Platform Privacy Policy · Beeps Messaging Platform

How we handle messaging data on behalf of our clients.

Beeps Digital Private LimitedCIN U62010KL2026PTC100348
Effective20 July 2026
Applies toBeeps messaging platform & connected Meta apps
Governing lawIndia · DPDPA 2023

Beeps Digital Private Limited operates a messaging platform that lets businesses manage their WhatsApp, Instagram and Messenger conversations in one place. This policy explains what data flows through that platform, why, how long we keep it, and how to get it deleted. It is separate from our website and academy privacy policy, which covers enquiries and course applications made on beepsdigital.com.

01Scope

This policy governs the Beeps messaging platform and the Meta applications we operate to deliver it, including our registered app BeepsAgent. It applies to three groups of people:

  • Our clients — businesses that connect their WhatsApp Business Account, Instagram professional account or Facebook Page to Beeps.
  • Our clients' customers — people who message those businesses and whose messages pass through our systems.
  • Named users — individual staff at a client business who hold a Beeps login.

If you messaged a business and reached this page, Beeps is the software that business uses to reply to you. The business decides what happens with your conversation; we carry it. See Section 2.

02Our two roles

We hold different responsibilities depending on whose data it is, and the distinction matters for who you contact.

As a Data Fiduciary

For our own client relationships — account signups, billing records, support tickets, named-user logins — we decide the purpose and means of processing. We are directly accountable to you for that data.

As a Data Processor

For everything that flows through a connected messaging account — conversations, contact details, delivery events — we act only on the documented instructions of the client business. They are the Data Fiduciary. We do not decide what those conversations are for, we do not use them for our own purposes, and we do not share them between clients.

If you are a customer of a Beeps client and want your conversation data deleted, the fastest route is to ask that business directly. You can also contact us at info@beepsdigital.com and we will route the request to them and act on their instruction. See Section 9.

03Data we receive

We receive data from Meta's platforms only after a client explicitly authorises the connection, and only for the accounts they select during that authorisation. We never request access to a client's personal Facebook profile, friends, or any account they did not connect.

Retention periods run from the date the data reaches us, unless a client instructs earlier deletion.
WhatWhere it comes fromWhy we hold itKept for
Message content and attached media WhatsApp, Instagram and Messenger webhooks Deliver conversations to the client's inbox, generate replies, maintain thread history 24 months
Sender phone number, WhatsApp profile name, Instagram username, Page-scoped user ID Same webhooks Identify who is in a conversation so replies reach the right person 24 months
Delivery events — sent, delivered, read, failed Same webhooks Show message status and produce delivery reporting 24 months
Account identifiers — WhatsApp Business Account ID, phone number ID, business ID, Instagram account ID, Page ID Connection flow Bind a client's Beeps account to the correct Meta assets Account life + 30 days
Access tokens issued by Meta Authorisation code exchange Make API calls on the client's behalf — nothing works without them Until revoked
Message template names, contents and approval status WhatsApp Business Management API Let clients create and send approved templates Account life + 30 days
Campaign and conversion metrics for click-to-message ads Marketing API, where the client connects an ad account Attribute conversations to the ad that started them 24 months
Product catalogue entries Commerce APIs, where the client connects a catalogue Send product messages in conversations Account life

We do not scrape, buy or infer contact data. Every phone number and profile in the system arrived because someone messaged one of our clients, or because the client imported their own records.

04Why we process it

  • Delivering the service the client configured — routing inbound messages, sending replies, running the automations and agents they built, and syncing conversation state across their team.
  • Generating replies. Where a client has enabled automated responses, message content is sent to a large language model to draft a reply. This happens in real time for that conversation only.
  • Reporting — response times, volumes, delivery rates and conversion attribution, shown to the client for their own account.
  • Keeping the platform running — diagnostics, error investigation, abuse prevention, and enforcing rate limits.
  • Legal and regulatory obligations, including Meta's platform terms and applicable Indian law.

05What we never do

These are commitments, not aspirations. Each one is enforced in how the platform is built.

  • We do not sell, rent or trade any data obtained through Meta's platforms, to anyone, for any purpose.
  • We do not use platform data to train machine learning models. Message content sent to a language model for reply generation is transmitted under a no-training, no-retention configuration and is not stored by that provider after the request completes. We do not fine-tune models on client conversations, our own or anyone else's.
  • We do not mix data between clients. Every record is scoped to a single client account and isolated at the database level. No client can see another's conversations, contacts or metrics.
  • We do not use conversation data for advertising — not our own, not anyone else's, and not to build audiences or profiles beyond what the client explicitly configures inside their own account.
  • We do not read client conversations except when a client asks us to investigate a specific problem, or where we are legally compelled to. Such access is logged.
  • We do not retain data after a client disconnects beyond the windows set out in Section 9.

