Privacy Policy

Last updated: August 9, 2026

This Privacy Policy explains how Wapikit Technologies Private Limited (“Wapikit”, “we”, “us”) handles personal data. Wapikit is a business-to-business customer engagement and retention platform built on the WhatsApp Business Platform.

1.Scope and our two roles

This policy covers our website at www.wapikit.com, our application at app.wapikit.com, and the surfaces we host on behalf of our customers, such as chat widgets and lead-capture forms.

We handle personal data in two distinct roles, and your rights differ by role.

SituationOur roleWho decides why the data is used
You visit our website, sign up, or use the platform as an Authorised UserData fiduciary / controllerWapikit
A business uses Wapikit to message, segment or support its own customersData processorThat business, as our customer

Where we act as a processor, we handle personal data only on our customer’s documented instructions, and that customer’s own privacy notice governs why the data was collected in the first place.

2.Definitions

Personal Data:
Any information relating to an identified or identifiable individual.
Account Data:
Data about our customer and its Authorised Users - name, work email, phone number, company name, role, billing details and login activity.
Client Data:
Data a customer uploads to, syncs into or generates within its workspace, including data about its own end customers.
End Customer:
An individual whose data a Wapikit customer processes through the platform - for example a contact, shopper or ticket requester.
Usage Data:
Technical data generated by use of the service, such as IP address, device and browser information, feature interactions and timestamps.
Subprocessor:
A third party we engage to process personal data on our behalf. Our current list is published at wapikit.com/subprocessors.

3.Data we collect

Data you give us

  • Account and profile data: name, work email, phone number, password hash, company name, role or designation, company website, and profile image.
  • Billing and tax data: billing contact and address, GSTIN, PAN where applicable, TDS withholding details and certificates, payment references, invoice history and wallet ledger records. Card and bank credentials are handled by our payment gateway and are never stored by us.
  • Support and sales data: messages you send us, demo and onboarding notes, and grievance correspondence.
  • Client Data: described in section 4.

Data we collect automatically

  • Usage Data: IP address, browser and operating system, device type, referring and exit pages, pages and features used, and the time of access.
  • Log, audit and security data: authentication events, API calls, permission changes, administrative actions and error traces.
  • Cookies and similar technologies: described in section 15.

We infer approximate location from IP address for security, fraud prevention and tax determination. We do not collect device GPS location.

Data we receive from others

  • Sign-in providers: if you sign in with Google, we receive your name, email address and profile image. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use that data for advertising, and we do not use it to develop, improve or train generalised or non-personalised AI or ML models.
  • Meta / WhatsApp Business Platform: message delivery and read status, conversation and pricing categories, template review status, quality ratings and messaging limits for the numbers our customers connect.
  • Integrations our customers authorise: commerce, checkout, logistics, review and scheduling platforms send us data at our customer’s instruction.
  • Payment providers: payment and settlement status, and dispute or chargeback notifications.

4.Data you process through Wapikit

When a business uses Wapikit, it processes data about its own end customers through our platform. Depending on the features it enables, that can include:

  • Contacts and segments: names, WhatsApp and phone numbers, email addresses, attributes, tags, consent and opt-out status, and segment membership.
  • Conversations: inbound and outbound WhatsApp messages and media, delivery and read receipts, notes, tags, ticket state and assignment history.
  • Commerce data: orders, line items, carts and abandoned carts, checkout and payment status, delivery and RTO signals, and returns.
  • Engagement and behavioural data: website and widget sessions, lead-capture submissions, back-in-stock requests, link clicks, campaign responses and revenue attribution.
  • Automation and journey state: which contacts entered which journey, at which step, and with what outcome.
  • Knowledge base content: documents and URLs uploaded to ground AI replies, and any personal data those documents happen to contain.

Each customer’s workspace is logically isolated. Access is scoped by organisation and enforced by role-based permissions. We access Client Data only to operate and secure the service, to provide support at the customer’s request, or where required by law.

5.How we use data

  • To provide the service: create and administer accounts, deliver messages and campaigns, run automations and journeys, sync integrations, and surface analytics.
  • To bill accurately: meter usage, price it against your agreed plan, debit the wallet, generate invoices and tax documents, and reconcile payments.
  • To keep the service secure: authenticate users, detect and prevent fraud, abuse and unauthorised access, enforce rate limits, and investigate incidents.
  • To support you: respond to requests, diagnose problems, and send service, security and billing notices. These are operational messages and cannot be opted out of while your account is open.
  • To improve the product: understand feature usage and reliability. We use aggregated or pseudonymised data for this wherever possible.
  • To operate AI features: as described in section 7.
  • To market to prospects: send product and marketing emails to business contacts who signed up or asked to hear from us. Every marketing email has an unsubscribe link.
  • To comply with law: meet accounting, tax, and regulatory obligations and respond to lawful requests.

