Colloquent

Privacy Policy

Effective 29 September 2026 · Syslice Technologies Private Limited
Dhaka Ka Bas, Nawalgarh, Jhunjhunu, Rajasthan 333305, India

This policy describes what Colloquent does with personal data. It is written to be checked against the product rather than to reassure, so where something survives a deletion request, or cannot be reached at all, it says so.

1. Two roles, and which one applies to you

Businesses use Colloquent to talk to their own customers on WhatsApp. That puts us in two distinct positions, and your rights differ depending on which one you are in.

If you are…We are the…Meaning
A business using Colloquent, or a user in one of its workspaces Data fiduciary / controller We decide what account data is needed to provide and bill for the service. Exercise your rights directly with us.
An end customer messaging a business that uses Colloquent Data processor That business decides what happens to your conversation; we process it on their instructions. Ask them first — we will also act directly, see Data deletion.

2. What we collect

2.1 From businesses that sign up

  • Identity and contact details for the application and verification — business name, legal entity details, contact name, email, phone, website, country, and where applicable a GSTIN.
  • A description of how you intend to use WhatsApp messaging. We read it: approving an applicant who plans to message people who never opted in harms every other business on the platform.
  • Account records — workspaces, team members and roles, sign-in times, and an append-only audit log of administrative actions.
  • Billing records — plan, usage counts, invoices, payments, and the tax fields an invoice must legally carry.
  • Technical records when you use the product — IP address, browser user agent, request logs.

2.2 From conversations on your WhatsApp number

When a customer messages a business on Colloquent, or the business messages them, Meta delivers and we store, on that business’s behalf:

  • The customer’s WhatsApp ID (their phone number in international format) and their chosen WhatsApp profile name.
  • Message content — text, and media such as images, documents, audio and video.
  • Message metadata — timestamps, delivery and read receipts, error codes, and the pricing category Meta applies.
  • Consent records — when someone opted in or out, by what means, and the evidence.
  • Whatever the business adds itself: names, tags, notes, custom fields.

We do not receive, and cannot read, messages sent to any business that does not use Colloquent.

2.3 What we do not do

  • We do not sell personal data, and never have.
  • We do not use anyone’s conversations to advertise to them, or share them with advertisers.
  • We do not use one customer’s conversation data to train models for anyone else.
  • This website sets no cookies of its own, runs no analytics, and loads nothing from another domain — see Cookies, which names the one script it does run and the security cookie our CDN may set.

3. Why we process it

PurposeBasis
Delivering the messaging service a business asked forPerformance of a contract
Reviewing a signup application, including sanctions and denied-party screeningLegal obligation; legitimate interests
Billing, invoicing, tax recordsLegal obligation
Keeping the service secure and investigating abuseLegitimate interests
Service email — invitations, password resets, account noticesPerformance of a contract
Processing end-customer conversationsOn the instructions of the business, as its processor

4. How long we keep it

These are periods the product enforces, not aspirations.

DataRetained
Raw webhook deliveries from Meta, kept for replay and fault diagnosis 30 days, then the body is erased by a scheduled sweep. A record that the delivery happened outlives the body.
Message media re-hosted from WhatsApp 90 days, then the file is deleted and the message shows the attachment as expired.
Messages, contacts and conversations As long as the business keeps them, or until it deletes the contact or closes the account.
Consent records (opt-in and opt-out decisions) For the life of the account, including after an erasure — they are the proof that someone asked not to be messaged. The free-text evidence is redacted on erasure; the decision and its date are not.
Invoices, tax and payment records Eight years, as Indian law requires.
Backups A rolling 30-day schedule. A deletion made today is not applied retroactively to a backup taken yesterday; that backup expires on its own schedule.

5. Who we share it with

Only the parties needed to run the service, each listed with what it receives and why on the Sub-processors page — the page to watch for changes.

In summary: Meta Platforms, because WhatsApp is Meta’s network and every message necessarily passes through it; our hosting provider, which holds the encrypted databases and media; Cloudflare, which sits in front of our public endpoints and therefore sees request traffic; and an email relay for service email. We also disclose where legally required, and will tell the affected business unless we are prohibited from doing so.

6. Where it is stored

Colloquent’s databases and media storage are hosted in Mumbai, India. Each business’s conversation data lives in its own separate database rather than in shared tables — that isolation is structural, not a filter applied at query time.

Messages travel through Meta’s global infrastructure and are subject to WhatsApp’s own privacy policy in transit. Where personal data of people in the EEA or UK is transferred outside those regions, we rely on the European Commission’s Standard Contractual Clauses.

7. Security

Set out on the Security page. In short: encrypted transport throughout; a separate database per business; WhatsApp access tokens encrypted at rest with AES-256-GCM and never written to logs; an append-only audit log of administrative actions; and an internal operations console that is not reachable from the public internet.

8. Your rights

Under the Digital Personal Data Protection Act, 2023 (India), and under the GDPR and UK GDPR where they apply, you may ask us to:

  • confirm what personal data we hold about you and give you a copy;
  • correct data that is wrong or incomplete;
  • erase data — see Data deletion, which is specific about what erasure reaches and what it does not;
  • restrict or object to processing, and withdraw consent where consent is the basis;
  • nominate someone to exercise these rights on your behalf in the event of death or incapacity, as the DPDP Act provides;
  • complain to a supervisory authority — in India, the Data Protection Board.

If you are an end customer of a business using Colloquent, that business decides what happens to your conversation, so ask them first. We will act on a request sent to us as well, and will tell you plainly if something cannot be deleted and why.

We answer within 30 days. We may ask you to verify your identity first: acting on an unverified erasure request is itself a way to destroy someone’s records.

9. Children

Colloquent is a business product, not directed at children, and we do not knowingly take anyone under 18 as an account holder. Where a business messages a customer who is a child, the DPDP Act’s restrictions are that business’s responsibility as controller, and our Acceptable Use Policy requires compliance with them.

10. Changes

Any change is posted here with a new effective date. For a change that materially reduces your rights or adds a sub-processor, we give account owners at least 30 days notice by email.

11. Contact and Grievance Officer

Privacy questions and rights requests: [email protected].

As required by the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, our Grievance Officer is:

Rajbir
Grievance Officer, Syslice Technologies Private Limited
[email protected]
Dhaka Ka Bas, Nawalgarh, Jhunjhunu, Rajasthan 333305, India
+91 888 2222 826

We acknowledge a grievance within 24 hours and resolve it within 15 days, as those Rules require.