Legal

Privacy policy

What personal data 3xRetention handles, why, where it is kept, and how you can use your rights under India's DPDP Act 2023.

1. Who we are and what this policy covers

This policy is published by 3xRetention (registered legal entity: [to be added before launch]), [registered address to be added before launch], Bengaluru, Karnataka, India (“3xRetention”, “we”, “us”). We run a WhatsApp-based sales and retention service for businesses in India.

We handle personal data in two different roles under the Digital Personal Data Protection Act 2023 (the “DPDP Act”), and this policy explains both.

  • As a Data Fiduciary — for data about people who visit this website, fill in our forms, or use a 3xRetention account on behalf of their business. We decide why and how this data is used, and this policy is our notice to you about it.
  • As a Data Processor — for data about our business customers’ own customers: the people who message those businesses on WhatsApp. Here the business is the Data Fiduciary. We process that data only on the business’s instructions and under a written contract. The business’s own privacy notice governs how it uses that data, and requests about it should go to that business first.

How the two roles work in practice is set out in more detail on our DPDP compliance page.

2. What data we collect and why

When you contact us or book a demo

Our demo form asks for your name, email address, WhatsApp number, business name, type of business, where you sell, roughly how many customer conversations you handle, and optionally a link to your website or store and a catalogue file. Our contact form asks for your name, email address, WhatsApp number, the topic and your message.

We use this to reply to you, prepare and run your demo, and follow up about 3xRetention. We do not use it for anything else.

When your business has an account

We collect the names, email addresses and phone numbers of the people your business adds to its account, the business’s billing details (business name, billing address and GSTIN), and records of invoices and payments. We use these to run the account, let your team sign in, bill you, send service and account emails, and meet our tax obligations.

If you pay us online, your card, UPI or bank details are entered with the payment provider that processes the payment. We receive a confirmation of the payment, not your full card number.

Data we process for our business customers

To run the service, we process data about the people who message our business customers on WhatsApp: their name and WhatsApp number, the messages exchanged, their orders, whether a payment link was paid, and their opt-in and opt-out records. The business also gives us its catalogue, prices and rules so the agent can answer correctly.

We use this data only to provide the service to that business, on its instructions. We do not use it for our own purposes, we do not combine one business’s contacts with another’s, and we never use it to train AI models.

Technical data

Like any website, the servers that host this site and our service record basic technical information when you connect — such as your IP address, browser type, the pages requested and the time of the request. We use this to keep the service running, secure it and investigate misuse.

We do not sell personal data, and we do not share it with anyone for their own marketing. We disclose it outside the sub-processors listed in section 5 only where Indian law requires us to, for example in response to a lawful order.

Under the DPDP Act, personal data may be processed with the person’s consent, or for one of the “legitimate uses” the Act lists. Where we are the Data Fiduciary, we rely on:

  • Your consent — when you submit a form on this website, for the purpose the form describes. You can withdraw consent at any time by emailing contact@3xretention.com. Withdrawing does not affect anything done before you withdrew.
  • Data you have given us voluntarily for a specific purpose — for example, the contact details your business provides so we can run its account and bill it.
  • Compliance with law — for example, keeping invoices as tax law requires, or responding to a lawful order.

Where we are a Data Processor, the business we work for is responsible for having a lawful basis — usually its customers’ consent, including the WhatsApp opt-in that Meta requires before a business can message someone. We process that data under a contract with the business, as section 8(2) of the Act requires.

4. How data is stored and secured

Customer data — contacts, conversations, orders and catalogues — is stored in India.

  • Data is encrypted while it travels to and from our servers, and encrypted where it is stored.
  • Each business’s data is isolated from every other business’s at the database level.
  • Access to an account is limited to the team members that business adds.
  • Every conversation the agent has is logged, so the business can check exactly what was said.

No system is perfectly secure. If a personal data breach affects data we hold, we act on it straight away and notify as the DPDP Act and Rules require — or, where we are the Data Processor, we tell the business promptly so it can meet its own duties. More detail is on our Trust & Security page.

