Home / Privacy Policy

Privacy Policy

How WatsBizz handles your account information and the contacts and messages you send through the platform, who we share data with, and how to exercise your rights.

Last reviewed: 1 September 2026

This policy explains what WatsBizz does with personal information — both the information we hold about you as our customer, and the information about other people that you upload and send through the platform. Those are two different things with two different sets of rules, and section 2 explains the distinction because it decides who is responsible for what.

WatsBizz is operated by Axiomatic Web Solutions Private Limited (“WatsBizz”, “we”, “us”), [registered office address], India. You can reach us at [email protected].

1. Scope

This policy covers the WatsBizz website, the customer dashboard, our API, and the WatsBizz Connect plugin for WordPress and WooCommerce. It does not cover WhatsApp itself, which is operated by Meta under its own privacy policy, or any third-party service you choose to connect.

2. Two different roles

Whether we decide how personal data is used, or merely act on your instructions, changes who is accountable. There are two cases:

3. Information we collect

3.1 Account and billing information

When you register we collect your name, email address, mobile number, and a password, which is stored only as a bcrypt hash and is never recoverable in readable form. We also record your plan, timezone, language, account status and the time of your last login. When you buy a plan we record the transaction, the amount, the currency and the processor's reference. We do not receive or store your card number, UPI PIN, CVV or bank credentials — those go directly to the payment processor.

3.2 Contacts you upload

Contact records consist of a phone number, an optional name, an optional group, and any custom fields (“variables”) you choose to add, such as an order number or a city. You control what goes in these fields. Do not put sensitive information there — health details, financial account numbers, government identifiers — unless you have a specific lawful basis for it and have told us in writing.

3.3 Message content

We store the messages you send and the replies you receive, including the recipient's number, the message body, any attached media, the delivery status and the timestamps. We need this to send messages, retry failures, show you conversations in Live Chat, and give you reporting. Staff do not read message content except where it is strictly necessary to investigate a fault you have reported to us, to comply with the law, or to act on a credible report of abuse.

3.4 WhatsApp connection data

To link a WhatsApp number you scan a QR code from your phone. This creates a session credential that is stored on our servers and allows the platform to send and receive on that number until you disconnect it or WhatsApp invalidates it. Treat that credential as equivalent to access to the linked WhatsApp account. Disconnecting the device in the dashboard, or unlinking it from your phone under WhatsApp's linked-devices screen, revokes it.

3.5 Technical information

Our servers log IP addresses, browser and device information, pages and API endpoints requested, and timestamps. We keep error diagnostics when something breaks. This is used to operate the service, investigate faults, and detect abuse.

4. How we use information

We do not sell personal information. We do not use the contents of your messages or your contact lists to build advertising profiles, and we do not use them to train AI models.

5. Legal grounds

Where India's Digital Personal Data Protection Act, 2023 applies, we process your account data on the basis of your consent and for the legitimate uses that Act permits, including performing the service you signed up for. Where the EU or UK GDPR applies, our bases are performance of a contract (running your account), legitimate interests (security, abuse prevention, improving the service), legal obligation (tax and accounting records) and consent where we ask for it.

6. Who we share information with

We share personal information only with service providers that help us run the platform, and only to the extent each one needs:

We may also disclose information where the law requires it, to enforce our Terms, to protect our rights or someone's safety, or to a buyer as part of a merger or acquisition — in which case this policy continues to apply until you are told otherwise.

7. WhatsApp

Every message you send through WatsBizz travels over WhatsApp and is subject to Meta's own terms and privacy policy. WatsBizz is an independent product. It is not affiliated with, endorsed by, or certified by Meta Platforms, Inc. or WhatsApp. We connect to WhatsApp using an unofficial client library rather than the official WhatsApp Business Cloud API. Section 4 of our Terms of Service explains what that means for you, including the risk to your number, and you should read it before connecting a number you depend on.

8. Cookies and local storage

We keep your login token in your browser's local storage rather than in a cookie, and it stays until you log out or it expires. Cloudflare sets cookies that are necessary for security, bot protection and routing. If our administrators enable web analytics, Google Analytics and Microsoft Clarity may set cookies to measure how the marketing site is used; these are not enabled by default and are never applied to message content. You can clear this data through your browser at any time, though clearing the login token will sign you out.

9. How long we keep information

Account records are kept while your account is open. Contacts and messages are kept while your account is open, or until you delete them — deleting a contact or a conversation in the dashboard removes it from our active systems. Invoices and payment records are kept for as long as Indian tax and company law requires, currently eight years, even after you close your account. Server logs and error diagnostics are kept for a short operational period. After you close your account we delete or anonymise the rest within 90 days, apart from anything we must keep by law or to resolve a dispute.

10. Security

Traffic is encrypted in transit with TLS. Passwords are stored as bcrypt hashes. Access to production systems is restricted to staff who need it. Sessions can be revoked, and we support one-time-password verification and two-factor authentication on login. No system is perfectly secure, and we cannot guarantee absolute security — but if a breach affects your personal data we will notify you and the Data Protection Board of India as the law requires.

11. International transfers

We are based in India and our infrastructure is operated from India. Some of the providers in section 6 — payment processors, Cloudflare, Sentry, our email provider and the AI providers — process data outside India, including in the United States and the European Union. Where we transfer personal data internationally we rely on the recipient's contractual commitments and, where GDPR applies, on standard contractual clauses.

12. Your rights

You may ask us to give you a copy of the personal information we hold about you, correct it if it is wrong, delete it, or restrict how we use it. You may withdraw consent where we relied on it, and you may nominate someone to exercise your rights if you die or become incapacitated, as the DPDP Act provides. Much of this is available directly in the dashboard: you can edit your profile, and delete contacts and conversations yourself.

There is currently no self-service button to delete an entire account. To close your account and have your data erased, email [email protected] from your registered address. We will confirm your identity and act within 30 days.

If you are unhappy with how we have handled your information, contact our grievance officer, [name], at [email protected]. You may also complain to the Data Protection Board of India, or, if you are in the EU or UK, to your local supervisory authority.

13. If you upload other people's data

You are responsible for the contacts you upload and the messages you send to them. That means having a lawful basis to hold their number and to message them, honouring opt-out requests, and giving them whatever privacy notice their law requires. You must not upload lists you bought, scraped, or otherwise obtained without the person's knowledge. We act on your instructions, and we will return or delete this data on your request — but if a recipient complains to us about your messages, we will tell them you are the sender.

14. Children

WatsBizz is a business product and is not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.

15. Changes

We may update this policy. If a change materially affects your rights we will tell you by email or in the dashboard before it takes effect. The date at the top shows when it was last reviewed.

16. Contact

Axiomatic Web Solutions Private Limited
[registered office address], India
Email: [email protected]
WhatsApp: +91 77040 50426

Back to WatsBizz.