Skip to content
Login
Legal & Compliance

Privacy Policy — Your Data. Your Rights.

WAAPIBOX is built on trust. This policy explains exactly how we collect, use, store, protect and share your data — in plain language, not legal jargon.

Effective: 10 October 2026 Last updated: 10 October 2026 DPDP Act Compliant GDPR Ready
This Privacy Policy was last updated on 10 October 2026 and replaces all previous versions. It applies to all WAAPIBOX products, websites and services.
01

Introduction

Welcome to WAAPIBOX. We operate the WAAPIBOX platform — a business automation product that includes WhatsApp Business API, AI chatbots, voice agents, CRM, ERP, POS, and 20+ integrations — based in Surat, Gujarat, India.

This Privacy Policy describes how WAAPIBOX collects, uses, stores, shares, and protects your personal information when you:

  • Visit our website at waapibox.in or any WAAPIBOX sub-domain;
  • Sign up for a WAAPIBOX account or free trial;
  • Use any WAAPIBOX product, dashboard, app or API;
  • Interact with our sales, support, or partner teams;
  • Interact with a business that uses WAAPIBOX to serve you (our customer).

By using WAAPIBOX, you agree to the collection and use of information as described in this policy. If you do not agree with any part of this policy, please discontinue using our services.

Plain-English Summary: We collect only the data needed to run our services well. We never sell your data. We protect it with enterprise-grade security. You control it — and you can ask us to delete it anytime.
02

Scope & Consent

This Privacy Policy applies to:

  • Website visitors — anyone who browses our public website, blog or resources;
  • Prospects & leads — anyone who submits a demo request, enquiry form or downloads content;
  • Customers — businesses and individuals with a WAAPIBOX account;
  • End-users — customers, patients, students, leads or contacts who interact with a business using WAAPIBOX to communicate with them.

Consent Under India's DPDP Act 2023

Under the Digital Personal Data Protection Act, 2023, we rely on your free, specific, informed and unambiguous consent to process your personal data. You provide this consent when you:

  1. Register for a WAAPIBOX account or free trial;
  2. Submit a contact, demo, or enquiry form on our website;
  3. Accept our Terms of Service and this Privacy Policy;
  4. Opt-in to receive marketing or product communications.

You may withdraw your consent at any time by contacting us at support@waapibox.com. Withdrawal of consent does not affect the lawfulness of processing done before withdrawal.

Consent for Business Customers (Data Fiduciary Role)

When a business uses WAAPIBOX to communicate with its customers or leads, the business is the Data Fiduciary (as defined under the DPDP Act) and WAAPIBOX is the Data Processor. The business is responsible for obtaining valid consent from its customers. We process data only on the business's documented instructions.

03

Definitions

To make this policy easier to understand, here are the key terms we use:

TermMeaning
Personal DataAny information that identifies or can identify a natural person — name, email, phone number, IP address, etc.
Data PrincipalThe individual to whom the personal data belongs (you), as per the DPDP Act 2023.
Data FiduciaryThe entity that determines the purpose and means of processing personal data. Our customers are Data Fiduciaries for their end-users.
Data ProcessorThe entity that processes data on behalf of a Data Fiduciary. WAAPIBOX acts as a Data Processor for our customers.
ProcessingAny operation performed on personal data — collection, storage, use, sharing, deletion, etc.
ConsentA clear, affirmative action by the Data Principal permitting processing for specified purposes.
End-UserAn individual who interacts with a WAAPIBOX-powered business (e.g., a customer chatting with a business on WhatsApp).
04

Data We Collect

We collect only the data we need to deliver our services, comply with the law, and improve your experience. Here is exactly what we collect:

A. Information You Provide Directly

  • Identity data: Full name, company name, designation, GST number (for Indian businesses), PAN (where applicable);
  • Contact data: Email address, phone number, WhatsApp number, postal address;
  • Account data: Username, password (encrypted), two-factor authentication details;
  • Billing data: Billing address, payment method details (processed by PCI-DSS-compliant gateways like Razorpay/Stripe — we never store full card numbers);
  • Business data: Product catalog, pricing, FAQs, knowledge base, and other content you upload to train the AI or configure the platform;
  • Communication data: Support tickets, chat logs with our team, feedback, survey responses.

