1. Who we are
ShunyaX Private Limited (“ShunyaX”, “we”, “us”) operates the ShunyaX Console platform at console.shunyax.com. Registered office: C-102, Shree Shubham CHS Ltd., Mahavir Nagar, Kandivali West, Mumbai 400067, India. This policy explains what data the Console handles, why, and your choices. It is written to meet India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and Meta’s Platform requirements.
2. Who this policy covers
Two kinds of people interact with the Console:
- Clients — businesses that hold a Console account. For your account data we are the Data Fiduciary (controller).
- End Users — your customers and website visitors who interact with the tools you run (WhatsApp bot, web chat, campaign pages). For that data we act only as a Data Processor on your instructions; you are the controller. End Users should also read the privacy policy of the business whose service they are using.
3. What we collect and store — by product
We list this per product so you know exactly what each feature touches.
Account, billing & platform
Your name, business name, email, phone, and login password (stored only as a one-way scrypt hash, never in plain text). An API token (HMAC-based), your plan, status, service permissions, and a usage/credit ledger. Payment records (amount, method, reference). We do not store card or bank-account numbers — card payments are handled by our payment processor (see §5).
WhatsApp AI Automation
When you connect a WhatsApp number we store, per account: your WhatsApp Business Account ID (WABA ID), Phone Number ID, phone number, and the Meta access token used to send and receive messages; your contacts’ WhatsApp names, phone numbers, an enquiry number, conversation state, any details the bot collects, tags, and opt-out status; inbound questions and the bot’s answers. Media an End User sends is downloaded from Meta and forwarded to you by email; it is processed transiently for that forwarding, not kept as a media library. End Users can send STOP/UNSUBSCRIBE at any time to stop automated messages.
Website Chat Widget
Chat sessions and messages (visitor and assistant turns) and the page URL where the chat happened; leads (a name, email and/or phone the visitor provides or that is auto-detected in conversation). A visitor’s IP address is used only transiently for abuse rate-limiting, not stored as a profile. Widgets are domain-locked and run only on domains you approve.
Knowledge Base
Documents you upload (PDF/TXT/MD/DOCX) or a public URL you point us to. Files are stored in object storage (§5) and their text is processed and indexed so the assistant can answer from them. You can delete any document at any time; deletion removes the document and its indexed content.
Live API Actions (optional)
If you configure live API lookups, the assistant fetches current data from your own HTTP API during a conversation (read-only, behind a security guard). This data is read live and not stored on the Console.
Meta Ads & Compliance Audit
Meta ad-account OAuth tokens you authorise, used to manage your campaigns. Ad copy/creative you submit for AI compliance auditing is processed by our AI provider (§5) to return an approval-likelihood score and suggested fixes; results are stored against your account.
Reel Forge (AI reels / video)
Text prompts, generated images, generated voiceover audio, and finished videos (stored in object storage and served via a public media URL). Instagram and YouTube OAuth tokens you authorise, used only to publish your own reels to your own accounts.
Blog & Social Content
Draft post content you generate or edit. Social connection credentials for X (Twitter) and LinkedIn — your own developer keys or an OAuth token — used only to publish your posts to your own accounts. These posting tokens are encrypted at rest with AES-256-GCM.
WordPress Campaign Plugin
The plugin verifies your ShunyaX API token against the Console to unlock Pro features; we log those verification lookups. Form submissions captured on your WordPress site go to destinations you configure (e.g. your own Google Sheet, or a payment via your payment provider); ShunyaX does not centrally store those form leads unless you route them into a ShunyaX product.
4. How we use data
To provide and operate the features above (answering messages, generating content and media, publishing to accounts you authorise, capturing leads for you, and notifying you of new enquiries by email); to meter usage and bill you; and to secure the platform and prevent abuse. We do not sell personal data, and we do not use End-User conversation content for advertising. AI outputs are generated by the third-party models in §5 from the inputs described above; we treat model outputs as untrusted and never pass them to shells, databases, or file paths.