We do not sell or rent personal data, and we do not use Client Data for our own advertising or to profile individuals for third parties.

7.AI processing

Where a customer enables AI features, we send the context needed to generate a response — typically knowledge base content, recent conversation context and the configured business rules — to our AI processing provider. Today that provider is the Azure OpenAI Service operated by Microsoft, under an enterprise agreement.

  • Prompts and responses are not used to train the provider’s foundation models, and are not shared with other customers of the provider.
  • We do not use Client Data to train generalised, cross-customer or shared AI models. Any tuning we do is scoped to the originating workspace.
  • We apply automated redaction to reduce the personal data included in AI context where it is not needed to answer.
  • AI output is generated, not verified. Our customer remains responsible for the messages its workspace sends.

8.How we share data

We share personal data only in these situations:

  • Subprocessors. Providers who host, secure, analyse, message, bill or support on our behalf, under contracts that restrict them to our instructions. The current list is at wapikit.com/subprocessors.
  • The WhatsApp Business Platform. To deliver a message, its content and the recipient’s number are necessarily transmitted to Meta.
  • Integrations you authorise. When a customer connects a third-party platform, data flows to and from that platform at the customer’s instruction and is then governed by that provider’s terms.
  • Professional advisers. Auditors, accountants and lawyers under duties of confidentiality.
  • Legal and safety. Where required by law, court order or a valid request from a public authority, or to establish, exercise or defend legal claims. We review such requests and disclose only what is required.
  • Corporate transactions. In a merger, acquisition, financing or sale of assets, data may transfer as part of the business, subject to this policy continuing to apply.
  • Aggregated data. Statistics that cannot reasonably identify any individual, customer or end customer.

9.Where data is stored and transferred

Our primary infrastructure runs on Microsoft Azure. Personal data may be stored and processed in India and in other countries where we or our subprocessors operate facilities, including the United States and the European Union.

Where personal data is transferred outside its country of origin, we rely on contractual protections with each subprocessor — including standard contractual clauses where applicable — and on the technical and organisational measures described in section 11. India’s Digital Personal Data Protection Act, 2023 permits transfer other than to countries the Central Government restricts; we comply with any such restriction as it is notified.

10.How long we keep data

We keep personal data only as long as we need it for the purpose it was collected, or as long as the law requires. Our default periods are:

CategoryRetention
Account and Authorised User dataFor the term of your account, then 30 days after closure
Contacts, conversations, campaigns and commerce dataFor the term of your account, then 30 days after closure - or earlier if you delete the records or ask us to
Knowledge base documents and AI configurationUntil you delete them, or 30 days after account closure
Billing, wallet ledger, invoices and tax recordsAt least 8 years from the end of the relevant financial year, as required under Indian company and tax law - retained even after account closure
Security, audit and access logsUp to 12 months, or longer where needed to investigate an incident
Product analytics and usage telemetryUp to 24 months, in aggregated or pseudonymised form
Support and grievance correspondenceUp to 3 years from resolution

Customers may delete records within their workspace at any time, and may request deletion of an entire workspace. Once deletion completes, data cannot be recovered. Backups are overwritten on a rolling cycle, so deleted data may persist in backups for a short period before being purged. Financial and tax records are retained regardless of deletion requests, because we are legally required to keep them.

11.How we protect data

  • Encryption of data in transit (TLS) and at rest;
  • Application-level encryption for sensitive credentials such as integration and API tokens;
  • Tenant isolation: every query, job, cache entry and export is scoped to a single organisation;
  • Role-based access control, with least-privilege internal access and audit logging;
  • Automated redaction of personal data in AI context where it is not required;
  • Hashing of identifiers used for internal signal processing;
  • Bot and abuse protection, rate limiting, and monitoring and alerting on anomalous activity; and
  • Regular dependency patching, vulnerability review and access review.

No system is completely secure and we cannot guarantee absolute security. If we become aware of a personal data breach affecting you, we will notify you and the relevant authorities as required — including reporting to CERT-In within the timelines prescribed under Indian law, and notifying the Data Protection Board and affected individuals as required by the Digital Personal Data Protection Act, 2023. Report a suspected vulnerability or incident to [email protected].

