Security & data handling
How we handle your accounts and your customers' data
Plain-language summary. The binding terms are in the privacy policy, the terms (Data Processing Addendum) and the service level agreement.
Accounts and access
- Your platform accounts (Meta, WhatsApp, Google, broker, payment) stay in your name. We work through partner or admin access you grant, and you can revoke it at any time.
- Credentials are kept in an encrypted secrets store, never in chat, email or documents.
- Contractors, when used, get access limited to their task and revoked at handover.
Where things run
- Website hosting: Hostinger (Asia region).
- Automations: our own servers in India or Google Cloud asia-south1 (Mumbai), depending on the setup.
- Model providers: Anthropic (Claude) by default; OpenAI where a setup specifies it. Telephony: Twilio internationally, Exotel in India.
Data retention
- Lead-form data: 12 months.
- End-customer conversation logs: 90 days by default; you can shorten or extend in writing.
- Operational backups: 30 days. After a care plan ends, exported data is deleted from our systems 30 days after termination.
Incidents
- Critical outages caused by us: acknowledged within 1 business day, fix target 24 hours.
- Personal-data breaches: you are notified within 72 hours of us becoming aware, with what happened, what data, and what we did.
What we never do
- Sell or share your data with third parties for their own purposes.
- Send bulk messages to your customers without your instruction and their consent.
- Train public models on your data.
Questions or a security report: support@bharataisaathi.com.