Engees Communications Private Limited
Effective Date: 27-05-2022 | Last Updated: September 2026
Prepared in accordance with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, the “DPDP Framework”), and the Information Technology Act, 2000.
1. Overview
This Privacy Policy (“Policy”) is issued by Engees Communications Private Limited (“11za”, “we”, “us”, “our”), operator of the 11za WhatsApp Business API platform and related website, mobile application, and services (collectively, the “Service”). It explains what personal data we collect, why we collect it, how we use, store, share, and protect it, and the rights available to you under the DPDP Framework.
For the purposes of the DPDP Act, 2023, 11za acts as a “Data Fiduciary” in respect of the personal data of our direct account holders (our business customers), and as a processor/service provider facilitating our customers’ own processing of their end-users’ personal data (see Section 11).
2. Information We Collect
We collect the following categories of information:
- Name, business name, and business registration details
- Email address and phone number
- Location and/or business address
- Billing and payment details (processed via our payment partner; card data is not stored on our servers)
Where you use our mobile application, we additionally request the following device permissions. Each is requested only at the point it is needed for a specific feature, used solely for the stated purpose, and you may revoke it at any time via your device settings — though this may limit the corresponding feature:
|
Permission |
Why We Ask For It |
|
Internet / Network Access |
To enable the application to connect to our services, send and receive messages, synchronise data, and provide online functionality |
|
Contacts |
To allow you to select, share, and manage contact information within the application’s communication and messaging features |
|
Camera |
To allow you to capture photos or other media for sharing, uploading profile images, or using other relevant application features |
|
Photos / Media / Gallery |
To allow you to select, upload, save, or manage media and other supported files within the application |
|
Microphone / Audio Recording |
To enable voice messaging, voice notes, audio recording, and other audio-based communication features initiated by you |
|
Audio / Music Access |
Where applicable, to enable supported audio or media-related features you request |
|
Location (Approximate or Precise) |
To enable location-based features where available and requested by you. Depending on the feature, the application may request approximate or precise location access |
|
Speech Recognition |
To enable voice-to-text or other speech recognition features when used by you |
|
Files / Documents / Storage |
To allow you to upload, download, open, save, share, or manage supported documents and files, including recorded audio files where applicable |
|
Audio Settings |
To support proper audio playback and recording functionality within voice and communication features |
|
Notifications |
To alert you when a customer sends a new message, so you can respond promptly |
|
Call-Related Information (Android only) |
To support call-related and business communication features. Where supported by your device and operating system, the application may access relevant call-related information only when necessary for the requested functionality and with your applicable consent or authorisation |
We do not access any of the above beyond the specific feature you use them for, and we do not use device permissions to track you across other apps or websites.
Call-Related Information access is available only on Android, only within your authenticated 11za business account, and only where approved by Google Play under its enterprise CRM permitted-use policy. This feature is not available on iOS, where no equivalent access exists. We access only call metadata (such as timing and duration) required for this feature and do not use it for any other purpose.
3. WhatsApp Message Content
We store WhatsApp message content (text, media, and metadata) sent and received through the Platform on behalf of our business customers, for as long as your account remains active, or as required to provide chat history, analytics, and support features. We do not access or use this content for any purpose other than providing and improving the Service, or as required by law.
4. Meta and WhatsApp Policies (Reference Links)
The Service operates on the WhatsApp Business Platform, provided by Meta Platforms, Inc. In addition to this Policy, the following Meta/WhatsApp policies govern how message data is handled on that platform, as amended by Meta from time to time:
- WhatsApp Business Messaging Policy: https://www.whatsapp.com/legal/business-policy
- WhatsApp Business Terms of Service: https://www.whatsapp.com/legal/business-terms
- WhatsApp Commerce Policy: https://www.whatsapp.com/legal/commerce-policy
- WhatsApp Messaging Guidelines: https://www.whatsapp.com/legal/messaging-guidelines
- Meta Platform Terms (Developer Terms): https://developers.facebook.com/terms/
- WhatsApp Legal Resources (full index): https://www.whatsapp.com/legal
These policies are controlled by Meta, not by 11za, and may change independently of this Policy. We encourage you to review them periodically, particularly before any major Meta policy update takes effect.
