BUZZFLOW PRIVACY POLICY

Platform & Data Processing Privacy Policy | Domain: Buzzflow.co.in

Effective Date: August 2026

PRIVACY STATEMENT & SCOPE

BUZZFLOW (operated under https://Buzzflow.co.in) is committed to protecting the privacy, confidentiality, and security of personal information collected through our SaaS platform, WhatsApp Business API services, and website. This Privacy Policy details how we collect, use, store, process, and safeguard data in compliance with the Digital Personal Data Protection Act (DPDPA), 2023 (India), the Information Technology Act, 2000, and global data privacy standards.

1. INTRODUCTION AND DEFINITIONS

1.1. This Privacy Policy governs the processing of data collected by Buzzflow ("we", "us", "our", or "Buzzflow") via the website https://Buzzflow.co.in, web applications, customer portals, APIs, and associated communication services.

1.2. In providing our SaaS suite and WhatsApp automation services, Buzzflow acts in two distinct capacities:

a) Data Fiduciary (Controller): We act as a Data Fiduciary / Controller with respect to account registration details, direct customer communications, billing records, and website interaction data.

b) Data Processor / Service Provider: We act as a Data Processor with respect to end-user contact lists, broadcast recipients, chat logs, media files, and customer messages uploaded or processed through our platform by our business clients.

2. CATEGORIES OF DATA WE COLLECT

2.1. Direct Customer / Account Information (Data Fiduciary Role):

Account Details: Name, business email address, official phone number, company name, designation, and billing address.

Billing & Financial Information: Transaction identifiers, GSTIN, invoice history, and payment gateway tokens (note: full credit/debit card numbers and net banking credentials are processed directly by certified third-party payment gateways and are never stored on Buzzflow servers).

Technical & Usage Data: IP addresses, browser type, operating system, login timestamps, device identifiers, and platform feature usage metrics.

2.2. Service & Message Data Processed for Business Clients (Data Processor Role):

End-User Contact Records: End-user phone numbers, names, tags, custom contact attributes, and opt-in status imported by business clients.

Conversation & Communication Data: Template message payloads, interactive chatbot flows, multimedia messages, incoming customer inquiries, and timestamp logs transmitted via the WhatsApp Business API.

Meta / WABA Credentials: Meta Business Manager ID, WABA ID, Phone Number ID, and API access tokens configured for service provisioning.

3. LEGAL GROUNDS AND PURPOSES OF PROCESSING

Buzzflow processes personal data solely for legitimate, defined, and lawful purposes, including:

Service Provisioning: Provisioning user accounts, authenticating logins, enabling shared team inboxes, and routing automated chatbot flows.

API & Message Routing: Interfacing with Meta Platforms, Inc. to deliver pre-approved template broadcasts, customer service chats, and OTP authentication messages.

Billing & Wallet Accounting: Managing subscription billing, monitoring prepaid messaging wallet credit consumption, issuing tax invoices, and preventing fraudulent transactions.

Security & Regulatory Compliance: Ensuring platform security, investigating abusive messaging behavior, monitoring spam feedback rates, and meeting statutory record-keeping mandates under Indian law.

Customer Communications: Sending critical platform maintenance notices, feature updates, and customer support responses.

4. WHATSAPP BUSINESS API AND META ECOSYSTEM INTEGRATION

4.1. Buzzflow enables connectivity between client accounts and the Meta WhatsApp Business Platform (Cloud API/On-Premises).

4.2. In order to route and deliver messages, relevant communication payloads (including recipient phone numbers and message content) are transmitted via Meta's infrastructure. Such data handling is governed by Meta's Data Policy and WhatsApp Business Terms.

4.3. Buzzflow does not sell, rent, lease, or monetize customer communication logs or contact lists to any third party.

5. DATA DISCLOSURE AND THIRD-PARTY SUB-PROCESSORS

We share personal data strictly on a need-to-know basis with trusted service providers and sub-processors who adhere to stringent security standards:

Communication Infrastructure: Meta Platforms, Inc. / WhatsApp LLC for message transport and WABA provisioning.

