Legal

Privacy Policy

Last updated June 2026

TemplateFor review by counsel

This document is a working template provided for transparency. It is not legal advice and should be reviewed and finalised by qualified counsel before being relied upon. Defined terms, retention windows, and sub-processor names are placeholders pending finalisation.

1. Introduction

This Privacy Policy explains how Vyapnova Technologies Private Limited (“Vyapnova”, “we”, “us”) collects, uses, shares, and protects personal data in connection with our omnichannel AI sales and support platform (the “Service”). The Service helps merchants in India reply to customer messages across channels such as Instagram, WhatsApp, and a website widget, answer questions from the merchant’s own catalogue, capture leads, and escalate to a human when needed.

It is written to be aware of India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and applies to personal data processed when you visit our website, create an account, or use the Service. By using the Service, you acknowledge the practices described here.

2. Information we collect

We collect the following categories of data:

  • Account data. Information you provide when registering and managing your account — name, business name, email, phone number, billing details, and authentication identifiers.
  • Merchant catalogue. Product, pricing, availability, and policy content you upload or connect so the agent can answer accurately on your behalf.
  • End-customer conversation data. Messages, contact identifiers, language, and lead details exchanged between your customers and the agent. This data is processed on the merchant’s behalf — see Section 4.
  • Usage and cost data. Logs, device and connection metadata, feature usage, message volumes, and model-cost metering used to operate, secure, and bill the Service.

3. How we use it

We use personal data to:

  • Provide, operate, and maintain the Service, including generating and routing agent replies across channels.
  • Ground responses in the merchant's catalogue and detect or mirror the customer's language.
  • Capture and organise leads, and escalate conversations to a human agent when required.
  • Meter usage, calculate model and infrastructure costs, and process billing.
  • Secure the Service, prevent abuse, debug issues, and improve quality and reliability.
  • Communicate service, security, and account notices, and comply with legal obligations.

We do not sell personal data. We do not use end-customer conversation data to train foundation models, and we instruct our sub-processors not to do so.

5. Sharing and sub-processors

We share personal data only as needed to run the Service, with sub-processors bound by confidentiality and data-protection obligations. Categories include:

  • LLM and AI providers that generate, classify, or translate replies. Conversation content sent for inference is processed under no-training terms where available.
  • Messaging platforms (e.g., Meta / WhatsApp) that deliver and receive messages on the channels you connect, subject to their own platform terms.
  • Cloud hosting and storage providers that host the application, databases, and backups.
  • Operational service providers for payments, analytics, error monitoring, and customer support.

We may also disclose data to comply with law or a valid legal request, or in connection with a merger, acquisition, or asset transfer, subject to this Policy. A current list of named sub-processors is available on request.

6. Data retention

We retain personal data only as long as necessary for the purposes described here, or as required by law. Account and billing records are retained for the life of the account plus any statutory period. Conversation and lead data are retained per the merchant’s configured retention settings; where not configured, default retention windows apply and are documented in the product. On account termination, we delete or anonymise personal data within a reasonable period, subject to legal-hold and backup-rotation timelines.

7. Your rights as a Data Principal

Subject to the DPDP Act, individuals (Data Principals) have the right to access a summary of their personal data, request correction or completion, request erasure, nominate another person to exercise rights, and raise a grievance. Where Vyapnova is the Data Fiduciary, contact us using Section 12. Where the merchant is the Data Fiduciary, direct requests to that merchant; we will assist them in responding.

To support these rights, the Service exposes data export and erasure endpoints so merchants can retrieve or delete an end-customer’s conversation and lead data on request.

8. Security

We implement reasonable technical and organisational safeguards, including:

  • Encryption of data in transit (TLS) and at rest.
  • Role-based access control, least-privilege access, and authentication on administrative interfaces.
  • Network isolation, audit logging, and monitoring of access to systems holding personal data.
  • Routine backups and a documented process for responding to security incidents.

No method of transmission or storage is fully secure; we cannot guarantee absolute security but work to protect data using accepted industry practices.

9. International transfers

Some sub-processors may process personal data outside India. Where this occurs, we transfer data consistent with the DPDP Act and applicable restrictions, and put in place appropriate contractual safeguards with the recipient. We will not transfer personal data to any jurisdiction restricted by the Government of India.

10. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data of children except as may be incidental to a merchant’s own customer interactions, for which the merchant is responsible for obtaining verifiable parental consent where the DPDP Act requires it. If you believe a child’s data has been collected in error, contact us and we will take appropriate steps to delete it.

11. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified through the Service or by email, and the “Last updated” date above will be revised. Continued use of the Service after an update constitutes acknowledgement of the revised Policy.

12. Contact

For privacy questions or to exercise your rights, contact Vyapnova Technologies Private Limited, India:

  • Privacy team: privacy@vyapnova.com
  • Grievance Officer (India): As required under the DPDP Act, our designated Grievance Officer can be reached at privacy@vyapnova.com. We aim to acknowledge grievances promptly and respond within the period prescribed by law.