5. Collection and Use of Google User Data
If you link a Google account or use Google services through our App, we may collect Google profile information (email, name, profile picture) and, with your specific consent, data from services such as Google Drive or Contacts strictly needed for the feature you use.
We use Google user data ONLY to provide or improve the App’s core functions. We will NEVER use Google user data, nor permit any third party we share it with, for:
- Targeted, personalised, or retargeted advertising
- Selling to data brokers or providing to information resellers
- Determining credit-worthiness or lending purposes
- Any purpose unrelated to the App’s core functionality
If you enable Google account integration, we may use relevant Google user data (e.g., contact information) solely to facilitate service messages you initiate via WhatsApp, such as sign-up confirmations, terms updates, and account expiry notices. These are transactional service messages, not marketing.
6. Purpose and Legal Basis of Processing
Under the DPDP Act, 2023, we process your personal data on the following lawful bases:
- Consent — collected through clear, itemised, and unbundled consent requests at sign-up and at each point new data is requested
- Contractual necessity — to provide, maintain, and support the Service you have subscribed to
- Legal obligation — to comply with tax, billing, and statutory record-keeping requirements
- Legitimate/certain permitted uses — for fraud prevention, platform security, and core business operations as permitted under the DPDP Act
You may withdraw consent at any time by contacting our Grievance Officer (Section 17). Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may limit our ability to continue providing the Service or specific features.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. On expiry of the applicable retention period, or on your verified request, data is deleted or anonymised, except where continued retention is legally mandated (e.g., financial records).
|
Data Category |
Retention Period |
Trigger / Basis |
|
Account & profile data (name, email, phone, business details) |
Retained for the duration of your active subscription, and thereafter until you submit a written deletion request |
Deletion requests are processed within 180 days of account closure (see note below) |
|
WhatsApp message content & chat logs |
Retained for the duration of your active subscription, and thereafter until you submit a written deletion request |
Required to provide chat history, CRM, and analytics features; deletion requests processed within 180 days of account closure |
|
Billing & invoice records |
8 years from date of transaction |
Income Tax Act, 1961 and applicable statutory requirements — not eligible for early deletion |
|
Support tickets & correspondence |
3 years from ticket closure |
Quality assurance, dispute resolution |
|
Marketing consent records |
Until consent is withdrawn, plus 1 year |
Evidence of consent obtained/withdrawn |
|
Uploaded contact lists / imported data |
Retained for the duration of your active subscription, and thereafter until you submit a written deletion request |
Provided by you for use of the Service; you remain responsible for its lawful basis; deletion requests processed within 180 days of account closure |
|
Voice call recordings & transcripts (Voice Agent add-on, where enabled) |
Retained for the duration of your active subscription, and thereafter until you submit a written deletion request |
Stored by 11za’s Voice Vendor to provide call history and quality features; deletion requests processed within 180 days of account closure |
As a default, we retain data (other than statutory records such as billing) for as long as your account remains active, and thereafter until we receive a written deletion request from you. Where such a request is submitted, it will be processed within 180 days from the date of account closure. Records we are legally required to retain for a longer statutory period (e.g., billing/tax records) will not be deleted early, regardless of request.
8. Disclosure of Information
We keep your personal information confidential and share it only in the following circumstances:
- With subprocessors engaged to deliver the Service (see Section 9), under binding data processing agreements
- Where required by a court order or a lawful directive from a government or regulatory authority
- In connection with a business transfer, merger, or acquisition, subject to equivalent privacy protections
We do not sell, rent, or share your personal information, including Google user data, with third parties for marketing, advertising, or purposes unrelated to providing and improving the Service.
9. Subprocessors and Data Storage Location
Your data is hosted on servers located in India, on Google Cloud Platform (India region). We engage the following categories of subprocessors to help deliver the Service:
- Cloud hosting — Google Cloud Platform (India region)
- Payment processing — Razorpay
- Voice calling infrastructure (where the Voice Agent add-on feature is enabled) — India-hosted third-party voice technology vendor; see Section 13
- Additional subprocessors as reasonably required to operate the Service (e.g., SMS/OTP verification, customer support tooling)
Each subprocessor is bound by a data processing agreement requiring it to protect personal data to a standard consistent with this Policy and applicable law. A current list of subprocessors is available on request by writing to our Grievance Officer.
