Privacy Policy
Last updated: August 3, 2026
1. Who we are
UdyamSync is a business communication and WhatsApp management software service operated as a sole proprietorship in India. In this Policy, “UdyamSync”, “we”, “us” and “our” refer to UdyamSync, a sole proprietorship operating in India.
Website and application: https://connect.udyamsync.com. Public location: Jaipur, Rajasthan, India. Privacy and support contact: support@udyamsync.com.
2. Scope and privacy roles
This Policy applies to visitors, account holders, workspace users, trial users, paying customers and people who contact us. It also explains how we handle personal data processed through customer workspaces.
UdyamSync acts as the data fiduciary/controller for account registration, mobile verification, billing, security, service administration, support and our own business operations.
For contacts, WhatsApp conversations, media and other information uploaded or connected by a customer, the customer normally determines the purpose and means of processing and acts as the data fiduciary/controller. UdyamSync processes that information as a data processor/service provider on the customer’s documented instructions, subject to the Data Processing Addendum.
3. Information we collect
Account and identity information: name, business or workspace name, email address, mandatory mobile number, password hash, mobile-verification status, account status, user roles and permissions.
Business and billing information: legal or trading name, address, contact details, invoice details, plan information and tax or registration identifiers where voluntarily provided or legally required. We do not require Aadhaar for ordinary account registration.
Authentication information: Firebase/Google processes the mobile number and one-time password flow for registration, mobile verification and password recovery. UdyamSync stores the mobile number and verification result, but does not store the actual OTP code.
WhatsApp and customer data: customer contact records, phone numbers, consent or opt-out records, conversation content, message templates, delivery/read/failure status, message metadata, images, documents, audio, video and other media processed through the connected WhatsApp Business account.
Meta connection data: WhatsApp Business Account ID, Phone Number ID, business profile information, template information and encrypted access credentials or tokens needed to operate the connection.
Payment and subscription data: Razorpay order, payment, refund and transaction identifiers, amount, currency, payment status, plan, invoice, refund and dispute information. UdyamSync does not store full card numbers, CVV, UPI PINs, banking passwords or equivalent sensitive payment credentials.
Device, security and operational data: IP address, browser and device details, timestamps, session information, login events, security events, audit activity, request and error information, and technical logs needed to operate and protect the service. Operational logs are not intended to be a message archive.
Support and communications: emails, requests, complaints, attachments and other information supplied when you contact us.
Cookies: strictly necessary session, security, CSRF and “Remember Me” cookies as described in the Cookie Notice. We do not use Google Analytics, Meta Pixel or advertising trackers.
4. How we use information
To create and administer accounts, verify mobile numbers, authenticate users and recover accounts.
To provide the inbox, contacts, WhatsApp connection, conversation history, media handling, campaigns, templates, delivery status, billing and other features described on the applicable plan page.
To process subscriptions and refunds, issue invoices, reconcile payments and prevent payment abuse or fraud.
To secure the service, detect abuse, investigate incidents, maintain audit records, enforce our Terms and comply with Meta/WhatsApp requirements.
To provide customer support, respond to grievances, maintain service communications and notify users about security, billing, policy or operational matters.
To comply with legal, accounting, regulatory and lawful government requirements, and to establish, exercise or defend legal claims.
To send promotional communications only where the recipient has explicitly opted in. Promotional messages will include an unsubscribe or opt-out method.
We do not sell or rent personal data. We do not use customer messages, contacts or media to train general-purpose artificial-intelligence models.
5. Legal grounds and customer responsibilities
We process personal data for lawful purposes connected with providing the service, performing our contract, acting on valid consent where required, meeting legal obligations, preventing fraud and security threats, and other legitimate uses permitted by applicable law.
Customers are responsible for giving their contacts an appropriate privacy notice, obtaining and recording any consent or opt-in required for WhatsApp communications, respecting opt-outs, and ensuring that their use of UdyamSync complies with applicable law and Meta/WhatsApp policies.
6. Sharing and subprocessors
We disclose data only as needed to provide, secure and support the service, process payments, comply with law, or protect rights and safety.
Current key service providers are BigRock for hosting, database, storage, rotating backups and cPanel-based email infrastructure; Meta Platforms/WhatsApp for the WhatsApp Business Platform and Cloud API; Razorpay for payment processing; and Google Firebase Authentication for mobile OTP verification.
These providers process information under their own terms and privacy practices. A current list and processing purpose is published in the Subprocessor List.
