Legal
Privacy Policy
What we collect, why we collect it, and how it is protected under the DPDP Act 2023.
Pending legal review
This is a structured draft. The final, legally reviewed text will be published here before launch, and this notice will be removed only once legal sign-off is confirmed. Nothing here is binding while this notice is shown.
Still awaiting founder/legal input: grievance officer name and email, cross-border processor locations, effective date.
1. Who this policy covers, and who we are
This policy explains how Gatre Enterprise ("we", "us"), a Data Fiduciary under the DPDP Act 2023, Currency Tower, Telibandha, Raipur, CG 492001, handles personal data when you use wassapp.in.
2. What personal data we collect
We collect two distinct categories of personal data, and our role differs for each:
- Business-user data — the details of the people who use your account: name, email, phone number, business details and payment information. We are the Data Fiduciary for this data.
- End-customer data — the contacts of your business and the messages they exchange with you. We process this only as a Data Processor on your instructions, and you remain the Data Fiduciary for it.
3. Why we collect it
We use personal data only for the purposes it was collected for:
- Creating and operating your account.
- Sending the messages you initiate through Meta.
- Billing, wallet management and GST invoicing.
- Fraud prevention, security and service integrity.
- Support and service communications.
4. Legal basis
We process business-user data on the basis of your consent at signup, and for billing and fraud-prevention as permitted carve-outs under the Act. For end-customer data, the lawful basis is your instruction to us as Data Processor; you are responsible for having a valid basis for the contacts you upload and message.
5. Consent and how to withdraw it
Consent is taken at signup and can be withdrawn as easily as it was given — from your account settings, not only by emailing us. Withdrawing consent may mean we can no longer provide parts of the service.
6. Data sharing and processors
We share personal data only with the processors needed to run the service, each under a data-processing arrangement:
- Meta / WhatsApp — to deliver the messages you send and receive status updates.
- Razorpay — to process wallet recharges and refunds.
- Amazon Web Services — infrastructure hosting, with the database in the ap-south-1 (Mumbai) region.
- Sentry — error monitoring, configured to scrub personal data before events leave our systems.
7. Cross-border transfer
Our primary data store is in AWS ap-south-1 (Mumbai, India). Some processors (Meta, and possibly Razorpay) may process or store data outside India as part of delivering their services — [CROSS_BORDER_CONFIRM — confirm the exact processor locations with counsel].
8. Data retention and erasure
We keep personal data only while its purpose is served. Active tenant data is retained while your account is open; data for inactive accounts is archived after 90 days; and a deletion/erase request through the Danger Zone flow hard-deletes the relevant data, subject to records we must keep for financial and legal retention (for example, invoices and the append-only wallet ledger).
9. Your rights as a Data Principal
Under the DPDP Act you may exercise the following rights. Each is available through your account settings or by contacting the grievance officer below.
- Access — request a summary of the personal data we hold about you.
- Correction — have inaccurate or incomplete data corrected.
- Erasure — have your data erased once its purpose is served.
- Grievance redressal — raise a complaint about how we handle your data.
- Nomination — name someone to exercise these rights on your behalf.
10. Security measures
Data is protected in transit with TLS and at rest; WhatsApp access tokens are encrypted with AES-256-GCM. Tenant data is isolated at the database layer using row-level security, so one tenant cannot read another’s data. Access to production systems is restricted.
11. Children's data
The service is intended for businesses and is not directed at children. We do not offer a verifiable parental-consent flow; account holders confirm that they are 18+ and acting for a business.
12. Grievance officer and contact for complaints
For any question, request or complaint about this policy or your personal data, contact our grievance officer: Grievance officer: to be added, Grievance email: to be added. You may also write to support@wassapp.in. This is our own contact point — complaints are not handled only through Meta or Razorpay.
13. Changes to this policy
We may update this policy. Material changes will be notified by email and an in-app notice before they take effect.
14. Effective date
This policy takes effect on [EFFECTIVE_DATE — set at publication after legal sign-off], not before.