Cloud Infrastructure & Database Hosting: ISO/IEC 27001 and SOC-2 compliant cloud hosting providers (e.g., AWS / Google Cloud) maintaining localized server facilities.

Payment Processing: RBI-authorized payment gateways (e.g., Razorpay / Cashfree / Stripe) for secure processing of subscription dues and wallet top-ups.

System Notifications: Transactional email and SMS gateway providers for platform alerts, verification OTPs, and password reset workflows.

Legal & Regulatory Disclosures: Law enforcement or statutory authorities only when strictly required pursuant to a valid judicial order or binding regulatory directive under applicable law.

6. DATA SECURITY AND STORAGE MEASURES

Buzzflow employs multi-layered technical, administrative, and physical safeguards to prevent unauthorized access, disclosure, alteration, or destruction of personal data:

Encryption Standards: All data in transit is encrypted using Transport Layer Security (TLS 1.3), and sensitive data at rest is encrypted utilizing industry-standard AES-256 protocols.

Access Control: Strict role-based permissions, multi-factor authentication (MFA), and session timeout rules are enforced across all internal operational systems.

Vulnerability Management: Periodic security audits, automated vulnerability scanning, and routine penetration testing are performed to ensure continuous platform resilience.

7. DATA RETENTION AND ACCOUNT TERMINATION

7.1. Account Data: We retain active client profile data for the duration of the active subscription to provide uninterrupted service.

7.2. Conversation Logs: End-user chat records, broadcast logs, and media payloads are retained on the platform for standard operational cycles (default 60 to 90 days, or as configured by the client's data retention parameters), after which logs are systematically archived or purged.

7.3. Offboarding & Purging: Following account cancellation or termination, the client has a 30-day window to export data. Upon expiration of this grace period, Buzzflow deletes or irreversibly anonymizes all associated Customer Data, except where retention is mandated by applicable tax, accounting, or legal statutes.

8. DATA PRINCIPAL RIGHTS

Under the Digital Personal Data Protection Act, 2023 and applicable privacy regulations, users and data principals have specific rights regarding their personal data:

Right to Access: The right to obtain confirmation and a summary of personal data processed by Buzzflow.

Right to Correction: The right to request correction, updating, or completion of inaccurate or incomplete personal data.

Right to Erasure: The right to request deletion of personal information where processing is no longer necessary for the specified purpose, subject to statutory retention obligations.

Right to Grievance Redressal: The right to readily access grievance redressal mechanisms regarding data processing practices.

To exercise any of these rights, users may submit a formal request to our designated Grievance Officer.

9. COOKIES AND TRACKING TECHNOLOGIES

9.1. The website https://Buzzflow.co.in uses essential cookies required for session authentication, security verification, and load balancing.

9.2. We may utilize aggregated, anonymized analytical cookies to evaluate website performance, understand user navigation patterns, and enhance user experience. Users can manage or disable cookie preferences via their browser settings.

10. UPDATES TO THIS PRIVACY POLICY

Buzzflow reserves the right to revise, update, or amend this Privacy Policy periodically to reflect changes in legal regulations, platform features, or operational practices. Any material modifications will be posted on https://Buzzflow.co.in with an updated revision date, and active account holders will be notified through dashboard alerts or official email.

11. GRIEVANCE REDRESSAL AND CONTACT DETAILS

In compliance with the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and associated intermediary guidelines, the details of the designated Grievance Officer are set out below:

Designation: Grievance Officer, Buzzflow Technologies

Website: https://Buzzflow.co.in

Email: support@Buzzflow.co.in / privacy@Buzzflow.co.in

Address: Indore, Madhya Pradesh, India

We endeavor to acknowledge and address all data protection inquiries, concerns, or grievances within thirty (30) business days from the date of receipt.

Last Updated: August 2026 | Buzzflow (operated under https://Buzzflow.co.in) | Indore, Madhya Pradesh, India