Platform Privacy Policy · Beeps Messaging Platform
How we handle messaging data on behalf of our clients.
Beeps Digital Private Limited operates a messaging platform that lets businesses manage their WhatsApp, Instagram and Messenger conversations in one place. This policy explains what data flows through that platform, why, how long we keep it, and how to get it deleted. It is separate from our website and academy privacy policy, which covers enquiries and course applications made on beepsdigital.com.
01Scope
This policy governs the Beeps messaging platform and the Meta applications we operate to deliver it, including our registered app BeepsAgent. It applies to three groups of people:
- Our clients — businesses that connect their WhatsApp Business Account, Instagram professional account or Facebook Page to Beeps.
- Our clients' customers — people who message those businesses and whose messages pass through our systems.
- Named users — individual staff at a client business who hold a Beeps login.
If you messaged a business and reached this page, Beeps is the software that business uses to reply to you. The business decides what happens with your conversation; we carry it. See Section 2.
02Our two roles
We hold different responsibilities depending on whose data it is, and the distinction matters for who you contact.
As a Data Fiduciary
For our own client relationships — account signups, billing records, support tickets, named-user logins — we decide the purpose and means of processing. We are directly accountable to you for that data.
As a Data Processor
For everything that flows through a connected messaging account — conversations, contact details, delivery events — we act only on the documented instructions of the client business. They are the Data Fiduciary. We do not decide what those conversations are for, we do not use them for our own purposes, and we do not share them between clients.
If you are a customer of a Beeps client and want your conversation data deleted, the fastest route is to ask that business directly. You can also contact us at info@beepsdigital.com and we will route the request to them and act on their instruction. See Section 9.
03Data we receive
We receive data from Meta's platforms only after a client explicitly authorises the connection, and only for the accounts they select during that authorisation. We never request access to a client's personal Facebook profile, friends, or any account they did not connect.
| What | Where it comes from | Why we hold it | Kept for |
|---|---|---|---|
| Message content and attached media | WhatsApp, Instagram and Messenger webhooks | Deliver conversations to the client's inbox, generate replies, maintain thread history | 24 months |
| Sender phone number, WhatsApp profile name, Instagram username, Page-scoped user ID | Same webhooks | Identify who is in a conversation so replies reach the right person | 24 months |
| Delivery events — sent, delivered, read, failed | Same webhooks | Show message status and produce delivery reporting | 24 months |
| Account identifiers — WhatsApp Business Account ID, phone number ID, business ID, Instagram account ID, Page ID | Connection flow | Bind a client's Beeps account to the correct Meta assets | Account life + 30 days |
| Access tokens issued by Meta | Authorisation code exchange | Make API calls on the client's behalf — nothing works without them | Until revoked |
| Message template names, contents and approval status | WhatsApp Business Management API | Let clients create and send approved templates | Account life + 30 days |
| Campaign and conversion metrics for click-to-message ads | Marketing API, where the client connects an ad account | Attribute conversations to the ad that started them | 24 months |
| Product catalogue entries | Commerce APIs, where the client connects a catalogue | Send product messages in conversations | Account life |
We do not scrape, buy or infer contact data. Every phone number and profile in the system arrived because someone messaged one of our clients, or because the client imported their own records.
04Why we process it
- Delivering the service the client configured — routing inbound messages, sending replies, running the automations and agents they built, and syncing conversation state across their team.
- Generating replies. Where a client has enabled automated responses, message content is sent to a large language model to draft a reply. This happens in real time for that conversation only.
- Reporting — response times, volumes, delivery rates and conversion attribution, shown to the client for their own account.
- Keeping the platform running — diagnostics, error investigation, abuse prevention, and enforcing rate limits.
- Legal and regulatory obligations, including Meta's platform terms and applicable Indian law.
05What we never do
These are commitments, not aspirations. Each one is enforced in how the platform is built.
- We do not sell, rent or trade any data obtained through Meta's platforms, to anyone, for any purpose.
- We do not use platform data to train machine learning models. Message content sent to a language model for reply generation is transmitted under a no-training, no-retention configuration and is not stored by that provider after the request completes. We do not fine-tune models on client conversations, our own or anyone else's.
- We do not mix data between clients. Every record is scoped to a single client account and isolated at the database level. No client can see another's conversations, contacts or metrics.
- We do not use conversation data for advertising — not our own, not anyone else's, and not to build audiences or profiles beyond what the client explicitly configures inside their own account.
- We do not read client conversations except when a client asks us to investigate a specific problem, or where we are legally compelled to. Such access is logged.
- We do not retain data after a client disconnects beyond the windows set out in Section 9.
