Privacy Policy
Updated Date: 2025-10-01
Who we are
HextGen AI MedTech Private Limited provides a software platform that helps businesses send and receive messages via the WhatsApp Business Platform (Cloud API). Our registered address is: HextGen AI, VVInspire Co-Working Space, 3rd Floor, Sreeji Towers, Sardar Patel Rd, above Woodlands Showroom, Begumpet, Hyderabad. Contact: hextgen.info@gmail.com
Scope
This policy explains how we collect, use, share, and secure information when (a) you use our website, dashboard, and APIs; (b) we process WhatsApp events and messages for our customers ("Clients"); and (c) you contact us for support. For processing performed on behalf of Clients, we act as a data processor; Clients are the data controller and are responsible for end‑user notices, consents, and lawful instructions.
Information we collect
- Client Account & Admin Data - company name, business identifiers, billing details, admin user name, email, phone, authentication data.
- WhatsApp Configuration Data - WABA ID, phone_number_id(s), display name, template names/IDs, template categories & statuses, quality rating, webhook configuration, meta app IDs, system user IDs/tokens (encrypted), and delivery status IDs.
- Messaging Data - end-user phone numbers, consent/opt-in flags, conversation IDs, timestamps, delivery/read receipts, error codes, and message content only if the Client enables content storage. By default we process message bodies transiently to deliver them to Meta/WhatsApp and do not retain bodies longer than necessary for delivery, troubleshooting, or legal obligations.
- Logs & Telemetry - IP addresses, user agent, request/response timestamps, event IDs, and diagnostics for security and reliability.
- Support & Communications - emails, tickets, attachments, call notes.
- Website & Cookies - limited analytics and functional cookies. See our Cookie Notice for details.
How we use information
- Provide and operate the messaging platform, including sending/receiving WhatsApp messages, template management, routing, and analytics.
- Authenticate users, prevent fraud/abuse, secure our systems, and debug issues.
- Measure deliverability and quality, and comply with WhatsApp/Meta policies.
- Billing, account management, customer support.
- Legal compliance (e.g., recordkeeping, sanctions screening) and enforcement of our Terms.
Legal bases (EEA/UK): contract performance, legitimate interests (to secure and improve the service), consent (where required), and legal obligations.
Sharing of information
We do not sell personal data. We only share information as necessary to provide and improve the Service, as described below:
- Meta / WhatsApp and telecommunications partners: to deliver messages through the WhatsApp Business Platform (Cloud API).
- Sub-processors / service providers: for infrastructure, hosting, monitoring, email delivery, and related services. Our primary hosting platform is AWS (Mumbai Region) and database services are located in MongoDB (Mumbai Region).
- Professional advisors and authorities: where disclosure is legally required (e.g., compliance, investigations).
- Successor entities: in connection with a merger, acquisition, or corporate reorganization, subject to appropriate safeguards.
International Transfers
Our primary hosting service AWS (Mumbai Region) and for database services MongoDB (Mumbai Region). Where data is transferred across borders (for example, to the US, EU, or UK), we implement appropriate safeguards, including the EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA) addendum, and additional technical and organizational measures to protect personal data.
Retention
- Messaging content: default 30 days unless Client configures a different period or law requires longer/shorter.
- Message metadata & delivery receipts: 12 months for audit/reconciliation.
- Logs: 90 days (rolling).
- Account & billing records: account life + 7 years.
Security
We use TLS in transit, encryption at rest, HSM/Key‑vault backed key management for tokens, least‑privilege access, audit logging, network isolation, and regular vulnerability management. Webhooks are verified using X‑Hub‑Signature‑256 (HMAC‑SHA256) and app secret. We train staff and follow incident response procedures.
Your rights
Depending on your location, you may have rights to access, correct, delete, or port your data, and to object or restrict processing. For end‑users of our Clients, please contact the relevant business first; we will support them in responding. You can also reach us at hextgen.info@gmail.com.
Children
Our services are not directed to children and should not be used by individuals under the age of 13 (or 16 where applicable). We do not knowingly collect such data.
Contact
HextGen AI MedTech Private Limited
HextGen AI, VVInspire Co-Working Space, 3rd Floor, Sreeji Towers, Sardar Patel Rd, above Woodlands Showroom, Begumpet, Hyderabad.
Email: hextgen.info@gmail.com
