1. Our data-protection principles
We process personal data lawfully, fairly and transparently; only for specified, lawful purposes; limited to what is necessary; kept accurate; retained only as long as needed; and protected with appropriate security. These mirror the obligations of a Data Fiduciary under the DPDP Act.
2. Fiduciary & Processor roles
NaWaBiz is the Data Fiduciary for the personal data of its website visitors and account holders. For the End-User data our customers manage through the Service, the customer is the Data Fiduciary and NaWaBiz is a Data Processor acting on the customer's documented instructions.
3. Technical & organisational safeguards
- Encryption in transit using TLS for all connections;
- Encryption at rest for sensitive secrets (system tokens, 2FA PINs, payment and webhook keys) using AES-256-GCM, with the master key held only in the environment, never in the database;
- Access control with separate identity realms for platform administrators, business owners, and agents, and least-privilege access;
- Audit logging of administrative and impersonation actions, with a tenant identifier on every log line;
- Webhook signature verification (Meta
X-Hub-Signature-256and RazorpayX-Razorpay-Signature) to reject forged payloads; - Rate limiting and abuse protection on public endpoints;
- Upload validation for knowledge-base and media files.
4. Tenant isolation
The Service is multi-tenant. Every business's data is isolated at the application layer through mandatory tenant-scoped query filtering, and each business's AI knowledge base is stored in its own isolated vector collection queried only with that business's identifier. One customer can never access another customer's contacts, conversations, or documents.
5. Sub-processors
We engage a limited set of sub-processors to deliver the Service, including Meta Platforms (WhatsApp Cloud API), Razorpay (payments), and infrastructure and AI/vector-database providers. We require them to maintain appropriate safeguards and to process personal data only as needed to provide their services. A current list is available on request from our Grievance Officer.
6. Breach notification
We maintain procedures to detect, investigate and respond to personal data breaches. In the event of a breach, we will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines required by the DPDP Act, and, where we act as Processor, we will inform the relevant customer without undue delay so they can meet their own obligations.
7. Data Processing terms for customers
Where NaWaBiz processes personal data on a customer's behalf, we do so only on the customer's documented instructions; ensure persons authorised to process it are bound by confidentiality; implement the safeguards above; assist the customer with Data Principal requests and breach obligations to the extent applicable; and, on termination, delete or return the personal data except where retention is required by law. Customers requiring a signed Data Processing Addendum may request one from our Grievance Officer.
8. Data Principal rights & requests
Data Principals may request access, correction, completion, updating, or erasure of their personal data, withdraw consent, nominate another person to exercise their rights, and seek grievance redressal. We respond within the timelines prescribed by law. Where a request concerns data we process for a customer, we will refer it to, or assist, that customer as the Data Fiduciary. See Your rights.
9. Grievance Officer
Our named Grievance Officer under the DPDP Act, 2023 and the Information Technology Act, 2000 is:
NarneTech Software Solutions
75-12-61, Vamsi Tulasi Enclave, 1st Floor, Bank Center, Beside HP Petrol Bunk, NH-9, Mahendra Nagar, Gollapudi, Vijayawada, Andhra Pradesh, 520012, India
Email: kranthi@narnetech.co · +91 888 525 8951
If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India.