Privacy Policy
1. Who We Are
Chatzen is a Software-as-a-Service (SaaS) platform that enables businesses to automate customer conversations on WhatsApp, Instagram, Facebook Messenger, and other messaging channels using Artificial Intelligence, bulk messaging campaigns, and a multi-agent shared inbox.
2. Platform Overview - What Chatzen Does
Understanding what our Platform does helps clarify why we process certain data. Chatzen provides the following core services:
3. Data We Collect
3.1 Account & Registration Data
When you register a Chatzen account, we collect:
- Full name, email address, phone number, and organization name
- Password (stored as a salted bcrypt hash - we never store plaintext passwords)
- Role within your organization (e.g., Admin, Agent)
- Profile photo (if uploaded)
- Time zone and language preferences
3.2 Organization & Business Data
- Organization name, logo, brand colors, and custom domain (for white-label)
- Industry type and business description
- Subscription plan and billing cycle
- WhatsApp Business Account (WABA) ID and phone number IDs connected via Meta Embedded Signup
- Facebook Business Manager account details obtained during OAuth authorization
- Meta access tokens (stored AES-256 encrypted in our database; used solely to make WhatsApp API calls on your behalf)
3.3 WhatsApp & Messaging Data
This is the most sensitive data we process on your behalf as a data processor:
- Content of inbound and outbound WhatsApp messages (text, images, documents, audio, video, stickers, reactions)
- Names and WhatsApp phone numbers of your customers / contacts
- Message delivery status, timestamps, and read receipts
- Contact metadata you add: tags, labels, notes, lead status, custom fields
- Campaign contact lists and their opt-in status records
- Human handoff events, agent assignment logs, and internal team notes
3.4 AI & Knowledge Base Data
- Documents, PDFs, spreadsheets, website URLs, and FAQ content you upload to train your AI agents
- AI agent configurations: name, persona, instructions, response style settings, fallback behaviors
- AI agent conversation logs: queries sent to AI models and responses received
- Embedding vectors generated from your knowledge base (stored in vector database)
3.5 Billing & Payment Data
- Subscription plan, billing cycle, and payment history
- Invoice records and GST/VAT details (where applicable)
- Payment is processed by our third-party processors (Razorpay / Stripe). We do not store card numbers, CVVs, or bank account details on our systems.
3.6 Usage & Technical Data
- Pages visited, features used, buttons clicked, and actions taken within the Platform
- Login timestamps, IP addresses, and geographic location (country/city level)
- Device type, browser, operating system, and screen resolution
- Session duration and navigation patterns
- Error logs, crash reports, and performance metrics
- API request logs (endpoint, timestamp, response code) for security monitoring
3.7 Website Chat Widget Data
When a visitor uses an AI chat widget embedded by one of our clients on their website:
- Messages typed by the visitor and AI responses
- Session ID (randomly generated per visit - not linked to personal identity unless the visitor provides it)
- Browser type and approximate location (country level)
- The widget does not set persistent tracking cookies on visitor browsers
4. How We Use Your Data
| Purpose | Data Used | Legal Basis (DPDP 2023) |
|---|---|---|
| Provide and operate the Platform and all its features | All account, messaging, and usage data | Contract performance |
| Authenticate users and maintain secure sessions | Email, password hash, IP, session tokens | Contract performance / Legitimate interest |
| Deliver WhatsApp messages and campaigns initiated by you | Contact lists, message content, WABA tokens | Contract performance |
| Generate AI responses via large language models | Message content, knowledge base embeddings | Contract performance |
| Process billing and manage subscriptions | Email, organization name, plan data | Contract performance / Legal obligation |
| Send transactional emails (receipts, alerts, OTPs) | Email address, name | Contract performance |
| Platform performance monitoring and bug fixing | Error logs, usage data, technical data | Legitimate interest |
| Security monitoring and fraud prevention | IP address, login logs, API logs | Legitimate interest / Legal obligation |
| Comply with legal obligations (tax, regulatory) | Payment records, invoices, user records | Legal obligation |
| Product improvement and feature development | Aggregated, anonymized usage analytics only | Legitimate interest |
5. Data Sharing & Sub-processors
We share data only with the following parties, strictly as necessary to provide the Platform. All sub-processors are contractually bound to protect your data.
