Legal & Compliance
Privacy Policy
- Effective date
- 1 April 2020
- Last updated
- 28 July 2026
Privacy Policy
How Azmarq collects, uses, protects, and shares personal data — and the rights you hold over it.
Draft for legal review. This document is a review-ready template prepared for Azmarq Technovation Pvt. Ltd. (India). It is not legal advice. Confirm all
[PLACEHOLDER]values and have qualified counsel review it against the Digital Personal Data Protection Act, 2023, the IT Act 2000 and SPDI Rules 2011, and — where EU/EEA or UK individuals' data is processed — the GDPR / UK GDPR before publishing.
1. Introduction
Who we are and what this notice covers.
This Privacy Policy ("Policy") explains how Azmarq Technovation Pvt. Ltd. ("Azmarq", "we", "us", or "our") collects, uses, discloses, stores, and protects personal data when you visit our websites (including azmarq.com), use our communications platform and APIs, or otherwise interact with us.
Azmarq operates a Communications-Platform-as-a-Service (CPaaS) and related products enabling businesses to send and receive messages and manage customer engagement across WhatsApp Business API, Google RCS, SMS (including SMPP), voice (Voice 360), and email, together with Click-to-WhatsApp Ads (CTWA), My CDP, Customer Journeys and Drip Campaigns, Unified Inbox, WhatsApp Commerce features, and AI Agent Studio. In providing these services we act in two distinct capacities, and your rights differ depending on which applies:
- As a Data Fiduciary / Data Controller for personal data we determine the purposes of — for example, data about our website visitors, prospective customers, and the authorised users of our customers' accounts.
- As a Data Processor acting on the documented instructions of our business customers when we transmit or process the end-user data that our customers upload or route through the platform. In that case, our customer is the Data Fiduciary, and their own privacy notice governs. Our handling of that data is set out in our Data Processing Agreement.
Product- and channel-specific processing notes appear in our Service-Specific Terms, AI & Automated Processing Policy, and Data Retention Policy.
2. Scope and applicable law
The laws this Policy is built to satisfy.
This Policy is designed to comply with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the SPDI Rules, 2011 of India, and — where we handle personal data of individuals in the EU/EEA or UK — the GDPR / UK GDPR as applicable. It applies to personal data collected when you visit our sites, communicate with us, use our services, register for an account, attend our events, or access our content.
Our services are intended for businesses and their professional users. We do not knowingly collect personal data from children as defined under applicable law. Where the DPDP Act's provisions on children's data apply to any processing, we will obtain verifiable consent as required.
3. Definitions
Key terms used throughout this Policy.
"Personal data" means any data about an individual who is identifiable by or in relation to such data. "Data Principal" (or "Data Subject") is the individual to whom the personal data relates. "Data Fiduciary" (or "Controller") determines the purpose and means of processing. "Data Processor" processes personal data on behalf of a Data Fiduciary. "Processing" means any operation performed on personal data. "Sensitive personal data" carries the meaning given under applicable law.
4. Personal data we collect
The categories of data we may process, and how we obtain them.
Depending on how you interact with us, we may collect:
- Business contact and identity data — name, job title, employer, business email, phone number, country, and role, provided when you register, enquire, or contact us.
- Account and authentication data — login credentials, API keys, IP allow-lists, and security settings for platform users (including Unified Inbox agents and API developers).
- Usage and technical data — IP address, device and browser type, operating system, pages viewed, session activity, and diagnostic logs, some of it collected via cookies and similar technologies (see our Cookie Policy).
- Communications data — the content of enquiries, support tickets, and correspondence, including call recordings where you are notified.
- Transaction and billing data — plan, usage volumes (messages, conversations, voice minutes, SMPP traffic), invoices, payment references, and tax identifiers.
- Customer-routed end-user data — message content, sender/recipient identifiers, delivery metadata, journey/drip enrolment attributes, inbox conversation content, CDP profile fields, CTWA lead fields, commerce order-related fields, voice call metadata/recordings (where enabled), and AI Agent Studio prompts/transcripts that our customers submit for transmission or processing. We process this as a Data Processor under our customer's instructions.
We collect data directly from you, automatically as you use our services, and occasionally from third parties such as our partners (including Meta), resellers, and public business sources.
5. Purposes and legal bases for processing
Why we process personal data and the lawful grounds we rely on.
