Privacy Policy
This Privacy Policy ("Policy") describes how ALLWAYSLIVE PRIVATE LIMITED ("Allways", "we", "us", "our") collects, uses, discloses, retains, secures and otherwise processes personal data in connection with the Platform. It is issued in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), read with the Information Technology Act, 2000 and rules thereunder, and constitutes the notice required under Section 5 of the DPDP Act. By accessing or using the Platform, or by messaging a business that uses the Platform, you acknowledge that you have read and understood this Policy.
1. Definitions
"Business" / "Customer" means a business entity or its authorised personnel that registers for and uses the Platform.
"End-Customer" means an individual who communicates with a Business over WhatsApp through a number connected to the Platform.
"Data Principal", "Data Fiduciary", "Data Processor", "Personal Data", "Processing", and "Consent" have the meanings given in the DPDP Act.
"Platform Data" means data submitted to, generated by, or processed through the Platform, including Business account data, knowledge content, and End-Customer conversation data.
2. Our roles: when we are a Data Fiduciary vs a Data Processor
The Platform involves two distinct data relationships, and our obligations differ in each:
- Business account data — we are the Data Fiduciary (controller). In respect of the personal data of the Business and its personnel (name, work email, phone, business details, billing data, portal usage), we determine the purposes and means of processing and are responsible as the Data Fiduciary under the DPDP Act.
- End-Customer conversation data — we are a Data Processor. When a Business connects its WhatsApp number, we process the messages exchanged between that Business and its End-Customers strictly on the Business's behalf and on its documented instructions, solely to provide the automated customer-service, bookings and enquiry features. In this relationship the Business is the Data Fiduciary and Allways is a Data Processor; WhatsApp/Meta acts as a further processor for message transmission. The terms of this processing are set out in our Data Processing Addendum, which forms part of the Business's agreement with us.
3. Personal data we process, and the purpose and lawful basis for each
| Category of data | Purpose of processing | Lawful basis (DPDP Act) |
|---|---|---|
| Identity & contact (owner/team name, email, phone) | Account creation, authentication, support, service communications | Consent; performance of the service requested (Sec. 7 legitimate uses) |
| Business profile & knowledge content (hours, services, prices, policies, FAQs) | Enable the AI to answer the Business's own End-Customers accurately | Consent / instruction of the Business |
| End-Customer WhatsApp messages & generated replies | Provide automated customer service, bookings and enquiries on the Business's behalf | Processed on the Business's instruction as its Processor; End-Customer initiates contact |
| Booking & appointment details | Create, confirm, reschedule and manage bookings for the Business | Instruction of the Business; performance of the interaction the End-Customer requested |
| Usage, analytics & diagnostics (message counts, resolution metrics, logs) | Operate, secure, debug and improve the Service; show the Business its performance; billing | Consent; legitimate operational use |
| Billing & transaction data (plan, invoices, GST details, payment status) | Process subscriptions, invoices, taxes and payments | Consent; legal obligation (tax/accounting) |
| Device & connection data (IP, browser, cookies/session) | Security, session management, fraud prevention | Legitimate use; consent for non-essential cookies |
We process personal data only for the purposes stated above or purposes compatible with them. We do not sell personal data, and we do not use End-Customer conversation content to serve advertising or to train third-party general-purpose AI models.
4. Consent, notice and withdrawal
Where processing is based on consent, that consent is sought through a clear, itemised notice presented at or before the point of collection, and is free, specific, informed, unconditional and unambiguous, given by an affirmative action, and limited to the personal data necessary for the stated purpose, as required by Section 6 of the DPDP Act. You may withdraw consent at any time, with the ease with which it was given, by contacting our Grievance Officer (Section 12) or using in-Platform controls; withdrawal does not affect processing carried out before withdrawal, and may limit or end your ability to use the Service. For End-Customers, the lawful basis for us answering a message is that the End-Customer initiates contact with the Business, together with the Business's instruction as controller.
5. How End-Customer data is handled (processor commitments)
In our capacity as Data Processor for End-Customer data, we: (a) process such data only on the documented instructions of the Business; (b) do not use it for our own purposes; (c) ensure personnel authorised to process it are bound by confidentiality; (d) engage sub-processors only under written terms no less protective than these; (e) assist the Business, taking into account the nature of processing, in responding to Data Principal requests and in meeting its security and breach-notification obligations; and (f) on termination, delete or return such data per the Data Processing Addendum. This mirrors our obligations to Meta under the WhatsApp Business Solution Terms and the Business Terms for Service Providers.
