Privacy Policy
Version 2026-08-10Effective 10 August 2026Updated 10 August 2026
- Product
- Calanai Connect
- Operated by
- CALANAI HQ LLP
- Registered address
- No.11/41, Narasinghapuram Street, Anna Road, Chennai - 600002, Tamil Nadu, India
Privacy Policy
1. Introduction
This Privacy Policy describes how CALANAI HQ LLP collects, uses, discloses, and protects personal data in connection with Calanai Connect (the "Service") — a business messaging and customer engagement platform that enables businesses to communicate with their customers over WhatsApp and other messaging channels we may support from time to time.
This policy applies to our websites, our customer-facing dashboard and applications, our APIs, and the messaging and automation services we operate on behalf of our business customers.
By using the Service, you acknowledge that you have read and understood this policy.
2. Our two roles
Our responsibilities differ depending on whose data is involved. Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") we act as a Data Fiduciary in one case and a Data Processor in the other; under the GDPR the equivalent terms are Controller and Processor.
We act as a Controller / Data Fiduciary for personal data relating to our business customers and their personnel — the individuals who register for, administer, and use the Service. We determine how that data is handled and are directly responsible for it.
We act as a Processor for personal data relating to the end customers of our business customers — the individuals who communicate with a business through the Service. In this case the business is the Controller / Data Fiduciary. We process that data on the business's instructions, as configured through the Service, for the purpose of delivering the services that business has engaged us to provide.
If you are an individual who messaged a business through our platform: that business determines how your data is handled. Please direct requests to that business in the first instance. You may also contact us at privacy@calanaihq.com and we will route your request to the relevant business and assist them in responding. See Section 10.
3. Definitions
| Term | Meaning |
|---|---|
| Business Customer | A business that holds an account with us and uses the Service to communicate with its own customers. |
| Authorised User | An individual permitted by a Business Customer to access the Service under that customer's account. |
| End Customer | An individual who communicates with a Business Customer through the Service. |
| Customer Data | Data submitted to, or generated within, the Service under a Business Customer's account. |
| Meta | Meta Platforms, Inc. and its affiliates, which operate WhatsApp and the WhatsApp Business Platform. |
4. Personal data we process
The categories below describe the types of personal data we may process. Not all categories apply to every user, and the specific data processed depends on the features a Business Customer has enabled and how they configure the Service.
4.1 Data relating to Business Customers and Authorised Users
- Identity and contact data — such as name, business email address, telephone number, job title, and role.
- Account and authentication data — such as account identifiers, authentication credentials and tokens, session information, security settings, and access permissions.
- Business information — such as business name, type, description, address, operating hours, time zone, and messaging account identifiers.
- Integration credentials — credentials and configuration for third-party systems that a Business Customer chooses to connect. These are held in encrypted form.
- Configuration data — settings, content, automation rules, message templates, and other configuration created within the Service.
- Usage and activity data — such as records of actions taken in the Service, feature usage, message volumes, and interaction logs.
- Technical data — such as IP address, device and browser information, and diagnostic and performance information.
- Commercial data — such as billing contacts, tax identifiers, subscription details, invoices, and payment records.
4.2 Data relating to End Customers
We process this category on behalf of, and under the instructions of, the relevant Business Customer.
- Contact and identity data — such as telephone number, messaging profile name, name, and any other contact or profile details volunteered by the individual, entered by the Business Customer, or obtained from systems the Business Customer connects.
- Communications data — the content and metadata of messages exchanged between the individual and the Business Customer through the Service, including text, structured and interactive message content, attachments and media, message identifiers, delivery and read status, timestamps, and related conversation records.
- Conversation and service records — such as conversation state and history, assignment and handling records, internal notes recorded by the Business Customer's personnel, and records of automated processing.
- Enquiry and commercial data — such as enquiries, requirements, preferences, interests, budget or value indications, and related records; and, where the Business Customer enables the relevant features, transactional information such as order, delivery, invoice, payment, return, product, and service history.
- Preference data — such as language preference, communication preferences, and consent and opt-out status.
- Any other data a Business Customer chooses to process through the Service, or that an individual chooses to provide in the course of a conversation.
4.3 Sensitive personal data
The Service is not designed or intended for the processing of sensitive or special categories of personal data, and Business Customers are contractually restricted from using it for that purpose without our prior written agreement.
We cannot technically prevent an individual from volunteering such information in the course of a free-text conversation. Where this occurs, the information is handled as ordinary communications content under this policy. Business Customers remain responsible for handling any such disclosure in accordance with applicable law.
4.4 Children
The Service is a business-to-business product and is not directed at children. Authorised Users must be adults. Business Customers must not use the Service to direct communications at children, or to process children's data, without the verifiable parental consent required by applicable law. We do not knowingly collect personal data from children, and will delete such data promptly if we become aware of it.
