This policy explains how Asyscraft (“we”, “us”) handles personal data in AsysConnect. It is written to meet the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000 and its rules.
1. Who we are and what this covers
We handle personal data in two roles:
- As a Data Fiduciary for data about our own users and visitors: people who sign up, team members of a workspace, people who fill in our contact form or raise a support ticket, and visitors to our website.
- As a Data Processor for the businesses that use AsysConnect. The contacts and WhatsApp conversations a business keeps in AsysConnect belong to that business, which decides how they are used. If you are a customer of one of those businesses, please contact the business first; section 4 explains more.
2. What we collect
- Account details: name, email address, password (stored only as a secure hash), the workspace you belong to and your role.
- Business details: business name, WhatsApp Business account and phone number details from Meta, and billing details such as GSTIN where you give them.
- Payment records: amounts, taxes and payment references for wallet top-ups. Card, UPI and bank details are collected by our payment partner, not by us.
- Content you add: contacts, tags, custom fields, opt-in records, message templates, broadcasts, WhatsApp messages sent and received, and support tickets.
- Technical data: IP address, browser and device type, sign-in times, and logs we need to keep the Service secure and working. If you use our mobile app and allow notifications, we store your device’s push notification token.
- Contact form: the name, email, phone, business name and message you send us.
3. How we use it
- To create and run your account and provide the Service you asked for.
- To send and receive WhatsApp messages and show them to your team.
- To take payments, keep your wallet balance and issue tax invoices.
- To send service emails, such as email verification, password resets, invitations and replies to support tickets.
- To answer your questions and give support.
- To keep the Service secure, prevent fraud and abuse, and fix problems.
- To meet legal duties, such as tax records and lawful requests from authorities.
We use your data on the basis of your consent, to perform our agreement with you, and for the other legitimate uses the DPDP Act allows. We do not sell personal data, and we do not use your customers’ data for our own marketing. We send you product news only if you agree, and every such email lets you unsubscribe.
4. Data we process for businesses
When a business uses AsysConnect to talk to its customers, the business decides what data to collect and why, and is responsible for having its customers’ consent to message them. We process that data only to provide the Service to the business, keep it separate from every other workspace, and do not use it for any other purpose.
If you received a WhatsApp message from a business that uses AsysConnect, you can reply STOP to stop marketing messages from it, and you can ask that business to access, correct or delete your data. If you cannot reach the business, contact us and we will pass your request on.
5. Who we share it with
We share personal data only with service providers that help us run AsysConnect:
- Meta (WhatsApp), to send and receive WhatsApp messages and manage templates and phone numbers.
- Anthropic (Claude), only for workspaces that turn on AI replies: the chat and the workspace's knowledge base are sent to write an answer. Anthropic does not use this data to train its models.
- Our payment partner (currently Razorpay), to take wallet top-ups.
- Our hosting and email providers, to run our servers, store backups and send service emails.
- Expo, Apple and Google, to deliver notifications to our mobile app if you turn them on. A notification contains the contact’s name and a short preview of the message.
We may also share data when the law requires it, to protect the rights and safety of our users or the public, or as part of a merger or sale of our business, in which case this policy will continue to apply.
6. Where data is stored
We store data on servers run by our hosting provider. Some providers, including Meta for WhatsApp messages, process data on their own systems, which may be outside India. Where data leaves India we do so only as the DPDP Act permits, and we choose providers that protect it to a comparable standard.
7. How long we keep it
- We keep account and workspace data while the account is active.
- When a workspace is closed we delete its content within 90 days, except records we must keep by law, such as tax invoices and payment records, which we keep for as long as tax law requires (currently up to 8 years).
- Database backups are kept for up to 14 days and then overwritten.
- Media customers send on WhatsApp stays on Meta’s servers for about 30 days, as Meta’s platform decides.
- Contact form messages are kept for up to 2 years unless you become a customer.
8. How we protect it
- All connections to AsysConnect use HTTPS.
- Each workspace’s data is separated at the database level, so one business cannot see another’s contacts or chats.
- Passwords are stored only as secure hashes, and WhatsApp access tokens are encrypted at rest.
- Access inside the Service is limited by role, and staff access is restricted.
No system is completely secure. If a personal data breach affects you, we will tell you and the Data Protection Board of India as the law requires.
9. Your rights
Under the DPDP Act you can:
- ask for a summary of the personal data we hold about you and how we use it;
- ask us to correct, complete, update or erase it;
- withdraw consent you gave us, which does not affect what we did before;
- nominate someone to exercise your rights if you die or cannot do so; and
- complain to us, and then to the Data Protection Board of India.
To use these rights, email our Contact page from your account email address. We may ask you to confirm your identity. Some data we must keep by law even if you ask us to erase it.
10. Cookies
We use only the cookies needed to keep you signed in securely. We do not use advertising or cross-site tracking cookies.
11. Children
AsysConnect is for businesses and is not meant for anyone under 18. We do not knowingly collect data about children as our own users. Businesses must not use AsysConnect to message children without verifiable consent from a parent or guardian, as the DPDP Act requires.
12. Changes to this policy
We may update this policy. We will change the date at the top and, for significant changes, tell you by email or in the Service before they take effect.
13. Grievance Officer and contact
For questions, requests or complaints about your personal data, contact our Grievance Officer. We acknowledge complaints within 24 hours and aim to resolve them within 15 days.
- Email: our Contact page