Section 1
Our two roles, and why the difference matters
We handle personal data in two distinct capacities. Which one applies determines who you should contact about your data.
We are the controller of data about our Clients and their staff, the people who sign up for and log into Yukto. We decide why and how that data is processed.
We are a processor of End User data, specifically the phone numbers, profile names, and message content of the people our Clients message on WhatsApp. We process that data only on the documented instructions of the Client, who is the controller.
If you are an End User who received a WhatsApp message sent through Yukto and want your data accessed, corrected or deleted, contact the business that messaged you. They control that data. If you cannot reach them, write to us at privacy@yukto.app and we will route your request to that Client and support them in responding.
Section 2
Data we collect
2.1 Client account data (we are controller)
| Data | Purpose |
|---|---|
| Name, business name, email address, phone number | Account creation, authentication, support |
| Password (stored only as a salted hash, never in plain text) | Authentication |
| Business address, GSTIN, tax identifiers | Invoicing and statutory tax compliance |
| Billing records, wallet balance, transaction history | Billing, dispute resolution, accounting |
| Role and permission assignments | Access control within the Client organisation |
2.2 WhatsApp Business credentials (we are controller of the credential, processor of the traffic)
To send and receive messages on a Client's behalf we store their WhatsApp Business Account ID, Phone Number ID, Meta App ID, access tokens and app secrets. Access tokens and app secrets are encrypted at rest using AES 256. We use them solely to operate the Service for that Client and never to access unrelated assets in their Meta account.
2.3 End User data (we are processor)
| Data | Source |
|---|---|
| Phone number (WhatsApp ID) | Uploaded by the Client, or received when the End User messages the Client |
| WhatsApp profile name | Provided by Meta in the webhook payload |
| Message content including text, images, documents, audio, video, location, interactive replies | Sent or received through the Client's WhatsApp number |
| Delivery, read and failure receipts, timestamps | Meta |
| Voice call records and, where the Client enables it, call recordings | The WhatsApp Business Calling API |
| Contact attributes, tags and notes added by the Client | The Client |
| Conversation and chatbot session history | Generated by the Service |
2.4 Technical and usage data (we are controller)
IP address, browser and device type, pages viewed, feature usage, API request logs, error and audit logs, and cookies or similar technologies strictly necessary to keep you signed in and protect the Service.
2.5 What we do not collect
We do not collect government identity numbers, payment card numbers (our payment processor handles those directly), biometric data, or precise geolocation, except where an End User voluntarily shares a location pin in a WhatsApp message to a Client.
Section 3
How we use data
- To transmit messages to and from WhatsApp via Meta's Cloud API
- To run chatbot flows, keyword rules and AI generated replies configured by the Client
- To route conversations to the Client's human agents and manage transfers and SLAs
- To produce delivery, engagement and cost analytics for the Client
- To authenticate users and enforce the Client's role based permissions
- To calculate charges, maintain wallet balances and issue invoices
- To provide support, investigate incidents and debug faults
- To detect, prevent and investigate spam, fraud, abuse and security incidents
- To comply with law and with Meta's platform requirements
We do not sell personal data. We do not share End User data between Clients: every record is scoped to a single Client organisation. We do not use End User message content to train our own machine learning models.
Section 4
Artificial intelligence processing
Where a Client enables AI auto reply, the content of inbound messages, together with recent conversation history and any knowledge base the Client has configured, is transmitted to the AI provider that Client has selected, in order to generate a reply.
Supported providers are OpenAI, Anthropic and Google. The choice of provider, the API key used, and whether the feature is switched on at all are controlled entirely by the Client. Data sent to these providers is governed by their respective terms; Clients using this feature are responsible for confirming that the provider's terms are compatible with the commitments they have made to their own End Users. AI features are off by default.
