Privacy Policy
Version 2.1 · Effective date: 6 July 2026 · Last updated: 10 July 2026
This Privacy Policy describes how Conversaa handles personal data in connection with an artificial-intelligence assistant that helps businesses respond to their customers on WhatsApp Business and Instagram. Please read it together with our Terms & Conditions.
1. Overview
Conversaa (“Conversaa”, “we”, “us” or “our”) provides an artificial-intelligence assistant that helps businesses respond to their customers on WhatsApp Business and Instagram (the “Service”), available at conversaa.in. The Service lets businesses connect their WhatsApp Business account and use artificial intelligence to help draft and manage replies to their customers.
This Privacy Policy explains what personal data we process, why, the legal bases we rely on, who we share it with, how long we keep it, how we protect it, and the rights you have. It is written to meet the requirements of the EU and UK General Data Protection Regulation (GDPR / UK GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), India’s Digital Personal Data Protection Act, 2023 (DPDP Act), and other applicable data-protection laws.
By using the Service you acknowledge this Policy. If you do not agree with it, please do not use the Service.
2. Our role, and yours
Data protection law distinguishes between a “controller” (who decides why and how data is processed) and a “processor” (who processes data on the controller’s instructions). Our role depends on the data:
- Account & billing data of our business customers. For the people who register for and administer a Conversaa account, we act as a controller.
- End-customer / conversation data. When a business uses the Service to communicate with its own customers over WhatsApp and Instagram, that business is the controller of those end-customers’ personal data, and we act as a processor acting on the business’s documented instructions. In that case the business is responsible for having a lawful basis and the necessary consents/opt-ins, and for its own privacy notice to its customers.
Where we act as a processor, our processing is governed by a Data Processing Addendum (DPA). A copy of our standard Data Processing Addendum, with EU Standard Contractual Clauses annex (controller-to-processor), is available from privacy@conversaa.in within 5 business days of request.
3. Personal data we collect
a. Information you give us
- Account data: name, work email address, password (stored only as a secure hash), business/organization name, role, and preferences.
- Business profile & knowledge base: information you add so the AI can answer accurately — business hours, products, services, policies, FAQs, and custom instructions.
- Support & communications: messages you send us and their contents.
b. WhatsApp & Instagram conversation data (processed on the business’s behalf)
When connected to the WhatsApp Business Platform and Instagram Messaging (both Meta platforms), we receive and store the messages exchanged in your WhatsApp and Instagram conversations so the Service can function. This can include:
- customer phone numbers, WhatsApp profile names, and Instagram usernames/IDs;
- the content of inbound and outbound messages (text and media such as images, documents, audio);
- message metadata (timestamps, delivery/read status, message IDs);
- conversation state, tags, notes, and assignments created by your team.
This data may include personal data of your end-customers. It is processed under your control as described in section 2.
c. Information collected automatically
- Usage & device data: pages viewed, features used, approximate location (derived from IP), IP address, browser type, device and operating system, and diagnostic/log data.
- Cookies and similar technologies: strictly-necessary cookies and local storage used to keep you signed in and to operate the Service (see section 15).
- AI operational metadata: tokens consumed, latency, confidence scores, and model used, recorded to monitor cost and quality.
We do not knowingly collect special-category (sensitive) data or government IDs, and we ask that you do not submit them to the Service unless strictly necessary and lawful.
4. How we use personal data
We use personal data to:
- provide, operate, secure, and maintain the Service and your account;
- deliver, receive, and store WhatsApp messages and generate suggested or automatic AI replies grounded in your business profile and knowledge base;
- route difficult or low-confidence conversations to a human on your team (escalation);
- provide analytics, reporting, and usage/cost tracking to you;
- respond to your support requests and communicate about the Service;
- detect, prevent, and investigate fraud, abuse, security incidents, and violations of our Terms;
- comply with legal obligations and enforce our agreements.
We do not sell personal data, and we do not use the content of your WhatsApp conversations to train our own or third parties’ general AI models. Message content is sent to AI providers only to generate a reply for that conversation (see section 7).
5. Legal bases for processing (EEA / UK)
Where GDPR / UK GDPR applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — to provide the Service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — to secure, improve, and support the Service, and prevent abuse, balanced against your rights.
