This Privacy Policy explains how Veda Tech World ("WhatFlare", "we", "us", "our") handles personal data in connection with the WhatFlare platform, our websites, APIs, and related services (together, the "Services").
We take a deliberately narrow approach to personal data: we collect what the Services need to function, we do not sell it, and we do not use the message content our customers send through WhatsApp to train advertising models or general-purpose AI systems.
1.Who we are
WhatFlare is a product of Veda Tech World, a sole proprietorship based in Gujarat, India.
Legal entity: Veda Tech World (sole proprietorship)
Registered address: 220, Navuparu, Kaniyad, Botad, Gujarat 364710, India
Phone: +91 94267 67777
Company email: [email protected]
General contact: [email protected]
Privacy contact: [email protected]
2.Controller and processor — an important distinction
WhatFlare handles two different categories of data, and our responsibilities differ for each. Understanding which is which will tell you who to contact about your data.
| Category | Our role | What it means |
|---|---|---|
| Account data Our customers and their team members |
Data controller | We decide why and how this data is processed. This Policy governs it directly, and you can exercise your rights with us. |
| Customer data End-user contacts and WhatsApp conversations belonging to our customers |
Data processor | Our customer is the controller. We process it only on their documented instructions, under our Data Processing Addendum. |
We are the processor, not the controller, of that conversation. The business that messaged you decides what data it holds about you and why. Direct access, correction and deletion requests to that business. If you cannot identify or reach them, contact us at [email protected] and we will help route your request — but we cannot act on their data without their instruction.
3.Data we collect
3.1 Account and identity data
- Name, business name, work email address and phone number
- Login credentials (passwords are stored only as salted hashes — we never see them)
- Workspace and team-member roles
- Business verification details you provide for WhatsApp onboarding
3.2 Billing data
- Billing name, address and tax identifiers (GSTIN, VAT number)
- Subscription plan, wallet balance, invoices and transaction history
- Payment method details are processed by our payment gateways. We receive a token and the last four digits — we never store full card numbers.
3.3 Customer data processed on your behalf
- Contact lists you upload or sync (names, phone numbers, attributes, tags)
- WhatsApp message content, media and delivery metadata
- Conversation history, agent notes and assignment records
- Chatbot flow state and AI agent conversation context
3.4 Technical and usage data
- IP address, browser type, device type, operating system
- Pages viewed, features used, timestamps and referring URLs
- Server logs, API request records and error diagnostics
4.How we use data
- Providing the Services — routing messages, running automations, rendering the inbox, storing your templates and flows
- Billing — calculating message charges, wallet deductions, invoicing and collecting payment
- Support — diagnosing issues you report. Support staff access customer data only when necessary and only with an access record
- Security and abuse prevention — detecting fraud, spam, account compromise and platform abuse
- Service communications — outage notices, security alerts, billing notices and material changes to terms
- Product improvement — aggregated and de-identified usage analytics
- Legal compliance — tax records, lawful requests, dispute resolution
We do not sell personal data. We do not share customer data with advertisers. We do not use the content of our customers' WhatsApp conversations to train general-purpose AI models. AI features operate on a conversation only to generate a response for that conversation.
5.Legal bases for processing
Where the EU/UK GDPR applies, we rely on the following bases:
- Contract — to deliver the Services you signed up for
- Legitimate interests — security, abuse prevention, service improvement and direct business communications, balanced against your rights
- Legal obligation — tax, accounting and lawful requests
- Consent — optional analytics and marketing cookies, and marketing email. You may withdraw consent at any time
Where India's Digital Personal Data Protection Act, 2023 applies, we process personal data for the lawful purpose for which you provided it, or on the basis of your consent where required.
6.WhatsApp and Meta
WhatFlare delivers messages through the official WhatsApp Business Platform (Cloud API) operated by Meta Platforms, Inc. and its affiliates. This has consequences you should understand:
- Message content, phone numbers and delivery metadata are transmitted to and processed by Meta in order to deliver messages. Meta's handling of that data is governed by Meta's own terms and privacy policies, not this one.
