PRIVACY POLICY
(Wapzio acting as Data Fiduciary)
Document key: PRIVACY · Version: 2.0 · Effective: 03/09/2026
2.1 Scope — read this first
This Privacy Policy explains how Anantkamal Software Labs ("Wapzio") handles personal data for which Wapzio itself decides the purpose and means — that is, where Wapzio is the Data Fiduciary under the DPDP Act, 2023.
It covers: website visitors, prospects and enquirers, account holders and their authorised Users, billing contacts, support requesters, applicants, and persons whose data appears in Wapzio's own security and audit logs.
It does not cover personal data that Wapzio processes on behalf of a Client — for example, a Client's contact lists, WhatsApp Recipients, conversation content and campaign audiences. For that data, the Client is the Data Fiduciary and Wapzio is only a Data Processor. That relationship is governed by the Data Processing Agreement, and the Client's own privacy notice governs the Recipient's rights.
If you received a WhatsApp message sent through Wapzio and want it stopped or your data deleted: the business that messaged you controls that data. Reply STOP to that conversation, and contact that business directly. Wapzio cannot delete a business's records on your instruction, but we will forward your request to the relevant Client and record it — write to privacy@anantkamalsoftwarelabs.com with the sending business name and the number that contacted you.
2.2 What we collect
| Category | Examples | Source |
|---|---|---|
| Identity & contact | Name, business email, phone, designation, company, GSTIN | You |
| Account & authentication | User ID, hashed password, MFA state, session and login records, API key metadata | You / generated |
| Billing | Plan, invoices, transaction IDs, payment status, billing address, tax IDs. We do not store card numbers, CVV or UPI PINs — payments are processed by our gateway | You / gateway |
| Technical & log | IP address, device and browser type, user agent, timestamps, pages viewed, referrer, error traces, API call metadata | Automatic |
| Security | Authentication events, access-control changes, anomaly and abuse signals, audit-trail entries | Automatic |
| Communications | Support tickets, emails, chat transcripts, call notes, feedback | You |
| Acceptance evidence | Which legal document version you accepted, when, from which screen, and the document hash | Automatic |
| Marketing | Campaign source, UTM parameters, webinar/demo registration, preferences | You / partners |
We do not knowingly collect data of children under 18 for the Services. We do not collect Aadhaar numbers. We do not use personal data to train general-purpose AI models.
2.3 Why we process it, and on what basis
| Purpose | Basis under DPDP Act |
|---|---|
| Create and administer your Account; provide the Services | Performance of contract / consent given at signup |
| Authenticate you and secure the platform | Consent + legitimate use (s.7) + legal obligation |
| Bill you, issue invoices, comply with tax law | Legal obligation (Companies Act, CGST Act) |
| Provide support | Consent / contract |
| Detect and prevent fraud, spam and abuse | Legal obligation + legitimate use |
| Maintain audit, acceptance and security logs | Legal obligation (CERT-In Directions; IT Rules 2021) and defence of legal claims |
| Improve the Services using aggregated, de-identified data | Legitimate use |
| Send service and security notices | Contract / legal obligation |
| Send marketing about our own products | Consent, withdrawable at any time |
| Comply with lawful orders and defend claims | Legal obligation |
Where we rely on consent, you may withdraw it at any time with the same ease as it was given, by writing to privacy@anantkamalsoftwarelabs.com or using the in-product controls. Withdrawal does not affect processing already carried out, and does not affect processing on another lawful basis — in particular we will continue to retain security, audit and billing records where the law requires it.
2.4 Who we share it with
- Sub-processors and service providers — cloud hosting, email delivery, payment gateway, error monitoring, analytics, support desk, communications. The current list is published at
https://www.wapzio.com/legal/subprocessorswith vendor name, service, purpose, data categories and processing location. - Professional advisers — lawyers, auditors, insurers, under duties of confidence.
- Authorities — where required by a valid legal process. See our Law Enforcement Request Policy.
- Corporate transactions — an acquirer or successor in a merger, restructuring or sale of assets, subject to confidentiality and this Policy.
We do not sell personal data. We do not share personal data with data brokers or for third-party advertising.
2.5 Where it is processed
Primary hosting is in [India — AWS ap-south-1 / GCP asia-south1]. Some sub-processors may process data outside India. Where they do, we apply contractual and technical safeguards and comply with section 16 of the DPDP Act and any restriction notified by the Central Government on transfers to particular countries. Logs required to be retained under the CERT-In Directions are maintained within India. The processing location of each sub-processor is stated in the sub-processor list.
