1.Introduction
This Privacy Policy describes how EvolvePro Tech Solutions Private Limited ("Splashify Pro", "we", "us", or "our") collects, uses, discloses, stores, and protects information about you when you visit splashifypro.com (the "Website"), use our mobile applications, or subscribe to our software services (collectively, the "Services").
We are a Meta-verified WhatsApp Business Solution Provider (BSP) headquartered in India. We are committed to protecting your privacy and complying with applicable data protection laws, including the Digital Personal Data Protection Act, 2023 ("DPDP Act") of India and, where applicable, the EU General Data Protection Regulation ("GDPR").
By accessing or using our Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, please do not use our Services.
2.Data Controller / Data Fiduciary
For the purposes of the DPDP Act and GDPR, the data controller / data fiduciary responsible for your personal data is:
EvolvePro Tech Solutions Private Limited
(operating as "Splashify Pro")
Shimultala, Motiganj, Bongaon
North 24 Parganas, West Bengal - 743235, India
CIN: U62012WB2025OPC281483
GSTIN: 19AAJCE0527G1ZQ
Email: [email protected]
Phone: +91 90466 15888
You may contact our Data Protection Officer at [email protected] for any privacy-related questions, complaints, or requests to exercise your rights.
3.Information We Collect
3.1 Information you provide to us
- Account information: name, email address, mobile number, business name, GSTIN (where applicable), billing address, password (stored only as a salted bcrypt hash).
- Payment information: processed securely by our payment partners (Razorpay, Zoho Payments, PhonePe, PayU). We do not store full card numbers, CVV, or UPI PIN. We retain only payment-method tokens, last 4 digits of card, payment references, and transaction status.
- Business content: WhatsApp message templates, broadcast content, chatbot flows, contact lists you upload, custom contact fields, AI agent knowledge base content, media (images, videos, documents) you upload to our platform.
- Communications: support tickets, demo requests, contact-form submissions, chat-widget conversations with our Maya AI assistant, and email correspondence.
- KYC documents: for RCS messaging activation, business verification, or compliance purposes. Government-issued business identifiers, registration certificates, and authorised-signatory information.
3.2 Information we collect automatically
- Device & log data: IP address, browser type, operating system, device identifiers, referring URL, pages visited, timestamps, click events, and session duration.
- Cookies & similar technologies: session cookies, preference cookies, and analytics cookies (see Section 8 below for details).
- WhatsApp / Instagram / RCS data: when you connect your business channels, we receive and process inbound and outbound message metadata, contact phone numbers, message status events (sent / delivered / read), and webhook payloads from Meta and partner networks.
- Customer-of-customer data: when your end-customers message your connected WhatsApp / Instagram / RCS number, we process their phone numbers, profile names (where shared by Meta), and message content. You are the data controller / fiduciary for this data; we act as a data processor on your behalf.
3.3 Information from third parties
- Meta (Facebook & Instagram): when you connect your WhatsApp Business Account or Instagram via Embedded Signup, Meta provides us with your account details, phone numbers, page identifiers, and webhook events.
- Payment partners: Razorpay, Zoho, PhonePe, and PayU share payment confirmation, refund status, and dispute information.
- Reseller partners: if you are a client of a Splashify Pro reseller, the reseller may share your account information with us as part of provisioning.
4.How We Use Your Information
We use your personal data for the following lawful purposes:
- Service delivery: create and manage your account, authenticate logins, provision WhatsApp / Instagram / RCS channels, route messages, store templates and conversation history, process broadcasts, run chatbot flows, generate AI agent responses.
- Billing & payments: process subscription payments, generate GST-compliant invoices, deduct per-message charges from your wallet, issue refunds, prevent fraud.
- Customer support: respond to support tickets, troubleshoot issues, provide demos, train you on platform features.
- Service improvement: analyse aggregated, de-identified usage patterns to improve features, fix bugs, and prioritise roadmap.
- Communications: send transactional emails (account confirmations, password resets, billing receipts, security alerts) and, with your consent, promotional emails about new features.
- Legal & compliance: comply with applicable laws, court orders, regulatory requirements, Meta WhatsApp Business policies, and to enforce our Terms of Service.
- Security: detect and prevent abuse, fraud, account takeovers, spam, and platform misuse.
5.Lawful Basis for Processing
Under the DPDP Act and GDPR, we rely on the following lawful bases:
- Performance of contract: to provide the Services you have signed up for.
- Legitimate interests: for service security, fraud prevention, product improvement, and communicating service-essential updates.
- Legal obligation: to comply with tax, accounting, anti-money laundering, and other regulatory requirements.
- Consent: for marketing communications, optional analytics cookies, and any processing not covered by the bases above. You may withdraw consent at any time without affecting the lawfulness of prior processing.