| Sub-processor | Purpose | Data Shared | Country |
|---|---|---|---|
| Meta Platforms, Inc. | WhatsApp Business API message delivery and management | Phone numbers, message content, media files, WABA tokens | USA |
| OpenAI, L.L.C. | AI response generation (GPT models) | Message content and knowledge base text sent for AI inference | USA |
| Anthropic, PBC (optional) | AI response generation (Claude models - alternate model) | Message content and knowledge base text sent for AI inference | USA |
| Amazon Web Services / Google Cloud Platform | Cloud hosting, database storage, object storage (S3/GCS), and compute infrastructure | All Platform data | India / USA |
| Razorpay / Stripe | Payment processing and subscription billing | Billing details, email, amount (card data processed by them directly) | India |
| SendGrid / Amazon SES | Transactional email delivery (OTPs, invoices, alerts) | Email address, name, email content | USA |
| Vector Database Provider (e.g., Pinecone / Qdrant) | Storage and retrieval of AI knowledge base embeddings | Embedding vectors derived from your knowledge base content | USA / EU |
We do not share your data with any other third parties. We will disclose data to law enforcement or regulatory authorities only where required by applicable law and only to the extent legally required, and will notify you where permitted by law.
6. WhatsApp-Specific Disclosures
6.1 Meta API Relationship
Chatzen operates as a Business Solution Provider (BSP) or integrates with Meta's WhatsApp Business Cloud API. When you connect your WhatsApp Business Account (WABA) to our Platform via Meta Embedded Signup, you authorize us to send and receive WhatsApp messages on your behalf using your WABA credentials. All message delivery is subject to Meta's infrastructure, and we cannot guarantee delivery outcomes that are within Meta's control.
6.2 End-User Privacy (Your Customers)
When your customers message your WhatsApp Business number, their messages pass through Meta's infrastructure and are stored in our Platform on your behalf. As a Chatzen client, you are the data controllerfor your customers' personal data. You are responsible for:
- Informing your customers that their conversations are managed using a third-party platform
- Ensuring your customers have given valid consent to receive messages from your business
- Honoring data deletion and access requests from your customers
- Maintaining your own privacy policy covering your use of WhatsApp
6.3 Opt-In Compliance
WhatsApp requires that all recipients of business-initiated messages have explicitly opted in. We require all clients to confirm opt-in compliance at the point of campaign creation. Sending messages to contacts without valid opt-in consent is a violation of our Terms of Service and may result in immediate account suspension.
6.4 Message Data & AI Processing
When AI is enabled on a conversation, message content is transmitted to our AI provider (OpenAI or Anthropic) for inference. We send only the minimum context necessary for the AI to generate a relevant response. We do not use your message data to train foundational AI models at the AI provider.
7. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| WhatsApp conversation messages and media | 12 months from message date (or until account deletion, whichever is earlier) | Operational - conversation history access |
| Conversations from a disconnected channel (WhatsApp number, Facebook, or Instagram) | Archived on disconnect and permanently deleted 30 days later, unless you reconnect the channel (which restores them) or choose to delete them immediately | Storage limitation - retained briefly only to allow recovery on reconnection |
| Account and organization profile data | Duration of subscription + 30 days post-deletion | Operational - service provision |
| AI knowledge base documents and embeddings | Until deleted by you or account termination | Operational - AI agent function |
| Campaign contact lists and delivery logs | 12 months from campaign date | Analytics and compliance |
| Security and audit logs (login, API access) | 2 years | Security monitoring and legal compliance |
| Payment records and invoices | 7 years | Statutory financial record-keeping requirement |
| Opt-in consent records | Duration of contact relationship + 2 years | WhatsApp policy compliance and legal defence |
| Backup snapshots | Overwritten within 60 days of deletion date | Disaster recovery |
Disconnecting a messaging channel. When you disconnect a WhatsApp number, Facebook page, or Instagram account from the Platform, the associated conversations are immediately hidden from your dashboard and archived. They are kept for a 30-day recovery window and then permanently deleted (along with their messages and media). If you reconnect the same channel within that window, the archived conversations are restored. You may also choose to delete them permanently at the moment of disconnection instead of waiting for the 30-day window. This retention window is configurable by us at the platform level and defaults to 30 days.
