Privacy Policy
1 Who We Are
Kpyxal Solutions LLP is a Limited Liability Partnership registered in India under the LLP Act, 2008, with its principal place of business in Gandhinagar, Gujarat, India. We operate PyxWA (accessible at wa.store.kpyxal.com), a B2B SaaS platform that enables businesses ("Clients") to send, receive, and automate WhatsApp Business messages through Meta's official Cloud API.
Our platform is a business tool — we provide infrastructure to Clients, who in turn communicate with their own customers. We are a data processor for Client-owned contact data and a data controller for account and platform data.
2 Information We Collect
2.1 Account & Client Information
When a business registers on PyxWA, we collect:
- Business name, contact name, and email address
- Billing information (processed securely by our payment provider)
- WhatsApp Business Account (WABA) credentials — phone number ID, WABA ID, business name
- API access tokens (encrypted at rest)
- Webhook URLs and secrets (encrypted at rest)
- IP addresses used to access the platform
2.2 Usage & Platform Data
- Message logs — metadata (direction, status, timestamps) and message content for messages sent/received through our platform
- Template definitions and approval status
- Campaign configurations and performance metrics (sent, delivered, read, failed counts)
- Webhook delivery logs and API request logs
- Browser and session data when using the web dashboard
2.3 Contact Data (Your Customers)
Clients upload or create contact records containing:
- Phone numbers (required)
- Names, email addresses, and custom metadata (optional, Client-controlled)
- Opt-in/opt-out status
- WhatsApp profile names (auto-captured from inbound messages)
3 How We Use Your Information
| Purpose | Legal Basis | Data Used |
|---|---|---|
| Providing and operating the PyxWA service | Contract performance | Account data, message logs, contact data |
| Processing and delivering WhatsApp messages | Contract performance | Contact data, message content, API credentials |
| Billing and payment processing | Contract performance, legal obligation | Account data, usage metrics, wallet transactions |
| Platform security and fraud prevention | Legitimate interest | IP addresses, API logs, access patterns |
| Customer support | Contract performance | Account data, message logs (with Client consent) |
| Platform analytics and improvement | Legitimate interest | Aggregated, anonymised usage data |
| Legal compliance and audit | Legal obligation | Transaction records, access logs |
| Service notifications (downtime, policy changes) | Legitimate interest | Email address |
We do not sell, rent, or use your data or your customers' data for advertising purposes.
4 WhatsApp & Meta Data Sharing
PyxWA uses Meta's WhatsApp Business Cloud API. When you send or receive messages through our platform:
- Message content and recipient phone numbers are transmitted to Meta's servers as required to deliver messages
- Message template definitions are submitted to Meta for approval
- Media files (images, videos, documents) sent in messages are uploaded to Meta's servers
- Webhook events (delivery receipts, read receipts, inbound messages) are received from Meta and processed by us on your behalf
Meta's use of this data is governed by WhatsApp's Business Policy and Meta's Privacy Policy. By using PyxWA, your use is also subject to these policies.
We integrate directly with Meta's WhatsApp Business Cloud API. We do not share your data with Meta beyond what is necessary to deliver the messaging service on your behalf.
5 Your Customers' Data (Contact Data)
As a Client, you act as the data controller for the personal data of your customers that you provide to PyxWA. We process this data strictly on your behalf as a data processor.
5.1 Your Obligations
- You must obtain valid, documented consent from your customers before adding their phone numbers to PyxWA and before sending marketing messages
- You must comply with India's Digital Personal Data Protection Act, 2023 (DPDPA) and any other applicable data protection laws
- You must comply with WhatsApp's Business Policy, including its opt-in requirements
- You must honour opt-out requests promptly and update opt-out status in PyxWA
- You must not upload data acquired through scraping, purchased lists, or any means that lacks genuine opt-in consent
5.2 Our Obligations
- We process contact data only as instructed by you through platform features
- We do not use your customers' data for our own marketing or third-party purposes
- We implement technical and organisational security measures to protect contact data
- We will notify you of any data breach affecting your contact data as soon as reasonably practicable
6 Third-Party Services
PyxWA integrates with the following third-party services in the course of providing our platform:
| Service | Purpose | Data Shared |
|---|---|---|
| Meta (WhatsApp Cloud API) | Message delivery and template management | Message content, phone numbers, media files |
| Cloud Hosting Provider | Infrastructure and data storage | All platform data (stored in India or region selected) |
| Payment Processor | Billing and wallet top-ups | Transaction amount, billing contact details |
| Email Service (Transactional) | Service notifications, alerts | Client email address, notification content |
We select sub-processors that provide adequate data protection guarantees and bind them to confidentiality obligations.
7 Data Retention
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 3 years after closure |
| Message logs and content | 90 days (configurable per plan) |
| Billing and transaction records | 7 years (statutory requirement under Indian law) |
| API and access logs | 30 days rolling |
| Contact data | Until deleted by Client or account closure |
| Webhook delivery logs | 30 days |
| Template definitions | Duration of account |
After the retention period, data is securely deleted or anonymised. You may request earlier deletion — see Section 10.
8 Security
We implement industry-standard technical and organisational measures to protect your data:
- Encryption at rest — API keys, access tokens, and webhook secrets are encrypted using AES-256
- Encryption in transit — All data is transmitted over TLS 1.2+
- Access controls — Role-based access control; production data access is limited and audited
- API authentication — All API requests require signed, hashed API keys
- Queue isolation — Message processing runs in isolated job queues
- Monitoring — Automated alerts for anomalous access patterns and failures
No system can be guaranteed 100% secure. In the event of a security breach affecting your data, we will notify you without undue delay and take all reasonable steps to mitigate harm.
9 Cookies & Tracking
The PyxWA dashboard uses the following cookies and browser storage:
- Session cookies — Required for authentication; expire when you close your browser
- CSRF tokens — Security tokens to prevent cross-site request forgery
- Preference storage — Local storage for UI preferences (table column visibility, sort order)
We do not use advertising cookies, third-party tracking pixels, or analytics that profile individual users. Our usage analytics are aggregated and server-side only.
10 Your Rights
Under the Digital Personal Data Protection Act, 2023 (India) and other applicable laws, you have the right to:
- Access — Request a copy of the personal data we hold about you
- Correction — Request correction of inaccurate or incomplete personal data
- Erasure — Request deletion of your personal data (subject to legal retention obligations)
- Portability — Receive your account and contact data in a machine-readable format
- Withdrawal of consent — Withdraw consent where processing is based on consent
- Complaint — Lodge a complaint with the Data Protection Board of India
To exercise any of these rights, contact us at hello@kpyxal.com. We will respond within 30 days.
For contact data belonging to your customers, requests should be directed to you as the data controller. We will assist you in fulfilling such requests upon written instruction.
11 Children's Privacy
PyxWA is a B2B platform intended solely for use by businesses and their authorised personnel. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor's data has been provided to us in error, please contact us immediately at hello@kpyxal.com.
12 Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify registered Clients by email at least 14 days before the changes take effect
- Display a notice on the PyxWA dashboard
Your continued use of PyxWA after the effective date constitutes acceptance of the updated policy.
13 Contact Us
Questions or Concerns?
If you have any questions about this Privacy Policy or our data practices, please reach out to us:
Kpyxal Solutions LLP
Gandhinagar, Gujarat, India
We endeavour to respond to all privacy-related inquiries within 30 days. For urgent data breach notifications, please mark your email as URGENT.