Two kinds of data, two different roles
Everything in this policy depends on one distinction, so we put it first:
— we are the FiduciaryData about you, our customer: who signed up, your workspace users, your billing details, how you use the product. We decide why and how this is processed, so we are the Data Fiduciary (controller) for it.
— we are the ProcessorData about your customers: their phone numbers, names, message content, media and history. You decide why it is collected and what happens to it. You are the Data Fiduciary; Zanoo is your Data Processor, acting on your instructions.
If you are an end customer who received a WhatsApp message from a business using Zanoo: the business that messaged you is responsible for your data, not Zanoo. Your access, correction and deletion requests should go to that business. Section "If you are an end customer" below explains what we can do to help.
Zanoo is operated by Codexlab Enterprise Pvt Ltd, [building, street], Kandivali West, Mumbai [PIN], Maharashtra, India. Privacy contact: support@zanoo.in.
Account data we collect about you
- Registration — business name, your name, work email, phone number, country, and the password hash or federated identity you sign in with.
- Workspace — users you invite, their names, emails, roles and permissions.
- Business verification — the details required to onboard your WhatsApp Business Account: legal entity name, address, website, display name and the documents Meta asks for.
- Billing — plan, billing address, GSTIN, invoices, payment history and the last four digits and type of the card. We never see or store full card numbers, CVVs or UPI PINs — those go directly to our payment gateway.
- Usage and telemetry — logins, IP address, device and browser, pages and features used, message volumes, template and campaign counts, error traces and performance data.
- Support — the content of tickets, emails and in-app chats with us, and any screenshots or logs you send.
- Cookies — strictly necessary cookies for session, security and load balancing; and, where you consent, product analytics cookies. You can manage non-essential cookies from the in-app cookie settings, and withdraw consent at any time.
We use account data to create and secure your workspace, provision your WABA, provide support, bill you, prevent fraud and abuse, send service notices, understand which features work, and — where you have consented — send product and marketing updates with a working unsubscribe link in every one.
Conversation data we process for you
To run the inbox, chatflows, campaigns and analytics you configure, Zanoo processes:
- Contact records — phone number, profile name as supplied by WhatsApp, and any name, email, tags, attributes or notes you or your Users add or import.
- Message content — inbound and outbound text, images, documents, audio, video, location, contacts, buttons and interactive replies.
- Message metadata — timestamps, direction, template used, message and conversation category, delivery, read and failure status, and the assigned agent.
- Workflow data — chatflow state, queue and routing history, escalations, internal notes, resolution status and CSAT responses.
- Web chat data — where you deploy our web widget, the visitor’s messages and the technical data needed to maintain the chat session.
We process this only on your instructions. We do not use your Contacts’ message content for our own purposes, do not sell it, do not share it with advertisers, and do not use it to train machine-learning models that serve other customers. Where you switch on an AI feature inside Zanoo, we tell you before it runs and what it sends where.
Our staff access conversation content only when you ask us to for support, when a specific security or abuse investigation requires it, or where the law compels it. Such access is role-restricted, logged, and limited to what the task needs.
What WhatsApp and Meta see
Zanoo sends and receives your messages through Meta’s WhatsApp Business Platform (Cloud API), which Meta hosts. That has privacy consequences you and your customers should understand:
- Messages between your business and your customers are transmitted through and processed by Meta’s infrastructure. Meta is an independent controller of the data it holds under its own terms and privacy policy.
- Because the business endpoint is hosted in Meta’s cloud, business messaging does not carry the same end-to-end encryption guarantee as person-to-person WhatsApp chats. Meta describes this in its own documentation, and WhatsApp shows users a notice when they message a business that uses hosted services.
- Meta processes phone numbers, message content and metadata to deliver messages, apply its policies, calculate charges and enforce quality ratings.
- Your customers’ relationship with WhatsApp itself is governed by WhatsApp’s own privacy policy, not by ours.
You are responsible for telling your customers, in your own privacy notice and opt-in wording, that you communicate over WhatsApp and that Meta processes those messages.
Sub-processors and who else touches the data
We use a small set of vetted providers to run Zanoo. Each is bound by contract to process data only on our instructions, keep it confidential and apply appropriate security safeguards.
