Appsthentic

Privacy Policy

Last updated: 19 August 2026

This policy explains what information Appsthentic Technology LLP (“Appsthentic,” “we,” “us”) collects, why we collect it, who we share it with, how long we keep it, and how you can have it deleted. It covers appsthentic.com, our direct client engagements, and our software products — AppsJewel, AppsWorkPro, and AppsWAPro, our WhatsApp CRM built on the official WhatsApp Business Platform.

If you are here because you received a WhatsApp message sent through AppsWAPro and want that stopped or your data removed, skip to Opt-in and opt-out and Deleting your data.

Who we are

Appsthentic Technology LLP is a limited liability partnership registered in India (LLPIN AAZ-7907), with its registered office at Vaidahi Tower, F 201, P No 196 & 197, Sewadal, Nagpur, Maharashtra 440027, India and its operating office at Z Software Building, 95, IT Park Rd, Bandu Soni Layout, Parsodi, Gayatri Nagar, Trimurti Nagar, Nagpur, Maharashtra 440022, India.

For privacy questions, rights requests, deletion requests, and grievances, contact us at info@appsthentic.com — see Grievances and complaints.

The two roles we play

Which parts of this policy apply to you depends on how your data reaches us, so it is worth being precise about it.

As a controller. For our own website visitors, enquiries, marketing contacts, clients, and job applicants, we decide why and how the data is processed. That processing is described in this policy.

As a processor. When a business uses AppsWAPro (or our other products) to communicate with its own customers, that business decides what to collect and who to message. It is the controller; we process that data only on its documented instructions, under the agreement we have with it. If you are the end customer of one of those businesses, your relationship is with them, and their privacy policy governs their use of your data. We will still act on a deletion request you send us directly — see Deleting your data — and we will pass it to the relevant business where we are not permitted to act alone.

Information we collect

Contact and enquiry information. When you fill in our contact form, email us, call us, or message us on WhatsApp, we collect what you send — typically your name, email address, phone number, subject, and the details of your enquiry, together with the page you submitted from.

Website usage data. Our hosting and analytics tools log standard technical information — IP address, browser and device type, pages visited, referring site, and timestamps — so we can understand traffic and fix problems.

Client and account information. For clients and product accounts: business name, billing and tax details, the named users you register, and the records needed to run the engagement.

WhatsApp Business Platform data. When a business connects its WhatsApp Business account to AppsWAPro, we handle: the business phone number and WhatsApp Business Account and phone number identifiers issued by Meta; message templates and their approval status; contact lists the business uploads or imports; the phone numbers, WhatsApp profile names, and message content of conversations between that business and its customers; and delivery, read, and failure statuses returned by Meta. We also hold the access tokens that authorise our connection to Meta on the business's behalf.

What we do not collect. We do not collect data from a person's WhatsApp account beyond what is needed to carry the conversation they are having with the business messaging them. We do not read personal WhatsApp chats, we have no access to conversations a person has with anyone other than the connected business, and we do not buy contact lists.

How we use information

  • To respond to enquiries and follow up on project requests
  • To deliver, support, secure, and improve our services and products
  • To transmit, deliver, and display the messages a business sends and receives through AppsWAPro
  • To send service and project communication over email or WhatsApp, with consent where required
  • To detect and prevent abuse, spam, and fraud
  • To understand website usage and improve the site
  • To meet legal, tax, accounting, and contractual obligations

We do not sell personal information, and we do not share it with third parties for their own marketing. We do not use the content of our clients' WhatsApp conversations for advertising, to build profiles of the people in them, or to train general-purpose AI models. Where a client enables an AI feature inside AppsWAPro, that processing happens to serve that client's own conversations and nothing else.

Legal bases for processing

Where the GDPR, the UK GDPR, or India's Digital Personal Data Protection Act, 2023 applies, we rely on: contract, to provide the services you or your employer engaged us for; consent, for marketing messages and non-essential analytics, which you can withdraw at any time; legitimate interests, to secure our systems, prevent abuse, and respond to business enquiries; and legal obligation, for tax, accounting, and statutory record-keeping.

