Legal

Privacy Policy

This Privacy Policy explains how Yukto handles personal data when you use our Service, create a Client account, connect a WhatsApp Business number, or communicate with a business through a Client's WhatsApp number.

Effective 19 September 2026Applies to Yukto and the Service
This Privacy Policy describes how Yukto processes personal data in connection with its software as a service platform and related services (the "Service"). It is written for Clients that use Yukto and for End Users who send or receive communications through a Client's WhatsApp Business number.

Section 1

Our two roles, and why the difference matters

We handle personal data in two distinct capacities. Which one applies determines who you should contact about your data.

We are the controller of data about our Clients and their staff, the people who sign up for and log into Yukto. We decide why and how that data is processed.

We are a processor of End User data, specifically the phone numbers, profile names, and message content of the people our Clients message on WhatsApp. We process that data only on the documented instructions of the Client, who is the controller.

If you are an End User who received a WhatsApp message sent through Yukto and want your data accessed, corrected or deleted, contact the business that messaged you. They control that data. If you cannot reach them, write to us at privacy@yukto.app and we will route your request to that Client and support them in responding.

Section 2

Data we collect

2.1 Client account data (we are controller)

DataPurpose
Name, business name, email address, phone numberAccount creation, authentication, support
Password (stored only as a salted hash, never in plain text)Authentication
Business address, GSTIN, tax identifiersInvoicing and statutory tax compliance
Billing records, wallet balance, transaction historyBilling, dispute resolution, accounting
Role and permission assignmentsAccess control within the Client organisation

2.2 WhatsApp Business credentials (we are controller of the credential, processor of the traffic)

To send and receive messages on a Client's behalf we store their WhatsApp Business Account ID, Phone Number ID, Meta App ID, access tokens and app secrets. Access tokens and app secrets are encrypted at rest using AES 256. We use them solely to operate the Service for that Client and never to access unrelated assets in their Meta account.

2.3 End User data (we are processor)

DataSource
Phone number (WhatsApp ID)Uploaded by the Client, or received when the End User messages the Client
WhatsApp profile nameProvided by Meta in the webhook payload
Message content including text, images, documents, audio, video, location, interactive repliesSent or received through the Client's WhatsApp number
Delivery, read and failure receipts, timestampsMeta
Voice call records and, where the Client enables it, call recordingsThe WhatsApp Business Calling API
Contact attributes, tags and notes added by the ClientThe Client
Conversation and chatbot session historyGenerated by the Service

2.4 Technical and usage data (we are controller)

IP address, browser and device type, pages viewed, feature usage, API request logs, error and audit logs, and cookies or similar technologies strictly necessary to keep you signed in and protect the Service.

2.5 What we do not collect

We do not collect government identity numbers, payment card numbers (our payment processor handles those directly), biometric data, or precise geolocation, except where an End User voluntarily shares a location pin in a WhatsApp message to a Client.

Section 3

How we use data

  • To transmit messages to and from WhatsApp via Meta's Cloud API
  • To run chatbot flows, keyword rules and AI generated replies configured by the Client
  • To route conversations to the Client's human agents and manage transfers and SLAs
  • To produce delivery, engagement and cost analytics for the Client
  • To authenticate users and enforce the Client's role based permissions
  • To calculate charges, maintain wallet balances and issue invoices
  • To provide support, investigate incidents and debug faults
  • To detect, prevent and investigate spam, fraud, abuse and security incidents
  • To comply with law and with Meta's platform requirements

We do not sell personal data. We do not share End User data between Clients: every record is scoped to a single Client organisation. We do not use End User message content to train our own machine learning models.

Section 4

Artificial intelligence processing

Where a Client enables AI auto reply, the content of inbound messages, together with recent conversation history and any knowledge base the Client has configured, is transmitted to the AI provider that Client has selected, in order to generate a reply.

Supported providers are OpenAI, Anthropic and Google. The choice of provider, the API key used, and whether the feature is switched on at all are controlled entirely by the Client. Data sent to these providers is governed by their respective terms; Clients using this feature are responsible for confirming that the provider's terms are compatible with the commitments they have made to their own End Users. AI features are off by default.