We process personal data to provide, operate, secure, and improve our services; to onboard and authenticate users; to route and deliver communications across supported channels; to run journeys, drips, inbox workflows, CDP features, CTWA lead capture, commerce flows, and AI-assisted agents as configured by customers; to bill and collect payment; to provide support; to send administrative and, where permitted, marketing communications; to detect, prevent, and investigate fraud, spam, and abuse; to comply with legal and regulatory obligations (including TRAI/DLT and telecom requirements); and to establish, exercise, or defend legal claims.
Our lawful bases include your consent, the necessity of processing to perform a contract with you, compliance with a legal obligation, and our legitimate interests (or, under the DPDP Act, the applicable "legitimate uses"), balanced against your rights. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.
6. Cookies and tracking technologies
How we use cookies and how you can control them.
We use strictly necessary, functional, analytics, and — where consented — marketing cookies. You can manage your preferences through our cookie banner and your browser settings. Full details are in our Cookie Policy.
7. How we share personal data
The parties we may disclose data to, and why.
We may share personal data with: our group companies and affiliates (where engaged to support the India entity's services); sub-processors and service providers who host, secure, analyse, or support the platform under contractual confidentiality and data-protection obligations (see our Sub-processors list); telecom operators, aggregators, and channel partners (including Meta) strictly to route and deliver your communications; professional advisers, auditors, and insurers; and acquirers or successors in the event of a reorganisation, merger, or sale. We may also disclose data where required to comply with law, respond to lawful requests from public authorities, enforce our terms, or protect the rights, safety, and property of Azmarq, our customers, or others (see our Law Enforcement Guidelines). We do not sell personal data.
8. Cross-border data transfers
How we handle data that moves across borders.
Azmarq hosts production infrastructure in AWS Mumbai (India) to support data-localisation for Indian traffic. Where personal data is transferred outside India — for example, to certain sub-processors or channel providers required to deliver a message — we implement transfer mechanisms required by applicable law, such as contractual safeguards, and only transfer to jurisdictions permitted under the DPDP Act and other applicable regimes.
9. Data retention
How long we keep personal data.
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, to comply with legal, tax, accounting, and regulatory obligations, and to resolve disputes and enforce agreements. Product-specific retention practices are summarised in our Data Retention Policy. When data is no longer required, we delete, anonymise, or securely archive it in line with that schedule.
10. Security
The measures we take to protect personal data.
Azmarq maintains an information security programme certified to ISO/IEC 27001:2022 and independently assessed under SOC 2 Type II, alongside ISO 9001:2015 quality management. We apply technical, organisational, and physical safeguards including encryption in transit and at rest, access controls, network segmentation, monitoring, and regular testing. No system is completely secure; if you believe your data or account has been compromised, contact us immediately using the details in Section 13.
11. Your rights
What you can ask us to do with your personal data.
Subject to applicable law, you have the right to: access your personal data and information about its processing; correct or update inaccurate or incomplete data; request erasure; withdraw consent; nominate another individual to exercise your rights in the event of death or incapacity (under the DPDP Act); and seek grievance redressal. Where GDPR applies, you additionally have rights to object, to restrict processing, and to data portability.
To exercise any right, contact our Grievance Officer / Data Protection Officer at the details below. We may need to verify your identity before acting. We will respond within the timelines prescribed by applicable law, and in any event without undue delay. Exercising your rights will not result in denial of service or discriminatory treatment. End users of a customer should typically contact that customer first; we assist as processor where required.
12. Changes to this Policy
How we notify you of updates.
We may update this Policy from time to time. Material changes will be reflected by revising the "Last updated" date and, where required by law, by additional notice. Please review it periodically.
13. Contact — Grievance Officer / Data Protection Officer
Who to contact with questions, requests, or complaints.
Data Fiduciary: Azmarq Technovation Pvt. Ltd.
Registered office: B012, 1st Floor, Tower B, ATS Bouquet, Sector 132, Noida, Uttar Pradesh, India 201304
CIN: U74999UP2016PTC125340
Grievance Officer / Data Protection Officer: Contact via email below
Email: dpo@azmarq.com / legal@azmarq.com
The Grievance Officer will address complaints regarding the processing of personal data within the timelines prescribed under the DPDP Act and other applicable law.