Compliance
Last updated: August 26, 2026
WhizzTalk is operated by WhizzAct Private Limited. This page is the index to how we handle personal data — the roles we take on, the law that applies, who we rely on to run the service, and what we do when something goes wrong.
1. Who is responsible for what
Two different relationships run through this platform, and they carry different duties:
- Your account with us. For the data you give us to open and run a WhizzTalk account — your name, email, business details, billing records — WhizzAct is the controller (the "data fiduciary" under India's DPDP Act).
- The visitors who chat with your widget. For everything your embedded widget collects from people on your own website — names, phone numbers, email addresses, answers, uploaded images, tickets — you are the controller and WhizzAct is only the processor. We act on your instructions, we don't decide what your flow asks, and we don't use that data for our own purposes.
That split matters in practice: if a visitor to your site asks us to delete their data, we refer them to you and then act on your instruction.
2. The law we work to
- Digital Personal Data Protection Act, 2023 (India) — our primary regime, including the published Grievance Officer contact.
- GDPR and UK GDPR — where you or your visitors are in the EU/EEA or the UK, including data-subject rights, transfers, and our Data Processing Addendum.
- Privacy Policy and Cookie Policy — what we actually collect and store, in plain terms.
- Terms of Service and Refund & Cancellation Policy — the commercial side.
3. Sub-processors
Running the service means passing some data to specialist providers. This is the current list. We tell account holders before adding a sub-processor that handles visitor data, so there is time to object.
| Provider | Purpose | Data involved |
|---|---|---|
| Cloud hosting (India) | Application servers, database, file storage | All account and chat data at rest |
| OpenAI | AI features, where you use our shared key or your own OpenAI key | Question and answer text sent for that turn |
| Google (Gemini) | AI features, where Gemini is the selected provider | Question and answer text sent for that turn |
| MSG91 | SMS delivery for OTP and ticket updates | Phone number and message content |
| Meta (WhatsApp Cloud API) | WhatsApp ticket updates, where enabled | Phone number and message content |
| Cashfree Payments | Subscription payments | Billing contact and payment details, handled by the gateway |
| Email delivery provider | Verification, password reset, plan and ticket emails | Email address and message content |
Where you connect your own AI provider key, that provider is your sub-processor rather than ours, and their terms govern what they do with the text your flow sends them.
4. How the platform is secured
- Passwords are stored as bcrypt hashes; we can never read them back.
- API keys and provider credentials you save — AI, SMS, notification — are encrypted at rest and are never shown back to you or returned by any API response.
- Every tenant's records are isolated by a database-level scope, and access inside a tenant is controlled by roles and per-permission checks.
- The embeddable widget's public endpoints are authorized by widget key plus an Origin allow-list and are rate-limited; they never expose your dashboard session.
- Payment webhooks are verified against the gateway's own signature before being acted on.
- Email verification and password reset links are signed and expire.
5. Retention and deletion
Chat sessions that never captured a contact detail are pruned automatically once they have been idle for 24 hours — along with their messages and uploads — because they are not leads, only clutter. Everything else is kept while your account is active and for as long as you choose to keep it: leads, tickets, and categories can be deleted from the dashboard at any time, and a full account deletion request is honoured within 30 days, except where we must retain billing records to meet tax and accounting law.
6. If there is a breach
If personal data we hold is breached, we investigate immediately, contain it, and notify affected account holders without undue delay — with what happened, what data was involved, and what we're doing about it — so that you can meet your own notification duties. Where the GDPR applies we notify the relevant supervisory authority within 72 hours of becoming aware, and where the DPDP Act applies we notify the Data Protection Board of India and affected Data Principals as required.
7. Your compliance obligations
You control what your widget asks visitors for. Only collect what your stated purpose needs, tell visitors who you are and why you're asking, don't use the OTP or notification channels for marketing people never consented to, and keep your own privacy notice current on the site where the widget runs. The platform gives you the controls; the lawfulness of what you ask for is yours.
8. Contact
Compliance questions, data-processing agreements, and security queries: privacy@whizzact.com. Complaints can be raised with our Grievance Officer at grievance@whizzact.com (see the DPDP page for the full escalation path).
More from WhizzAct
WhizzAct Private Limited · https://whizzact.com