Rajamahendravaram, Andhra Pradesh, India
1. Scope and our data-protection roles
This policy applies when you visit our website, request information, create or use an account, purchase or receive services, join a customer workspace, contact support, participate in a meeting, or interact with an authorised Varada Nexus integration.
For public-site, sales, account, billing, security and direct customer-administration data, Varada Nexus ordinarily determines why and how the data is processed and acts as the Data Fiduciary or controller. For message content, contact lists, documents, leads and other records uploaded or controlled by a business customer, that customer ordinarily determines the purpose and means of processing and Varada Nexus acts as its Data Processor or service provider. The customer must provide its own notices and obtain all required permissions from the individuals whose data it directs us to process.
This policy does not replace the privacy policies of Meta, WhatsApp, Facebook, Instagram, Google, payment providers or other independent third parties.
2. Categories of personal data we collect
- Identity and business profile: name, business name, job title, role, country, company size, business type and account identifiers.
- Contact details: business email, telephone or WhatsApp number, postal address and communication preferences.
- Account and authentication data: username, one-way password hash, session identifiers, multi-factor or recovery information, login timestamps and account status. We do not store readable passwords.
- Organisation and onboarding data: legal and trading name, website, authorised representative details, intended use cases, business verification status, connected numbers and Meta Business assets.
- Customer content: messages, templates, media, documents, contact records, conversation assignments, notes, tags, approvals, campaigns, opt-in records, support tickets and other content submitted to a workspace.
- Connected-platform data: platform identifiers, business account and Page details, professional profile data, permissions, tokens, content, comments, messages, leads, insights, advertising records, catalogues and delivery events made available through authorised APIs.
- Commercial and transaction data: plan, order, invoice, tax details, credits, payment status, service usage and third-party platform charges. Payment-card details are handled by authorised payment providers unless expressly stated otherwise.
- Technical, device and network data: IP address, browser and device type, operating system, referring URL, timestamps, diagnostic events, security signals and approximate location derived from IP.
- Audit and compliance data: permissions, administrator actions, consent evidence, deletion requests, policy acknowledgements, incident records and legally required logs.
- Communications: emails, call or meeting details, support correspondence, survey responses and feedback.
Please do not submit passwords, payment-card credentials, government identification, health data or other sensitive records unless a specific service requires them and an authorised, secure collection method has been provided.
3. Sources of data
We receive data directly from you; from your organisation and its administrators; from people who communicate with a customer using WhatsApp or another connected channel; automatically from devices and service use; from payment, identity, hosting and security providers; from Meta and other platforms you authorise; from professional advisers and partners; and from lawful public sources. We do not obtain contact lists from data brokers for unsolicited WhatsApp messaging.
4. Why we process personal data
| Purpose | Typical data | Ground or justification |
|---|---|---|
| Provide and administer services | Account, profile, workspace, content and usage data | Performance of a contract, requested service, consent or permitted legitimate use |
| Authenticate and secure accounts | Credentials, sessions, IP, device, audit and threat signals | Contract, security obligations, prevention of fraud and unauthorised access |
| Onboard WhatsApp and connected assets | Business identity, Meta asset IDs, numbers, permissions and tokens | Your affirmative authorisation and performance of requested services |
| Billing, accounting and tax | Orders, invoices, tax identity and payment status | Contract and legal obligations |
| Support and service improvement | Correspondence, diagnostics, usage patterns and feedback | Contract, requested support and legitimate service improvement |
| Legal, compliance and claims | Account, audit, transaction and communication records | Compliance with law, establishment or defence of legal claims |
| Marketing our services | Business contact and preference data | Consent or permitted business communication, with an opt-out |
Where consent is required, it must be free, specific, informed, unconditional and unambiguous, expressed through clear affirmative action. Consent may be withdrawn as easily as it was given. Withdrawal does not affect processing already lawfully completed, and we may retain data where another law requires it.
5. WhatsApp, Meta and business messaging data
When a customer connects WhatsApp Business Platform or another Meta asset, we process only the permissions and data needed to supply the selected functions. This may include WhatsApp Business Account and phone-number identifiers, business profile data, message templates and status, inbound and outbound message content and media, delivery/read events, customer phone numbers, conversation metadata, opt-in or opt-out records, quality or restriction information and webhook events.
Customers are responsible for obtaining and preserving all notices, permissions and consents required to contact a person, honouring opt-outs, using approved templates where required, observing conversation rules, and complying with the WhatsApp Business Messaging Policy, Commerce Policy, applicable Meta terms and all laws. Data received from WhatsApp about a person must not be used for unrelated profiling or purposes beyond supporting authorised communication with that person.
Meta and WhatsApp independently process information under their own terms and privacy policies. Their systems, review decisions, pricing, retention and security are outside our control. Disconnecting Varada Nexus does not automatically erase records held independently by Meta or a customer.
6. Customer-controlled data and instructions
For customer-controlled data, we process documented instructions necessary to provide the service, protect it, meet legal obligations and assist with verified rights requests. We do not claim ownership of customer content. A customer administrator may access, export, correct or delete workspace data subject to role permissions and retention requirements. If you are an end customer or contact of one of our business customers, direct your request to that business first; we will assist it where required.
7. Cookies, local storage and diagnostics
We use strictly necessary cookies, browser storage and session technologies for authentication, security, fraud prevention, preferences and service operation. We may use limited analytics or performance technologies to understand reliability and improve pages. Where applicable law requires consent for non-essential technologies, we will request it before activation. Browser controls can restrict cookies, but necessary features may then fail.
