1. Introduction
Responseify ("we," "us," "our") is a WhatsApp-based Customer Relationship Management (CRM) platform operated by Responseify. This Privacy Policy describes how we collect, use, store, and protect your personal data when you use our website, platform, and services (collectively, the "Services").
This policy is structured in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India and applicable rules thereunder. By using our Services, you acknowledge that you have read and understood this Privacy Policy.
2. Definitions
- Data Principal: The individual to whom the personal data relates — this includes you, your contacts, and your end users.
- Data Fiduciary: Responseify, as the entity that determines the purpose and means of processing personal data.
- Personal Data: Any data that relates to a natural person, including name, email, phone number, usage data, and communication content.
- Processing: Any operation performed on personal data, including collection, storage, retrieval, use, disclosure, and deletion.
3. Data We Collect
We collect the following categories of personal data:
3.1 Account Data
- Full name and email address (from signup or SSO)
- Phone number (optional, for account recovery)
- Profile avatar (optional)
- Account role (owner, admin, agent, viewer)
3.2 Contact Data (CRM)
- Contact names, phone numbers, email addresses, and company names
- Custom fields and tags you assign to contacts
- Lead scores and segment memberships
3.3 Communication Data
- WhatsApp messages sent and received through the platform
- Message templates and their content
- Broadcast campaign details and recipient lists
- Support ticket content, comments, and attachments
3.4 Transactional Data
- Wallet balance and top-up history
- Invoice and billing records
- Subscription and plan details
- Message delivery costs (conversation type, cost per message)
3.5 Usage Data
- Login timestamps and session activity
- Feature usage patterns and navigation paths
- IP address and browser/device metadata
- Automation and flow execution logs
3.6 AI Processing Data
- Messages processed by AI auto-reply (OpenAI, Gemini, or rule-based)
- AI response content and accuracy metrics
- Usage counts per AI provider
4. How We Use Your Data
We process your personal data for the following purposes:
- Service Delivery: To provide, maintain, and improve the Responseify CRM platform and its features.
- WhatsApp Messaging: To send and receive WhatsApp messages on your behalf through the Meta Business Platform, including template submissions, message delivery, and webhook processing.
- Billing & Payments: To process wallet top-ups via Razorpay, manage subscriptions, generate invoices, and maintain financial records.
- AI Auto-Reply: To process incoming messages through AI providers (OpenAI, Google Gemini) for automated responses, subject to your configuration.
- Analytics & Reporting: To generate usage analytics, campaign performance metrics, and business intelligence dashboards.
- Support: To manage support tickets, provide customer service, and track issue resolution.
- Security: To detect fraud, prevent abuse, enforce rate limits, and maintain platform security.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
5. Legal Basis for Processing
Under the DPDP Act, we process personal data based on the following legal bases:
- Consent: You provide explicit consent when creating an account and using our Services. You may withdraw consent at any time.
- Contractual Necessity: Processing necessary to perform our contract with you (providing the CRM service).
- Legal Obligation: Processing required under applicable Indian law, including tax regulations and financial record-keeping requirements.
- Legitimate Interest: Processing for platform security, fraud prevention, and service improvement, where such interests are not overridden by your rights.
6. Data Sharing & Third Parties
We share personal data with the following categories of third parties:
- Meta Platforms (WhatsApp Business API): Contact phone numbers and message content are shared with Meta for message delivery. Meta processes this data under their Privacy Policy.
- Supabase: Our database and authentication infrastructure provider. Data is stored in secure, encrypted databases.
- Razorpay:Payment processing for wallet top-ups and subscriptions. Financial data is processed under Razorpay's PCI-DSS compliant infrastructure.
- OpenAI / Google Gemini: Message content may be sent to AI providers for auto-reply processing, only when AI auto-reply is enabled on your account. No contact data is stored by these providers beyond the processing request.
- Analytics Providers: Anonymized usage data may be shared with analytics services to improve our platform.
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
7. Data Retention
We retain personal data for as long as necessary to provide our Services:
- Account Data: Retained for the duration of your account. Deleted within 30 days of account closure.
- Contact & Communication Data: Retained while your account is active. Deleted within 30 days of account closure or upon explicit deletion request.
- Billing Records: Retained for 8 years as required under Indian tax laws (Income Tax Act, 1961 and GST regulations).
- Support Tickets: Retained for 2 years after resolution for quality assurance and dispute resolution.
- Audit Logs: Retained for 1 year for security and compliance purposes.
- AI Processing Logs: Retained for 30 days, then purged. Only anonymized usage counts are retained longer.
8. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Row-level security (RLS) on all database tables ensuring tenant isolation
- Role-based access control (RBAC) with granular permission levels
- API key authentication with scoped permissions for programmatic access
- WhatsApp message encryption with per-tenant encryption keys
- Regular security audits and penetration testing
- Automated vulnerability scanning in our CI/CD pipeline
- SOC 2 Type II compliant infrastructure (Supabase, Vercel)
9. Your Rights Under the DPDP Act
As a Data Principal, you have the following rights:
- Right to Access (Section 11): You may request a copy of all personal data we hold about you. We will provide this within 72 hours of a verified request.
- Right to Correction (Section 12): You may request correction of inaccurate or incomplete personal data. You can update most data directly from your account settings.
- Right to Erasure (Section 13): You may request deletion of your personal data. We will comply within 72 hours, except where retention is required by law.
- Right to Nominate (Section 14): You may nominate a person to exercise your rights in the event of your death or incapacity.
- Right to Withdraw Consent (Section 6): You may withdraw consent at any time. Withdrawal will not affect the lawfulness of processing conducted prior to withdrawal.
- Right to Grievance Redressal (Section 8): You may file a complaint with our Data Protection Officer if you believe your rights have been violated.
10. Data Breach Notification
In the event of a personal data breach, we will:
- Notify the Data Protection Board of India within 72 hours of becoming aware of the breach
- Notify affected Data Principals without delay if the breach is likely to cause significant harm
- Document the breach, its effects, and the remedial measures taken
- Take immediate steps to contain and mitigate the breach
11. Cross-Border Data Transfer
Your data may be transferred to and processed in countries other than India, including the United States (where our infrastructure providers operate). Such transfers are conducted in compliance with the DPDP Act, ensuring adequate protection standards are maintained through contractual safeguards and data processing agreements with our service providers.
12. Children's Data
Our Services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly. If you believe a child has provided us with personal data, please contact our Data Protection Officer immediately.
13. Cookies & Tracking
We use the following types of cookies:
- Essential Cookies: Required for authentication, session management, and security. These cannot be disabled.
- Preference Cookies: Store your theme, language, and display preferences.
- Analytics Cookies: Help us understand how the platform is used to improve our services.
You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent the platform from functioning correctly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-platform notification at least 7 days before they take effect. The "Last updated" date at the top of this page indicates when this policy was last revised.
15. Contact & Grievances
For any questions, requests, or grievances related to this Privacy Policy or your personal data, contact our Data Protection Officer:
If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India established under the DPDP Act, 2023.