06Sub-processors

We use a small number of infrastructure providers to run the platform. Each is bound by contract to process data only on our instructions.

  • Meta Platforms, Inc. — the source and destination of all messaging traffic.
  • n8n GmbH (n8n Cloud) — receives inbound messages from Meta and runs the automation workflows that route and answer them. Message content passes through and is processed on n8n Cloud infrastructure.
  • Cloudflare, Inc. — DNS, content delivery and security for beepsdigital.com, and hosting for our web properties.
  • [LLM provider] — reply generation, under a no-training and no-retention agreement.

We do not transfer data to any other third party without the client's instruction, except where required by Indian law or a competent authority.

Where your data is processed

Our automation layer runs on n8n Cloud, whose infrastructure is located in [region]. This means messages you send to a business using Beeps are processed outside India. India's Digital Personal Data Protection Act, 2023 permits such transfers, and we remain fully accountable for your data wherever it is processed. If you require that your data stay within India, contact us at info@beepsdigital.com and we will tell you whether we can accommodate it.

07Retention

Retention periods are listed per data type in Section 3. In summary:

  • Conversation content and delivery events are held for 24 months, then permanently deleted.
  • Account identifiers and configuration survive for 30 days after an account closes, so a client who disconnects by mistake can be restored.
  • Access tokens are destroyed immediately on revocation, disconnection or account closure.
  • Billing and tax records are kept for 8 years as required by Indian law, and contain no message content.

A client can set a shorter retention period for their own account at any time by writing to info@beepsdigital.com. We honour the shorter of the two.

08Security

  • All traffic is encrypted in transit using TLS 1.2 or higher.
  • Access tokens are encrypted at rest using envelope encryption, with keys held in a managed key service and never in application code or environment variables.
  • Every database record is keyed to a single client account, and queries are scoped to that key at the application layer.
  • Access to production systems is restricted to named engineers, requires multi-factor authentication, and is logged.
  • Webhook payloads from Meta are signature-verified before processing.

No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board of India as required under the DPDPA 2023.

09Deletion & disconnection

If you are a Beeps client

Disconnect your Meta accounts from inside your Beeps account settings, or revoke our access directly at Facebook Business Integrations or Instagram Apps and Websites. On disconnection we stop receiving your data immediately and destroy your access tokens. To erase everything rather than just disconnect, email info@beepsdigital.com from your registered address with the subject Data deletion request. We complete deletion within 30 days and confirm in writing.

If you messaged a business that uses Beeps

Ask that business to delete your conversation — they control it. If you cannot reach them, email info@beepsdigital.com with the business name and the phone number or Instagram handle you messaged from. We will identify the record, pass the request to the business, and act on their instruction within 30 days.

Automatic deletion

When you remove our app through Meta's own settings, Meta notifies us automatically and we treat that as a deletion instruction for the associated tokens and account identifiers without you having to contact us.

Deletion is permanent. Once a conversation is erased it cannot be recovered, including by the business that held it. Backups are purged on a rolling 35-day cycle, after which no copy remains.

10Your rights

Under India's Digital Personal Data Protection Act, 2023, you have the right to:

  • Access — a summary of the personal data we hold about you and how it is processed.
  • Correction — to have inaccurate or incomplete data corrected.
  • Erasure — to have your data deleted where it is no longer needed for its original purpose.
  • Grievance redressal — to raise a complaint with our Grievance Officer, and to escalate to the Data Protection Board of India if it is not resolved.
  • Nomination — to nominate another person to exercise these rights in the event of your death or incapacity.

We respond within 30 days. Where we hold your data as a processor for a client business, we will tell you who that business is so you can exercise your rights against them directly.

If you are outside India, we handle your request under this policy and any additional rights your local law grants you.

11Children

The Beeps platform is a business tool and is not directed at children. We do not knowingly process the personal data of anyone under 18 as a Data Fiduciary. Where a child messages one of our client businesses, that business is responsible for obtaining any consent its own sector requires. If you believe we hold a child's data in error, contact our Grievance Officer and we will delete it promptly.

12Grievance officer

Under the DPDPA 2023 and the Information Technology Act, 2000:

Grievance Officer — Beeps Digital Private Limited
Near Indira Gandhi Institute of Dental Sciences
Nellikuzhi, Kothamangalam
Ernakulam, Kerala 686691, India

Email  info@beepsdigital.com
Phone  +91 89218 04806
Response  within 30 days of receipt

13Changes

We may update this policy as the platform changes. When we do, we revise the effective date at the top of this page, and we notify clients by email at least 14 days before any change that materially affects how we handle their data. Continued use after that date constitutes acceptance.

This policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023. Disputes are subject to the jurisdiction of the courts of Ernakulam, Kerala.