Privacy Policy
Last updated: 3 August 2026
Chatzyn is a customer-messaging platform operated by PROXCELERATE LLP, a limited liability partnership registered in India ("we", "us", "our"). It lets businesses manage their WhatsApp and Instagram conversations through the official Meta APIs. This policy explains what data we handle, in which role, and what rights you have. It is written to comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and takes account of the EU/UK GDPR where it applies to you.
1. Our two roles
We handle personal data in two distinct capacities:
- As a data fiduciary (controller) for the account data of the people who sign up for and use Chatzyn — workspace owners, agents, and agency staff.
- As a data processor for the end-customer data (messages, contacts) that our business customers process through Chatzyn. That data belongs to the business you are messaging; the business is the data fiduciary/controller and decides why and how it is used. If you are an end customer of a business that uses Chatzyn, please direct requests about your data to that business first — we act on their instructions.
2. Account data we collect (as fiduciary)
- Email address and optional name. Sign-in is by one-time email code (OTP), or by a password if you choose to set one. A password is never stored in plain text — only a salted cryptographic hash.
- One session cookie.
chatzyn_sessionis the only cookie we set. It is an essential, httpOnly authentication cookie valid for up to 30 days. We use no analytics, advertising, or tracking cookies. - Operational records. Workspace membership, roles, audit logs of significant actions, and basic technical logs (IP address, user agent) kept for security.
- Billing records. Payments are handled by Razorpay; we store invoices and subscription state. We never see or store your card details — those are entered on Razorpay's own checkout.
- Payout details, only if you enter them. If you are an agency billing your own clients, or an affiliate claiming a commission, the bank account number, IFSC code, account holder name or UPI id you enter is stored so invoices can show it and payouts can be made. It is used for nothing else. Leave those fields empty and we hold none of it.
3. Business-customer data we process (as processor)
When a business connects its WhatsApp Business account or Instagram professional account to Chatzyn, we process on that business's behalf, exclusively via official Meta Platforms APIs (WhatsApp Business Platform / Cloud API and the Instagram Platform):
- messages and message metadata (delivery status, timestamps) sent to and from the business;
- contact identifiers such as phone numbers, WhatsApp IDs, Instagram handles, and profile names;
- media attachments and voice notes exchanged in those conversations;
- consent and opt-in/opt-out records the business maintains for its marketing;
- message content and knowledge-base documents, when a business enables optional AI-assisted reply or lead-scoring features — see Section 5 for the providers involved;
- payment and order details, when a business uses payment links or commerce features. These are processed through the business's own connected payment provider (for example, their own Razorpay account), which Chatzyn does not select or control.
We use this data solely to provide the service to that business, including any optional features the business has enabled. We do not use it for advertising and do not build cross-customer profiles from it. Chatzyn does not train AI models on your data. Where a business enables an AI-assisted feature, message content is sent to the third-party AI providers listed in Section 5 to generate that feature's output; those providers' own data-handling and retention terms govern their processing of it.
4. No sale of data
We do not sell personal data. We do not share it with anyone for their own marketing.
5. Subprocessors and service providers
We use a small set of infrastructure providers, each bound by contract to protect your data:
- Meta Platforms, Inc. — WhatsApp Business Platform and Instagram messaging APIs (message transport).
- Neon, Inc. / Amazon Web Services — managed PostgreSQL database hosting (Singapore region).
- Upstash, Inc. — managed Redis for message queues.
- Cloudflare, Inc. — media storage and content delivery.
- Razorpay Software Pvt. Ltd. — payment processing for Chatzyn subscriptions (India). Separately, a business using our payment-link or commerce features connects and pays through its own provider (typically its own Razorpay account); that processing is between the business and its provider, not a Chatzyn subprocessor relationship.
- Groq, Inc. and OpenRouter, Inc. — large-language-model providers used to power optional AI-assisted reply and lead-scoring features. When a business enables these features, relevant message content and knowledge-base documents are sent to these providers to generate a response or score. We do not have zero-retention or no-training commitments from these providers at this time; treat data sent to them as shared with a third party, not merely processed on our behalf.
6. Retention
- Account data is kept while your account is active and deleted within 30 days of account deletion, except records we must keep under law (e.g. tax and invoicing records).
- Conversation data is kept while the owning workspace is active. When a business requests deletion of its workspace or of specific conversation data, we process that request and remove the data from active systems that support erasure today; any part of the request our systems cannot yet complete automatically is completed manually by our team.
- Residual copies in encrypted backups are purged on the backup rotation cycle (up to 90 days).
7. Security
All traffic is encrypted in transit (TLS). Access tokens and credentials are encrypted at rest (AES-256-GCM). Tenant data is isolated with database row-level security so one workspace can never read another's data. Access by our staff is limited and logged.
8. Your rights and how to delete your data
Under the DPDP Act 2023 you have the right to access, correct, and erase your personal data, the right to grievance redressal, and the right to nominate. If the GDPR applies to you, you additionally have rights to data portability, restriction, and objection, and you may lodge a complaint with your supervisory authority. We do not discriminate against you for exercising any right.
You can request deletion three ways:
- In the app: ask the workspace owner to remove you from the workspace, or to delete the workspace. Removing you from a workspace revokes your access to it; it does not by itself erase your personal data from our systems — email us (below) to request full erasure.
- By email: write to support@chatzyn.com from your registered address.
- Via Meta: Meta-initiated deletion requests are received automatically — see our data deletion page for how that works and how to track a request.
We aim to complete verified erasure requests within 30 days. Where a request cannot be fully automated by our current systems, our team completes it manually within that window.
9. International transfers
Data is primarily stored in the AWS Asia-Pacific (Singapore) region. Our subprocessors may process limited data in other regions under appropriate safeguards (for GDPR-covered data, standard contractual clauses or equivalent mechanisms).
10. Children
Chatzyn is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18 as account holders.
11. Changes and contact
We will post any material changes to this policy on this page with an updated date. Questions, requests, and grievances go to our support and grievance contact: support@chatzyn.com (the canonical support address for Chatzyn), or by post to PROXCELERATE LLP, India.