5. How we collect personal data
We collect personal data:
- Directly — when a Business Customer registers, configures the Service, or communicates with us.
- Automatically — through use of the Service, including logs, diagnostics, and analytics.
- From messaging platforms — including Meta, which transmits inbound messages and related information to us so that we can deliver them to the relevant Business Customer.
- From systems a Business Customer connects — such as customer relationship, resource planning, commerce, or other business systems.
- From service providers — such as identity, payment, and infrastructure providers acting on our behalf.
- From an End Customer — through the content of their communications with a Business Customer.
6. How we use personal data
We use personal data for the following purposes:
- Providing the Service — operating, delivering, maintaining, and supporting the platform and its features, including message delivery and receipt, automated responses, routing, conversation management, integrations, reporting, and any additional features a Business Customer enables.
- Automation and intelligent features — as described in Section 7.
- Account administration — registration, authentication, provisioning, configuration, and account management.
- Analytics and reporting — generating insights, statistics, dashboards, and reports for Business Customers about their own accounts and communications.
- Billing and finance — invoicing, payment processing, cost attribution, collections, and statutory accounting.
- Support and communication — responding to enquiries, providing technical support, and sending service, security, and administrative notices.
- Security and integrity — authentication, access control, monitoring, fraud and abuse prevention, incident detection and response, and enforcement of our terms and policies.
- Service improvement — maintaining, developing, testing, and improving the Service and developing new features and products.
- Legal and compliance — complying with legal obligations, responding to lawful requests, establishing, exercising, or defending legal claims, and meeting our obligations to platform providers including Meta.
- Marketing — promoting our products and services to businesses and business prospects, subject to applicable law and to any consent required.
We may also use personal data for other purposes disclosed to you at the time of collection or as otherwise permitted by law.
6.1 Legal bases
Where the GDPR or similar law applies, we rely on: performance of a contract; compliance with legal obligations; our legitimate interests in operating, securing, and improving the Service and in communicating with business contacts; and consent, where required. Where we act as a Processor, we process on the documented instructions of the relevant Controller.
Where the DPDP Act applies, we rely on consent or on legitimate uses permitted under that Act, as applicable, and where we act as a Data Processor we process on behalf of the relevant Data Fiduciary.
6.2 Consent for communications with End Customers
Applicable law and the policies of messaging platforms require that a business obtain consent before sending certain communications to an individual.
Obtaining, recording, and honouring that consent is the responsibility of the Business Customer, not ours. We provide functionality that allows Business Customers to manage consent and opt-out preferences within the Service. We do not verify the validity of any consent obtained by a Business Customer, and we do not obtain consent on their behalf. Business Customers warrant to us that they hold the necessary consent for all communications they send.
7. Automation, artificial intelligence, and machine learning
The Service uses automated processing, including artificial intelligence and machine learning technologies provided by us and by third parties, to deliver and improve its features. Such processing may be used for purposes including:
- interpreting and categorising the content and intent of communications;
- extracting, validating, structuring, and enriching information contained in communications;
- generating, drafting, suggesting, or personalising responses and content;
- summarising conversations, enquiries, and records;
- searching, matching, ranking, and recommending products, content, or responses;
- routing, prioritising, and assigning conversations;
- analytics, forecasting, scoring, quality assurance, and reporting; and
- detecting spam, fraud, abuse, and security threats.
To provide these features, communications content and related data may be transmitted to and processed by third-party artificial intelligence providers acting as our service providers. We select such providers on the basis of their security and confidentiality commitments and bind them by contract.
Model training. We do not use Customer Data to train or improve generally available machine learning models operated by third parties, and we contract with our providers on terms intended to prevent them from doing so. Where we develop or improve models or features using Customer Data, we do so in accordance with our contractual commitments to the relevant Business Customer, using aggregated or de-identified data wherever practicable.
Limitations. Automated systems may produce results that are inaccurate, incomplete, or unexpected. Business Customers are responsible for reviewing and supervising the automated behaviour they configure, and for the communications sent from their accounts. Output generated by the Service is not professional, legal, medical, or financial advice.
Human involvement. The Service is designed so that a Business Customer's personnel can review, take over, or intervene in any conversation. Automated processing carried out through the Service is not intended to produce legal effects concerning an individual or to similarly significantly affect them. If you believe you have been adversely affected by automated processing, contact us at privacy@calanaihq.com and we will refer the matter to the relevant Business Customer for human review.
8. Disclosure of personal data
We do not sell personal data. We do not share personal data with third parties for their own independent advertising or marketing purposes. We do not use one Business Customer's Customer Data for the benefit of another Business Customer.
