Skip to content

Legal

Privacy Policy

Last updated: 19 July 2026

This policy explains, in plain language, what NudgeDesk collects when you connect your Instagram and WhatsApp business accounts, how we use it to answer and qualify your customers' messages, who we share it with, and the rights you and your customers have under India's DPDP Act and Europe's GDPR.

Template for review. This document is a working draft written to reflect how NudgeDesk operates. It is not legal advice. Have your counsel review and adapt it before launch.

Scope

NudgeDesk is an AI lead desk that answers your business's Instagram and WhatsApp messages, qualifies leads, and helps you collect payment. This policy covers two groups of people: the businesses that use NudgeDesk (our customers) and the people who message those businesses (your customers).

For the conversations that flow through NudgeDesk, your business is the data controller (the fiduciary, under DPDP) and NudgeDesk is your data processor. We act on your instructions to run your lead desk. For the account you create with us and how we run our own service, NudgeDesk is the controller.

Data we collect

We collect only what is needed to run your lead desk. In practice, that is:

  • Business account connection When you connect through Meta's Embedded Signup, we receive the tokens and identifiers for your WhatsApp Business Account and Instagram professional account, plus the settings, catalog, price list and FAQ content you choose to give the AI.
  • Customer message content (Meta Platform Data) The messages your customers send, and the replies the AI sends back: text, images, voice notes, and the post or ad a conversation came from. Under Meta's terms this is "Platform Data", and we handle it under Meta's Platform Terms and Developer Policies as well as this policy.
  • Contact and lead details The lead information captured in a conversation: a name, phone number, WhatsApp number, email if given, what the customer asked for, and the qualification and consent status attached to that lead.
  • Account and billing data The details you give us to open and pay for your account: your name, work email, business name, and the payment reference held by our payment gateway. We do not store full card numbers.
  • Usage and diagnostic data Basic logs needed to keep the service reliable and secure: message delivery status, error and rate-limit events, and per-message cost by category. We do not sell this or use it for cross-site advertising.

How we use your data

We use the data above to deliver the service you asked for, and for nothing unrelated to it. Specifically, to:

  • Read incoming messages and generate a reply in the customer's own language.
  • Qualify, score and route leads, and alert you when a lead is hot.
  • Send a payment link or native UPI request, and record the paid or unpaid outcome.
  • Keep memory across sessions so a returning customer is not treated as a stranger.
  • Operate, secure and support the service, and meet our legal obligations.

Our lawful bases are the performance of our contract with you, your and your customers' consent where required (for example, opt-in for WhatsApp marketing), and our legitimate interest in keeping the service safe.

AI processing

The AI that reads and writes messages runs on a bound cloud provider under a data-processing agreement with zero data retention. Your conversations are sent to the model only to generate the next reply, and are not retained by the model provider after that reply is produced.

We never train shared or public AI models on your customer conversations. Your data is used to run your workspace, not to improve a model that other businesses touch.

Because message content is Meta Platform Data, the model provider is engaged as a bound service provider, not a consumer API. WhatsApp's end-to-end encryption ends at the official Cloud API, the point where your business itself receives the message, so the AI reads and answers it on your behalf, exactly as your own staff would.

Data retention

We keep conversation and lead data for as long as your account is active, so memory and history work as intended. You can delete an individual conversation or lead at any time and it is removed. When you close your account, we erase your data on a defined schedule, save for the minimum we are legally required to retain (for example, billing and tax records) and limited backups that age out on a rolling cycle.

Some platform data has its own limits set by Meta. For example, WhatsApp media identifiers are re-fetchable for seven days, and Instagram media URLs expire, so we capture what a conversation needs at the time it arrives.

Sharing and sub-processors

We do not sell your data, and we do not share it for advertising. We share it only with the providers needed to run the service, each under a contract that limits them to processing on our instructions:

  • Meta Platforms To send and receive messages over the official WhatsApp Cloud API and Instagram Platform. Meta processes this as the platform operator under its own terms.
  • Bound AI provider To generate replies, under a data-processing agreement with zero data retention, as described above.
  • Payment gateways To process UPI and card payments (for example a UPI, Razorpay or Cashfree gateway). They handle payment details directly under their own PCI-compliant terms.
  • Infrastructure and tooling sub-processors Cloud hosting, transcription for voice notes, and error and delivery monitoring, each bound by a data-processing agreement. A current list is available on request and before any material change.

We may also disclose data where the law requires it, or to protect the safety and rights of our customers and their customers.

Your rights

Under India's Digital Personal Data Protection Act (DPDP) and the EU General Data Protection Regulation (GDPR), you and your customers have rights over personal data. Depending on where you are, these include the right to:

  • Access the personal data held about you, and get a copy of it.
  • Correct data that is inaccurate or incomplete.
  • Erase your data, subject to the limited legal retention noted above.
  • Withdraw consent, and, under GDPR, object to or restrict certain processing.
  • Port your data out in a portable format, and complain to your data-protection authority.

Because your business is the controller for your customers' conversations, a request from one of your customers is usually handled by you, and we support you as your processor. If you are a NudgeDesk customer, you can export your data and request erasure from your dashboard, or by writing to us. We respond within the timeframes the applicable law requires.

Security

We protect your data with per-tenant isolation, encryption in transit, access controls, and conservative rate limits so no account can endanger another. Each business runs on its own WhatsApp Business Account and its own isolated data boundary, so one tenant's data cannot leak into another's. For a full account of our encryption, certified infrastructure, DPDP and GDPR plumbing, and per-tenant architecture, see our Security & Compliance page.

International transfers

NudgeDesk is built India-first and serves businesses worldwide, so data may be processed in countries other than your own, including by our sub-processors. Where data moves across borders, we rely on the safeguards the applicable law requires, such as standard contractual clauses for transfers out of the EU, and region-aware handling for tenants and their customers.

Children

NudgeDesk is a tool for businesses and is not directed at children. We do not knowingly collect personal data from children. If you believe a child's data has reached us, contact us and we will delete it.

Changes to this policy

We may update this policy as the product and the law evolve. When we make a material change, we will update the date at the top and, where appropriate, tell you in the product or by email. Continuing to use NudgeDesk after a change takes effect means you accept the updated policy.

Contact

For any privacy question, or to exercise a right above, write to us at privacy@nudgedesk.io. You can also review our Terms of Service.

Want to see exactly how your data flows?

Bring your questions to the demo. We will walk through the whole path, on your own catalog, in fifteen minutes.