🎉 Every plan includes a 14-day free trial - no credit card required. See plans →

Privacy Policy

1. Two different roles we play

It is important to distinguish between two situations, because our responsibilities differ:

  • When you deal with us directly - for example, you browse our website, fill in a contact or demo form, or your organisation subscribes to the Service - we act as the Data Fiduciary (controller) of that personal data, and this Privacy Policy governs it.
  • When our customers use the Service to manage their own contacts - the leads, customers, and messages our business customers store in the CRM - we act only as a Data Processor, processing that data on the customer's documented instructions. That processing is governed by our Data Processing Agreement, and the customer (as Data Fiduciary) is responsible for its lawful collection and use.

2. Personal data we collect

a. Website visitors and enquiries

  • Contact details you submit through forms or email - name, work email, phone number, company name, and the content of your message.
  • Basic technical and usage data - IP address, browser and device type, and pages viewed - collected through essential and analytics cookies. See our Cookie Policy.

b. Account and user data (our customers' staff)

  • Name, work email, phone number (used for WhatsApp reminders), a securely hashed password, assigned role, and the organisation you belong to.
  • Product usage, activity logs, and support correspondence.

c. Customer content processed within the CRM

To provide the Service, we store and process the data our customers enter or capture, including lead and contact names, phone numbers, email addresses, company names, deal values, notes, WhatsApp message content, uploaded photos and documents, and interaction history. We process this only as a processor on the customer's behalf (see Section 1 and the DPA).

3. How we use personal data

  • To provide, operate, secure, and improve the Service, including sending follow-up reminders and notifications over WhatsApp.
  • To set up and administer accounts, authenticate users, and provide customer support.
  • To process subscriptions, billing, and taxes.
  • To communicate with you about your account, service updates, and (where permitted) relevant product information. You can opt out of marketing messages at any time.
  • To detect, prevent, and address security incidents, fraud, or misuse, and to comply with legal obligations.

We process personal data on the basis of your consent, the performance of our contract with you, our legitimate business interests, and compliance with law, as recognised under the DPDP Act.

4. WhatsApp messaging

The Service operates on your organisation's WhatsApp Business number through the official WhatsApp Business Platform. Messages sent and received are processed to deliver CRM functionality. Your use of WhatsApp is also subject to WhatsApp's own terms and policies, over which we have no control.

5. How we share personal data

We do not sell personal data. We share it only as follows:

  • Service providers (sub-processors). We use a small number of vetted third-party providers for cloud hosting, messaging delivery, and secure file storage, strictly to run the Service. They are bound by confidentiality and data-protection obligations and may only process data on our instructions. A current list of sub-processor categories is available on request at jaimin@dataproconsult.com.
  • Legal and safety. Where required by law, court order, or to protect our rights, users, or the public.
  • Business transfers. In connection with a merger, acquisition, or sale of assets, subject to this Policy.

6. Data retention

We retain account and customer data for as long as your subscription is active. After termination, we delete or return the data within 60 days, unless a longer retention period is required by law. Website enquiry data is retained only as long as needed to respond and for our legitimate record-keeping.

7. How we protect data

  • Encryption of data in transit, and access restricted on a need-to-know basis.
  • Role-based access controls (agents see only their own leads; managers and admins have scoped visibility).
  • Logical isolation of each customer organisation's data (multi-tenant separation).
  • Regular backups and reasonable security safeguards appropriate to the risk.

No method of transmission or storage is completely secure, but we take reasonable steps to protect personal data and to notify affected parties and authorities of a personal-data breach as required by the DPDP Act.

8. Your rights

Subject to the DPDP Act, you have the right to access a summary of your personal data, to seek correction or completion, to seek erasure, to nominate another person to exercise your rights in the event of death or incapacity, and to grievance redressal. If the personal data is held by us as a processor on a customer's behalf, we will refer your request to that customer (the Data Fiduciary) or assist them in responding.

To exercise any right or raise a grievance, contact us at jaimin@dataproconsult.com. We will respond within the timelines required by law.

9. Children

The Service is intended for business use by persons aged 18 or over. We do not knowingly collect personal data of children. If you believe a child's data has been provided to us, contact us and we will delete it.

10. Where data is processed

We currently process and store personal data in India. If, in future, we process data in or transfer it to other jurisdictions, we will do so in accordance with applicable law and update this Policy.

11. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here with a revised "Last updated" date and, where changes are material, take reasonable steps to notify you.

12. Contact us

DataSmart Global Consultants LLP
Registered office: Hari Om, Navjyot Park-1, B/H Jade Blue, 150-ft Ring Road, Rajkot, Gujarat 360005, India
Email: jaimin@dataproconsult.com