B. Information We Collect Automatically

  • Device & browser data: IP address, browser type, OS, device identifiers, screen size;
  • Usage data: Pages visited, features used, time spent, clickstream, session duration;
  • Log data: API calls, errors, security events, timestamps;
  • Cookies & similar technologies: See Section 6 for details.

C. Information We Process on Behalf of Our Customers (End-User Data)

When a business uses WAAPIBOX to talk to their customers or leads, we may process the following on the business's behalf:

  • Names, phone numbers, email addresses, and WhatsApp numbers of the business's customers;
  • Message content (text, images, documents, voice notes) exchanged on WhatsApp, Instagram, Facebook, Telegram, SMS, RCS, Email, or Voice channels;
  • Order details, appointment data, payment status, feedback;
  • Metadata such as read receipts, delivery status, timestamps.
Note: For End-User Data, we act strictly as a Data Processor. We process it only as instructed by the business, only to deliver the service, and never for our own marketing purposes.

D. Information We Do NOT Collect

  • Full credit/debit card numbers (handled by payment gateways);
  • Aadhaar, PAN or other government IDs (unless required for WhatsApp Business API verification, in which case we collect via secure Meta flows);
  • Sensitive personal data such as biometrics, health records, religious or political beliefs;
  • Data from children under 18 (see Section 17).
05

How We Collect It

  • When you sign up — register for a free trial, create an account, or subscribe;
  • When you contact us — demo forms, contact forms, WhatsApp messages, email, calls;
  • When you use the platform — every action inside the WAAPIBOX dashboard generates usage data;
  • When you integrate channels — connecting WhatsApp, Instagram, Facebook, Telegram, Email, SMS, or Voice APIs shares relevant metadata with us;
  • When you make payments — processed via Razorpay, Stripe or other payment partners, who share transaction metadata with us (never full card numbers);
  • Automatically through cookies — analytics, preferences, and security;
  • From third parties — marketing platforms (Meta, Google Ads), CRM partners, or referral partners — only with your consent or as legally permitted.
06

Cookies & Tracking

We use cookies and similar technologies to enhance your experience, analyse usage, and secure our platform.

Types of Cookies We Use

TypePurposeExample
EssentialRequired for the platform to function — login, session, securitySession ID, CSRF token
PreferenceRemember your settings & language choicesDashboard theme, locale
AnalyticsUnderstand how visitors use the site to improve UXGoogle Analytics, self-hosted analytics
MarketingShow relevant ads on other platformsMeta Pixel, Google Ads

Your Cookie Choices

  • You can manage or disable non-essential cookies at any time via our cookie banner or your browser settings;
  • Disabling essential cookies may affect platform functionality;
  • We honour Global Privacy Control (GPC) signals and Do Not Track (DNT) headers.
Note: Third-party cookies (Google, Meta) are governed by their own privacy policies. We recommend reviewing them if you are concerned about cross-site tracking.
07

How We Use Your Data

We use your data only for legitimate business purposes. Specifically:

  • To provide services: Deliver the WAAPIBOX platform, process payments, host your dashboard, run automations on your behalf;
  • To improve our products: Analyse usage patterns, fix bugs, add features, improve AI accuracy;
  • To communicate: Send transactional emails (receipts, password resets), service alerts, product updates, and — with your consent — marketing communications;
  • To provide support: Respond to tickets, resolve issues, offer training;
  • To ensure security: Detect fraud, prevent abuse, protect against unauthorised access;
  • To comply with the law: Respond to legal requests, meet tax & regulatory obligations, enforce our Terms of Service;
  • To train AI models for you: When you upload content (FAQs, catalogs, policies), we use it to train your private AI instance — never shared across customers.
We never: Sell your data, rent it, share it with advertisers for their own use, or use End-User Data for our marketing.
09

Meta / WhatsApp Compliance

WAAPIBOX is built on the official WhatsApp Business API (Cloud API) and other official Meta APIs. Our privacy practices are aligned with Meta's Platform Terms and Business Policies.

How We Handle WhatsApp Data

  • All WhatsApp messages are processed through Meta's official Cloud API infrastructure;
  • We never use grey-market tools, unofficial APIs, or automation methods that violate Meta's terms;
  • End-user WhatsApp numbers and message content are encrypted in transit (TLS) and at rest (AES-256);
  • We retain WhatsApp message data only as long as necessary for the service, or as instructed by the business;
  • We support data deletion requests in line with Meta's Data Deletion API requirements.