Upon verified account deletion request, all personal data and conversation data are permanently deleted within 30 days, except data subject to statutory retention requirements (e.g., financial records). We will provide written confirmation of deletion upon request.
8. Your Rights
Under the Digital Personal Data Protection Act, 2023 (India), and where applicable under the GDPR (for EU/EEA data subjects), you have the following rights:
Right to Access
Request a copy of all personal data we hold about you. We will respond within 30 days.
Right to Correction
Request correction of inaccurate or incomplete personal data. Most data can be updated directly in your account settings.
Right to Erasure
Request deletion of your personal data. We will delete within 30 days, subject to legal retention requirements.
Right to Data Portability
Export your data in JSON or CSV format from Settings → Export Data, or request a full export from us.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
Right to Nominate
Under DPDP Act 2023, you may nominate an individual to exercise your rights on your behalf in case of death or incapacity.
Right to Restrict Processing
Request that we restrict processing of your data in certain circumstances while a dispute is resolved.
Right to Grievance Redressal
Lodge a complaint with our Grievance Officer. We will acknowledge within 48 hours and resolve within 30 days.
9. Data Security
We implement industry-standard technical and organizational measures to protect your data:
Encryption
- All data in transit encrypted with TLS 1.3
- All data at rest encrypted with AES-256
- Meta API access tokens stored encrypted
- Passwords stored as salted bcrypt hashes
Authentication & Access
- JWT-based authentication with 15-minute access token expiry
- HTTP-only refresh token cookies (XSS-resistant)
- Role-Based Access Control (RBAC) - least privilege principle
- Multi-factor authentication available for all accounts
Infrastructure
- Database not publicly accessible - internal network only
- VPC network isolation for all production systems
- Automated daily backups with point-in-time recovery
- DDoS protection and rate limiting on all API endpoints
Monitoring & Response
- Audit logs for all sensitive admin actions
- Anomaly detection for login and API activity
- Incident response plan with 72-hour breach notification
- Regular third-party penetration testing
Despite our security measures, no system is 100% secure. In the event of a data breach that affects your personal data, we will notify you within 72 hours of discovery and cooperate fully with your investigation and any regulatory reporting obligations. Report security vulnerabilities to security@chatzen.in.
11. Children's Data
The Platform is a business-to-business (B2B) service directed exclusively at companies and individuals aged 18 and above. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that a minor has created an account or provided personal data, we will delete that data immediately. If you believe a minor has provided us data, contact us immediately at privacy@chatzen.in.
12. International Data Transfers
Chatzen is based in India. Some data processing occurs in the USA via our AI and infrastructure sub-processors (see Section 5). We ensure all international data transfers are protected by appropriate safeguards including:
- Standard Contractual Clauses (SCCs) with all sub-processors based outside India
- Sub-processors who participate in recognized data protection frameworks (e.g., EU-US Data Privacy Framework)
- Contractual obligations requiring sub-processors to maintain protection equivalent to Indian and applicable international standards
Data processed for AI inference is transmitted to AI providers' servers in the USA for the duration of inference only and is not retained by the AI provider for model training purposes under our enterprise agreements.
13. Changes to This Policy
We review this Privacy Policy at least annually and whenever there is a material change to our data practices. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Send an email notification to your registered email address at least 14 days before the change takes effect
- Display an in-app notification banner in the Platform dashboard
- For significant changes, request re-acceptance where required by law
Continued use of the Platform after the effective date of updated terms constitutes your acceptance of the revised Privacy Policy.
14. Contact & Grievance Officer
Privacy & Data Rights
privacy@chatzen.inFor access, deletion, correction, and portability requests. Response within 30 days.
Security Incidents
security@chatzen.inFor reporting data breaches or security vulnerabilities. We respond within 24 hours.
Grievance Officer
grievance@chatzen.inFor complaints and escalations. Acknowledgement within 48 hours.
General: info@uvdigitalsolution.com