Privacy Policy
How Wbotz collects, uses, stores and protects personal data.
Last updated 8 August 2026
Wbotz is a conversational messaging platform that lets businesses run and automate conversations on WhatsApp and other messaging channels (the Service). It is owned and operated by ByteWeb IT Solutions Private Limited, a company incorporated in India with its registered office in Vadodara, Gujarat, India, on behalf of itself and its affiliates and group companies. In this Policy, Wbotz, We, Us and Our all mean that company, and it is the Data Fiduciary responsible for the personal data described here. The Service is available through a web browser at wbotz.com and app.wbotz.com (the Website) and as a mobile application on Android and iOS (the App).
This Privacy Policy (the Policy) helps anyone who visits the Website or App and uses the Service (You or Your) understand what information is collected, why it is collected, how it is used, who receives it, and how it is protected. We take the protection and proper use of Your information seriously. Please read this Policy before You use the Website or App, use the Service, or create an account. If You do not agree with it, please do not use the Website, the App or the Service.
This Policy is published in accordance with the Digital Personal Data Protection Act, 2023, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, made under the Information Technology Act, 2000. Where We handle the personal data of people in the European Economic Area or the United Kingdom, it is also published in accordance with the General Data Protection Regulation. Capitalised terms not defined here carry the meaning given in Our Terms and Conditions.
Wbotz is built for businesses. We do not offer the Service to children. If We learn that We hold Personal Information about a person under 18 that was given without the consent of a parent or guardian, We will delete it. If You believe We hold such information, write to [email protected].
Two roles, and why the difference matters
We handle two different kinds of data, and Your rights differ between them.
- Data We decide about. Information about You as a visitor, an enquirer or an account holder. Here We are the Data Fiduciary under the Digital Personal Data Protection Act, and the controller under the GDPR. This Policy governs it in full.
- Data Our customers decide about. The contacts, chat histories, files and campaign lists that a business using Wbotz uploads or exchanges with its own customers. We only process that on the instruction of the business, as its Data Processor under the DPDP Act and its processor under the GDPR. If You are a customer of a business that uses Wbotz and You want Your messages or contact record removed, contact that business. We will help them do it, but We cannot act on that data on Our own initiative.
Information We collect
Personal Information
Information relating to You as a natural person which, directly or together with other information available to Us, can identify You. We collect this when You request a demo, start a free trial, contact Us, or open an account:
- Your name and Your designation
- Your work email address
- Your phone number, including the WhatsApp number You want replies on
- Your company name and its web address
- What You tell Us in a message or on a call
- Billing details, including GSTIN and the details Our payment gateway needs to take a payment. Card numbers are handled by the gateway and are never stored on Our systems.
- Account credentials, and the identifiers returned by a social or business login if You choose to sign in that way
We do not ask for financial account details, health data, biometric data, caste, religion or political affiliation, and We ask that You do not send them to Us. Any category that qualifies as sensitive personal data or information under the 2011 Rules is treated accordingly if it does reach Us.
Usage Information
Information about how the Website and App are used, which does not identify You on its own:
- the date, time and length of Your visits, and the pages You read
- what You searched for inside the Service
- time zone, language, screen size and the display settings You choose
- the page or advertisement that referred You to Us
- IP address, operating system, browser type, referring and exit pages, and device identifiers, including the push notification token if You allow notifications
Device Information
Information about the device You use to reach Us: operating system and version, hardware and software versions, browser, available storage, network or mobile operator, connection speed, and identifiers that let Us recognise the same device across sessions. On the App, We ask the operating system for permission before using the camera, the photo library or files, and each of those permissions can be withdrawn in Your device settings.
Location
We infer an approximate city or country from Your IP address, which We use for security and for choosing the right currency and tax treatment. We do not collect precise GPS location from the Website. If a feature of the App ever needs precise location We will ask first, and You can decline or withdraw it later in Your device settings without losing the rest of the Service.
Contacts, conversations and files
The Service exists to send and receive messages, so when a business uses Wbotz it uploads or syncs contact records containing names, mobile numbers, email addresses and its own custom fields, and it exchanges messages, images, audio, video and documents with those contacts through Us. That content belongs to the business. We store and transmit it to run the Service, keep it available to that business's authorised team members, and do not use it to build profiles, to train generalised artificial intelligence models, or for Our own marketing.
