Privacy Policy
Last updated: 05 October 2026
This Privacy Policy explains how Dhanamitra Infotech LLP, the company that operates Vaanexa ("Vaanexa", "we", "us" or "our"), collects, uses, shares and protects personal data when you visit vaanexa.com or use the Vaanexa platform, apps, APIs, AI features and related services (the "Services"). Vaanexa is an AI revenue platform that helps businesses manage WhatsApp, Instagram, Messenger and Threads conversations, run AI agents, capture leads, send campaigns, manage ads and collect payments. If anything here is unclear, write to privacy@vaanexa.com.
1. Who we are and who this policy covers
The Services are provided by Dhanamitra Infotech LLP, a limited liability partnership registered in India (LLPIN [LLPIN], GSTIN [GSTIN]), with its registered office at [REGISTERED ADDRESS LINE], Greater Noida West, Uttar Pradesh, India.
This policy covers visitors to our website; the businesses that subscribe to Vaanexa ("Customers") and the people they invite into their workspace ("Users"); and the people who message, call or buy from our Customers through Vaanexa ("End Customers"). For End Customers, the privacy notice of the business you dealt with is the primary notice, and this policy explains our supporting role.
2. Our two roles
For data about you as a Vaanexa account holder, such as your name, email, phone, login history, billing details, GSTIN, product usage and details you leave on our website, we decide how it is used. We are therefore its Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") and its controller under the GDPR.
The data your business brings into Vaanexa is different. This "Customer Data" includes your End Customers' names, phone numbers, messages, media, leads, orders, appointments, notes and, where voice is enabled, call recordings. Your business is its Data Fiduciary or controller, and Vaanexa acts only as a Data Processor on your instructions, as set out in our Data Processing Addendum. End Customers who want to access, correct or delete their information should contact that business first. If you contact us instead, we will pass your request on and help the business respond.
3. The information we collect
Most information comes directly from you. When you sign up, we collect your name, work email, mobile number, password, business name, industry and team size. For billing, we collect your legal business name, GSTIN (from which your PAN is derived), billing address, state, plan and billing cycle. We also collect the names, emails and roles of colleagues you invite, your support conversations, and the content you upload, such as knowledge-base documents, catalogue items, templates, flows, media, quotes and invoices. When you connect integrations, we store the credentials they need, such as payment-gateway keys, pixel IDs, webhook URLs and API keys, always encrypted.
Our servers automatically record your IP address, request times, the pages and features you use, the referring URL and any errors. They also record device details such as browser, operating system, language and an approximate location derived from your IP address. We use cookies as described in section 9.
When you connect a WhatsApp Business account, Instagram account, Facebook Page, Messenger, Threads or a Meta ad account, Meta sends us account and asset identifiers, phone-number and page details, access tokens, message and comment events, lead-form submissions and advertising metrics. When you pay for a subscription, Cashfree tells us whether the payment succeeded and gives us a payment reference. We never receive your full card number, CVV or UPI PIN. Leads you import or send by webhook reach us exactly as you provide them.
4. How we use information and why
We use account information to create and secure your account, sign you in, run two-factor authentication and prevent fraud. We use Customer Data only to provide the features you switch on, such as the inbox, AI agent, flows, campaigns, lead management, sales tools and ads. We use billing information to charge you, issue GST invoices and meet tax obligations. We use contact details for support, service messages and security alerts. We use usage and device data, largely aggregated or de-identified, to keep Vaanexa fast and reliable, fix bugs and enforce plan limits and AI-credit metering. We never try to re-identify de-identified data. We send marketing emails only with your consent or where the law permits, and you can unsubscribe at any time. We may also process information to comply with the law and to establish or defend legal claims.
Under the DPDP Act, we rely on your consent or on a "legitimate use" recognised by section 7 of the Act, such as using data you voluntarily gave us for the purpose you gave it, or complying with the law. Where the GDPR or UK GDPR applies, we rely on performance of our contract with you, legal obligations, our legitimate interests in running a secure and reliable service, and your consent.