Data Deletion Callback

If you are an end-user of a WAAPIBOX-powered business and want your WhatsApp data deleted, you can:

  1. Contact the business directly (they are your Data Fiduciary);
  2. Email support@waapibox.com with your WhatsApp number — we will action the request within 30 days;
  3. Use Meta's data deletion request form (linked from each business's privacy policy).
Verification: We may ask for verification (e.g., a message from your WhatsApp number) before processing any data deletion request — to prevent unauthorised requests.
10

Data Sharing

We do not sell your data. We share it only with parties essential to running our service:

Categories of Recipients

  • Cloud infrastructure providers: AWS (Mumbai region), Google Cloud (Mumbai) — data stored in India;
  • Meta / WhatsApp: for delivering WhatsApp Business API messages;
  • Payment gateways: Razorpay, Stripe — for processing payments;
  • Communication tools: Email, SMS (DLT-registered providers), Voice (telephony partners) — for service notifications;
  • AI model providers: OpenAI, Google (Gemini) — under strict data processing agreements that prohibit training on your data;
  • CRM & integration partners: Only when you explicitly connect them (Zoho, HubSpot, Salesforce, Tally, etc.);
  • Support tools: Zendesk-like platforms for managing tickets;
  • Legal authorities: When required by law, court order, or valid government request;
  • Successor entities: In case of merger, acquisition, or asset sale — you will be notified.

What We Never Do

  • Sell your data to third parties;
  • Share End-User Data across customers;
  • Share data with advertisers for their own purposes;
  • Allow partners to use your data for their own marketing.
11

Data Storage & Security

The security of your data is a top priority. Here is how we protect it:

Technical Safeguards

  • Encryption in transit: TLS 1.2+ for all data in motion;
  • Encryption at rest: AES-256 for all stored data;
  • Hashing: Passwords hashed with bcrypt (never stored in plain text);
  • Network security: Firewalls, WAF, DDoS protection, intrusion detection;
  • Backups: Automated daily backups, encrypted, geographically redundant;
  • Audit logs: Every sensitive action is logged for traceability.

Organisational Safeguards

  • Role-Based Access Control (RBAC): Only trained personnel with legitimate need access customer data;
  • Least privilege: Access is granted for specific roles and revoked immediately when no longer needed;
  • Security training: All employees undergo regular data protection & security training;
  • Background checks: For employees with access to customer data;
  • Non-disclosure agreements: Signed by every employee and contractor;
  • Vendor management: All sub-processors are vetted and contractually bound to GDPR/DPDP-equivalent standards.

Data Residency (India)

Your WAAPIBOX data is stored in Indian data centres (AWS Mumbai & Google Cloud Mumbai regions). We do not move your data outside India without your explicit consent — except where strictly necessary to deliver a service you've requested (e.g., global AI models operated via encrypted tunnels).

Incident Response

In the unlikely event of a data breach:

  1. We detect & contain the incident within hours;
  2. We notify affected customers within 72 hours (as required by DPDP & GDPR);
  3. We notify the relevant Data Protection Authorities where required;
  4. We conduct a root cause analysis & share learnings with affected parties.
12

Data Retention

We retain data only for as long as necessary to fulfil the purposes described in this policy, or as required by law:

Data TypeRetention Period
Account & profile dataActive account + 90 days after closure
Billing & invoices8 years (Indian tax law requirement)
WhatsApp message logsConfigurable — default 12 months
Support tickets3 years from ticket closure
Marketing consent recordsAs long as consent is active + 3 years
Security & audit logs12 months
Analytics dataAggregated & anonymised after 24 months
End-user data (as processor)As instructed by the business customer

After the retention period, we securely delete or anonymise the data. Backups are overwritten on a rolling 90-day cycle.

13

International Transfers

WAAPIBOX is headquartered in India, and our primary data storage is in Indian data centres. However, some of our service providers (like AI model providers or global payment processors) may process data outside India.

When We Transfer Data Internationally

  • We transfer only the minimum data necessary for the specific service;
  • We rely on Standard Contractual Clauses (SCCs) or equivalent safeguards;
  • We ensure the recipient country has adequate data protection laws, or contractual protections are in place;
  • We honour restrictions under India's DPDP Act, and under GDPR for EU/UK customers.

Your Rights Over International Transfers

You can request information about where your data is transferred and can object to transfers that you believe pose a risk to your rights. Email support@waapibox.com with your concern.

