Skip to main content
NaWaBiz
Features Pricing About Contact Sign in Get started

Data Protection Policy

Last updated: 2 August 2026 · Aligned with the DPDP Act, 2023
This policy describes how NaWaBiz, operated by NarneTech Software Solutions, protects personal data and meets its obligations under India's Digital Personal Data Protection Act, 2023. It complements our Privacy Policy.
Contents
  1. Our data-protection principles
  2. Fiduciary & Processor roles
  3. Technical & organisational safeguards
  4. Tenant isolation
  5. Sub-processors
  6. Breach notification
  7. Data Processing terms for customers
  8. Data Principal rights & requests
  9. Grievance Officer

1. Our data-protection principles

We process personal data lawfully, fairly and transparently; only for specified, lawful purposes; limited to what is necessary; kept accurate; retained only as long as needed; and protected with appropriate security. These mirror the obligations of a Data Fiduciary under the DPDP Act.

2. Fiduciary & Processor roles

NaWaBiz is the Data Fiduciary for the personal data of its website visitors and account holders. For the End-User data our customers manage through the Service, the customer is the Data Fiduciary and NaWaBiz is a Data Processor acting on the customer's documented instructions.

3. Technical & organisational safeguards

  • Encryption in transit using TLS for all connections;
  • Encryption at rest for sensitive secrets (system tokens, 2FA PINs, payment and webhook keys) using AES-256-GCM, with the master key held only in the environment, never in the database;
  • Access control with separate identity realms for platform administrators, business owners, and agents, and least-privilege access;
  • Audit logging of administrative and impersonation actions, with a tenant identifier on every log line;
  • Webhook signature verification (Meta X-Hub-Signature-256 and Razorpay X-Razorpay-Signature) to reject forged payloads;
  • Rate limiting and abuse protection on public endpoints;
  • Upload validation for knowledge-base and media files.

4. Tenant isolation

The Service is multi-tenant. Every business's data is isolated at the application layer through mandatory tenant-scoped query filtering, and each business's AI knowledge base is stored in its own isolated vector collection queried only with that business's identifier. One customer can never access another customer's contacts, conversations, or documents.

5. Sub-processors

We engage a limited set of sub-processors to deliver the Service, including Meta Platforms (WhatsApp Cloud API), Razorpay (payments), and infrastructure and AI/vector-database providers. We require them to maintain appropriate safeguards and to process personal data only as needed to provide their services. A current list is available on request from our Grievance Officer.

6. Breach notification

We maintain procedures to detect, investigate and respond to personal data breaches. In the event of a breach, we will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines required by the DPDP Act, and, where we act as Processor, we will inform the relevant customer without undue delay so they can meet their own obligations.

7. Data Processing terms for customers

Where NaWaBiz processes personal data on a customer's behalf, we do so only on the customer's documented instructions; ensure persons authorised to process it are bound by confidentiality; implement the safeguards above; assist the customer with Data Principal requests and breach obligations to the extent applicable; and, on termination, delete or return the personal data except where retention is required by law. Customers requiring a signed Data Processing Addendum may request one from our Grievance Officer.

8. Data Principal rights & requests

Data Principals may request access, correction, completion, updating, or erasure of their personal data, withdraw consent, nominate another person to exercise their rights, and seek grievance redressal. We respond within the timelines prescribed by law. Where a request concerns data we process for a customer, we will refer it to, or assist, that customer as the Data Fiduciary. See Your rights.

9. Grievance Officer

Our named Grievance Officer under the DPDP Act, 2023 and the Information Technology Act, 2000 is:

Kranthi Kumar Narne — Grievance & Data Protection Officer
NarneTech Software Solutions
75-12-61, Vamsi Tulasi Enclave, 1st Floor, Bank Center, Beside HP Petrol Bunk, NH-9, Mahendra Nagar, Gollapudi, Vijayawada, Andhra Pradesh, 520012, India
Email: kranthi@narnetech.co · +91 888 525 8951

If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India.

NaWaBiz

The all-in-one WhatsApp Business Platform — prepaid, no hidden markup.

Product

  • Features
  • AI Chatbot
  • Team Inbox
  • Pricing

Company

  • About us
  • Contact
  • Sign in
  • Get started

Legal

  • Terms & Conditions
  • Privacy Policy
  • Data Protection
  • Refund & Cancellation

Compliance

  • WhatsApp & Meta Policy
  • Acceptable Use
  • Cookie Policy
  • Grievance Officer
Kranthi Kumar Narne, Grievance & DP Officer · kranthi@narnetech.co · +91 888 525 8951 NarneTech Software Solutions, 75-12-61, Vamsi Tulasi Enclave, 1st Floor, Bank Center, Beside HP Petrol Bunk, NH-9, Mahendra Nagar, Gollapudi, Vijayawada, Andhra Pradesh, 520012, India
© 2021–2026 NarneTech Software Solutions. All rights reserved. WhatsApp is a trademark of Meta Platforms, Inc. NaWaBiz is an independent Business Solution Provider, not endorsed by or affiliated with Meta.

Please confirm