Section 5
Who we share data with
| Recipient | Why | Data involved |
|---|---|---|
| Meta Platforms, Inc. and affiliates (WhatsApp Business Cloud API) | Essential: message delivery is impossible without it | Phone numbers, message content, media, template parameters |
| AI providers (OpenAI, Anthropic, Google) | Only if the Client enables AI replies | Message content and conversation context |
| Cloud hosting and infrastructure providers | Hosting, storage, backups | All Service data, encrypted in transit and at rest |
| Payment processors | Wallet top ups and invoicing | Billing contact details and transaction amounts. Card data goes directly to the processor and never reaches our servers |
| Professional advisers, auditors | Accounting, legal and tax obligations | Billing and corporate records |
| Law enforcement or regulators | Where legally compelled | As strictly required by a valid legal request |
We do not share data with advertising networks or data brokers.
Your use of WhatsApp is additionally governed by Meta's own terms and privacy policies. We have no control over Meta's independent processing of data on the WhatsApp network.
Section 6
International transfers
Our infrastructure and our subprocessors, including Meta and the AI providers, operate servers outside India, including in the United States and the European Union. Where personal data is transferred across borders we rely on the transfer mechanisms permitted by applicable law and require contractual safeguards from our subprocessors.
Section 7
Retention
| Data | Retention |
|---|---|
| Client account and billing records | For the life of the account, then as long as tax and company law require (in India, currently 8 years for books of account) |
| Messages, contacts and conversation history | For the life of the account, or until the Client deletes them, whichever is sooner |
| Call recordings | Only for the period configured for the relevant feature or Client purpose, unless the Client sets a shorter period |
| Audit and security logs | 12 months |
| Backups | Up to 30 days after deletion, after which they are overwritten |
Call recordings are retained only where the Client enables the relevant calling feature. Because no single numeric retention period applies to every Client configuration, the applicable period is the one configured for that feature or Client purpose. Legal holds, dispute resolution, security investigations, and applicable legal obligations may require data to be retained for longer.
On account closure, see the Data Deletion Policy.
Section 8
Security
We apply measures appropriate to the sensitivity of the data, including AES 256 encryption at rest for access tokens and other secrets, TLS in transit, hashed passwords, role based access control, tenant isolation so no Client can reach another Client's data, audit logging of sensitive actions, and restricted internal access on a need to know basis.
No system is perfectly secure. If a personal data breach occurs that is likely to result in harm, we will notify affected Clients and the relevant supervisory authority within the timeframes the law requires, and we will support Clients in notifying their End Users.
Section 9
Your rights
Subject to applicable law, including the Digital Personal Data Protection Act, 2023 in India, and the GDPR where it applies, you may request to:
- Access the personal data we hold about you
- Correct data that is inaccurate, incomplete or out of date
- Delete your personal data (see the Data Deletion Policy)
- Withdraw consent where processing is based on consent
- Port your data in a structured, readable format
- Object to or restrict certain processing
- Complain to a supervisory authority
To exercise any of these, email privacy@yukto.app. We respond within 30 days. We may ask you to verify your identity first. Exercising a right is free; we may charge a reasonable fee only for requests that are manifestly excessive or repetitive.
Remember the distinction in section 1: if you are an End User, your request belongs with the business that messaged you.
Grievance Officer
As required under Indian law (Information Technology Act and DPDP Act), grievances may be sent to grievance@yukto.app or to the address listed in section 13. Yukto acknowledges grievances within 24 hours and aims to resolve them within 15 days. Where a specific Grievance Officer is appointed, the current contact details will be made available through this page or the relevant in-product notice.
Section 10
Children
The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children. Clients must not use the Service to message individuals they know to be children without the verifiable consent their local law requires.
Section 11
Cookies
We use only cookies that are strictly necessary to operate the dashboard: an httpOnly authentication cookie that keeps you signed in, and a CSRF token that protects against cross site request forgery. We do not use advertising or third party tracking cookies in the application.
Section 12
Changes
We may update this Policy. Material changes will be notified by email and by an in product notice at least 14 days before they take effect. The Effective date above always reflects the current version.
Section 13
Contact
Yukto
Sudama Sadan, Vivekanand Marg,Salempur, District Deoria,
Uttar Pradesh 274509
Privacy & Data Rights
privacy@yukto.appGrievance Officer (DPDP / IT Act)
grievance@yukto.appLegal & Compliance
legal@yukto.appSecurity Disclosures
security@yukto.appCustomer Support
support@yukto.appGeneral Inquiries
contact@yukto.app