5. Artificial intelligence features
Vaanexa uses AI to draft and send replies, score leads, summarise conversations, suggest follow-ups, build flows, write ad copy and content plans, and analyse ad performance. To do this, we send only the context the task needs, such as recent messages, contact fields, your knowledge base and business settings, to Google through the Gemini API. We use Google's paid API terms, under which prompts and responses are not used to train Google's models. We do not use Customer Data to train any model of our own.
AI output can be inaccurate, incomplete or inappropriate. Each Customer therefore decides whether the AI replies on its own or only drafts messages for review, and sets confidence thresholds and hand-off rules. Customers should not rely solely on AI output for decisions with legal or similarly significant effects on a person, such as decisions about credit, employment, housing, insurance, healthcare or legal matters. Where the law requires it, they must tell End Customers they may be talking to an automated assistant.
6. Meta platforms
Vaanexa connects to Meta only through Meta's official APIs. These include the WhatsApp Business Platform (Cloud API) via Embedded Signup, the Instagram and Messenger platforms, the Threads API, Lead Ads, the Marketing API and the Conversions API. We access only the permissions you approve and use the data only for the features you enable. We never sell Meta platform data, use it for unrelated purposes or build profiles from it for others. If you turn on conversion tracking, we send event data such as hashed emails and phone numbers to Meta on your behalf, and you are responsible for having the necessary lawful basis and consent.
You can disconnect a channel at any time from Settings, or remove Vaanexa's access in your Meta Business Settings. To have us delete data received through a Meta integration, email privacy@vaanexa.com with the subject "Data Deletion". Include your business name and the connected Page, Instagram account or WhatsApp number. We will confirm deletion within 30 days, unless the law requires us to keep certain records.
7. Who we share information with
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We use service providers ("subprocessors") under written contracts that require confidentiality and security: a hosting provider in an Indian data centre for our servers, database and queues; Cloudflare for file storage (R2), content delivery and attack protection; Google for the Gemini AI API, and for Google Analytics on vaanexa.com only; Cashfree Payments India for Vaanexa subscription billing; an email delivery provider for account emails.
When our voice features launch, Exotel, Deepgram and ElevenLabs will provide telephony, speech-to-text and text-to-speech, but only for Customers who switch voice on. Customers covered by our Data Processing Addendum receive advance notice of subprocessor changes.
We also send data to the platforms you choose to connect, such as Meta, a webhook endpoint you configure, or your own payment gateway. Gateways such as Razorpay, PhonePe, PayU or your own Cashfree account are your service providers, not ours. Within your workspace, Users see data according to the roles your admins set. We may disclose information where required by law, court order or a government authority, including CERT-In, or to protect the rights and safety of Vaanexa, our Customers or others. In a merger, acquisition or sale of assets, data may be transferred, and it will remain protected by this policy.
8. International transfers
Our primary database is hosted in India. Some subprocessors, including Google, Meta and Cloudflare, process data in other countries, such as the United States and EU member states. Transfers out of India follow the DPDP Act and any restrictions notified by the Central Government. Transfers from the European Economic Area, the United Kingdom or Switzerland are protected by the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or the Swiss equivalent. Where available, we also rely on certifications such as the EU-U.S. Data Privacy Framework.
9. Cookies
Strictly necessary cookies keep you signed in and protect your session; the Services cannot work without them. Preference storage remembers settings such as your theme. Google Analytics cookies help us understand traffic on our public website and are used in line with your cookie choices. We use no advertising cookies in the Vaanexa app. You can block cookies in your browser or install Google's Analytics opt-out add-on. We do not respond to Do-Not-Track signals, as there is no common standard for them. Where the law requires, we honour Global Privacy Control signals, although we do not sell or share personal data in any case.
10. How long we keep information
We keep account information while your account is active. If an account has had no sign-in and no active subscription for 36 months, we delete or anonymise it.
Customer Data stays under your control. Admins can set automatic retention for messages, contacts and webhook logs, from one day to ten years or indefinitely, and can delete contacts or erase the whole business at any time. When a subscription ends, Customer Data remains available for export for 30 days. It is then deleted from live systems, and from backups within a further 90 days.
