Privacy Policy
Last updated: 1 January 2026
1. Who We Are
Msgtoday Technologies, with its principal place of business at Floor 1, Flat 905, Anandam Apartment, Hossainpur Main Road, Madurdaha, Kolkata, West Bengal 700107, is the data controller for your personal information. Our Data Protection Officer can be reached at dpo@msgtoday.com.
2. Data We Collect
| Category | Examples | Purpose |
|---|---|---|
| Account data | Name, email, phone, company | Create and manage your account |
| Billing data | Invoice address, GST number | Process payments and comply with tax law |
| Usage data | API call logs, dashboard events | Provide and improve the service |
| Message metadata | Timestamps, delivery status IDs | Deliver messages and generate reports |
| Technical data | IP address, browser, device | Security, fraud prevention |
We do not read, store, or process the content of your customers' WhatsApp messages beyond the routing necessary for delivery. Message content transits our infrastructure encrypted and is not retained after delivery confirmation.
3. Legal Bases for Processing
- Contract performance — to provide the service you subscribed to
- Legitimate interests — security, fraud prevention, service improvement
- Legal obligation — tax, regulatory, and law enforcement requirements
- Consent — marketing communications (you can withdraw at any time)
4. How We Share Data
We share personal data only with:
- Meta Platforms, Inc. — required to route WhatsApp API messages
- Payment processors (Razorpay, Stripe) — for billing
- Cloud providers (AWS, GCP) — infrastructure hosting
- Analytics providers (aggregated, anonymised data only)
We do not sell personal data. We do not share data with advertisers.
5. Data Retention
Account and billing data is retained for 7 years from the end of the relationship for tax and legal purposes. Usage logs are retained for 90 days. Deleted accounts are fully purged within 90 days, except where legal holds apply.
6. Your Rights
Under the DPDP Act 2023 and GDPR (where applicable), you have the right to access, correct, delete, or export your personal data. You may also object to processing or withdraw consent. To exercise any right, email privacy@msgtoday.com. We respond within 30 days.
7. Security
We implement AES-256 encryption at rest, TLS 1.3 in transit, SOC 2 Type II controls, and regular penetration testing. In the event of a data breach, we will notify affected users and regulators within 72 hours as required by applicable law.
8. Cookies
See our Cookie Policy for full details on how we use cookies and similar technologies.
9. Contact
For privacy questions: privacy@msgtoday.com | DPO: dpo@msgtoday.com