Cookies and similar technologies
We and Our service providers use cookies, web beacons, pixels and local storage to keep the Website working, to measure how it is used, and, if You allow it, to measure advertising. Nothing beyond the strictly necessary cookies is set until You allow it, and You can change Your mind at any time. Our Cookie Policy names every cookie We can set, who sets it, why, and how long it lasts.
Information from third parties
We receive information about You from the platforms We are built on and the services We use to run the business:
- Meta. When a business connects a WhatsApp Business Account through Us, Meta gives Us the account, phone number, template and message delivery information needed to operate that account.
- Advertising and analytics partners. Google, Meta and LinkedIn report which campaign led to a visit or an enquiry, in aggregate and, where You have allowed advertising cookies, matched to their own identifiers.
- Social and business logins. If You sign in using Google or another provider, We receive the identifiers and profile fields that provider releases, and no password.
- Referrals and partners. If a Wbotz partner refers You, We receive Your name, company and contact details from that partner, who is responsible for having a basis to share them.
Use of Google user data
Wbotz's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google data to serve advertising, and We do not use Google data, including Google Workspace API data, to develop, improve or train generalised or non personalised artificial intelligence or machine learning models.
Use of Meta user data
Wbotz's use and transfer of information received from Meta APIs follows Meta's Platform Terms and Developer Policies. We do not use Meta data to serve advertising, and We do not use it to train generalised artificial intelligence or machine learning models.
Why We use Your information, and on what basis
We use Your information to run, support and improve the Service, to let You use its features, and to enforce Our Terms and Conditions. Under the DPDP Act We rely on Your consent, or on the legitimate uses that Act recognises. Under the GDPR We rely on one of the following for each purpose, as set out below.
| What We do | Why | GDPR basis |
|---|---|---|
| Create and run Your account, deliver the Service, take payment | Without this there is no Service to give You | Performance of a contract |
| Answer Your enquiry, run a demo, set up a trial | You asked Us to | Steps taken at Your request before a contract |
| Support, troubleshooting, quality assurance | To keep the Service working for You | Contract and legitimate interests |
| Security, fraud prevention, abuse detection, rate limiting | To protect Your account, Our systems and other users | Legitimate interests |
| Aggregate analytics and product research | To see what works and fix what does not | Consent for cookies, legitimate interests for the analysis |
| Service messages, such as billing, downtime and policy changes | You need to know these to use the Service | Contract and legal obligation |
| Marketing email, advertising measurement and remarketing | To reach businesses likely to find Wbotz useful | Consent, withdrawable at any time |
| Tax records, statutory registers, responding to authorities | Indian law requires it | Legal obligation |
We do not sell or rent Your Personal Information to anyone, at any time, for any price. We do not use Your business's conversation content to train generalised artificial intelligence models. We do not make decisions about You by automated means that produce a legal effect on You.
Who We share it with
We share only what a recipient needs, under a contract that limits them to processing it on Our instruction.
- Meta Platforms. Message content and phone numbers pass through the WhatsApp Business Platform, because that is the network the Service delivers on.
- Cloud hosting and storage providers, who hold the data that runs the Service.
- Payment gateways, who take payments and hold the card details We never see.
- Communication and support tools, such as the systems We use to send transactional email and to answer Your tickets.
- Analytics and advertising partners, being Google, Meta and LinkedIn, and only to the extent You have allowed the relevant cookie category.
- Professional advisers, such as auditors and lawyers, under a duty of confidence.
- Our group companies, where they perform part of the Service or Our internal operations.
- Authorities, where We are required to respond to a summons, court order, lawful request or investigation, or to establish, exercise or defend a legal claim.
- An acquirer, if Our business or a part of it is sold, merged or reorganised. We will tell You before Your information becomes subject to a different privacy policy.
We may publish or share information that has been aggregated or anonymised so that it no longer identifies anyone.
Where it is stored, and for how long
We store and process information in India and in other countries where We or Our providers keep facilities. Where information leaves India or the European Economic Area, We rely on the recipient's standard contractual clauses and on the safeguards required by applicable law, and We do not transfer to a country the Central Government has restricted under the DPDP Act.
We keep information only as long as the purpose needs, and then for as long as the law requires. In practice:
- Enquiry and demo records: up to 24 months from Our last contact with You, unless You ask Us to erase them sooner.
- Account and conversation data: for as long as the account is active, and up to 90 days after it closes, so that an account reopened by mistake can be restored. On written request We delete it within 30 days.
- Invoices, tax and statutory records: eight years, as required by Indian tax and company law.
