1. Scope
This policy explains how the Company handles personal data when users visit the website, enquire or use Bulk SMS, RCS, Bulk Voice Call and WhatsApp Business API services. It references the Information Technology Act, 2000 and rules, the Digital Personal Data Protection Act, 2023 and applicable TRAI regulations. For client recipient data, the client is the data fiduciary and the Company acts as processor on instructions.
2. Data we collect
Client/enquiry data: name, company name, designation, email, phone/WhatsApp number, DLT/WhatsApp KYC documents, billing details and payment references.
Service data: Sender IDs, templates, campaign content/schedules, recipient mobile numbers/contact lists, message/call logs, delivery reports, timestamps and IVR response data.
Technical data: IP address, browser/device type, pages viewed, referring page, API-call and platform-login logs.
3. How we use data
To provide/support services; complete DLT/operator/platform onboarding; route messages/calls and return delivery reports; invoice and maintain accounting; respond to enquiries; detect/prevent fraud, spam and misuse; and meet legal/regulatory/law-enforcement obligations. The policy states that personal data is not sold and client contact lists are not used for the Company’s own marketing.
4. Basis of processing
Processing is based on consent, contract performance, legitimate business interests in operating/securing the platform, and compliance with legal obligations. Marketing consent may be withdrawn.
5. Sharing and disclosure
Data may be shared as needed with telecom operators and aggregators, Google for RCS, Meta for WhatsApp, payment gateways/banks/accountants, hosting/infrastructure providers, and regulators/courts/law-enforcement agencies where required by law.
6. Retention
Message/call logs, delivery reports and campaign records are retained as required by TRAI/operator regulations and dispute needs; invoices and tax records as required by Indian tax law. Client contact lists are retained while accounts are active and deleted on request under the Data Deletion Policy. Data no longer required is deleted or anonymised.
7. Security
Reasonable security practices include platform access control, HTTPS/TLS encryption in transit, restricted internal access on a need-to-know basis and administrative activity logging. No system is completely secure; users must protect credentials and API keys.
8. Your rights
Subject to applicable law, users may ask the Company to confirm/access personal data, correct inaccuracies, delete data no longer required, withdraw consent or nominate a person to exercise rights. Requests go to office@digiweapons.in; the policy states responses will be provided within 30 days. Message recipients may be referred to the client controlling their data.
9. Children
Services are provided to businesses. The Company does not knowingly collect children’s personal data for its own purposes, and clients must not use the platform to target children in breach of applicable law.
10. Grievance contact
Thakares Digiweapons Pvt Ltd, Plot no. 23, L S No.101A, Fule Colony, Paregaon Rd, Yeola, Nashik 423401, Maharashtra, India. Email: office@digiweapons.in. Phone: +91 878 804 2878. WhatsApp: +91 89566 75708.