As our infrastructure is India-hosted, we do not routinely transfer personal data outside India. Where any limited cross-border transfer becomes necessary (for example, a global sub-vendor), it will be carried out strictly in accordance with the DPDP Act, 2023 and any applicable directions issued by the Central Government, and will be disclosed to you.
10. Use of Data by 11za Group Companies (Affiliate Data Use)
From time to time, we may share data with other companies within the Engees Communications group of companies (“Affiliates”) for the purpose of improving, developing, or building new features for the 11za platform — for example, analysing messaging patterns to recommend better send times, or studying engagement trends to improve platform performance. As of the date of this Policy, no such sharing arrangement is currently in place; this section is included to describe the safeguards that will apply if and when it is.
Where such sharing occurs, it will be subject to the following safeguards:
- Data shared with an Affiliate for platform improvement purposes will be anonymised or aggregated before it is shared — meaning direct identifiers such as names, phone numbers, and verbatim message content will be removed, and the data will not be capable of being re-linked to an identifiable individual
- Any resulting insights, models, or improvements will be used solely to enhance the 11za platform, and not to build a separate product, database, or profile outside of 11za
- We will not share identifiable personal data (including phone numbers or message content tied to a specific individual) with any Affiliate for analytics, profiling, or persona-building purposes without obtaining separate, specific consent from the relevant Data Principal
- Any Affiliate given access to anonymised data will be bound by a written data-sharing agreement requiring it to handle that data to a standard consistent with this Policy and the DPDP Act, 2023, and to use it only for the stated purpose
This section does not authorise, and should not be read as authorising, the sale or sharing of your personal data with any unrelated third party. It applies only to companies within the Engees Communications group, and only for the platform-improvement purpose described above. If this arrangement changes to include identifiable data or a different purpose, we will update this Policy and, where required, seek your fresh consent before doing so.
11. Your Responsibility as a Business Customer — Imported Data & Consent
11za is a technology platform. When you use the Service to upload contact lists, import customer data, or send WhatsApp communications — whether manually or through an integration, plugin, API connection, or automated sync (including but not limited to Shopify, WooCommerce, Tally TDL, or any custom-built connector) — you (the business customer) act as the Data Fiduciary for that data, and 11za acts as your data processor for that specific data set. Third-party platforms and tools you choose to connect to 11za remain governed by your own agreement with those providers and are not, by virtue of that connection, subprocessors of 11za.
You represent and warrant that:
- You have obtained valid, verifiable consent from each end-user/contact whose data you upload, sync, or message through the Platform, in accordance with WhatsApp’s Business Messaging Policy and the DPDP Act, 2023
- You will not upload, import, or sync personal data that you are not legally authorised to process
- You are solely responsible for honouring data-subject rights (access, correction, erasure, withdrawal of consent, grievance redressal, and nomination) raised by your own end-users in respect of data you have imported or synced, however it reached the Platform
Where you import or sync a data set for bulk messaging or CRM use, you will be required to accept a Data Import Consent & Responsibility Declaration (a signed/e-signed undertaking) confirming the above representations before the import is processed. 11za retains a copy of each such declaration as evidence of your acceptance. This declaration does not transfer your compliance obligations to 11za; it records that you, as the uploading party, take full responsibility and indemnify 11za for any claim, penalty, or liability arising from data you have imported or synced without a valid legal basis.
11za acts as a technology processor and does not independently verify the source or consent basis of contact lists uploaded or synced by customers, through any method, but reserves the right to suspend or terminate any account found in violation of WhatsApp’s policies or applicable law.
12. Third-Party AI Integration
Where you (a business customer) connect a third-party AI agent, model, or API — such as one built on OpenAI, Anthropic, or a similar provider — to your 11za account using your own credentials, that AI provider processes the resulting conversation data as your own chosen technology partner, not as an 11za subprocessor. 11za does not select, operate, or have a contractual relationship with your Third-Party AI provider, and does not access, store, or use the content it generates for any purpose other than facilitating the connection to WhatsApp.