14

Your Rights Under DPDP Act

As a Data Principal under India's Digital Personal Data Protection Act, 2023, you have the following rights:

  • Right to Access: Request a copy of the personal data we hold about you;
  • Right to Correction: Request correction of inaccurate, incomplete or outdated data;
  • Right to Erasure: Request deletion of your personal data, subject to legal obligations;
  • Right to Grievance Redressal: File a complaint if you believe your data has been mishandled;
  • Right to Nominate: Nominate someone to exercise your rights in case of death or incapacity;
  • Right to Withdraw Consent: Withdraw consent at any time — we will stop processing unless another legal basis applies;
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
Response time: We respond to all rights requests within 30 days. Complex requests may take up to 60 days, and we will notify you if an extension is needed.
15

GDPR Rights (EU / UK Customers)

If you are located in the European Union or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to be informed: Know how your data is used (this policy);
  • Right of access: Get a copy of your data;
  • Right to rectification: Correct inaccurate data;
  • Right to erasure ("Right to be Forgotten"): Delete your data;
  • Right to restrict processing: Limit how we use your data;
  • Right to data portability: Receive your data in a portable format;
  • Right to object: Object to processing based on legitimate interests or direct marketing;
  • Rights related to automated decision-making: Not be subject to decisions based solely on automated processing that produce legal effects.

EU/UK customers can also lodge a complaint with their local Data Protection Authority (e.g., ICO in the UK, or the relevant DPA in their EU country).

16

How to Exercise Your Rights

To exercise any of your rights, you can:

  1. Email us at support@waapibox.com — the fastest method;
  2. Use the in-dashboard Privacy Center — click "Privacy" from your account settings;
  3. Contact our Grievance Officer — see Section 20;
  4. Write to us at our Surat office (address below).

Please include the following in your request:

  • Your full name and registered email/phone number;
  • The specific right you want to exercise;
  • Any supporting details that help us identify the data in question;
  • Proof of identity (we may request verification to prevent impersonation).

There is no fee for exercising your rights, unless the request is manifestly unfounded or excessive.

17

Children's Privacy

WAAPIBOX is a business platform intended for use by organisations and adults (18 years or older). We do not knowingly collect personal data from children under 18.

If we learn that we have inadvertently collected data from a child under 18, we will delete it promptly. If you believe a child has provided us with personal data, please contact support@waapibox.com immediately.

Note for businesses: If you use WAAPIBOX to communicate with minors (e.g., a school contacting students), you must obtain verifiable parental consent as required by the DPDP Act and any applicable laws.
18

Third-Party Links

Our website, dashboard, or documentation may contain links to third-party websites, integrations, or resources. This Privacy Policy does not cover those third parties. We encourage you to review their privacy policies before providing any personal information.

Examples of third parties you might interact with through WAAPIBOX:

  • Meta (WhatsApp, Instagram, Facebook) — governed by Meta's Privacy Policy;
  • Google (Analytics, RCS, Speech) — governed by Google's Privacy Policy;
  • Razorpay, Stripe — governed by their respective privacy policies;
  • Zoho, HubSpot, Salesforce — if you connect them to WAAPIBOX.
19

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make material changes, we will:

  • Notify registered users via email and in-dashboard alerts;
  • Post the updated policy with a new "Last Updated" date at least 30 days before it takes effect;
  • Where required by law, obtain fresh consent before processing under the new terms.

Your continued use of WAAPIBOX after the effective date constitutes acceptance of the updated policy. If you do not agree, please stop using our services and request account deletion.

20

Grievance Officer

As required by India's DPDP Act, 2023 and the Information Technology Act, 2000, WAAPIBOX has appointed a Grievance Officer to address your data protection concerns.

Grievance Officer Details
Designation Grievance Officer
Address Surat, Gujarat, India
Response Time Within 30 days

If you are not satisfied with our response, you have the right to escalate your complaint to the Data Protection Board of India once it is established under the DPDP Act.

21

Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to us:

WAAPIBOX
Support & Privacy support@waapibox.com
Security Team support@waapibox.com
Grievance Officer support@waapibox.com
Office Surat, Gujarat, India

Questions About Your Privacy?

Our team is here to help. Reach out for any data-related requests, or chat with us about our compliance practices.

Email Support
Response within 30 days · All requests acknowledged within 48 hours
Call now