Privacy Policy
Messagify Technologies Pvt. Ltd. provides cloud-based business communication and customer engagement solutions. We process personal data for our own business and platform operations and, where applicable, process customer-controlled personal data on behalf of our business customers. We do not sell personal data, and we apply technical, organisational and operational safeguards designed to protect personal data and customer information within systems under our control.
1Overview
Messagify provides cloud-hosted messaging, bot, CRM, workflow, and omnichannel customer engagement solutions. Communication services may include SMS, WhatsApp, RCS, Email, chatbots, and other business communication capabilities depending on the customer's configuration.
This Privacy Policy explains how Messagify collects, uses, stores, discloses, and protects personal data when you:
- visit or interact with our website;
- submit an inquiry or contact request;
- create or use a Messagify account;
- use our SaaS platform or services;
- communicate with our support or sales teams; or
- interact with services that are operated by our business customers through the Messagify platform.
Messagify's services are primarily designed for businesses and their authorised users.
Our Key Privacy Commitments
- We do not sell, rent, or trade personal data.
- We process personal data only for identified business, contractual, operational, security, or legally permitted purposes.
- Customer-controlled data is processed in accordance with applicable customer instructions, contractual requirements, and applicable law.
- We apply appropriate technical and organisational safeguards to protect personal data.
- We retain information only for as long as reasonably necessary for the applicable purpose, contractual requirements, operational needs, and legal obligations.
- Our privacy and security program is continuously being implemented and improved as our platform, customer requirements, and applicable legal obligations evolve.
2Data Roles & Customer-Controlled Data
Messagify may have different privacy roles depending on the nature and purpose of the processing activity.
Messagify as Data Fiduciary
Where Messagify determines the purpose and means of processing personal data for its own business operations, Messagify acts as the Data Fiduciary, where applicable under Indian data-protection law.
Examples may include personal data relating to:
- website visitors and inquiry contacts;
- customer account administrators;
- business contacts;
- billing and payment contacts;
- sales and marketing communications;
- support requests;
- security and operational activities; and
- other information that Messagify processes for its own business purposes.
Messagify determines the purposes and means of these processing activities and applies the requirements applicable to such processing.
Messagify as Data Processor
Where a business customer determines the purpose and means of processing personal data and uses Messagify to process that information on its behalf, Messagify acts as a Data Processor, where applicable.
Customer-controlled data may include:
- contact information;
- phone numbers;
- email addresses;
- customer records;
- message content;
- communication history;
- templates;
- media;
- bot conversations;
- CRM information;
- delivery and engagement information; and
- other information submitted or processed through the customer's use of Messagify.
In these circumstances, the customer remains responsible for determining the purposes and lawful basis for processing such information, while Messagify processes the information in accordance with the customer's documented instructions, applicable agreements, and applicable law.
Customers are responsible for ensuring that they have the necessary rights, permissions, notices, and consents required to provide or process such information through Messagify.
Customer Data Rights and Interests
Customers retain their rights and interests in business data, messages, contacts, templates, media, and other content submitted to or processed through the Messagify platform, subject to applicable law and the terms of the applicable customer agreement.
3Information We Collect
We collect information that is reasonably necessary to operate our business, provide services, support customers, maintain security, and meet applicable legal or contractual requirements.
Personal Information
Depending on how you interact with Messagify, this may include:
- name;
- email address;
- phone number;
- company name;
- job title;
- account information;
- billing and payment-related information;
- inquiry information;
- support communications;
- business contact information; and
- other information voluntarily provided to us.
Technical and Usage Information
When you use our website or platform, we may automatically collect technical and usage information such as:
- IP address;
- browser type;
- device type;
- operating system;
- session information;
- referral information;
- application and API activity;
- security and authentication events;
- error and diagnostic information; and
- other technical metadata necessary for security, performance, and service operations.