- Consent (Art. 6(1)(a)) — where required, e.g. for non-essential communications; you may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)) — to comply with laws that apply to us.
For end-customer data processed on a business’s behalf, the business is responsible for establishing the legal basis and obtaining any required WhatsApp opt-in/consent.
6. WhatsApp, Instagram, and Meta platforms
The Service uses the WhatsApp Business Platform and Instagram Messaging (both Meta platforms) provided by Meta Platforms, Inc. and its affiliates (“Meta”). To send and receive messages, data is transmitted through Meta’s systems and is also subject to Meta’s own terms and privacy practices, including the WhatsApp Business Messaging Policy, the WhatsApp Business Terms, and the Instagram Platform terms.
You are responsible for using WhatsApp and Instagram in compliance with those policies, including obtaining valid opt-in from recipients and only sending permitted message types. We process the messages Meta delivers to your account solely to provide the Service.
Not affiliated with Meta. Conversaa is an independent product. “WhatsApp”, “Instagram”, and “Meta” are trademarks of Meta Platforms, Inc. This Service is not endorsed, certified, sponsored by, or otherwise affiliated with Meta, WhatsApp, or Instagram.
7. Artificial intelligence and sub-processors
To generate replies, the relevant conversation context (your business profile, selected knowledge-base entries, and recent messages) is transmitted to third-party AI providers that process it on our behalf and return a suggested reply. These providers act as our sub-processors:
- OpenAI, L.L.C. (United States) — primary AI provider (chat completions using gpt-4.1-mini). We use OpenAI's API on terms that prohibit training OpenAI's general models on your data. Privacy policy.
- Google LLC (Google AI / Gemini) — fallback AI provider (chat completions). Used only when the primary provider is unavailable. Same no-training terms. Privacy policy.
We contractually require these providers to process data only to provide their service, not to train their general models on it (as offered under their applicable API terms), and to maintain appropriate security. The specific model used for a given business can be configured, and a business may request that AI features be disabled for its account.
We also rely on core infrastructure sub-processors:
- Meta Platforms, Inc. — WhatsApp Business Platform (message delivery) (United States / global).
- Cloudflare, Inc. — Object storage (media) and DNS (Global).
- Hostinger International Ltd. — Cloud server hosting.
A current list of sub-processors is available on request at privacy@conversaa.in. We will give notice of material changes so controllers may object.
9. International data transfers
We and our sub-processors may process personal data in countries other than your own, including the United States. Where we transfer personal data out of the EEA, the UK, or other regulated regions, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum / IDTA) or an applicable adequacy decision. You may request a copy of the relevant safeguards at privacy@conversaa.in.
10. Data retention
We keep personal data only for as long as necessary for the purposes described in this Policy, then delete or anonymize it. In general:
- Conversation & message data is retained for a default period of 12 months from the date of the message, or the shorter period configured by the business in its account settings, whichever is shorter. Retention on Meta’s WhatsApp and Instagram systems is subject to Meta’s own retention practices, which we do not control.
- Account & business data is retained for the life of the account and for a limited period afterward to meet legal, tax, and security obligations.
- Logs & diagnostics are typically retained for up to 12 months.
When you or your business closes an account, we delete or anonymize the associated personal data within 90 days, except where we must retain it to comply with law, resolve disputes, or enforce our agreements. See section 14 for how to request deletion sooner.
11. How we protect your data
We implement technical and organizational measures designed to protect personal data, including: encryption in transit (HTTPS/TLS); encryption of stored secrets and access tokens; role-based access controls and least-privilege access; tenant isolation so one business cannot access another’s data; audit logging of sensitive actions; validated and signed inbound webhooks; and rate limiting.
- Meta access tokens (WhatsApp Business Account tokens and Instagram Business Login tokens) are stored encrypted at rest and are never exposed to browsers or logs.
- Personal data of Indian users is primarily processed on servers located in India (Hostinger VPS, India region). Where processing takes place outside India (e.g. AI model providers), we rely on the safeguards described in section 9 (international transfers).
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a personal-data breach that is likely to affect you, we will notify you and the competent authorities as required by law. Report suspected vulnerabilities to security@conversaa.in.