We keep some records for longer: invoices and tax records for eight years, as GST and income-tax law require; security logs for at least 180 days, as CERT-In directions require; website analytics for 14 months; support records for three years.
We may keep information longer where the law requires or to resolve disputes, isolated from any other use.
11. How we protect information
We follow reasonable security practices under the Information Technology Act, 2000, its 2011 rules on sensitive personal data, and the DPDP Act. Data travels over encrypted TLS connections, and we encrypt access tokens, gateway credentials and other secrets at rest. Passwords are stored only as salted hashes. Users can turn on two-factor authentication, and admins control access through role-based permissions. Each Customer's data is kept separate from every other's. Sensitive actions are recorded in audit logs, and erasing a business requires the admin's password and the business name typed in full. We also limit staff access, take regular backups, rate-limit sensitive endpoints and monitor for incidents. No internet-connected system is completely secure. If a breach affects you, we will notify you and the relevant authorities, including the Data Protection Board of India and CERT-In, within the time limits the law sets.
12. Children
Vaanexa is for businesses and is not intended for anyone under 18. We do not knowingly collect children's personal data, and we will delete it if we learn we have. Customers must not process children's data through Vaanexa without verifiable parental consent, as the DPDP Act requires.
13. Your privacy rights
Depending on where you live, you may have the right to: access a copy of your data; correct it; have it erased; receive it in a portable format; restrict or object to processing, including direct marketing; withdraw consent at any time.
Under the DPDP Act, you may also nominate someone to exercise your rights if you die or become incapacitated. We will never treat you differently for exercising these rights.
To exercise a right, write to privacy@vaanexa.com from your account email. Admins can also export all business data and correct, delete or opt out contacts directly in Settings. We may need to verify your identity, or an agent's authority to act for you. We respond within 30 days, or sooner where local law requires. If we decline a request, reply to our decision to appeal, and we will respond within 60 days.
14. Regional information
In India, you may withdraw consent as easily as you gave it. If you have a grievance, contact our Grievance Officer (section 15). We aim to resolve grievances within 30 days, and you may then escalate to the Data Protection Board of India.
In the European Economic Area, the United Kingdom and Switzerland, you may complain to your local data protection authority, such as the Information Commissioner's Office in the UK or the Federal Data Protection and Information Commissioner in Switzerland. Vaanexa does not itself make solely automated decisions with legal or similarly significant effects on you. Customers who configure such processing using our tools are responsible for it.
In California, the CCPA as amended by the CPRA applies. Over the past twelve months we have collected these categories of personal information: identifiers; customer and billing records; commercial information; internet activity; approximate geolocation; professional information.
We collected them from you, your devices, connected platforms and our Customers, and used and disclosed them as described in sections 4 and 7. The only sensitive information we collect is login credentials, used solely to provide the Services. We have not sold or shared personal information, including that of consumers under 16. You have the right to know, delete and correct your information, to opt out of sale or sharing, to limit the use of sensitive information and to be free from discrimination, and you may act through an authorised agent. Residents of Virginia, Colorado, Connecticut, Texas, Oregon and other states with privacy laws have similar rights, and if an appeal is denied may contact their state Attorney General.
In Canada, we handle personal information with your consent or as permitted by PIPEDA, and you may complain to the Office of the Privacy Commissioner of Canada.
15. Grievance Officer and contact
Under the Information Technology Act, 2000 and the DPDP Act, our Grievance Officer is [GRIEVANCE OFFICER NAME], Dhanamitra Infotech LLP, [REGISTERED ADDRESS LINE], Greater Noida West, Uttar Pradesh, India. You can reach them at grievance@vaanexa.com, or by phone on [PHONE] Monday to Friday, 10:00 to 18:00 IST. For general privacy questions, write to privacy@vaanexa.com. Report security issues to security@vaanexa.com.
16. Changes to this policy
We may update this policy as our Services and the law evolve, and the date at the top shows the latest version. For material changes, we will notify you in the app or by email at least 15 days in advance, unless legal or security reasons require faster action. Where the law requires consent to a change, we will ask for it. This policy should be read with our Terms of Service and Data Processing Addendum.