Privacy Policy
Last updated: August 9, 2026
This Privacy Policy explains how Wapikit Technologies Private Limited (“Wapikit”, “we”, “us”) handles personal data. Wapikit is a business-to-business customer engagement and retention platform built on the WhatsApp Business Platform.
1.Scope and our two roles
This policy covers our website at www.wapikit.com, our application at app.wapikit.com, and the surfaces we host on behalf of our customers, such as chat widgets and lead-capture forms.
We handle personal data in two distinct roles, and your rights differ by role.
| Situation | Our role | Who decides why the data is used |
|---|---|---|
| You visit our website, sign up, or use the platform as an Authorised User | Data fiduciary / controller | Wapikit |
| A business uses Wapikit to message, segment or support its own customers | Data processor | That business, as our customer |
Where we act as a processor, we handle personal data only on our customer’s documented instructions, and that customer’s own privacy notice governs why the data was collected in the first place.
2.Definitions
- Personal Data:
- Any information relating to an identified or identifiable individual.
- Account Data:
- Data about our customer and its Authorised Users - name, work email, phone number, company name, role, billing details and login activity.
- Client Data:
- Data a customer uploads to, syncs into or generates within its workspace, including data about its own end customers.
- End Customer:
- An individual whose data a Wapikit customer processes through the platform - for example a contact, shopper or ticket requester.
- Usage Data:
- Technical data generated by use of the service, such as IP address, device and browser information, feature interactions and timestamps.
- Subprocessor:
- A third party we engage to process personal data on our behalf. Our current list is published at wapikit.com/subprocessors.
3.Data we collect
Data you give us
- Account and profile data: name, work email, phone number, password hash, company name, role or designation, company website, and profile image.
- Billing and tax data: billing contact and address, GSTIN, PAN where applicable, TDS withholding details and certificates, payment references, invoice history and wallet ledger records. Card and bank credentials are handled by our payment gateway and are never stored by us.
- Support and sales data: messages you send us, demo and onboarding notes, and grievance correspondence.
- Client Data: described in section 4.
Data we collect automatically
- Usage Data: IP address, browser and operating system, device type, referring and exit pages, pages and features used, and the time of access.
- Log, audit and security data: authentication events, API calls, permission changes, administrative actions and error traces.
- Cookies and similar technologies: described in section 15.
We infer approximate location from IP address for security, fraud prevention and tax determination. We do not collect device GPS location.
Data we receive from others
- Sign-in providers: if you sign in with Google, we receive your name, email address and profile image. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use that data for advertising, and we do not use it to develop, improve or train generalised or non-personalised AI or ML models.
- Meta / WhatsApp Business Platform: message delivery and read status, conversation and pricing categories, template review status, quality ratings and messaging limits for the numbers our customers connect.
- Integrations our customers authorise: commerce, checkout, logistics, review and scheduling platforms send us data at our customer’s instruction.
- Payment providers: payment and settlement status, and dispute or chargeback notifications.
4.Data you process through Wapikit
When a business uses Wapikit, it processes data about its own end customers through our platform. Depending on the features it enables, that can include:
- Contacts and segments: names, WhatsApp and phone numbers, email addresses, attributes, tags, consent and opt-out status, and segment membership.
- Conversations: inbound and outbound WhatsApp messages and media, delivery and read receipts, notes, tags, ticket state and assignment history.
- Commerce data: orders, line items, carts and abandoned carts, checkout and payment status, delivery and RTO signals, and returns.
- Engagement and behavioural data: website and widget sessions, lead-capture submissions, back-in-stock requests, link clicks, campaign responses and revenue attribution.
- Automation and journey state: which contacts entered which journey, at which step, and with what outcome.
- Knowledge base content: documents and URLs uploaded to ground AI replies, and any personal data those documents happen to contain.
Each customer’s workspace is logically isolated. Access is scoped by organisation and enforced by role-based permissions. We access Client Data only to operate and secure the service, to provide support at the customer’s request, or where required by law.
5.How we use data
- To provide the service: create and administer accounts, deliver messages and campaigns, run automations and journeys, sync integrations, and surface analytics.