06Sub-processors
We use a small number of infrastructure providers to run the platform. Each is bound by contract to process data only on our instructions.
- Meta Platforms, Inc. — the source and destination of all messaging traffic.
- n8n GmbH (n8n Cloud) — receives inbound messages from Meta and runs the automation workflows that route and answer them. Message content passes through and is processed on n8n Cloud infrastructure.
- Cloudflare, Inc. — DNS, content delivery and security for beepsdigital.com, and hosting for our web properties.
- [LLM provider] — reply generation, under a no-training and no-retention agreement.
We do not transfer data to any other third party without the client's instruction, except where required by Indian law or a competent authority.
Where your data is processed
Our automation layer runs on n8n Cloud, whose infrastructure is located in [region]. This means messages you send to a business using Beeps are processed outside India. India's Digital Personal Data Protection Act, 2023 permits such transfers, and we remain fully accountable for your data wherever it is processed. If you require that your data stay within India, contact us at info@beepsdigital.com and we will tell you whether we can accommodate it.
07Retention
Retention periods are listed per data type in Section 3. In summary:
- Conversation content and delivery events are held for 24 months, then permanently deleted.
- Account identifiers and configuration survive for 30 days after an account closes, so a client who disconnects by mistake can be restored.
- Access tokens are destroyed immediately on revocation, disconnection or account closure.
- Billing and tax records are kept for 8 years as required by Indian law, and contain no message content.
A client can set a shorter retention period for their own account at any time by writing to info@beepsdigital.com. We honour the shorter of the two.
08Security
- All traffic is encrypted in transit using TLS 1.2 or higher.
- Access tokens are encrypted at rest using envelope encryption, with keys held in a managed key service and never in application code or environment variables.
- Every database record is keyed to a single client account, and queries are scoped to that key at the application layer.
- Access to production systems is restricted to named engineers, requires multi-factor authentication, and is logged.
- Webhook payloads from Meta are signature-verified before processing.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board of India as required under the DPDPA 2023.
09Deletion & disconnection
If you are a Beeps client
Disconnect your Meta accounts from inside your Beeps account settings, or revoke our access directly at Facebook Business Integrations or Instagram Apps and Websites. On disconnection we stop receiving your data immediately and destroy your access tokens. To erase everything rather than just disconnect, email info@beepsdigital.com from your registered address with the subject Data deletion request. We complete deletion within 30 days and confirm in writing.
If you messaged a business that uses Beeps
Ask that business to delete your conversation — they control it. If you cannot reach them, email info@beepsdigital.com with the business name and the phone number or Instagram handle you messaged from. We will identify the record, pass the request to the business, and act on their instruction within 30 days.
Automatic deletion
When you remove our app through Meta's own settings, Meta notifies us automatically and we treat that as a deletion instruction for the associated tokens and account identifiers without you having to contact us.
Deletion is permanent. Once a conversation is erased it cannot be recovered, including by the business that held it. Backups are purged on a rolling 35-day cycle, after which no copy remains.
10Your rights
Under India's Digital Personal Data Protection Act, 2023, you have the right to:
- Access — a summary of the personal data we hold about you and how it is processed.
- Correction — to have inaccurate or incomplete data corrected.
- Erasure — to have your data deleted where it is no longer needed for its original purpose.
- Grievance redressal — to raise a complaint with our Grievance Officer, and to escalate to the Data Protection Board of India if it is not resolved.
- Nomination — to nominate another person to exercise these rights in the event of your death or incapacity.
We respond within 30 days. Where we hold your data as a processor for a client business, we will tell you who that business is so you can exercise your rights against them directly.
If you are outside India, we handle your request under this policy and any additional rights your local law grants you.
11Children
The Beeps platform is a business tool and is not directed at children. We do not knowingly process the personal data of anyone under 18 as a Data Fiduciary. Where a child messages one of our client businesses, that business is responsible for obtaining any consent its own sector requires. If you believe we hold a child's data in error, contact our Grievance Officer and we will delete it promptly.
12Grievance officer
Under the DPDPA 2023 and the Information Technology Act, 2000:
Near Indira Gandhi Institute of Dental Sciences
Nellikuzhi, Kothamangalam
Ernakulam, Kerala 686691, India
Email info@beepsdigital.com
Phone +91 89218 04806
Response within 30 days of receipt
13Changes
We may update this policy as the platform changes. When we do, we revise the effective date at the top of this page, and we notify clients by email at least 14 days before any change that materially affects how we handle their data. Continued use after that date constitutes acceptance.
This policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023. Disputes are subject to the jurisdiction of the courts of Ernakulam, Kerala.