- When you connect a WhatsApp Business Account through our onboarding flow, you authorise WhatFlare to manage that account on your behalf, including registering phone numbers, submitting message templates and subscribing to webhooks.
- Access tokens issued to us are stored encrypted at rest and used solely to operate your account.
- You remain responsible for complying with the WhatsApp Business Messaging Policy and Meta's Commerce Policy, including obtaining valid opt-in before messaging any recipient. See our Acceptable Use Policy.
7.Sub-processors
We engage third parties to deliver parts of the Services. Each is bound by contractual confidentiality and data-protection obligations.
| Category | Purpose | Data involved |
|---|---|---|
| Meta Platforms | WhatsApp message delivery | Message content, phone numbers, metadata |
| Cloud hosting | Application and database hosting | All categories |
| Payment gateways | Subscription and wallet payments | Billing data |
| Email delivery | Transactional email | Name, email address |
| AI providers | AI agent and assistant features, where enabled | Conversation content submitted to the feature |
| Analytics | Aggregated product usage | Technical and usage data |
A current, named list of sub-processors is available on request from [email protected]. Customers on a Data Processing Addendum receive advance notice of new sub-processors and may object.
8.Sharing and disclosure
We disclose personal data only:
- To sub-processors, as described above
- To the customer whose workspace the data belongs to
- Where you direct us to — for example, when you connect a CRM or e-commerce integration
- To comply with law, a valid legal process, or to protect rights, safety and property. Where legally permitted, we will notify the affected customer before disclosing their data
- In a merger, acquisition or asset sale — with notice, and subject to this Policy continuing to apply
9.International transfers
We operate globally, and your data may be processed in countries other than your own, including India and the countries where our cloud providers and Meta operate.
Where we transfer personal data out of the EEA or UK, we rely on Standard Contractual Clauses approved by the European Commission (and the UK Addendum where applicable), together with supplementary technical measures including encryption in transit and at rest.
10.Data retention
| Data | Retention period |
|---|---|
| Account data | For the life of the account, then 90 days after closure |
| Customer data (contacts, conversations) | Until you delete it, or 90 days after account closure |
| Billing and invoice records | As required by tax law — typically 8 years in India |
| Server and security logs | 90 days |
| Backups | 35 days, then automatically overwritten |
On account closure you may request an export of your data before deletion. Deletion from live systems is immediate; deletion from backups follows the backup cycle above.
11.Security
- Encryption in transit (TLS) and at rest for sensitive fields including access tokens
- Role-based access control, so agents see only what their role permits
- Password hashing with a modern adaptive algorithm
- Audit logging of administrative actions
- Segregation of workspace data
- Regular patching and dependency updates
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the relevant supervisory authority as required by applicable law and without undue delay.
12.Your rights
Subject to your jurisdiction and to verification of your identity, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your data, subject to legal retention requirements
- Port your data in a structured, machine-readable format
- Restrict or object to certain processing, including direct marketing
- Withdraw consent where processing is based on consent
- Nominate another person to exercise your rights in the event of death or incapacity, where the India DPDP Act applies
- Complain to your supervisory authority or, in India, to the Data Protection Board
Send requests to [email protected]. We respond within 30 days. There is no charge unless a request is manifestly unfounded or excessive.
If your request concerns data held by a WhatFlare customer rather than by us, see section 2.
13.Cookies
We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. Analytics and marketing cookies are set only with your consent. Full detail is in our Cookie Policy.
14.Children
The Services are business tools and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact [email protected] and we will delete it.
15.Changes to this Policy
We may update this Policy as the Services evolve or the law changes. The "Last updated" date at the top always reflects the current version. For material changes we will notify account holders by email at least 30 days before the change takes effect, so you have time to review it or close your account.
16.Contact and grievance redressal
For any question, request or complaint about privacy:
Privacy enquiries: [email protected]
General support: [email protected]
Grievance Officer (India, DPDP Act 2023): Sonalben Rathod
Grievance email: [email protected]
Postal address: 220, Navuparu, Kaniyad, Botad, Gujarat 364710, India
If you are not satisfied with our response, you may escalate to the Data Protection Board of India, or to your local supervisory authority if you are in the EEA or UK.