- To bill accurately: meter usage, price it against your agreed plan, debit the wallet, generate invoices and tax documents, and reconcile payments.
- To keep the service secure: authenticate users, detect and prevent fraud, abuse and unauthorised access, enforce rate limits, and investigate incidents.
- To support you: respond to requests, diagnose problems, and send service, security and billing notices. These are operational messages and cannot be opted out of while your account is open.
- To improve the product: understand feature usage and reliability. We use aggregated or pseudonymised data for this wherever possible.
- To operate AI features: as described in section 7.
- To market to prospects: send product and marketing emails to business contacts who signed up or asked to hear from us. Every marketing email has an unsubscribe link.
- To comply with law: meet accounting, tax, and regulatory obligations and respond to lawful requests.
We do not sell or rent personal data, and we do not use Client Data for our own advertising or to profile individuals for third parties.
6.Legal bases for processing
Where the Digital Personal Data Protection Act, 2023 applies, we process personal data on the basis of consent or of legitimate uses recognised under that Act. Where the GDPR or comparable law applies, we rely on:
- Performance of a contract - to provide the service to our customer and to bill for it;
- Legitimate interests - to secure the service, prevent fraud and abuse, improve the product, and carry out business-to-business marketing, balanced against your rights;
- Legal obligation - to keep accounting and tax records and to respond to lawful requests; and
- Consent - for non-essential cookies and, where required, for marketing. You may withdraw consent at any time.
Where we act as a processor for Client Data, the legal basis is determined by our customer, not by us.
7.AI processing
Where a customer enables AI features, we send the context needed to generate a response — typically knowledge base content, recent conversation context and the configured business rules — to our AI processing provider. Today that provider is the Azure OpenAI Service operated by Microsoft, under an enterprise agreement.
- Prompts and responses are not used to train the provider’s foundation models, and are not shared with other customers of the provider.
- We do not use Client Data to train generalised, cross-customer or shared AI models. Any tuning we do is scoped to the originating workspace.
- We apply automated redaction to reduce the personal data included in AI context where it is not needed to answer.
- AI output is generated, not verified. Our customer remains responsible for the messages its workspace sends.
9.Where data is stored and transferred
Our primary infrastructure runs on Microsoft Azure. Personal data may be stored and processed in India and in other countries where we or our subprocessors operate facilities, including the United States and the European Union.
Where personal data is transferred outside its country of origin, we rely on contractual protections with each subprocessor — including standard contractual clauses where applicable — and on the technical and organisational measures described in section 11. India’s Digital Personal Data Protection Act, 2023 permits transfer other than to countries the Central Government restricts; we comply with any such restriction as it is notified.
10.How long we keep data
We keep personal data only as long as we need it for the purpose it was collected, or as long as the law requires. Our default periods are:
| Category | Retention |
|---|---|
| Account and Authorised User data | For the term of your account, then 30 days after closure |
| Contacts, conversations, campaigns and commerce data | For the term of your account, then 30 days after closure - or earlier if you delete the records or ask us to |
| Knowledge base documents and AI configuration | Until you delete them, or 30 days after account closure |
| Billing, wallet ledger, invoices and tax records | At least 8 years from the end of the relevant financial year, as required under Indian company and tax law - retained even after account closure |
| Security, audit and access logs | Up to 12 months, or longer where needed to investigate an incident |
| Product analytics and usage telemetry | Up to 24 months, in aggregated or pseudonymised form |
| Support and grievance correspondence | Up to 3 years from resolution |
Customers may delete records within their workspace at any time, and may request deletion of an entire workspace. Once deletion completes, data cannot be recovered. Backups are overwritten on a rolling cycle, so deleted data may persist in backups for a short period before being purged. Financial and tax records are retained regardless of deletion requests, because we are legally required to keep them.