- Security and access logs: up to 12 months.
- Cookie consent records: 180 days, after which We ask again.
A legal hold, an investigation or a pending dispute can extend any of these for as long as it lasts.
How We protect it
We follow generally accepted standards to protect the information You give Us, in transit and at rest. No method of transmission or storage is completely secure, so We cannot promise absolute security, but We do the following:
- Traffic to Our Website, App and APIs is encrypted with TLS, and data at rest is encrypted by Our hosting providers.
- Access to production systems is limited to named staff who need it, protected by multi factor authentication, and reviewed.
- Passwords are stored as salted hashes, never in a form We can read.
- Our databases sit behind private networking and are not reachable from the public internet.
- Staff are trained in handling personal data and are bound by confidentiality obligations.
- We log administrative access and review it for anomalies.
If a personal data breach occurs, We will notify the Data Protection Board of India and every affected person as required by the DPDP Act, and, where the GDPR applies, the lead supervisory authority within 72 hours of becoming aware. To report a vulnerability or a suspected breach, write to [email protected] with "Security" in the subject line.
Your rights
You can exercise any of the following by writing to [email protected]. We will verify who You are before We act, and We will answer within 30 days.
- Access. A confirmation of whether We process Your personal data, a summary of what We hold and what We do with it, and the identities of those We have shared it with.
- Correction and completion. To have inaccurate or incomplete data put right.
- Erasure. To have Your personal data deleted where We no longer need it and no law requires Us to keep it.
- Withdraw consent. At any time, as easily as You gave it. Withdrawal does not undo what We lawfully did beforehand.
- Grievance redressal. To have a complaint about how We handled Your data answered by Our Grievance Officer, and to escalate to the Data Protection Board of India if You are not satisfied.
- Nominate. To name someone who may exercise these rights on Your behalf if You die or become incapacitated.
- Portability, restriction and objection. Where the GDPR applies, to receive Your data in a structured, commonly used, machine readable format, to restrict processing, and to object to processing based on Our legitimate interests. We will stop unless We can show compelling grounds that override Your interests.
- Complain to a regulator. To the Data Protection Board of India, or, in the European Economic Area or the United Kingdom, to Your local supervisory authority.
You are also expected to give Us accurate information and to keep it up to date. Under the DPDP Act, raising a false or frivolous complaint is itself an offence, so please use these rights in good faith.
Keeping Your information current
If the details You gave Us change, update them in Your account settings, or write to Us and We will do it. You can close Your account from Your account settings or by writing to Us. We will keep what We must to meet legal obligations, resolve disputes and enforce Our agreements, and delete the rest on the timelines above.
Email and marketing choices
We do not spam. We send two kinds of email. Service messages, such as billing, security notices and changes to this Policy, come with the account and cannot be switched off while it is open. Marketing email is sent only if You asked for it or You are an existing customer, and every one carries an unsubscribe link that works. If unsubscribing does not work, write to [email protected] and We will remove You within seven working days. Please do not reply to a newsletter to unsubscribe, as those replies are not monitored.
Advertising measurement is controlled separately, through cookie preferences.
Links to other sites
The Website and App link to services We do not run, including Our scheduling tool, Our help centre, app stores and social networks. Their privacy practices are their own, a link is not an endorsement, and We are not responsible for what they do with information You give them. Read their policies before You share anything.
Changes to this Policy
We may update this Policy. When We do, We change the date at the top and post the new version here. If a change materially affects how We use Your information, We will tell You by email or in the product before it takes effect, and where the law requires consent, We will ask again rather than assume Your earlier answer still holds.
Grievance Officer and contact
For any question, request or complaint about this Policy or Our handling of Your data, write to Our Grievance Officer, appointed under the Information Technology Act, 2000 and the rules made under it, and Our contact for the purposes of the Digital Personal Data Protection Act, 2023:
ByteWeb IT Solutions Private Limited
Vadodara, Gujarat, India
Email: [email protected]
We publish the city rather than the street address, because a postal address on a public page is harvested for unsolicited mail within days. The full registered office as filed with the Registrar of Companies is given on written request to [email protected], and it is on Our invoices and on the public register maintained by the Ministry of Corporate Affairs.
We acknowledge complaints within 48 hours and resolve them within 30 days. This does not affect Your right to complain to the Data Protection Board of India or to Your own supervisory authority.
Questions about this document? Email [email protected] .
ByteWeb IT Solutions Private Limited, Vadodara, Gujarat, India