We may disclose information in response to a valid legal process, court or government order, or where reasonably necessary to investigate fraud, security incidents, unlawful activity or threats to rights and safety. Where legally permitted and practical, we may notify the affected customer.
We do not share a customer’s conversation with another customer.
7. International and cross-border processing
UdyamSync does not represent that all data remains in one country. Meta, Razorpay, Google/Firebase, BigRock or their infrastructure partners may process or store information in India or other countries where they or their service providers operate.
Where cross-border processing occurs, we use contractual, technical and organisational safeguards appropriate to the service and applicable law, and we will not intentionally transfer personal data to a destination prohibited by a binding Government of India notification.
8. Retention
Account, workspace, contact, message and media data may remain available while an account is active and may be retained after plan expiry or account closure until the customer requests deletion, unless the customer deletes data earlier through available product controls.
After a verified deletion request, eligible account and customer data will be deleted or anonymised within 30 days. Limited records may be retained where required for accounting, legal claims, fraud prevention, security investigations or compliance.
Deleted information may remain in protected rotating backups for up to 60 days before normal backup expiry.
Billing, payment and invoice records may be retained for 8 years or longer where required by tax, accounting or other applicable law.
Security and audit logs are generally retained for up to 180 days unless a longer period is needed for an active incident, legal claim or regulatory requirement.
Support emails and tickets may be retained for up to 3 years after closure.
Service providers may retain information under their own legal and operational retention rules.
9. Security
We use reasonable technical and organisational safeguards appropriate to the nature of the information, including HTTPS/TLS for service traffic, secure password hashing, role-based access, encrypted storage for sensitive integration credentials, token masking, rate limiting, access controls, protected backups and security monitoring.
Meta access tokens are not intended to appear in ordinary logs or user-facing screens. When a WhatsApp connection is disconnected, the token should be revoked or deleted; account identifiers and history remain subject to the retention rules above.
There is no routine human review of customer messages. Limited authorised access may occur only where strictly necessary for requested support, security investigation, abuse prevention, legal compliance or service recovery, with access controls and confidentiality obligations.
No internet or storage system is completely secure. Customers must use strong passwords, protect account credentials, restrict workspace access and promptly report suspected compromise.
10. Your rights and choices
Subject to applicable law and appropriate identity verification, you may request access to a summary of personal data, correction of inaccurate data, an export where technically feasible, deletion or anonymisation, withdrawal of consent where processing depends on consent, and grievance redressal.
Exports may be provided in a commonly used format such as CSV, JSON or ZIP where technically feasible.
To submit a request, email support@udyamsync.com from the registered account email and describe the account and request. We may ask for proportionate verification before releasing, correcting or deleting data.
Requests concerning contact or message data controlled by a UdyamSync customer should normally be directed first to that customer. We will reasonably assist the customer in responding.
If a grievance remains unresolved, you may use remedies available under applicable law, including approaching the Data Protection Board of India when the relevant statutory provisions apply.
11. Cookies and communications
Only strictly necessary cookies are used for login, sessions, security, CSRF protection and the optional “Remember Me” function. Because we do not use advertising or behavioural analytics cookies, we do not use an advertising-cookie opt-in banner. See the Cookie Notice for details.
Account, OTP, billing, security, support and service notices may be sent without marketing consent where necessary to operate the account. Marketing communications are sent only after explicit opt-in and may be stopped using the provided unsubscribe or opt-out method.
12. Children
UdyamSync is a business service. A person creating or administering an account must have legal authority to accept the Terms and act for the relevant business or organisation. Customers must not knowingly upload children’s personal data unless they have lawful authority and all required notices and consents.
13. Changes to this Policy
Material changes will be notified by email, in-app notice or another reasonable method at least 15 days before they take effect, unless an urgent legal, security or service-protection change requires faster action.
Non-material clarifications may take effect when published. The publication-controlled “Last updated” date will change only when a revised policy version is published.
14. Contact and grievance
Privacy and support requests: support@udyamsync.com.
Grievance Officer: Fiza Siddiqui, Grievance Officer, UdyamSync.
Postal address: Tambi Mansion, Gali No. 8, Shanti Prakash Marg, Govind Nagar East, Jaipur, Rajasthan - 302002, India.
Consumer complaints will be acknowledged within 48 hours and targeted for redressal within one month, subject to the nature of the complaint and applicable law.