WhatsApp Business Platform and Meta

AppsWAPro is built on the official WhatsApp Business Platform. Appsthentic is a Tech Provider on that platform: we hold a Meta application, we connect our clients' WhatsApp Business Accounts through Meta's onboarding flow, and we send and receive messages through Meta's Cloud API. Our use of that platform is governed by the Meta Platform Terms, the WhatsApp Business Terms of Service, and the WhatsApp Business Messaging Policy, in addition to this policy.

What this means for data. Messages sent or received through AppsWAPro pass through Meta's infrastructure in order to be delivered. When a business connects its account, Meta receives the business identifiers, phone numbers, message templates, and message content necessary to route those messages, and returns delivery status back to us. Meta processes that data as an independent party under its own terms, which we do not control. Meta's handling of it is described in the WhatsApp Business Data Processing Terms and the WhatsApp Privacy Policy.

Purpose limitation. We use data obtained through the WhatsApp Business Platform only as reasonably necessary to support the messaging between a business and the person it is messaging, plus the reporting that business sees in its own dashboard. We do not repurpose it, and we do not share one client's customer data with another client.

Access tokens and credentials. The tokens that let us call Meta's API on a client's behalf are stored encrypted and used only to operate that client's account. When a client disconnects their WhatsApp Business Account or ends their subscription, we revoke those tokens.

Opt-in and opt-out of WhatsApp messages

Opt-in is required. WhatsApp's Messaging Policy allows a business to message someone only if that person has given the business their phone number and has opted in to being contacted there. Businesses using AppsWAPro are contractually required to obtain that opt-in themselves, in a way that complies with the law that applies to them, to state clearly that the messages will come over WhatsApp and who they are from, and to keep a record of it. We provide the tooling; we do not obtain consent on their behalf, and uploading a list to AppsWAPro is not a substitute for having collected it.

Opting out. You can stop messages from a business at any time by replying to ask it to stop, by using any opt-out option offered in the message, or by blocking or reporting the number in WhatsApp. Businesses using AppsWAPro must honour those requests, on or off WhatsApp. If a business does not, tell us at info@appsthentic.com and we will investigate — we suspend accounts that ignore opt-outs.

To stop marketing messages from Appsthentic itself, reply to any such message or email info@appsthentic.com.

If your business uses AppsWAPro

As the controller of your customers' data, you are responsible for having a lawful basis and a valid opt-in for every number you message, for publishing your own privacy policy describing what you do with that data, for honouring opt-out and deletion requests from your customers, and for using message templates and content that comply with the WhatsApp Business Messaging Policy. Our agreement with you sets these out in full. Accounts used for unsolicited messaging are suspended.

Cookies and similar technologies

The website uses essential cookies needed to serve pages, and lightweight analytics to understand traffic patterns. We do not use these to build advertising profiles or sell data to ad networks. You can block or delete cookies in your browser settings; essential ones are required for the site to work.

Who we share information with

We share personal information only with providers that help us operate, and only to the extent each needs to do its job. Each is bound by contract to protect the data and is prohibited from using it for its own purposes. The categories are:

  • Meta Platforms — for transmitting and delivering WhatsApp messages through the WhatsApp Business Platform
  • Cloud hosting and infrastructure providers — for running the website and our applications
  • Email and communication providers — for enquiry notifications and service email
  • Analytics providers — for aggregate website traffic reporting
  • Payment and invoicing providers — for billing paid accounts and engagements
  • Professional advisers and authorities — where we are legally required to disclose, or need to establish or defend a legal claim

If Appsthentic is ever involved in a merger, acquisition, or sale of assets, personal information may transfer as part of that transaction; we will say so here before it takes effect.

A current list of the sub-processors we use for a specific product is available to clients on request at info@appsthentic.com.

How long we keep information

Website enquiries: up to 24 months from the last contact, unless the enquiry becomes an engagement.

