Privacy Policy
Effective date: 2026-07-12
Last updated: 2026-07-12
This Privacy Policy describes how the operator of this WhatsApp sales automation platform (the "Service") collects, uses, shares, stores, and protects information when businesses use the dashboard and automation features, and when end users interact with those businesses through WhatsApp.
1) Who We Are
Controller / Business name: OprixAI
Registered address: [Registered address to be published]
Support email: business@oprixai.in
Privacy contact: business@oprixai.in
DPO (if applicable): N/A
2) Scope of This Policy
This policy applies to:
- Business customers that sign up for and configure the Service.
- Authorized team members invited by business customers.
- End users (customers or leads) who message a business using WhatsApp where that business uses the Service.
- Visitors to Service websites and dashboards.
This policy does not apply to third-party platforms that have their own policies, including Meta, WhatsApp, cloud infrastructure providers, and payment providers.
3) Definitions
- Business Customer: organization using the Service to manage conversations and sales workflows.
- End User: person communicating with Business Customer over WhatsApp.
- Personal Data: information that identifies or can reasonably identify a person.
- Processing: collection, storage, analysis, transmission, deletion, and other use of data.
- Subprocessor: service provider processing data on our behalf.
4) Data We Collect
4.1 Business Account Data
- Name, email, phone number, and login credentials or authentication metadata.
- Tenant and workspace configuration.
- Billing and plan metadata (if applicable).
- User role and permission assignments.
4.2 Messaging and Conversation Data
- WhatsApp phone numbers and profile identifiers.
- Message content, media metadata, timestamps, message IDs, and delivery status.
- Conversation history and business-defined labels.
- Lead scoring, sales stage, and engagement metadata generated by workflows.
4.3 Integration and Credential Data
- OAuth tokens and refresh tokens for approved integrations.
- Integration account IDs and configuration metadata.
- Encrypted secret values required for runtime operations.
4.4 Technical and Security Data
- IP address, user agent, browser type, device metadata, request IDs.
- Authentication events, audit trails, error events, and access logs.
- Queue processing and worker runtime telemetry needed for reliability.
4.5 Website and Product Usage Data
- Session-level usage metrics for product improvement and diagnostics.
- Cookie or local-storage based technical data required for login/session management.
5) Sources of Data
We obtain information from:
- Direct input by Business Customers and their authorized users.
- End User messages sent through WhatsApp to Business Customers.
- Meta/WhatsApp APIs and webhooks used with customer authorization.
- Service telemetry and application logs generated by infrastructure.
6) Purposes of Processing
We process personal data to:
- Provide messaging automation and AI-assisted responses.
- Operate tenant onboarding, authentication, and account administration.
- Process inbound and outbound WhatsApp communication.
- Qualify and prioritize leads based on configurable business logic.
- Maintain service reliability, incident response, and abuse prevention.
- Meet contractual, legal, tax, and compliance obligations.
- Improve product features, quality, and security posture.
We do not sell personal data in the ordinary commercial sense.
7) Legal Bases for Processing
Depending on jurisdiction and processing context, we rely on one or more of:
- Contract necessity (to provide Service to Business Customers).
- Legitimate interests (security, fraud prevention, service reliability).
- Consent (where required by law for specific processing).
- Legal obligation (regulatory or law enforcement requirements).
Business Customers are responsible for establishing their own lawful basis to collect and process End User data via the Service.
8) AI and Automated Processing Disclosure
The Service may use AI models to classify messages, summarize context, and generate suggested or automated responses.
Data used for AI processing can include:
- Message text and conversation context.
- Business profile and workflow configuration.
- Operational instructions configured by Business Customer.
Business Customers should not submit sensitive categories of data unless legally permitted and operationally necessary.
9) Data Sharing and Disclosure
We may share data with:
- Infrastructure and hosting providers.
- Managed database and caching providers.
- AI inference or model providers.
- Email and notification providers.
- Monitoring and security tooling providers.
- Meta/WhatsApp where required for Service operation.
We may disclose data when legally required, including in response to valid legal process, regulatory obligations, fraud investigations, or safety/security incidents.
10) International Transfers
Data may be processed in countries outside the data subject's country of residence.
Where required, we apply safeguards such as contractual protections and access controls.
11) Data Retention
We retain data for as long as needed for service delivery, security, legal obligations, and dispute handling.
Retention by category:
- Account metadata: while account is active plus reasonable archival period.
- Conversation content: according to customer configuration and legal needs.
- Audit and security logs: for operational security and compliance windows.
- Backup data: retained according to backup lifecycle policies.
Business Customers can request account deletion; some records may be retained where legally required.
12) Security Measures
We apply technical and organizational controls, including:
- Encryption in transit (TLS) for external communications.
- Encryption at rest for supported managed services.
- Role-based access controls and least privilege.
- Secret storage and token protection mechanisms.
- Security logging, anomaly detection, and incident response procedures.
- Change management and access auditing.
No system can guarantee absolute security.
13) Data Subject Rights
Subject to applicable law, individuals may have rights to:
- Access data.
- Correct inaccurate data.
- Delete data.
- Restrict or object to processing.
- Request portability.
- Withdraw consent where consent is the basis.
For End User data processed on behalf of Business Customers, requests should generally be directed to the relevant Business Customer first. We support Business Customers in responding to valid requests.
14) Children's Data
The Service is not directed to children and is not intended for child-targeted processing. Business Customers must not use the Service in violation of child protection laws.
15) Cookies and Similar Technologies
The Service may use cookies, local storage, and similar technologies for:
- Authentication and session continuity.
- Security and fraud prevention.
- User preferences and basic analytics.
Where required, consent mechanisms should be presented by the website operator.
16) Third-Party Services
The Service may link to or depend on third-party services. Their processing is governed by their own terms and privacy policies. We are not responsible for third-party privacy practices outside our control.
17) Incident Response and Breach Notification
We maintain incident response procedures and investigate suspected security events. Where legally required, notifications are sent to affected customers and regulators within applicable timelines.
18) Meta and WhatsApp Platform Compliance
If the Service is used with Meta products, Business Customers must comply with applicable Meta Platform Terms, WhatsApp Business Terms, and policy requirements.
Business Customers are responsible for lawful messaging practices, notices, and opt-in/opt-out compliance in their jurisdictions.
19) Do Not Track and Similar Signals
Our services may not respond uniformly to all browser Do Not Track signals. Where required by law, we provide equivalent rights controls through account or support channels.
20) Policy Updates
We may update this Privacy Policy from time to time. Material changes are reflected by an updated effective date and, where appropriate, additional notice.
21) Contact and Complaints
Privacy inquiries: business@oprixai.in
Support inquiries: business@oprixai.in
If unresolved, users may have the right to lodge complaints with relevant supervisory authorities as allowed by local law.
22) Publishing Checklist (Complete Before Going Live)
Replace all placeholders:
- OprixAI
- [Registered address to be published]
- business@oprixai.in
- business@oprixai.in
- N/A
Confirm public links exist:
- Privacy policy URL
- Terms and Conditions URL
- Data deletion instructions URL (recommended for Meta app review)
Confirm operational alignment:
- Actual subprocessors used in production.
- Actual retention windows.
- Actual support and privacy contact channels.
23) Data Deletion and Access Request Intake (Recommended Public Note)
To request access, correction, or deletion, contact: business@oprixai.in
Include the following in request:
- Business name (if applicable)
- Phone number used in interaction
- Relevant date range
- Request type (access, correction, deletion)
We may require identity verification before processing requests.