6.How We Share Your Information
We do not sell your personal data. We share information only with the parties listed below, and only to the extent necessary to deliver the Services:
6.1 Service providers (sub-processors)
- Meta Platforms, Inc.: WhatsApp Business API, Instagram Graph API, Click-to-WhatsApp Ads, Conversion API.
- Payment gateways: Razorpay, Zoho Payments, PhonePe, PayU (transaction processing only).
- Cloud infrastructure: DigitalOcean (compute, storage, ScyllaDB clusters), CDN providers (asset delivery).
- AI providers: DeepSeek (chat, chatbot replies, AI agent reasoning; servers in the People's Republic of China), Google Gemini (embeddings, document OCR, and live audio for AI voice calls), Sarvam AI (Indian-language chat and speech synthesis), Microsoft Edge TTS (speech synthesis). Knowledge-base content, conversation context, and (for AI voice calls) the live audio of both parties are transmitted to these providers under their own terms. Pending legal reviewCross-border transfer to the PRC is the single highest-exposure disclosure on this page and needs counsel sign-off, including whether it is permissible under DPDP §16 as notified.
- Email & notifications. Zoho ZeptoMail and our own outbound mail infrastructure, Google Firebase Cloud Messaging (web and mobile push; replaced OneSignal), WhatsApp OTP delivery via Meta.
- Messaging gateways. Meta (WhatsApp Cloud API, reached via Interakt's proxy), Jio CX, Route Mobile and Interakt (RCS delivery). These receive recipient phone numbers and message content because they deliver the message.
- Analytics & diagnostics. Google Analytics 4, Google Tag Manager, Meta Pixel, PostHog (product analytics, United States), Google AdSense (advertising on blog articles only), Sentry (error tracking and error-triggered session replay, United States), ipinfo.io (IP geolocation of website visitors). All except Sentry are non-essential and load only with your consent. See Section 8.
- Billing & invoicing. Zoho Books for GST-compliant invoicing.
6.2 Resellers
If you signed up through a Splashify Pro reseller (white-label partner), the reseller can access your account, billing, and usage information necessary to provide support and manage your subscription. Resellers are contractually bound to handle your data in line with this Privacy Policy.
6.3 Legal disclosures
We may disclose information when required by Indian law, a valid court order, or a legitimate request from law enforcement. We will notify you of such disclosure unless legally prohibited.
6.4 Business transfers
If we undergo a merger, acquisition, or sale of assets, your information may be transferred to the successor entity. You will be notified by email and on this site.
7.Data Retention
We retain personal data only as long as necessary for the purposes collected:
- Active accounts: as long as your account is active.
- Closed accounts: account information retained for 90 days for recovery, then anonymised or deleted (except where law requires longer retention).
- Billing & tax records: retained for at least 8 years to comply with the Indian Income Tax Act and GST regulations.
- Conversation history: retained as long as your account is active or until you delete it from your dashboard. Backups are retained for an additional 30 days for disaster recovery.
- Activity & audit logs: retained for 12 months for security and compliance.
- Website visit records (only collected if you consent to analytics): 180 days, then deleted automatically.
- Consent records: kept for as long as we rely on the consent and for three years after it is withdrawn. Section 6(9) of the DPDP Act requires us to be able to prove the consent we acted on, so these records are deliberately not deleted along with the rest of an account.
- Messages sent to you by our business customers: where a business uses our platform to message you, that business decides how long its contact list and conversation history are kept. We hold that data on their instructions. If you ask us to erase it, we will act with them. See Section 12 and the data rights request form.
Pending legal reviewThe periods above describe our retention policy. Deletion is currently carried out on request by a member of staff rather than by an automated job on every table, and the erasure of an account does not yet reach every secondary index, log table or object-storage file. We are recording this here rather than describing an automation that does not exist. Counsel should advise on how this is stated, and engineering work to close the gap is tracked internally.
9.Data Security
We protect your data with the following technical and organisational measures:
- Encryption in transit: all traffic uses TLS 1.2 or higher.
- Encryption at rest: sensitive fields (access tokens, integration credentials) are encrypted with AES-256.
- Authentication: bcrypt-hashed passwords, JWT-based session tokens, two-factor authentication via WhatsApp OTP and email OTP.
- Access controls: role-based permissions, principle of least privilege, audit logs for all admin actions.
- Infrastructure: isolated network zones, automated security patching, DDoS protection, rate limiting.
- Backups: daily automated backups with encryption, retained for 30 days.
- Incident response: documented breach-notification procedure. In the event of a personal data breach affecting you, we will notify you within 72 hours of discovery, as required by the DPDP Act.
No system is 100% secure. While we use industry-standard safeguards, we cannot guarantee absolute security. You are responsible for protecting your account credentials.