Customer-Controlled Service Data
When our business customers use Messagify, we may process information submitted or generated through their use of the platform, including:
- communication metadata;
- message delivery status;
- event logs;
- contact information;
- message content;
- communication history;
- bot and workflow information;
- CRM information;
- media and templates; and
- other service-related data.
Such information is processed on behalf of the relevant customer where Messagify acts as a Data Processor.
4How We Use Personal Data
We use personal data for purposes including:
- providing, operating, and maintaining the Messagify platform;
- creating and managing customer accounts;
- authenticating users;
- providing customer support;
- responding to inquiries;
- delivering requested communication services;
- processing billing and payments;
- monitoring platform performance and reliability;
- detecting, preventing, and investigating security incidents and misuse;
- maintaining audit and operational records;
- improving our products and services;
- communicating important service, security, policy, or administrative updates;
- complying with applicable legal and regulatory obligations; and
- protecting the rights, property, security, and legitimate interests of Messagify, our customers, and other users.
Where marketing communications are sent, we will provide appropriate mechanisms to manage or withdraw applicable marketing preferences or consent.
5Legal Basis & Permitted Processing
Messagify processes personal data based on the circumstances and requirements applicable to the relevant processing activity.
These may include:
- consent, where required;
- providing or performing requested services;
- contractual requirements;
- compliance with applicable legal obligations;
- security, fraud prevention, and protection of systems and services;
- other purposes permitted under applicable law; and
- processing carried out by our customers for their own business purposes where Messagify acts as a Data Processor.
Where Messagify acts as a Data Processor, the relevant customer is responsible for determining the purposes and applicable legal basis for the processing, unless otherwise required by applicable law.
6Subprocessors & Third-Party Providers
Messagify may use selected third-party service providers and subprocessors to support the operation and delivery of its services.
These may include providers supporting:
- cloud infrastructure and hosting;
- messaging and communication delivery;
- WhatsApp, SMS, RCS, and email services;
- payment processing;
- analytics;
- customer support;
- security and monitoring;
- infrastructure and operational services; and
- AI-enabled functionality, where applicable.
Messagify evaluates relevant providers based on the nature of the services they provide and requires appropriate contractual, confidentiality, security, and data-protection safeguards where applicable.
Third-party providers process information only for authorised purposes and subject to their applicable contractual and legal obligations.
7Communication Infrastructure & Third-Party Platforms
Messagify integrates with third-party communication platforms, APIs, and technology providers to deliver services configured by our customers.
Depending on the services selected by a customer, information necessary to provide a communication service may be transmitted to the applicable provider.
Examples may include:
- WhatsApp and Meta services;
- SMS providers;
- RCS providers;
- email delivery providers;
- cloud infrastructure providers; and
- other communication or technology platforms.
The processing performed by such providers is also subject to their own terms, privacy policies, security controls, and applicable contractual arrangements.
Where Messagify acts as a Data Processor, customers are responsible for ensuring that their use of such communication services complies with applicable laws, platform policies, and customer obligations.
8International Data Processing & Transfers
Messagify's primary production application and database infrastructure is hosted in India.
However, certain communication, technology, support, analytics, AI, or infrastructure providers may process information outside India depending on the services used and the provider's infrastructure.
Where personal data is transferred or processed across jurisdictions, Messagify applies appropriate contractual, technical, organisational, and security safeguards and complies with applicable requirements governing such processing.
Customers should review the applicable service configuration and contractual terms where specific data-location or transfer requirements apply.
11Business Messaging
Customers are responsible for ensuring that communications sent through Messagify comply with applicable laws, regulations, consent requirements, and the terms and policies of the communication platforms they use.
This may include requirements applicable to:
- WhatsApp;
- SMS;
- RCS;
- Email;
- voice communications;
- automated messaging;
- marketing communications; and
- other communication channels.
Messagify provides the technical platform for configured communication services but does not determine the customer's independent business purpose for sending a particular communication.
12Artificial Intelligence
Certain Messagify services may include AI-enabled capabilities for purposes such as:
- message generation;
- workflow automation;
- customer support;
- conversational experiences;
- analytics;
- classification;
- summarisation; and
- operational assistance.
