  • Product application: strictly-necessary storage for authentication (session tokens) and product preferences. We do not run third-party advertising trackers in the product.

10. Retention

  • Waitlist and contact data: kept while we operate the waitlist and for up to 24 months after our last interaction with you, unless you ask us to delete it sooner.
  • Merchant account and business data: kept while the account is active; removed from live systems within 30 days of account deletion.
  • End-customer conversation and request data (including Platform Data): kept while the merchant's account and the relevant channel remain connected, so the merchant can serve returning customers. Deleted on the earlier of: the merchant erasing the customer, a verified erasure request (Section 11), channel disconnection where deletion is required, or merchant account deletion — in each case removed from live systems within 30 days.
  • Backups: encrypted backups roll off on a fixed cycle; data deleted from live systems leaves backups within 90 days.
  • Records we must keep: audit logs and records required for security, tax, or other legal compliance are retained for the period the law requires, then deleted.

11. Data deletion instructions

Anyone can request deletion of their personal data from Vyapnova. This section serves as our data deletion instructions for all users, including users who interact with our Meta platform integrations.

  • If you are a customer who messaged a business(on Instagram, WhatsApp, or a merchant's website): ask that business to delete your data — the Service gives every merchant a per-customer export and erase capability. You can also email hello@vyapnova.com directly, telling us the business you messaged and the handle or number you messaged from; we will verify the request, coordinate with the merchant as required, and confirm the deletion to you.
  • If you are a merchant: you can erase individual customers from your dashboard (export a copy first if you need one), disconnect channels at any time, or request full account deletion by emailing hello@vyapnova.com from your account email.
  • If you are on our waitlist or contacted us: email hello@vyapnova.com from the address you used.

We act on verified deletion requests within 30 days for live systems, with backups following per Section 10. Where we delete data in our processor role, we do so on the merchant's instruction or as the law requires.

12. Your rights

Wherever you are: you have the right to access a copy or summary of your personal data and the processing applied to it, to correction of inaccurate data, and to erasure. Where processing rests on consent, you may withdraw that consent at any time, without affecting processing already carried out.

If you are in India (DPDP Act): you additionally have the right to grievance redressal (Section 18), to nominate a person to exercise your rights in case of death or incapacity, and — if your grievance is not resolved through our process — to complain to the Data Protection Board of India.

If you are in the EEA, UK, or a jurisdiction with similar laws: you additionally have the rights to data portability, to restriction of processing, to object to processing based on legitimate interests, and to lodge a complaint with your local supervisory authority. We do not make automated decisions about you that produce legal or similarly significant effects.

To exercise any right, email hello@vyapnova.com. We verify requests, respond within 30 days, and will never discriminate against you for exercising your rights. For end-customer conversation data, your primary relationship is with the merchant (Section 2); we will route your request appropriately either way.

13. International transfers

We are an Indian company; processing occurs on cloud infrastructure in India and in other regions where our sub-processors operate (including the United States, where our AI providers and Microsoft are based). Where personal data crosses borders, we rely on contracts with our sub-processors that impose data-protection obligations and, for GDPR-covered data, on appropriate safeguards such as the European Commission's Standard Contractual Clauses. We do not transfer personal data to any jurisdiction restricted by the Government of India under the DPDP Act.

14. Security

  • Encryption in transit (TLS) for connections to the Service, and encryption at rest on our cloud storage and database infrastructure.
  • Passwords stored only as one-way hashes; platform access tokens held server-side and never exposed to browsers.
  • Role-based access control for merchant teams, with per-merchant data isolation in our data model.
  • Audit logging of sensitive actions, rate limiting, and content-moderation systems.
  • Least-privilege internal access; production secrets managed outside source code.

No system is perfectly secure and we cannot guarantee absolute security, but we work continuously to protect your data. See our Security page for more, and report suspected vulnerabilities to hello@vyapnova.com.

15. Data breach notification

If a personal data breach occurs, we will notify the Data Protection Board of India and affected individuals as required by the DPDP Act and, for GDPR-covered data, the competent supervisory authority without undue delay (and, where feasible, within 72 hours of becoming aware of the breach) and affected individuals where the breach is likely to result in a high risk to them. Notices will describe the nature of the breach, its likely consequences, and the measures taken.

16. Children

The Service is a business tool and is not directed at children, and merchants must be of legal age to contract. Where a merchant's end customers include children, the merchant is responsible, as Data Fiduciary / controller, for complying with applicable children's-data requirements — including verifiable parental consent where the law requires it; we process such data only on the merchant's instructions.

17. Changes to this Policy

We may update this Policy as the Service and the law evolve. The “Last updated” date above always reflects the current version, and we will notify registered users and waitlist members of material changes by email or in-product notice before they take effect.

18. Contact & Grievance Officer

Vyapnova Technologies Private Limited
Registered office: Gurugram, Haryana, India
Email (privacy requests, security reports, and all other matters): hello@vyapnova.com

Grievance Officer (India): Anirudh Kumar, Vyapnova Technologies Private Limited, Gurugram, Haryana, India — hello@vyapnova.com. We acknowledge grievances within 48 hours and aim to resolve them within 30 days. If you are outside India, you may also contact your local data protection authority.