10.Your Rights
Subject to the DPDP Act, GDPR (where applicable), and other relevant laws, you have the following rights regarding your personal data:
- Right to access: request a copy of the personal data we hold about you.
- Right to correction: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your data, subject to legal retention obligations.
- Right to data portability: receive your data in a structured, machine-readable format and request transfer to another controller (where technically feasible).
- Right to withdraw consent: at any time, without affecting the lawfulness of prior processing.
- Right to grievance redressal: raise a complaint with our Grievance Officer (details in Section 16). We acknowledge within 24 hours and respond within 30 days. If you are not satisfied, you may escalate to the Data Protection Board of India under the DPDP Act, or to your local supervisory authority under GDPR.
- Right to nominate: nominate another individual to exercise your rights in case of death or incapacity (DPDP Act, Section 14).
To exercise any of these rights, use the data rights request form. You do not need an account with us to use it. If you received a WhatsApp message, an RCS message or an email sent through our platform by one of our business customers, you are a Data Principal too, and the form is the route we ask you to use. We will identify the business that holds your details and act with them.
You can also email [email protected] (grievances, Section 13) or [email protected] (data protection queries). If you have an account, sending from your registered email address speeds up verification. We respond within 30 days; where we need to verify your identity first, that 30 days runs from the point verification completes.
11.International Data Transfers
Your data is primarily stored on servers located in India. Some sub-processors (Meta, Anthropic, Google) may process data outside India. When this occurs, we rely on:
- Standard Contractual Clauses (SCCs) for transfers from the EU.
- Compliance with the Indian Government's notified country list under DPDP Act Section 16.
- Contractual data-protection terms with each sub-processor.
12.Children's Privacy
Our Services are intended for businesses and are not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If you become aware that a child has provided us personal data without parental consent, contact [email protected] and we will delete the information promptly.
13.Email API for Developers
If you use the Splashify Pro Email API at partner.splashifypro.com to send email to your own end-customers, additional terms apply. In that scenario you act as the Data Fiduciary / Controller for the recipient personal data you send through our service, and we act as the Data Processor. The full processor obligations, sub-processor list, retention schedule, breach notification process, and audit rights live in our partner-side legal documents:
- Data Processing Agreement DPDP Act 2023 + GDPR Article 28 written contract.
- Acceptable Use Policy banned content, banned recipient practices, regulated industries.
- Anti-Spam Policy consent rules, list-acquisition restrictions, unsubscribe handling.
- Auto-Action System automated thresholds that throttle, pause, or terminate accounts.
- Incident Response vulnerability reports, abuse reports, breach notifications.
For email recipient data, we retain message bodies for 30 days, delivery metadata (open/click/bounce events) for 18 months, and suppression-list entries until the partner removes them or terminates the account. All processing is on the partner's documented instructions.
Recipients who wish to exercise rights under the DPDP Act or GDPR regarding email they received should contact the sender (the partner) directly. We process recipient data only on the sender's instruction. Where we receive direct requests from recipients, we forward them to the responsible partner within 48 hours.
14.Third-Party Websites
The Services may contain links to third-party websites (e.g., payment gateway pages, documentation hosted on partner platforms). We are not responsible for the privacy practices of those sites. Review their privacy policies before providing personal data.
15.Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. The "Effective" date at the top of this page indicates the latest revision. Material changes will be notified by email and via a prominent notice on the Website at least 7 days before they take effect. Your continued use of the Services after changes take effect constitutes acceptance.
16.Contact Us
The fastest route for any request about your own data is the data rights request form. It works whether or not you have an account with us, and it gives you a reference number you can quote.
Grievance Officer (Section 13, DPDP Act 2023 and Rule 3(2)(b), IT Rules 2021). If you are unhappy with how we have handled your personal data, contact the Grievance Officer. We acknowledge every grievance within 24 hours and resolve within 30 days. If you remain dissatisfied you may complain to the Data Protection Board of India.
Grievance Officer
EvolvePro Tech Solutions Private Limited
Email: [email protected]
Phone: +91 90466 15888
Registered Office: Shimultala, Motiganj, Bongaon, North 24 Parganas, West Bengal - 743235, India
Pending legal reviewThe DPDP Act requires a named individual to be identified as the person responsible for answering grievances. Only the role and the address are published here; counsel should confirm the named person and whether the same individual may hold both the Grievance Officer and Data Protection Officer roles.
For privacy questions and data protection queries:
Data Protection Officer
EvolvePro Tech Solutions Private Limited
CIN: U62012WB2025OPC281483 · GSTIN: 19AAJCE0527G1ZQ
Email: [email protected]
General queries: [email protected]
Support: [email protected]
Phone: +91 90466 15888
Registered Office: Shimultala, Motiganj, Bongaon, North 24 Parganas, West Bengal - 743235, India