We disclose personal data in the following circumstances:
- Service providers and sub-processors. We engage third parties to perform functions on our behalf — including cloud hosting and infrastructure, data storage, content delivery and network security, identity and authentication, artificial intelligence and machine learning, communications delivery, payment processing, analytics, error monitoring, and customer support tooling. These providers may process personal data only on our instructions and are bound by confidentiality and data protection obligations. A current list of sub-processors that process data on behalf of Business Customers is maintained at https://connect.calanaihq.com/sub-processors.
- Messaging platform providers. Delivering the Service necessarily involves transmitting communications and related data through the messaging platforms on which the Service operates, including Meta's WhatsApp Business Platform. Those providers process such data in accordance with their own terms and privacy policies, over which we have no control.
- Systems connected by a Business Customer. Where a Business Customer connects a third-party system, data flows between the Service and that system at the Business Customer's direction. Those systems are controlled by the Business Customer and are outside our responsibility.
- Within a Business Customer's account. Customer Data is accessible to the Authorised Users of the relevant Business Customer, in accordance with the permissions that customer configures.
- Professional advisers. Lawyers, auditors, accountants, insurers, and similar advisers, under duties of confidentiality.
- Corporate transactions. In connection with a merger, acquisition, financing, reorganisation, or sale of assets, personal data may be disclosed to, or transferred to, the relevant counterparty or successor, subject to obligations no less protective than those in this policy.
- Legal and safety. Where we believe disclosure is required or permitted by law, or is necessary to respond to lawful requests, to enforce our terms, to protect our rights, property, or safety or those of others, or to detect, prevent, or address fraud, security, or technical issues. Where we act as a Processor and are legally permitted to do so, we will notify the relevant Business Customer before responding to a request relating to their data.
- With consent or at your direction.
Aggregated and de-identified information. We may create and use aggregated, statistical, or de-identified information that does not identify any individual, Business Customer, or End Customer, and may retain and disclose such information for any lawful purpose, including operating, analysing, improving, and marketing the Service. We will not attempt to re-identify such information.
9. International transfers
We and our service providers operate in multiple countries. Personal data may therefore be transferred to, stored in, and processed in countries other than the country in which it was collected, including countries whose data protection laws differ from those of your own.
Our primary data store is located in India. Some of our service providers process personal data outside India, as recorded in our sub-processor list. Transfers of personal data out of India are made in accordance with the DPDP Act and any restrictions notified by the Central Government.
The Service is offered to business customers established in India. We do not currently offer the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent European transfer mechanism. If your use of the Service would involve personal data subject to the GDPR, the UK GDPR, or Swiss data protection law, contact us before entering into an agreement so that an appropriate mechanism can be agreed in writing.
Details of the locations in which our sub-processors operate are available at https://connect.calanaihq.com/sub-processors. You may request further information about our transfer safeguards at privacy@calanaihq.com.
10. Retention and deletion
10.1 How long we keep personal data
We retain personal data for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law.
In practice this means:
- Customer Data processed on behalf of a Business Customer is retained for the duration of that customer's account, so that the customer has continuous access to their communications history, contact records, and analytics — and thereafter for a limited period following termination as described below. Business Customers may configure shorter retention periods for certain categories of data where the Service provides that functionality, and may delete data within their account at any time.
- Business Customer and Authorised User account data is retained for the duration of the account relationship and for a reasonable period afterwards.
- Security, audit, and log data is retained for as long as necessary for security, accountability, and investigative purposes.
- Billing, tax, and statutory records are retained for the periods required by applicable law, which in India is currently up to eight years.
- Backups are retained on a rolling cycle, and data deleted from live systems is removed from backups in the ordinary course of that cycle.
The criteria we apply in determining retention periods include: the duration of our relationship with the Business Customer; the purposes for which the data is processed; the ongoing usefulness of the data to the Business Customer, including for historical reporting and analytics; our legal, regulatory, tax, accounting, and contractual obligations; and whether retention is advisable in light of an actual or anticipated dispute, investigation, or legal claim.
Aggregated and de-identified information may be retained indefinitely, as described in Section 8.
10.2 Following termination of an account
Following termination of a Business Customer's account, we will make Customer Data available for export on request for a limited period, and will thereafter delete or de-identify it in accordance with our standard practices and our agreement with that customer, except where retention is required by law. The applicable periods are set out in our agreement with the Business Customer.
10.3 Requesting deletion
Individuals may request deletion of their personal data as described in Section 11. Where we act as a Processor, we will forward the request to the relevant Business Customer and support them in responding.
Our procedure for requesting deletion of data, including the process required for applications operating on Meta's platforms, is published at https://connect.calanaihq.com/data-deletion.