2.6 How long we keep it
Set out in full in the Retention Schedule (Part 4 §6). In summary:
| Data | Period | Reason |
|---|---|---|
| Account records | Life of Account + 24 months | Contractual and limitation period |
| Billing and tax records | 8 years | Companies Act, 2013 s.128(5); CGST Act |
| ICT / system logs | ≥ 180 days, within India | CERT-In Direction (iv), 28.04.2022 |
| Security & audit logs | 12–24 months, longer under legal hold | Security and defence of claims |
| Legal acceptance records | Life of Account + 8 years | Evidence of contract formation |
| Support tickets | 24 months | Service quality and dispute defence |
| Marketing data | Until withdrawal + 6 months | Proof of withdrawal |
| Data under legal hold | Until hold released | Evidence preservation |
2.7 Security
We maintain reasonable security safeguards appropriate to the risk, including: encryption in transit (TLS 1.2+) and at rest; role-based access control and least privilege; multi-factor authentication for administrative access; secrets management; network segmentation; centralised, tamper-evident logging; vulnerability management and dependency scanning; encrypted backups with tested restoration; a documented incident-response process; and personnel confidentiality and security training. No system is perfectly secure; we do not guarantee absolute security.
2.8 Personal data breach
If a personal data breach occurs, we will:
- notify CERT-In within 6 hours of noticing the incident, where it falls within the reportable categories in the CERT-In Directions dated 28 April 2022;
- notify the Data Protection Board of India and each affected Data Principal without delay, with the information required by the DPDP Rules;
- notify affected Clients without undue delay where their data is affected, so they can discharge their own obligations; and
- record the incident, containment steps, root cause and remediation in our incident register.
2.9 Your rights
Subject to identity verification and lawful exceptions, you may:
| Right | How |
|---|---|
| Access a summary of your personal data and processing | privacy@anantkamalsoftwarelabs.com or in-app Privacy Centre |
| Correct, complete, update or erase | Same |
| Withdraw consent | Same, or in-product toggle |
| Nominate a person to exercise rights in the event of death or incapacity | privacy@anantkamalsoftwarelabs.com |
| Grievance redressal | sachink@anantkamalsoftwarelabs.com |
Response timelines. We acknowledge every request within 72 hours and respond substantively within 30 days. A grievance will be resolved within [90] days at the outside, in accordance with the DPDP Rules. Under the IT (Intermediary Guidelines) Rules, 2021 we acknowledge a grievance within 24 hours and dispose of it within 15 days.
If you are not satisfied, you may complain to the Data Protection Board of India in accordance with the DPDP Act.
Note: Making a false or frivolous grievance, impersonating another person, or suppressing material information when exercising a right is a breach of the duties of a Data Principal under section 15 of the DPDP Act and may attract a penalty.
2.10 Cookies
See the Cookie Policy at §6 of this Part.
2.11 Children
The Services are not offered to persons under 18. We do not knowingly process children's personal data as a Data Fiduciary. Where a Client's use would involve children's data, the Client is responsible for obtaining verifiable parental consent under section 9 of the DPDP Act and must not use the Services for tracking, behavioural monitoring or targeted advertising directed at children. Our AUP prohibits it. If we learn we hold a child's data without lawful basis, we will delete it.
2.12 Automated decision-making
We use automated risk scoring to detect spam, fraud and abuse, which may result in rate limiting or suspension of an Account. A human reviews any decision to suspend or terminate an Account, and the Client may appeal under clause 1.10.5 of the Terms.
2.13 Changes
We will update this Policy as law or processing changes. Every version carries a version number, effective date and archived copy. Material changes are notified at least 30 days in advance by email and in-product notice.
2.14 Contact us
| Role | Details |
|---|---|
| Data Protection Officer / Contact Person (DPDP Act s.8(9)) | Sachin A. Kaduskar, CTO, sachink@anantkamalsoftwarelabs.com, +919370098337 |
| Grievance Officer (IT Rules 2021 Rule 3(2); SPDI Rules Rule 5(9)) | Sachin A. Kaduskar, CTO, sachink@anantkamalsoftwarelabs.com, +919370098337 |
| Postal | Anantkamal Software Labs, 4th Floor, Gajanan Annex, Office No 2, Patil Lane Number 1, near Magnum Hospital, Nashik, Maharashtra, 422005, India, India |
| Grievance hours | [Mon–Fri, 10:00–18:00 IST] |
Compliance note (delete before publication): the name of a natural person, a working email and a postal address must actually be published. A generic alias alone does not satisfy Rule 3(2) of the IT Rules, 2021.