5. Who we share it with (sub-processors)
We use the following processors, each receiving only the data needed for its function:
| Sub-processor | Purpose |
|---|---|
| Anthropic (Claude) | AI answers, compliance audits, summaries |
| OpenAI | Blog draft generation |
| Google (Imagen) | Image generation; knowledge-base processing |
| ElevenLabs | Text-to-speech for reels |
| Meta Platforms | WhatsApp Cloud API, Instagram Graph API, Marketing API |
| Google (YouTube Data API) | Reel publishing to your channel |
| Resend | Transactional email (alerts, lead + media forwarding, login codes) |
| Cloudflare (R2) | Media & document storage (public URLs for published content) |
| Railway | PostgreSQL database hosting |
| Vercel | Application hosting |
| Razorpay | Payment processing (card data handled by Razorpay, not us) |
| Pexels | Stock video for reel backgrounds (search terms only) |
| WaveSpeed | AI video generation |
| Google Analytics, Microsoft Clarity | Anonymised usage statistics on public marketing pages |
Your WhatsApp messages, contacts, and reel content are processed by Meta’s servers under Meta’s data-processing terms. We update this list as our infrastructure changes.
6. WhatsApp Business API — Meta disclosure
We access WhatsApp Business Accounts through the Meta Cloud API under our Meta app, acting on each Client’s authorisation for that Client’s own WABA. We store the WABA ID, Phone Number ID, phone number, and access token solely to send and receive that Client’s business messages. WhatsApp message content and contact data are used only to operate the Client’s automation and are never used for advertising, resold, or shared beyond the sub-processors in §5. End Users can opt out of automated messages at any time (STOP/UNSUBSCRIBE). We comply with Meta’s Platform Terms and Developer Policies.
7. Cookies
The Console and portals use strictly-necessary authentication/session cookies (NextAuth). Public marketing pages use anonymised analytics (§5) and no advertising or cross-site tracking cookies.
8. Data retention
| Data | Retention |
|---|---|
| Contact / demo form submissions | Up to 12 months, then deleted |
| WhatsApp & web-chat conversations | While your subscription is active |
| Inactive accounts | Up to 6 months, then deleted |
| Knowledge-base documents | Until you delete them or your account closes |
| Payment records | 7 years (legal / tax compliance) |
| API & cost logs | 90 days, then deleted |
| Website analytics | Up to 14 months |
9. Data deletion
You can delete knowledge-base documents, contacts, chats, leads, and reels from the Console at any time. To delete your account or exercise an End User’s deletion request, see our Data Deletion page or email the grievance contact below. Disconnecting an integration deletes its stored access tokens.
10. Your rights (DPDP Act 2023)
Subject to law, you may request access to, correction of, or erasure of your personal data, nominate another person to exercise your rights, and withdraw consent. Clients act through account settings or the contact below; End Users should contact the relevant business (the controller), or us, and we will assist as processor.
11. Security
Passwords are stored as scrypt hashes with timing-safe verification; API tokens are HMAC-based; social-posting tokens (X, LinkedIn) are encrypted at rest with AES-256-GCM. Access credentials for connected platforms are held only to operate your integrations and are protected by access controls. Widget endpoints are domain-locked and rate-limited; live API Actions run behind an SSRF guard (host allowlist, blocks private/loopback/metadata addresses, read-only, timeouts). Data is encrypted in transit (HTTPS).
12. Data location
The Console runs on cloud infrastructure whose database (Railway) and object storage (Cloudflare R2), and the AI sub-processors in §5, may process and store data in regions outside India. By using the Console you authorise this processing.
13. Children
The Console is a business tool not directed at anyone under 18, and we do not knowingly collect data from children.
14. Changes
We may update this policy; the effective date above will change and material updates will be communicated to Clients.
15. Grievance Officer & contact
Sandip Chavda, Director, ShunyaX Private Limited
Email: business@shunyax.com · Phone: +91 85917 71948
We respond to every grievance within 7 working days.