5. Sub-processors

These are the other companies that handle some personal data so the service can run. Each is bound to protect it and to use it only to provide its service to us.

  • Cloud hosting: stores contacts, conversations, orders and catalogues, in India.
  • AI model provider: generates the agent’s replies from the business’s information and the conversation. It does not use this data to train its models.
  • Meta — WhatsApp Business Platform: carries every WhatsApp message between a business and its customers, through the official WhatsApp Business API. Meta also processes this data under its own terms.
  • Email: sends account and service emails to our business customers and their teams.
  • The business’s own payment gateway: when a customer pays through a payment link, they pay on the gateway’s page and the money settles into the business’s own gateway account. We never hold those funds or see card or UPI details.

The name of any provider not shown above is available on request — email contact@3xretention.com.

Processing outside India

Some sub-processors, including Meta, may process data outside India. The DPDP Act allows this unless the Government of India restricts transfers to a particular country. The processing location of each sub-processor is available on request.

6. How long we keep data

  • Enquiries and demo requests: for as long as we are talking to you. If you do not become a customer, we delete them within [confirm period] of our last contact, or sooner if you ask.
  • Account and team member details: for as long as your business’s account is open.
  • Data we process for a business: for as long as that business uses 3xRetention, unless it tells us to delete something sooner. After the business cancels, it can export everything and have the data permanently deleted. A single contact’s record can be deleted at any time.
  • Invoices and billing records: for the period Indian tax and company law requires.
  • Technical and security logs: for as long as needed to keep the service secure, and at least for the minimum period the DPDP Rules set for such logs.

When a retention period ends, the data is deleted, unless a law requires us to keep it longer.

7. Your rights and how to use them

Under the DPDP Act you have the right to:

  • Access — a summary of the personal data we hold about you and how we use it.
  • Correction and erasure — to have inaccurate or incomplete data corrected or updated, and data we no longer need erased.
  • Withdraw consent — as easily as you gave it, for anything we do on the basis of consent.
  • Grievance redressal — to complain to us and have the complaint answered.
  • Nominate — to name another person to use these rights for you if you die or become unable to.

How to make a request. Email our grievance officer at [grievance officer email to be added before launch] or write to contact@3xretention.com, with “Privacy request” in the subject line. Tell us what you are asking for. We may ask you to confirm your identity before we act, so we do not hand your data to someone else. We will respond within [confirm response time], and in any case within the period the DPDP Rules allow.

If you are a customer of a business that uses 3xRetention, that business decides how your data is used, so send your request to it. If you write to us instead, we will pass your request to the business and help it act on it.

If you are not satisfied with how we handle your grievance, you can complain to the Data Protection Board of India.

8. Grievance officer

The DPDP Act requires us to name a person who answers questions and complaints about how we handle personal data.

  • Name: [grievance officer name to be added before launch]
  • Email: [grievance officer email to be added before launch]
  • Postal address: 3xRetention (registered legal entity: [to be added before launch]), [registered address to be added before launch], Bengaluru, Karnataka, India

9. Cookies

This website does not set cookies for tracking or advertising, and it does not use third-party analytics. Our fonts are served from our own site, so loading a page does not send your details to a font provider.

If we add analytics or any other cookies that are not strictly necessary, we will update this section before they go live, and ask for your consent where the law requires it.

10. Children’s data

3xRetention is a service for businesses. This website and our accounts are not meant for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has sent us their data, email contact@3xretention.com and we will delete it.

A business using 3xRetention may have customers under 18. The DPDP Act requires that business, as the Data Fiduciary, to obtain verifiable consent from a parent or lawful guardian before processing a child’s data, and not to track, behaviourally monitor or target advertising at children. Our business customers agree to follow these rules when they use the service.

11. How changes are notified

When we change this policy, we publish the new version on this page with a new effective date. If a change materially affects how we handle your data, we will also email the account owners of our business customers, and anyone else we hold an email address for, before the change takes effect. Earlier versions are available on request.

12. Effective date

This policy takes effect on 29 September 2026. It is an initial version and will be replaced by a version reviewed by a lawyer; we keep a record of both. Questions about it can go to contact@3xretention.com.