Where AI functionality is enabled, information may be processed by Messagify and/or applicable technology providers as necessary to provide the requested functionality.
The applicable processing is subject to the relevant service configuration, contractual requirements, provider terms, and applicable law.
Customers are responsible for reviewing and appropriately using AI-generated outputs, particularly where such outputs may affect customers, end users, or business decisions.
Messagify does not represent that AI-generated content is always accurate or suitable for every purpose.
13Security & Data Protection
Messagify implements technical and organisational measures designed to protect personal data and customer information against unauthorised access, alteration, disclosure, loss, misuse, or destruction.
Depending on the system and service involved, security measures include:
- encryption of sensitive customer information using AES-256-GCM where applicable;
- Google Cloud encryption at rest;
- TLS encryption for data in transit;
- role-based access control;
- tenant-level authorization;
- least-privilege access principles;
- authentication and token-expiration controls;
- multi-factor authentication for privileged internal access;
- customer MFA capabilities where available;
- API authentication and security controls;
- input and request validation;
- rate limiting;
- CORS and CSRF protections where applicable;
- secret and credential management;
- audit logging;
- application and infrastructure monitoring;
- security alerting;
- backup and recovery procedures;
- incident-response procedures; and
- cloud-based edge security and DDoS mitigation controls.
Messagify's production environment is hosted on Google Cloud infrastructure.
Security controls are continuously reviewed and improved as the platform and threat environment evolve.
For additional information about our current security posture, please refer to our Security & Compliance page.
14Tenant Isolation & Access Controls
Messagify operates a multi-tenant SaaS architecture.
Customer environments are logically separated through application-level tenant authorization and access controls.
Requests accessing tenant-specific resources are subject to authentication, tenant identification, authorization, and resource-level access checks before customer data is accessed.
Production access to customer databases is restricted to authorised personnel based on operational requirements and applicable access controls.
Privileged internal access is subject to additional authentication and monitoring controls.
15Data Retention
Messagify retains personal data only for as long as reasonably necessary for the purpose for which it was collected or processed, contractual requirements, operational needs, security, dispute resolution, and applicable legal or regulatory obligations.
Typical retention periods may include:
| Website inquiries | Up to 2 years, subject to business and compliance requirements. |
| Platform logs & metadata | Typically up to 12 months, unless longer retention is required. |
| Billing & payment records | Up to 7 years or as required by applicable law. |
| Customer-controlled service data | According to applicable customer agreement, customer instructions, service configuration, and applicable legal requirements. |
Retention periods may vary depending on the nature of the information and the circumstances of processing.
Messagify is formalising and implementing data-category-specific retention and deletion controls as part of its ongoing privacy program.
16Data Deletion & Account Closure
Customers may request export or deletion of customer-controlled data, subject to the applicable customer agreement, technical capabilities, and legal requirements.
Upon termination or expiry of a customer's services, Messagify will handle customer-controlled data in accordance with the applicable agreement, customer instructions, operational procedures, and applicable law.
Certain information may be retained where reasonably necessary for:
- legal or regulatory obligations;
- accounting and financial records;
- security and fraud prevention;
- dispute resolution;
- enforcement of agreements;
- audit requirements; or
- other legally permitted purposes.
Backup copies may remain temporarily in accordance with applicable backup and recovery processes before being overwritten or securely deleted according to the relevant retention cycle.
Formal automated retention and deletion controls are being progressively implemented as part of Messagify's privacy program.
17Personal Data Breaches & Security Incidents
Messagify maintains procedures for identifying, assessing, containing, investigating, remediating, and recovering from security incidents and personal data breaches.
Where a personal data breach occurs, Messagify will assess the nature and scope of the incident and take appropriate response measures.
Where required by applicable law or contractual obligations, Messagify will provide notifications to relevant customers, authorities, or affected individuals within applicable timelines and through appropriate channels.