11. Your rights
Depending on your location and the applicable law, you may have rights in relation to your personal data, which may include the right to:
- obtain confirmation of whether we process your personal data, and access to that data and information about our processing;
- request correction, completion, or updating of inaccurate or incomplete data;
- request erasure of your personal data;
- request restriction of, or object to, certain processing;
- request a copy of your data in a portable format;
- withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing;
- nominate another individual to exercise your rights in the event of death or incapacity, where provided under the DPDP Act; and
- lodge a complaint with a supervisory authority, including the Data Protection Board of India or your local data protection authority.
11.1 Exercising your rights
Contact us at privacy@calanaihq.com. We will verify your identity before acting on a request, and may require additional information for that purpose. We respond within the period required by applicable law, and will inform you if we require an extension.
Where we process your personal data on behalf of a Business Customer, we are not able to act on your request without that customer's instruction. We will forward your request to them and assist them in responding. The obligation to respond rests with that customer.
We do not charge a fee for exercising your rights, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act, as permitted by law.
11.2 Grievance Officer
In accordance with the DPDP Act and the Information Technology Act, 2000, the following officer may be contacted in relation to any grievance concerning the processing of personal data:
Grievance Officer: Krish Chatterjie Designation: Designated Partner Email: privacy@calanaihq.com Address: No.11/41, Narasinghapuram Street, Anna Road, Chennai - 600002, Tamil Nadu, India
We will acknowledge and respond to grievances within the timeframes required by applicable law.
12. Security
We maintain administrative, technical, physical, and organisational safeguards designed to protect personal data against unauthorised or unlawful access, use, alteration, disclosure, loss, or destruction. These measures include, as appropriate to the risk: encryption of data in transit and of credentials and other sensitive data at rest; authentication and access controls applied on a least-privilege basis; logical separation of each Business Customer's data; verification of the authenticity of inbound platform communications; rate limiting and abuse protection; logging, monitoring, and audit trails; redaction of sensitive values from operational logs; confidentiality obligations on personnel; and secure development and change-management practices.
We restrict access to Customer Data by our personnel to circumstances where it is necessary — such as providing support at a customer's request, investigating a technical fault or security incident, or complying with law — and such access is subject to internal controls.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Business Customers are responsible for configuring the Service appropriately, managing their users' access, and safeguarding their credentials.
If you believe you have found a security vulnerability, please report it to security@calanaihq.com.
12.1 Incident notification
If we become aware of a personal data breach affecting personal data we process, we will notify affected Business Customers without undue delay and provide the information reasonably necessary for them to meet their own obligations. Where we act as a Controller, we will notify the relevant supervisory authority and affected individuals where and as required by applicable law.
13. Cookies and similar technologies
Our websites and dashboard use cookies and similar technologies for purposes including authentication and session management, security, remembering preferences, and understanding how our sites and product are used.
Strictly necessary technologies are required for the Service to function and cannot be disabled through our consent tools. Where required by law, we obtain consent before setting non-essential cookies and provide a means to manage your preferences. You may also control cookies through your browser settings; disabling certain cookies may affect the functionality of the Service.
Further detail is available in our Cookie Policy.
End Customers who interact with a Business Customer solely through a messaging channel are not subject to cookies or similar technologies from us.
14. Messaging platform disclosures
The Service operates on third-party messaging platforms, principally Meta's WhatsApp Business Platform. The following applies to communications sent through those platforms:
- Your use of WhatsApp is additionally governed by WhatsApp's Privacy Policy and WhatsApp's Business Messaging Policy.
- When you message a business that uses a cloud-hosted business messaging solution, the business — and the providers acting on its behalf, including us — receive, process, and may store the content of those messages.
- Meta independently determines its own processing and retention of data on its infrastructure. We do not control this.
- You may opt out of communications from a business at any time by informing that business, or by blocking or reporting the business within the messaging application.
- We access a Business Customer's messaging accounts only through permissions that customer has granted, and only for the purpose of providing the Service. We do not use data obtained through those permissions for advertising, for profiling unrelated to the Service, or for sale to third parties.
15. Third-party links and services
The Service and our websites may contain links to, or integrate with, third-party websites, applications, and services that we do not control. This policy does not apply to those third parties, and we are not responsible for their content, security, or privacy practices. We encourage you to review their privacy policies.
16. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology, legal requirements, or business. We will post the updated policy on this page and revise the "Last updated" date. Where a change is material, we will provide additional notice as required by applicable law or by our agreement with the relevant Business Customer. Your continued use of the Service after an update takes effect constitutes acceptance of the updated policy.
17. Contact
| Purpose | Contact |
|---|---|
| Privacy enquiries and rights requests | privacy@calanaihq.com |
| Grievances (India) | privacy@calanaihq.com |
| Security reports | security@calanaihq.com |
| General support | support@calanaihq.com |
| Postal | CALANAI HQ LLP, No.11/41, Narasinghapuram Street, Anna Road, Chennai - 600002, Tamil Nadu, India |