12.Your rights

Subject to the law that applies to you, you may have the right to:

  • Access the personal data we hold about you and information about how it is processed;
  • Correct data that is inaccurate, incomplete or out of date;
  • Erase data where it is no longer needed and we are not required to keep it;
  • Restrict or object to certain processing, including direct marketing;
  • Port data you gave us to another provider in a structured, machine-readable format, where technically feasible;
  • Withdraw consent where processing is based on consent, without affecting processing already carried out;
  • Nominate another individual to exercise your rights in the event of death or incapacity, as provided under the Digital Personal Data Protection Act, 2023; and
  • Complain to us and, if unsatisfied, to the Data Protection Board of India or your local supervisory authority.

To exercise a right, write to [email protected]. We may ask you to verify your identity. We respond within 30 days, and will tell you if we need longer or cannot act on a request and why. Exercising these rights is free; we may charge a reasonable fee only for manifestly unfounded or repetitive requests.

13.If you are an end customer of a Wapikit user

If you received a WhatsApp message from a business, or interacted with a chat widget or form powered by Wapikit, that business decided to contact you and holds your data. We process it only on that business’s instructions.

  • To stop receiving messages, reply to the conversation with a stop or opt-out request, or use the opt-out the business provides. That opt-out is recorded and honoured across the platform.
  • To access, correct or delete your data, contact the business directly — it can act on your request within its own workspace.
  • If you cannot identify or reach the business, write to [email protected] with the details and we will route your request to the relevant customer and support them in responding. We cannot decide the outcome of a request about data we do not control.

14.Your responsibilities as a Wapikit customer

If you use Wapikit to process data about your own customers, you are the data fiduciary or controller for that data. You are responsible for:

  • obtaining and being able to evidence valid consent or another lawful basis before uploading contacts or messaging them;
  • maintaining a privacy notice that accurately describes how you use Wapikit and what data you process;
  • honouring opt-outs and responding to your end customers’ rights requests;
  • keeping your workspace access under control — assigning appropriate roles, removing users who leave, and protecting API keys; and
  • not uploading data you are not permitted to process, and not placing sensitive data in a knowledge base that grounds AI replies.

If you need a data processing agreement, write to [email protected].

15.Cookies and tracking

Cookies are small files stored on your device. We and our providers use cookies and similar technologies for the purposes below.

CategoryWhat it is forExamples
Strictly necessarySign-in, session management, security, bot and abuse prevention. These cannot be switched off without breaking the service.Session and authentication cookies, Cloudflare Turnstile
FunctionalRemembering preferences such as your workspace, layout and dismissed notices.Local preference cookies
Performance and analyticsUnderstanding which features and pages are used so we can improve them. Aggregated; not used to build advertising profiles.PostHog (application), Microsoft Clarity and Vercel Analytics (website)

We do not use advertising or cross-site tracking cookies on the application. You can block or delete cookies in your browser settings, but strictly necessary cookies are required to sign in and use the platform. We honour browser Do Not Track and Global Privacy Control signals for non-essential analytics where the browser sends them.

Chat widgets, lead-capture surfaces and back-in-stock forms that our customers embed on their own websites set storage on those websites to remember a visitor’s session and submissions. Those surfaces are deployed by our customer and are covered by that customer’s cookie notice.

16.Children's data

Wapikit is a business product and is not directed at children. We do not knowingly collect personal data of anyone under 18 for our own purposes. If we learn that we have, we will delete it. Customers must not use the platform to knowingly process the personal data of children without the verifiable consent of a parent or guardian as required under the Digital Personal Data Protection Act, 2023, and must not direct behavioural targeting or advertising at children.

17.Changes to this policy

We may update this policy as our product, providers or legal obligations change. We will update the “Last updated” date and, for material changes, give notice by email to account administrators or by in-application notice before the change takes effect. Material changes to our subprocessor list are published on the Subprocessors page.

18.Grievance officer and contact

For any question, request or complaint about privacy, contact us at [email protected]. We have appointed a Grievance Officer under the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023:

Sarthak Jain

Grievance Officer, Wapikit Technologies Private Limited

Plot No. A-27A, Sector 62

Noida, Gautam Buddha Nagar

Uttar Pradesh 201301

India

Email: [email protected]

Working hours: Monday to Friday, 10:00 – 18:00 IST (excluding public holidays)

We acknowledge complaints within 24 hours and aim to resolve them within 15 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India or to your local supervisory authority. This policy should be read together with our Terms and Conditions.