12. Your privacy rights
Subject to applicable law, you have the right to: access your personal data; rectify inaccurate data; erase data (“right to be forgotten”); restrict or object to processing; data portability; withdraw consent; and lodge a complaint with a supervisory authority. Under the India DPDP Act you also have the right to grievance redressal and to nominate another person to exercise your rights.
To exercise these rights, contact privacy@conversaa.in. We will respond within the timeframe required by applicable law (generally within 30 days). We will not discriminate against you for exercising your rights, and we may need to verify your identity first.
To request deletion of your data, follow the instructions at conversaa.in/data-deletion.
If you are an end-customer whose data was collected by a business using Conversaa, please contact that business (the controller) directly; we will assist them in responding to your request.
EEA/UK users may also complain to their local Data Protection Authority. If you are in India, you may first raise a grievance with us at privacy@conversaa.in (or with our Data Protection Officer at dpo@conversaa.in); if it is not resolved to your satisfaction, you may complain to the Data Protection Board of India. Our supervisory contact for all privacy matters is our Data Protection Officer at dpo@conversaa.in.
13. Additional disclosures for California residents
Under the CCPA/CPRA, California residents have the rights to know, access, correct, and delete personal information, and to opt out of the sale or sharing of personal information and limit use of sensitive personal information.
In the preceding 12 months we have collected the following statutory categories of personal information, each collected for the business purposes described in section 4 and disclosed only to the service providers / sub-processors in sections 7–8:
- Identifiers — name, email address, phone number, WhatsApp profile name, IP address, and account identifiers.
- Customer records — business contact and profile information.
- Commercial information — records of your use of and interactions with the Service.
- Internet or other electronic network activity — usage, device, log, and diagnostic data.
- Geolocation data — approximate location derived from IP address.
- Professional or employment-related information — your role and organization.
- Other information you or your customers provide — the content of WhatsApp messages and media and your knowledge-base entries.
We have not sold or shared personal information (as those terms are defined by the CPRA) and do not do so, including for consumers we know to be under 16 years of age. To exercise your California rights, contact privacy@conversaa.in. You may use an authorized agent, and we will not discriminate against you for exercising your rights.
14. Data deletion and account removal
You can request deletion of your personal data and your account at any time:
- In-app: account and workspace administrators can delete conversations, knowledge, and workspace data from the Service’s settings, and can disconnect the WhatsApp integration to stop further data collection.
- By email: send a deletion request to privacy@conversaa.in from your registered email, with the subject line “Data Deletion Request”. We will verify your identity and delete the associated personal data within 90 days, confirming once complete.
We may retain a minimal amount of information where legally required (for example, to comply with tax or anti-fraud obligations), and backups are purged on our regular rotation cycle. Deletion of data held by Meta/WhatsApp is subject to Meta’s own retention and deletion practices.
16. Children’s privacy
The Service is a business tool intended for use by organizations and adults. It is not directed to children. For users in India, we do not knowingly collect personal data from anyone under 18 years of age, as required by the DPDP Act, 2023. In other jurisdictions we do not knowingly collect data from anyone under the age of digital consent (16 in the EEA/UK unless a member state has set it lower, 13 in the United States under COPPA). If you believe a child has provided us personal data, contact privacy@conversaa.in and we will delete it.
17. Third-party links and services
The Service may link to or integrate with third-party websites and services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. Please review their privacy policies before providing them with personal data.
18. Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you through the Service or by email. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.
19. How to contact us
If you have questions, requests, or complaints about this Policy or our processing of personal data, contact us:
- Legal entity: SourceKode Technologies LLP
- Entity type: Limited Liability Partnership registered in India under the LLP Act, 2008
- LLPIN: AAB-2848
- Registered office: 1, 46/10, Shakuntal Apartments, Law College Road, Erandwane, Pune, Maharashtra 411004
- GSTIN: 27ACGFS8559J2ZC
- General email: noreply@conversaa.in
- Privacy email: privacy@conversaa.in
- Data Protection Officer (DPO): dpo@conversaa.in
- Grievance Officer (India, per the DPDP Act and the IT Rules 2021, Rule 3(2)):
- Name: Sumit N (Designated Partner, SourceKode Technologies LLP)
- Email: grievance@conversaa.in
- Response SLA: acknowledgement within 24 hours; resolution within 15 days of receipt of a valid complaint
- Website: conversaa.in