Introduction
            
                Xpecto® IT Solutions Pvt Ltd, (“Xpecto”, “we”, “our”, “us”) respects your
                privacy and is committed to protecting the personal and business data of our users (“you”, “your”) when
                you use our WhatsApp Business API platform and website. This Privacy Policy explains:
            
            
                - •  What data we collect
 
                - •  How we use and share it
 
                - •  Your rights regarding your data
 
                - •  How we comply with international privacy laws, including GDPR and CCPA
 
            
            By using our platform, you consent to the practices described in this Privacy Policy.
            
            
                1. Information We Collect
                
                    1.1 Account Information
                    
                        - •  Business name, email address, phone number, organization details
 
                        - •  Login credentials (username, password)
 
                    
                 
                
                    1.2 API Usage Data
                    
                        - •  Messages sent and received, templates used
 
                        - •  Message delivery status, engagement metrics
 
                        - •  Phone numbers and contacts you provide for messaging
 
                    
                 
                
                    1.3 Device and Technical Information
                    
                        - •  IP address, device type, operating system, browser type, app version
 
                        - •  Crash logs and error reports from the app
 
                    
                 
                
                    1.4 Cookies and Analytics
                    
                        - •  Cookies or similar tracking technologies to improve website and API experience
 
                        - •  Google Analytics / Firebase / other third-party analytics may collect anonymized
                            usage data
 
                    
                 
                
                    1.5 Communications
                    
                        - •  Emails or messages exchanged with Xpecto support or notifications
 
                    
                 
             
            
            
                2. How We Use Your Data
                We use your data to:
                
                    
 Operate,
                        maintain, and improve the API platform and website 
                    
 Deliver
                        WhatsApp messaging services, including sending messages, templates, and notifications 
                    
 Monitor
                        usage, prevent abuse, and enforce policies 
                    
 Provide
                        support, troubleshoot errors, and respond to inquiries 
                    
 Send
                        updates, alerts, announcements, or promotional communications (if opted-in) 
                    
 Comply with
                        legal obligations 
                
             
            
            
                3. Legal Basis for Processing (GDPR)
                Where applicable, we process data based on:
                Consent: e.g., for marketing communications
                
                Contractual necessity: providing API services and platform
                    access
                Legitimate interest: improving services, preventing fraud,
                    security monitoring
                Legal obligation: complying with laws or court orders
             
            
            
                4. Data Sharing
                We do not sell your data. We may share data with:
                Service providers: Cloud hosting, analytics, payment
                    processors, support tools
                Legal authorities: To comply with laws, regulations, or
                    investigations
                Other users: Only public content shared via the API (e.g.,
                    messages to intended recipients)
             
            
            
                5. Data Retention
                
                    - •  Personal and business data is retained only as long as necessary to
                        provide services or meet legal requirements
 
                    - •  Deleted accounts: Data is removed or anonymized within a reasonable period
 
                    - •  Anonymized data may be retained indefinitely for analytics
 
                
             
            
            
                6. Security Measures
                We implement technical and organizational measures:
                
                    - •  Encryption of sensitive data at rest and in transit
 
                    - •  Access controls and multi-level authentication
 
                    - •  Regular backups, monitoring, and auditing
 
                
                Note: No system is 100% secure. Users should follow best practices to protect
                    credentials.
             
            
            
                7. Your Rights (GDPR / CCPA)
                As a user, you may have rights including:
                👉 Access: Request the data we hold about you
                👉 Correction: Rectify inaccurate or incomplete data
                👉 Deletion: Request removal of your data where permitted
                👉 Restriction: Limit processing in specific situations
                👉 Data portability: Receive data in structured,
                    machine-readable format
                👉 Object: Object to processing based on legitimate interest or
                    for marketing
                👉 Withdraw consent: Revoke consent for marketing or optional
                    processing
             
            
            
            
            
                8. International Transfers
                
                    - •  Data may be processed or stored outside your country, including countries outside the EU
                    
 
                    - •  We ensure adequate safeguards for international data transfers (e.g.,
                        standard contractual clauses)
 
                
             
            
            
                9. Cookies & Tracking
                
                    - •  Analytics cookies help monitor platform usage and improve services
 
                    - •  Users can manage cookies via browser or app settings
 
                
             
            
            
                10. Children’s Privacy
                
                    - •  Our platform is not intended for users under 13 years (or local minimum
                        age)
 
                    - •  We do not knowingly collect data from children; discovered data is deleted immediately
                    
 
                
             
            
            
                11. Updates to Privacy Policy
                
                    - •  This Privacy Policy may change to reflect new services, legal obligations, or
                        operational updates
 
                    - •  Changes will be posted with an updated effective date
 
                    - •  Continued use indicates acceptance of updated terms