The current list is maintained at support@zanoo.in on request. We give existing customers 30 days’ notice before adding a sub-processor that handles conversation data, and you may object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate the affected subscription and receive a pro-rata refund of prepaid fees.
We also disclose data to authorities where legally compelled, to professional advisers where genuinely required, and to a successor entity in a merger or sale — subject to this policy continuing to apply. We do not sell personal data.
Where data is stored and processed
We host Zanoo on [India-region / specify region] infrastructure and prefer India-region services. Meta and some of our other providers operate globally, so data may be processed outside India in the course of delivering messages and running the platform.
Transfers are made only to countries not restricted by the Central Government under section 16 of the DPDP Act, 2023, and are covered by contractual safeguards requiring protection consistent with this policy. Tell us at support@zanoo.in if you have data-residency requirements — we will confirm in writing what we can support.
How long we keep it
Security
- TLS in transit on every connection, and encryption at rest for databases, object storage and backups.
- Role-based access control inside your workspace, and least-privilege, logged, time-bound access for our own staff.
- Multi-factor authentication available for your users and enforced on our administrative accounts.
- Tenant isolation so one customer’s data is not reachable from another’s workspace.
- Secrets held in managed secret storage; webhook payloads signature-verified; API keys rotatable by you at any time.
- Dependency scanning, patching on a defined cadence, backups with tested restores, and monitoring with alerting.
If a personal data breach occurs, we will notify the Data Protection Board of India and affected individuals as required by the DPDP Act, and we will notify you without undue delay and in any case within 72 hours of becoming aware of a breach affecting your Customer Data, with the facts known at that point and updates as the investigation progresses.
Your rights as our customer
In respect of the account data we hold about you as Data Fiduciary, you may ask us to provide a summary of it, correct or complete it, erase it where we no longer need it and no law requires us to keep it, or withdraw a consent you gave. You may also nominate someone to exercise these rights on your behalf.
Email support@zanoo.in with the subject "DPDP request". We acknowledge within 48 hours and respond within 30 days. We may need to verify your identity first, and we will ask only for what is necessary.
Helping you meet your own obligations
Because you are the Data Fiduciary for your Contacts, we give you the controls to answer their requests:
- Export conversations and contact records at any time.
- Delete a contact and their conversation history, which removes it from your workspace and queues deletion from our systems.
- Configure retention so conversation data is purged automatically after a period you choose.
- Manage opt-outs centrally, with an audit record of when consent was captured and withdrawn.
- Audit logs of user access and administrative actions within your workspace.
We will also assist you, at your cost where the effort is substantial, with data principal requests, breach notifications and any data protection impact assessment you need to run. A data processing agreement is available on request.
If you are an end customer of a business using Zanoo
We hold your messages on behalf of the business you were chatting with. We cannot decide, on our own, to give you a copy or delete them — that is the business’s call, and going around them would itself be a privacy failure.
So: contact that business directly and exercise your rights with them. They can export or delete your data from Zanoo themselves. You may also:
- Reply STOP to a WhatsApp message to opt out of further non-service messages from that business, or block the number in WhatsApp.
- Write to support@zanoo.in if the business is unresponsive or you believe messages are being sent without your consent. We will pass your request to the business, require them to action it, and take enforcement action against accounts that ignore opt-outs — up to suspension.
- Report the business to Meta through WhatsApp, and escalate to the Data Protection Board of India.
We do not need to know who you are to accept a complaint, and we will not add you to any list of our own as a result of contacting us.
Children
Zanoo is a business product and is not directed at children. Do not create a Zanoo account if you are under 18. You must not use Zanoo to message anyone you know to be a child unless you have verifiable parental consent and comply with the additional protections the DPDP Act requires, including no tracking or behavioural advertising directed at children.
Changes to this policy
We will post any updated version here with a new effective date. For material changes affecting conversation data or sub-processors, we will notify account owners in-app or by email at least 30 days in advance where practicable.
Grievance officer and escalation
If our response does not resolve your complaint, you may escalate to the Data Protection Board of India.
This policy forms part of the Zanoo Terms & Conditions.
Zanoo is a product of Codexlab Enterprise Pvt Ltd · Kandivali West, Mumbai, Maharashtra, India