Section 5

Who we share data with

RecipientWhyData involved
Meta Platforms, Inc. and affiliates (WhatsApp Business Cloud API)Essential: message delivery is impossible without itPhone numbers, message content, media, template parameters
AI providers (OpenAI, Anthropic, Google)Only if the Client enables AI repliesMessage content and conversation context
Cloud hosting and infrastructure providersHosting, storage, backupsAll Service data, encrypted in transit and at rest
Payment processorsWallet top ups and invoicingBilling contact details and transaction amounts. Card data goes directly to the processor and never reaches our servers
Professional advisers, auditorsAccounting, legal and tax obligationsBilling and corporate records
Law enforcement or regulatorsWhere legally compelledAs strictly required by a valid legal request

We do not share data with advertising networks or data brokers.

Your use of WhatsApp is additionally governed by Meta's own terms and privacy policies. We have no control over Meta's independent processing of data on the WhatsApp network.

Section 6

International transfers

Our infrastructure and our subprocessors, including Meta and the AI providers, operate servers outside India, including in the United States and the European Union. Where personal data is transferred across borders we rely on the transfer mechanisms permitted by applicable law and require contractual safeguards from our subprocessors.

Section 7

Retention

DataRetention
Client account and billing recordsFor the life of the account, then as long as tax and company law require (in India, currently 8 years for books of account)
Messages, contacts and conversation historyFor the life of the account, or until the Client deletes them, whichever is sooner
Call recordingsOnly for the period configured for the relevant feature or Client purpose, unless the Client sets a shorter period
Audit and security logs12 months
BackupsUp to 30 days after deletion, after which they are overwritten

Call recordings are retained only where the Client enables the relevant calling feature. Because no single numeric retention period applies to every Client configuration, the applicable period is the one configured for that feature or Client purpose. Legal holds, dispute resolution, security investigations, and applicable legal obligations may require data to be retained for longer.

On account closure, see the Data Deletion Policy.

Section 8

Security

We apply measures appropriate to the sensitivity of the data, including AES 256 encryption at rest for access tokens and other secrets, TLS in transit, hashed passwords, role based access control, tenant isolation so no Client can reach another Client's data, audit logging of sensitive actions, and restricted internal access on a need to know basis.

No system is perfectly secure. If a personal data breach occurs that is likely to result in harm, we will notify affected Clients and the relevant supervisory authority within the timeframes the law requires, and we will support Clients in notifying their End Users.

Section 9

Your rights

Subject to applicable law, including the Digital Personal Data Protection Act, 2023 in India, and the GDPR where it applies, you may request to:

  • Access the personal data we hold about you
  • Correct data that is inaccurate, incomplete or out of date
  • Delete your personal data (see the Data Deletion Policy)
  • Withdraw consent where processing is based on consent
  • Port your data in a structured, readable format
  • Object to or restrict certain processing
  • Complain to a supervisory authority

To exercise any of these, email privacy@yukto.app. We respond within 30 days. We may ask you to verify your identity first. Exercising a right is free; we may charge a reasonable fee only for requests that are manifestly excessive or repetitive.

Remember the distinction in section 1: if you are an End User, your request belongs with the business that messaged you.

Grievance Officer

As required under Indian law (Information Technology Act and DPDP Act), grievances may be sent to grievance@yukto.app or to the address listed in section 13. Yukto acknowledges grievances within 24 hours and aims to resolve them within 15 days. Where a specific Grievance Officer is appointed, the current contact details will be made available through this page or the relevant in-product notice.

Section 10

Children

The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children. Clients must not use the Service to message individuals they know to be children without the verifiable consent their local law requires.

Section 11

Cookies

We use only cookies that are strictly necessary to operate the dashboard: an httpOnly authentication cookie that keeps you signed in, and a CSRF token that protects against cross site request forgery. We do not use advertising or third party tracking cookies in the application.

Section 12

Changes

We may update this Policy. Material changes will be notified by email and by an in product notice at least 14 days before they take effect. The Effective date above always reflects the current version.

Section 13

Contact

Yukto

Sudama Sadan, Vivekanand Marg,
Salempur, District Deoria,
Uttar Pradesh 274509

Privacy & Data Rights

privacy@yukto.app

Grievance Officer (DPDP / IT Act)

grievance@yukto.app

Legal & Compliance

legal@yukto.app

Security Disclosures

security@yukto.app

Customer Support

support@yukto.app

General Inquiries

contact@yukto.app