You are responsible for ensuring your arrangement with any Third-Party AI provider complies with WhatsApp’s Business Solution Terms — including that your provider does not use conversation data (even in anonymised or aggregated form) to train or improve its AI models — and for informing your end-users, where appropriate, that their messages may be handled by an automated system. Full terms governing Third-Party AI integrations are set out in our Terms & Conditions (Section 9).
13. Voice Agent Services (Add-On Feature)
Where you opt in to 11za’s Voice Agent feature, calls made or received on your behalf are processed through the infrastructure of a third-party voice technology vendor engaged by 11za (the “Voice Vendor”), and are hosted on servers located in India. Unlike Third-Party AI you connect yourself (Section 12 above), the Voice Vendor is engaged directly by 11za to provide this feature, and is treated as an 11za subprocessor for the purpose of data protection.
Voice call audio recordings and any resulting transcripts are stored by the Voice Vendor on 11za’s behalf, and are subject to the same data protection standards, retention terms (see Section 7), and breach notification commitments as other personal data described in this Policy.
11za provides the technical connection between your account and the Voice Vendor’s calling infrastructure. Compliance with telecom regulatory requirements applicable to voice calls in India — including consent registration, do-not-disturb scrubbing, and calling number/header registration under applicable Telecom Regulatory Authority of India (TRAI) regulations — is the responsibility of the Voice Vendor and/or the business customer initiating the calls, as agreed between those parties, and not of 11za. 11za does not verify TRAI-side registration or consent compliance for calls made using this feature, but reserves the right to suspend or disconnect the Voice Agent feature for any account found in violation of applicable telecom or data protection law.
If you enable Voice Agent calling over WhatsApp, the same responsibilities and safeguards described in this Section apply equally, regardless of whether the call is placed over standard telecom infrastructure or via WhatsApp’s calling features.
14. Security Practices and Procedures
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction, including encryption in transit, access controls, and regular security reviews. No method of transmission or storage is 100% secure, and while we work to protect your information, we cannot guarantee absolute security.
15. Data Breach Notification
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals without undue delay, in the manner and within the timelines prescribed under the Digital Personal Data Protection Rules, 2025, including details of the nature of the breach, its likely consequences, and remedial measures taken or proposed.
16. Your Rights as a Data Principal
Subject to the DPDP Act, 2023, you have the right to:
- Access a summary of the personal data we hold about you and the processing activities undertaken
- Correct, complete, or update your personal data
- Request erasure of your personal data, subject to legal retention requirements and the processing timelines set out in Section 7
- Withdraw consent at any time, as easily as it was given
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity
- Register a grievance regarding our handling of your personal data, and, if unresolved, escalate the complaint to the Data Protection Board of India
To exercise any of these rights, email our Grievance Officer at the address in Section 17. We will verify your identity before acting on a request.
17. Grievance Officer
In accordance with the DPDP Act, 2023, we have appointed the following Grievance Officer:
Name: Nirmitkumar Choraria
Address: 509, Nemi Eminent, Above MG Select, Bharthana – 395007, India
Email: nirmit@11za.com
We will acknowledge grievances within 72 hours of receipt and aim to resolve them within 15 days.
18. Significant Data Fiduciary Status
We continuously monitor our data processing scale and will comply with additional obligations, including appointment of a Data Protection Officer and conduct of Data Protection Impact Assessments, if and when we are notified as a Significant Data Fiduciary under the DPDP Act, 2023.
19. Children’s Data
The Service is intended for use by businesses to communicate with their adult customers and contacts. We do not knowingly collect personal data directly from children under 18. Where a business customer uploads contact information that may include a child’s data, it is that customer’s responsibility to ensure appropriate parental/guardian consent has been obtained in accordance with the DPDP Act, 2023 before processing such data through the Platform.
20. Cookies
Our website uses cookies and similar technologies to operate core functionality, remember preferences, and understand site usage. You can control cookies through your browser settings; disabling certain cookies may affect site functionality.
21. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or legal requirements. The updated version will be indicated by a revised “Last Updated” date and will be effective upon posting. Material changes will be notified to you via email or in-app notice. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
22. Contact Us
For questions about this Policy or our data practices, contact:
Engees Communications Private Limited — 509, Nemi Eminent, Above MG Select, Bharthana – 395007, India
Phone: +91 97266 54060 Email: nirmit@11za.com