Client and billing records: for the life of the engagement plus the period Indian tax and company law requires us to retain them.

WhatsApp conversation data in AppsWAPro: for as long as the client's account is active, or for any shorter retention period the client configures. When an account is closed, we delete or anonymise the associated data within 90 days, except where we are legally required to keep it.

Server and security logs: typically up to 12 months.

When a retention period ends, we delete the data or irreversibly anonymise it.

Deleting your data

You can ask us to delete the personal information we hold about you at any time. This is the channel Meta's Platform Terms require us to publish, and it applies to data we hold through the WhatsApp Business Platform as much as to anything else.

How to request deletion. Email info@appsthentic.com with the subject line “Data deletion request”, and include the phone number, email address, or account the data relates to, and — if you were messaged by a business using AppsWAPro — the name of that business if you know it. We may ask for one piece of information to confirm the request is genuinely yours; we do this to stop someone else deleting your data, and we will not use what you send for anything else.

What happens next. We acknowledge the request within 7 days and complete it within 30 days. Where we hold the data as a processor for one of our business clients, we cannot delete it on our own authority — in that case we forward the request to that client, act on their instruction, and tell you we have done so. Where deletion is not possible because the law requires us to retain a record, we will tell you which record and why, and delete the rest.

Deleting your data with us does not delete the messages already delivered to a recipient's WhatsApp app, or data held independently by Meta — for that, see WhatsApp's own privacy policy and in-app controls.

Security

We take reasonable technical and organisational measures to protect the information we hold: encryption in transit, encrypted storage of access tokens and credentials, access limited to staff who need it, and separation between client accounts. No system is completely secure, and we do not claim otherwise. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority as required by applicable law. If you believe your data has been compromised, tell us immediately at info@appsthentic.com.

Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to how we use it, withdraw consent, receive it in a portable format, and — for residents of India under the DPDP Act — to nominate someone to exercise these rights on your behalf. Residents of California, Virginia, and other US states with comparable laws have the rights those laws grant, including the right not to be discriminated against for exercising them.

To exercise any of these, email info@appsthentic.com. We respond within 30 days, and we do not charge for it. If we hold your data on behalf of one of our business clients, we will route the request to them and tell you.

Grievances and complaints

If you are not satisfied with how we have handled your data or your request, you can raise a grievance with us at info@appsthentic.com, marked “Grievance”, or by post at Z Software Building, 95, IT Park Rd, Bandu Soni Layout, Parsodi, Gayatri Nagar, Trimurti Nagar, Nagpur, Maharashtra 440022, India. We will respond within 30 days. This is the grievance redressal channel required under India's Digital Personal Data Protection Act, 2023.

If you remain unsatisfied, you may complain to the Data Protection Board of India or, if you are in the EEA or UK, to your local supervisory authority.

International transfers

We are based in Nagpur, India, and work with clients in India, the US, Canada, Mexico, and elsewhere. Your information may be processed in India and in other countries where our providers operate, including where Meta processes WhatsApp messages. Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.

Children's privacy

Our website, products, and services are directed at businesses and at people old enough to enter into a commercial engagement. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, contact info@appsthentic.com and we will delete it.

Changes to this policy

We may update this policy as our services and obligations evolve. The “Last updated” date above always reflects the current version, and we will give notice of material changes to account holders before they take effect.

Contact us

Questions about this policy, your data, a deletion request, or a grievance? Reach Appsthentic Technology LLP at info@appsthentic.com, by phone on +91 92717 77303, or by post at Z Software Building, 95, IT Park Rd, Bandu Soni Layout, Parsodi, Gayatri Nagar, Trimurti Nagar, Nagpur, Maharashtra 440022, India.

This policy is a good-faith description of our current data practices and is not a substitute for legal advice. If you need it reviewed against a specific jurisdiction's requirements — the DPDP Act, GDPR, CCPA — or against a specific Meta review, have it checked by counsel familiar with your situation.