Our incident-response process may include:
- 1. identification and initial assessment;
- 2. containment;
- 3. investigation;
- 4. remediation;
- 5. recovery;
- 6. customer or stakeholder communication where applicable; and
- 7. post-incident review and corrective actions.
18Privacy Rights & Grievance Redressal
Subject to applicable law and the nature of the processing, individuals may have rights relating to their personal data, including rights concerning:
- access to information about personal data processing;
- correction or updating of inaccurate information;
- deletion or erasure where applicable;
- withdrawal of consent where processing is based on consent;
- grievance redressal; and
- other rights available under applicable law.
Where personal data is processed through Messagify on behalf of a business customer, requests concerning that customer-controlled data may need to be directed to the relevant customer, as the customer may determine the purposes and means of processing.
Messagify will reasonably assist customers with applicable privacy requests relating to customer-controlled data, subject to contractual arrangements and applicable law.
To submit a privacy request or grievance, contact — Privacy Contact: info@messagify.in.
We will review and respond to requests within applicable legal or contractual timeframes.
19Children's Privacy
Messagify's services are designed for businesses and their authorised users and are not directed at children.
Messagify may nevertheless process customer-controlled information relating to individuals who are minors where a business customer uses the platform for a lawful business purpose.
Where customers process personal data relating to children through Messagify, the customer is responsible for ensuring that the processing, notices, consents, authorisations, and communications comply with applicable law.
Messagify does not knowingly use its website or SaaS services to directly target children as customers.
20Customer Security Responsibilities
Customers are responsible for using Messagify securely and lawfully.
Customer responsibilities include:
- protecting account credentials and API keys;
- using appropriate access controls;
- enabling available MFA capabilities where appropriate;
- ensuring authorised users have appropriate access;
- obtaining required permissions or consent for communications;
- complying with applicable privacy and communication laws;
- ensuring message content is lawful and appropriate;
- configuring communication channels correctly;
- promptly notifying Messagify of suspected account compromise or security incidents; and
- complying with applicable third-party communication platform requirements.
Messagify's security measures operate together with customer-side security practices under a shared-responsibility model.
21Changes to This Policy
Messagify may update this Privacy Policy periodically to reflect changes to:
- our services;
- data-processing practices;
- security controls;
- applicable laws and regulations;
- third-party services; or
- privacy and compliance requirements.
When material changes are made, Messagify will update the "Last Updated" date and, where appropriate, provide additional notice.
The current version of this Privacy Policy will be published on this page.
22Contact Information
If you have questions regarding this Privacy Policy, our data-processing practices, or privacy rights, please contact us.
| Company | Messagify Technologies Pvt. Ltd. |
| Privacy & Security Email | info@messagify.in |
| Phone | +91 97675 71283 |
| Address | C II 203/1, Deendyal Puri, Meerut Road, Ghaziabad — 201003, Uttar Pradesh, India |
| Website | https://www.messagify.in |
23Privacy & Compliance Program
Messagify is implementing a privacy and security program designed to support compliance with applicable Indian data-protection requirements, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, as applicable.
Our privacy program includes workstreams covering:
- personal-data inventory and classification;
- data-flow mapping;
- privacy notices;
- consent management where applicable;
- data-subject rights;
- data retention and deletion;
- vendor and subprocessor management;
- security safeguards;
- incident response;
- privacy governance; and
- ongoing compliance monitoring.
Messagify does not represent that it currently holds ISO 27001 or SOC 2 certification. Independent security assessments and additional compliance activities may be undertaken as part of our security and compliance roadmap.
The status of our broader security and compliance program is described on our Security & Compliance page.
24Governing Law
This Privacy Policy is governed by the laws of India.
Subject to any mandatory applicable law, disputes relating to this Privacy Policy will be subject to the jurisdiction of the courts in Ghaziabad, Uttar Pradesh, India.
© 2026 Messagify™ Technologies Pvt. Ltd. All rights reserved.