8. When we disclose personal data
We may disclose the minimum necessary data to:
- the customer organisation, its authorised administrators and workspace users;
- hosting, database, storage, email, communications, identity, monitoring, security, analytics, payment and customer-support providers acting under contract;
- Meta, WhatsApp, Facebook, Instagram, Google and other platforms a customer deliberately connects;
- professional advisers, auditors, insurers and financiers bound by confidentiality;
- a successor in a merger, financing, reorganisation or sale, subject to appropriate confidentiality and notice; and
- courts, regulators or public authorities where disclosure is legally required and passes our review process.
We do not sell or rent personal data. We require processors to use data only for authorised purposes, apply security safeguards, assist with rights and deletion, and notify us of relevant incidents.
9. International and cross-border processing
Connected platforms and infrastructure providers may process data outside your state or country. We assess provider protections and use contractual, technical and organisational safeguards appropriate to the data and applicable law. Transfers remain subject to restrictions or notifications issued by the Government of India and any additional rules applicable to a customer’s sector.
10. Retention and deletion
| Record | Typical retention approach |
|---|---|
| Prospect enquiries | Until the enquiry is resolved, then normally up to 24 months unless you opt out or a longer period is required for a dispute. |
| Account and workspace data | For the active account and a limited closure period needed for export, recovery, security, billing and claims. |
| Customer messages and content | According to the customer’s configuration and instructions, contract, deletion request and mandatory legal holds. |
| Authentication and security logs | For a proportionate security and investigation period, generally up to 24 months unless risk or law requires longer. |
| Invoices, tax and accounting records | For the period required under applicable tax, company and accounting laws. |
| Consent and opt-out evidence | As long as needed to demonstrate compliance and prevent renewed unwanted communication. |
| Backups | Until overwritten through controlled backup rotation; restored data remains subject to the original deletion restriction. |
We erase or irreversibly anonymise data when its purpose ends and no legal, security, accounting, dispute or contractual reason requires retention. Verified deletion requests are handled through our User Data Deletion process.
11. Security safeguards
Our safeguards are designed according to risk and may include tenant isolation, least-privilege access, role-based permissions, one-way password hashing, encryption in transit, protected secrets and access tokens, secure session controls, logging, backups, change review, vulnerability management, monitoring, incident response, vendor due diligence and staff confidentiality. Customers must configure roles carefully, protect credentials, maintain secure devices and report suspicious activity promptly. No internet service can guarantee absolute security.
12. Personal-data breaches and incidents
We investigate suspected incidents, contain affected systems, preserve evidence, assess the nature and impact of the event, remediate weaknesses and notify customers, affected individuals and the Data Protection Board of India or other authorities when required. Notification timing and content follow applicable law and may be coordinated with law enforcement where necessary.
13. Your privacy rights
Subject to applicable law and verified identity, you may request:
- a summary of personal data being processed and relevant processing activities;
- information about other Data Fiduciaries or processors with whom the data has been shared, where applicable;
- correction of inaccurate or misleading data, completion of incomplete data and updating of outdated data;
- erasure when the purpose is complete and retention is not required by law;
- withdrawal of consent, without affecting earlier lawful processing;
- grievance redressal and, after using our process, escalation to the Data Protection Board where available; and
- nomination of another individual to exercise rights in the event of death or incapacity, where applicable.
We may ask for proportionate verification and clarification. We will not request your password. Rights may be limited where disclosure would expose another person’s data, compromise security, violate privilege, interfere with an investigation or conflict with legal retention duties.
14. Marketing preferences and WhatsApp opt-outs
You may unsubscribe using the method in a message or contact us. For WhatsApp, you may reply with an appropriate opt-out request or block the business. Transactional or security communications necessary for an active service may continue. Customers using our platform must maintain auditable opt-in evidence and suppress opted-out recipients promptly.
15. Children
Our services are designed for organisations and authorised adult business users, not children. We do not knowingly create accounts for individuals under 18. Customers must not use our services to track, behaviourally monitor or target advertising to children, and must obtain verifiable parental consent before any processing for which applicable law requires it.
16. AI-assisted functions and automated processing
Some services may offer drafting, summarisation, classification, routing or analytics assisted by artificial intelligence. Such output may be inaccurate and must be reviewed by an authorised human before publication, messaging or material business action. We do not make solely automated decisions producing legal or similarly significant effects about individuals unless clearly disclosed and lawfully authorised. Customer data is not used to train a general-purpose third-party model unless this is separately disclosed and authorised.
17. Government and legal requests
We validate requester identity, jurisdiction, legal authority, scope and necessity; challenge defective or disproportionate requests where legally available; minimise responsive data; and document disclosures. See our Government Data Request Policy.
18. Changes to this policy
We may update this policy for product, operational or legal changes. We will update the date above and provide additional notice for material changes where appropriate. If a change requires new consent, we will request it before relying on that consent.
19. Contact and grievance redressal
Send privacy requests or grievances to varadanexus@gmail.com with the subject Privacy Request. Identify the service, organisation and account involved, but do not send passwords, access tokens or unnecessary identity documents. Varada Nexus Private Limited is located in Rajamahendravaram, Andhra Pradesh, India. We will acknowledge, verify, investigate and respond within the period required by applicable law.
