Privacy Policy
Last updated: 3 August 2026
Chatzyn is a customer-messaging platform operated by PROXCELERATE LLP, a limited liability partnership registered in India ("we", "us", "our"). It lets businesses manage their WhatsApp and Instagram conversations through the official Meta APIs. This policy explains what data we handle, in which role, and what rights you have. It is written to comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and takes account of the EU/UK GDPR where it applies to you.
1. Our two roles
We handle personal data in two distinct capacities:
- As a data fiduciary (controller) for the account data of the people who sign up for and use Chatzyn — workspace owners, agents, and agency staff.
- As a data processor for the end-customer data (messages, contacts) that our business customers process through Chatzyn. That data belongs to the business you are messaging; the business is the data fiduciary/controller and decides why and how it is used. If you are an end customer of a business that uses Chatzyn, please direct requests about your data to that business first — we act on their instructions.
2. Account data we collect (as fiduciary)
- Email address and optional name. Sign-in is by one-time email code (OTP); we never store a password.
- One session cookie.
chatzyn_sessionis the only cookie we set. It is an essential, httpOnly authentication cookie valid for up to 30 days. We use no analytics, advertising, or tracking cookies. - Operational records. Workspace membership, roles, audit logs of significant actions, and basic technical logs (IP address, user agent) kept for security.
- Billing records. Payments are handled by Razorpay; we store invoices and subscription state, not your card or bank details.
3. Business-customer data we process (as processor)
When a business connects its WhatsApp Business account or Instagram professional account to Chatzyn, we process on that business's behalf, exclusively via official Meta Platforms APIs (WhatsApp Business Platform / Cloud API and the Instagram Platform):
- messages and message metadata (delivery status, timestamps) sent to and from the business;
- contact identifiers such as phone numbers, WhatsApp IDs, Instagram handles, and profile names;
- media attachments exchanged in those conversations;
- consent and opt-in/opt-out records the business maintains for its marketing.
We use this data solely to provide the service to that business. We do not use it for advertising, do not build cross-customer profiles from it, and do not train AI models on it.
4. No sale of data
We do not sell personal data. We do not share it with anyone for their own marketing.
5. Subprocessors and service providers
We use a small set of infrastructure providers, each bound by contract to protect your data:
- Meta Platforms, Inc. — WhatsApp Business Platform and Instagram messaging APIs (message transport).
- Neon, Inc. / Amazon Web Services — managed PostgreSQL database hosting (Singapore region).
- Upstash, Inc. — managed Redis for message queues.
- Cloudflare, Inc. — media storage and content delivery.
- Razorpay Software Pvt. Ltd. — payment processing (India).
6. Retention
- Account data is kept while your account is active and deleted within 30 days of account deletion, except records we must keep under law (e.g. tax and invoicing records).
- Conversation data is kept while the owning workspace is active and is deleted when the workspace is deleted or when the controlling business instructs us to delete it.
- Residual copies in encrypted backups are purged on the backup rotation cycle (up to 90 days).
7. Security
All traffic is encrypted in transit (TLS). Access tokens and credentials are encrypted at rest (AES-256-GCM). Tenant data is isolated with database row-level security so one workspace can never read another's data. Access by our staff is limited and logged.
8. Your rights and how to delete your data
Under the DPDP Act 2023 you have the right to access, correct, and erase your personal data, the right to grievance redressal, and the right to nominate. If the GDPR applies to you, you additionally have rights to data portability, restriction, and objection, and you may lodge a complaint with your supervisory authority. We do not discriminate against you for exercising any right.
You can request deletion three ways:
- In the app: ask the workspace owner to remove you, or delete your workspace/account.
- By email: write to support@chatzyn.com from your registered address.
- Via Meta: Meta-initiated deletion requests are received automatically — see our data deletion page for how that works and how to track a request.
We answer verified requests within 30 days.
9. International transfers
Data is primarily stored in the AWS Asia-Pacific (Singapore) region. Our subprocessors may process limited data in other regions under appropriate safeguards (for GDPR-covered data, standard contractual clauses or equivalent mechanisms).
10. Children
Chatzyn is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18 as account holders.
11. Changes and contact
We will post any material changes to this policy on this page with an updated date. Questions, requests, and grievances go to our support and grievance contact: support@chatzyn.com (the canonical support address for Chatzyn), or by post to PROXCELERATE LLP, India.