11.How we protect data
- Encryption of data in transit (TLS) and at rest;
- Application-level encryption for sensitive credentials such as integration and API tokens;
- Tenant isolation: every query, job, cache entry and export is scoped to a single organisation;
- Role-based access control, with least-privilege internal access and audit logging;
- Automated redaction of personal data in AI context where it is not required;
- Hashing of identifiers used for internal signal processing;
- Bot and abuse protection, rate limiting, and monitoring and alerting on anomalous activity; and
- Regular dependency patching, vulnerability review and access review.
No system is completely secure and we cannot guarantee absolute security. If we become aware of a personal data breach affecting you, we will notify you and the relevant authorities as required — including reporting to CERT-In within the timelines prescribed under Indian law, and notifying the Data Protection Board and affected individuals as required by the Digital Personal Data Protection Act, 2023. Report a suspected vulnerability or incident to [email protected].
12.Your rights
Subject to the law that applies to you, you may have the right to:
- Access the personal data we hold about you and information about how it is processed;
- Correct data that is inaccurate, incomplete or out of date;
- Erase data where it is no longer needed and we are not required to keep it;
- Restrict or object to certain processing, including direct marketing;
- Port data you gave us to another provider in a structured, machine-readable format, where technically feasible;
- Withdraw consent where processing is based on consent, without affecting processing already carried out;
- Nominate another individual to exercise your rights in the event of death or incapacity, as provided under the Digital Personal Data Protection Act, 2023; and
- Complain to us and, if unsatisfied, to the Data Protection Board of India or your local supervisory authority.
To exercise a right, write to [email protected]. We may ask you to verify your identity. We respond within 30 days, and will tell you if we need longer or cannot act on a request and why. Exercising these rights is free; we may charge a reasonable fee only for manifestly unfounded or repetitive requests.
13.If you are an end customer of a Wapikit user
If you received a WhatsApp message from a business, or interacted with a chat widget or form powered by Wapikit, that business decided to contact you and holds your data. We process it only on that business’s instructions.
- To stop receiving messages, reply to the conversation with a stop or opt-out request, or use the opt-out the business provides. That opt-out is recorded and honoured across the platform.
- To access, correct or delete your data, contact the business directly — it can act on your request within its own workspace.
- If you cannot identify or reach the business, write to [email protected] with the details and we will route your request to the relevant customer and support them in responding. We cannot decide the outcome of a request about data we do not control.
14.Your responsibilities as a Wapikit customer
If you use Wapikit to process data about your own customers, you are the data fiduciary or controller for that data. You are responsible for:
- obtaining and being able to evidence valid consent or another lawful basis before uploading contacts or messaging them;
- maintaining a privacy notice that accurately describes how you use Wapikit and what data you process;
- honouring opt-outs and responding to your end customers’ rights requests;
- keeping your workspace access under control — assigning appropriate roles, removing users who leave, and protecting API keys; and
- not uploading data you are not permitted to process, and not placing sensitive data in a knowledge base that grounds AI replies.
If you need a data processing agreement, write to [email protected].
16.Children's data
Wapikit is a business product and is not directed at children. We do not knowingly collect personal data of anyone under 18 for our own purposes. If we learn that we have, we will delete it. Customers must not use the platform to knowingly process the personal data of children without the verifiable consent of a parent or guardian as required under the Digital Personal Data Protection Act, 2023, and must not direct behavioural targeting or advertising at children.
17.Changes to this policy
We may update this policy as our product, providers or legal obligations change. We will update the “Last updated” date and, for material changes, give notice by email to account administrators or by in-application notice before the change takes effect. Material changes to our subprocessor list are published on the Subprocessors page.
18.Grievance officer and contact
For any question, request or complaint about privacy, contact us at [email protected]. We have appointed a Grievance Officer under the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023:
Sarthak Jain
Grievance Officer, Wapikit Technologies Private Limited
Plot No. A-27A, Sector 62
Noida, Gautam Buddha Nagar
Uttar Pradesh 201301
India
Email: [email protected]
Working hours: Monday to Friday, 10:00 – 18:00 IST (excluding public holidays)
We acknowledge complaints within 24 hours and aim to resolve them within 15 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India or to your local supervisory authority. This policy should be read together with our Terms and Conditions.