PRIVACY POLICY — SMARTONE360 CONNECT

Effective Date: 2026-10-11

Last Updated: 2026-10-11

Version: 1.7

This Privacy Policy explains how SmartOne360 Connect collects, handles, stores, protects, and retains personal data, and outlines your statutory rights. This policy applies exclusively to SmartOne360 Connect; other products and corporate websites provided by SMARTTECH SOLUTIONS are governed by their respective privacy policies published on our corporate website.


1. Who We Are and Our Respective Roles

SMARTTECH SOLUTIONS, Coimbatore, Tamil Nadu ("SMARTTECH", "we", "us", or "our"), is the provider and operator of SmartOne360 Connect. Under applicable Indian information technology laws and the Digital Personal Data Protection Act, 2023 (DPDPA 2023):


2. Categories of Personal Data We Handle

2.1 Business Account and Team Information

2.2 Verification and Authentication Codes

2.3 Business's End-Customers and Contacts

2.5 Message Content and Transmission Data

2.6 Uploaded Contact Lists and Spreadsheets

2.7 WhatsApp Business Connection Credentials

2.8 Payments, Invoices, and Billing Data

2.9 Technical, Diagnostic, and Log Data

2.10 Cookies and Local Storage

We do not sell, rent, or trade personal data. We never use a business's customer contact details or customer message data for our own marketing or advertising.


3. Lawful Grounds and How We Use Data

We process personal data only when a lawful basis exists under applicable Indian data protection law, specifically:

  1. Consent: Where the Data Principal has given clear, specific, informed, and unconditional consent for the specified purpose (e.g., end-customers opting into WhatsApp updates from a business, or business owners subscribing to the service).
  2. Contractual Performance: To deliver core functionality of SmartOne360 Connect, manage subscriptions, process transactions, and provide technical assistance.
  3. Legitimate Uses & Legal Compliance: To verify GST registration, comply with applicable tax, accounting, and regulatory mandates, respond to judicial or statutory directives, detect and prevent fraud, mitigate cybersecurity threats, and enforce our service terms.

4. Third Parties and Sub-Processors

We share personal data only with trusted infrastructure providers and sub-processors bound by strict confidentiality and data protection obligations:

We may disclose personal data if required to do so by applicable law, regulation, court order, or formal request from law enforcement agencies or regulatory authorities in India. In the event of a merger, acquisition, corporate restructuring, or transfer of business assets, personal data will continue to be governed by the protections set forth in this policy.


5. Where Data Is Stored and How It Is Protected


6. Data Retention and Erasure Schedules

We retain personal data only for the duration necessary to satisfy the specific purposes outlined in this policy, unless a longer retention period is mandated by law:


7. Rights of Data Principals

Under the Digital Personal Data Protection Act, 2023 and applicable Indian regulations, Data Principals enjoy statutory rights, exercisable in accordance with rules notified by the Central Government:

  1. Right to Access Information: You have the right to request a summary of the personal data held about you, the processing activities carried out, and the identities of other Data Fiduciaries and Processors with whom the data has been shared.
  2. Right to Correction and Erasure: You have the right to request correction of inaccurate or misleading data, completion of incomplete data, updating of outdated data, and erasure of personal data that is no longer necessary for the purpose for which it was processed.
  3. Withdrawal of Consent: Where processing is based on consent, a Data Principal may withdraw consent in accordance with applicable law. The process for withdrawal will be made accessible, subject to the applicable requirements. Withdrawal does not retrospectively affect the lawfulness of processing undertaken before withdrawal. Certain records may still be retained where required by law or where another lawful ground applies.
  4. Right of Grievance Redressal: You have the right to accessible and prompt grievance redressal through our designated Grievance Officer.
  5. Right to Nominate: In accordance with Section 14 of the DPDPA 2023, a Data Principal has the right to nominate an individual who shall, in the event of death or incapacity of the Data Principal, exercise the rights of the Data Principal, subject to procedures prescribed under the Act.
  6. Right to Approach Regulatory Authorities: If a grievance is not resolved to your satisfaction through our internal grievance redressal mechanism, or if you believe there has been a statutory violation of your data rights, you have the right to register a complaint with the Data Protection Board of India (DPBI) once its complaint filing procedures are operationalized.

How to Exercise Your Rights:

7.1 Data Connected to Meta Sign-Up

When a business owner or authorized team member connects a WhatsApp account through Meta's sign-up flow, SmartOne360 Connect receives account and WhatsApp identifiers needed to connect the selected business WhatsApp account, along with access credentials used to provide the service. Sensitive WhatsApp connection credentials are stored using application-level encryption.

To request deletion of personal data associated with your Meta sign-up or connected WhatsApp account, email the Grievance Officer listed in Section 11 with the subject "Data deletion request". Include the business name and, where possible, the email address used with SmartOne360 Connect and enough information to identify the connection. Do not send passwords, access tokens, or other secret credentials in your request.

We will review the request, verify that you are authorized to make it, and explain any information needed to complete it. Where deletion is appropriate, we will remove or disconnect the relevant account credentials and identifiers from active service records, subject to technical feasibility and applicable legal obligations. Business-owned messages, contacts, consent records, invoices, and payment records may be subject to the retention and deletion rules described in Section 6. Copies in backups may remain until their applicable retention cycle expires. You may also remove the app from your Facebook settings; however, this policy does not promise that such removal automatically triggers deletion in SmartOne360 Connect.


8. Children and Minors

SmartOne360 Connect is a business-to-business (B2B) communications application and is not intended for, marketed to, or directed at children (defined under the DPDPA 2023 as an individual who has not completed 18 years of age).

Business subscribers are strictly prohibited from using SmartOne360 Connect to collect or process the personal data of children, or undertaking tracking, behavioral monitoring, or targeted advertising directed at children. If you become aware that personal data of a child has been processed without verifiable parental or guardian consent, please contact our Grievance Officer immediately so that prompt corrective action can be taken.


9. Cross-Border Data Transfers

The development and production database environments are hosted in India. Certain service providers, including Meta Platforms, may process or route data through infrastructure in other countries. Any international transfer is handled in accordance with applicable Indian law and the terms governing the relevant service providers. The exact locations and safeguards may differ by provider and service.


10. Updates to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our operational practices, technological enhancements, or statutory requirements. When modifications are made:


11. Grievance Redressal and Contact Information

For privacy and data protection inquiries, SMARTTECH has designated the following contact as its Grievance Officer.