6. Sub-processors and disclosures
We disclose personal data only to the categories of recipients below, each engaged under contractual data-protection obligations:
| Recipient | Location | Purpose |
|---|---|---|
| Meta Platforms, Inc. / WhatsApp | USA / global | Message transmission over the WhatsApp Business Platform |
| Anthropic, PBC | USA | Generating AI responses from the Business's own knowledge |
| Razorpay Software Private Limited | India | Subscription billing, invoicing and payment processing |
| Amazon Web Services (AWS) | India (Mumbai, ap-south-1) | Application hosting, compute and data storage |
| Railway | USA | Application hosting / deployment |
| Resend | USA | Account and transactional email |
We may also disclose personal data: (i) to comply with law, legal process, or a lawful request from a public authority; (ii) to enforce our terms or protect the rights, safety and property of Allways, our users, or the public; and (iii) in connection with a merger, acquisition or asset sale, subject to this Policy. A current list of sub-processors is available on request; we will give Businesses a reasonable mechanism to be informed of changes to sub-processors that process End-Customer data.
7. Cross-border transfers
Some recipients (e.g. Meta, Anthropic) process data outside India. We transfer personal data outside India only in accordance with the DPDP Act and any restrictions notified by the Central Government, and we require appropriate contractual and security safeguards for such transfers.
8. Retention
We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law. Indicative retention periods:
| Data | Retention |
|---|---|
| Business account & profile data | For the life of the account; deleted 90 days after account closure (subject to legal holds) |
| End-Customer conversation transcripts & bookings | 12 months from creation, then deleted or anonymised, unless the Business's plan or instructions specify otherwise |
| AI inference & derived data (cached prompts / knowledge derived from conversations used to serve the AI) | 180 days, then deleted or regenerated |
| Billing, invoice & tax records | As required under the Companies Act / GST law (typically up to 8 years) |
| Security logs | 12 months |
On account deletion, data is handled per Section 11 and our Data Deletion process.
9. Security safeguards
We implement reasonable security safeguards as required by Section 8(5) of the DPDP Act and the DPDP Rules, including: encryption of data in transit (TLS) and at rest where applicable; role-based access controls and least-privilege access; verification of the integrity and authenticity of inbound WhatsApp webhooks via cryptographic signature (X-Hub-Signature-256); tenant isolation and authorization checks preventing cross-account access; secrets management; audit logging of sensitive account actions; and periodic review of our controls. No system is perfectly secure; we cannot guarantee absolute security but continually work to protect personal data.
10. Personal data breach
In the event of a personal data breach, we will take reasonable measures to mitigate it and will notify the Data Protection Board of India and each affected Data Principal in the manner and within the timelines prescribed by the DPDP Rules (including, where applicable, without undue delay and within 72 hours). Where we act as Processor, we will notify the relevant Business (Fiduciary) without undue delay so it can meet its own notification obligations.
11. Rights of Data Principals
Subject to the DPDP Act, you have the right to: (a) obtain confirmation of, and access to, your personal data and a summary of processing; (b) correction, completion, updating and erasure of your personal data; (c) grievance redressal; and (d) nominate another individual to exercise your rights in the event of death or incapacity. Businesses can exercise many of these rights directly in the portal (Knowledge, Settings, and account deletion). To make a request, contact our Grievance Officer (Section 12); we will verify your identity and respond within the timelines prescribed by the DPDP Rules. End-Customers should direct requests concerning their conversation data to the Business they messaged (the Fiduciary); we will assist that Business as its Processor, and End-Customers may also contact us to be routed appropriately. You may also complain to the Data Protection Board of India after exhausting our grievance mechanism.
12. Grievance Officer
In accordance with Section 13 of the DPDP Act and the Information Technology (Intermediary Guidelines) rules, our Grievance Officer is:
Raghuvinder Chhabra, Grievance Officer, ALLWAYSLIVE PRIVATE LIMITED
Email: grievance@allways.live · Address: Unit No-518A, Tower-C, M3M Urbana, Sector-67, Gurugram, Haryana 122101, India
We will acknowledge grievances within 48 hours and resolve them within the period required by law (and in any case within the DPDP-prescribed timeline).
13. Children's data
The Platform is intended for businesses and is not directed to children (individuals under 18). We do not knowingly process a child's personal data without verifiable parental/guardian consent. If we learn we have processed a child's data without such consent, we will delete it. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
14. Cookies and similar technologies
The portal uses strictly necessary cookies for authentication and session management only; we do not set analytics or other non-essential cookies. You can manage cookies through your browser settings.
15. Significant Data Fiduciary status
If the Central Government notifies Allways as a Significant Data Fiduciary, we will comply with the additional obligations that apply, including appointment of a Data Protection Officer based in India, periodic Data Protection Impact Assessments, and independent audits, and will update this Policy accordingly.
16. Changes to this Policy
We may update this Policy to reflect changes in law or our practices. Material changes will be notified through the Platform or by email, and the "Last updated" date will be revised. Continued use after the effective date of changes constitutes acceptance.
17. Contact
ALLWAYSLIVE PRIVATE LIMITED · Unit No-518A, Tower-C, M3M Urbana, Sector-67, Gurugram, Haryana 122101, India · General queries: support@allways.live · Privacy/DPDP matters: privacy@allways.live.