converso

Privacy Policy

Effective date: 11 August 2026  |  Last updated: 11 August 2026
DPDP Act 2023 CompliantAWS Mumbai (ap-south-1)
This Privacy Policy explains how Thinkraft Technologies ("Converso", "we", "us") collects, uses, stores, shares and protects personal data in connection with the Converso CRM service available at getconverso.in and its mobile and web applications (together, the "Service"). We are based in India and this Policy is written primarily around the Digital Personal Data Protection Act, 2023 ("DPDP Act").

Quick Navigation

1. Two Different Roles2. Data We Collect3. How We Use Data4. Notifications5. Sub-processors6. Retention & Deletion7. Your Rights8. Security9. Children's Data10. Business Obligations11. Policy Changes12. Contact & Grievance

1. Two Different Roles — Please Read This First

Converso handles two distinct categories of personal data, and our responsibilities differ for each. Understanding which one applies to you determines who you should contact about your data.

WE ARE DATA FIDUCIARY

1.1 Account Data

If you sign up for Converso as a business owner, manager or staff member, we decide how your account information is handled. For that data we act as the Data Fiduciary (equivalent to a "controller"), and this Policy governs it directly. Your rights under Section 7 are exercised against us.

WE ARE DATA PROCESSOR

1.2 Lead & Customer Data

Converso is a tool that businesses use to store information about their own customers and enquiries ("Leads"). The business that subscribes to Converso decides what Lead information to collect, why, and for how long. That business is the Data Fiduciary for the Lead data; Converso is only a Data Processor acting on its instructions.

If you are an individual whose details were entered into Converso by a business — for example because you filled in their enquiry form, replied to their advertisement, or messaged them on WhatsApp — then that business, not Converso, is responsible for your data. Please direct access, correction or erasure requests to them. If you cannot identify or reach them, contact us using Section 12 and we will help route your request, but we cannot act on Lead data without the relevant business's instruction.

2. Personal Data We Collect

2.1 Account and Identity Data (We are the Fiduciary)

Data CategoryWhy We Hold It
Email addressAccount identity, sign-in one-time passcodes, service notifications
Mobile numberOptional sign-in, phone verification
NameDisplay within your team, attribution of activity
Business detailsBusiness name, time zone, working-hour settings for reminder scheduling
Role & permissionsOwner, manager, or staff access control within your business
Auth & sessionsAuthentication tokens and session records to keep you signed in & allow session revocation
Push tokensDevice push tokens and notification preferences for mobile push alerts
🔑 Passwordless Security: We use one-time passcodes (OTPs), not passwords. We do not store a password for your account.

2.2 Lead Data (We are a Processor)

Businesses using Converso may store the following about their enquiries: name, phone number, email address, service interest, location, lead source and source detail, stage and quality rating, deal value, follow-up schedule, notes and activity history, uploaded attachments, and — where the business has connected WhatsApp — conversation history, message content and media.

We also record consent metadata on each Lead: consent status, the time consent was given or withdrawn, the notice text shown at the time, and the IP address from which the enquiry was submitted. This exists so the business can demonstrate lawful collection under the DPDP Act.

2.3 WhatsApp Data

  • We receive and store messages that customers send to a connected WhatsApp Business number, including text, images, documents, audio, video, stickers, shared locations and contact cards.
  • We store customer WhatsApp phone numbers and public WhatsApp profile names.
  • We store delivery receipts (sent, delivered, read, failed) for messages sent by the business.
  • Media files are fetched from Meta and cached in our storage when a user first opens them (because Meta deletes media from its servers after approximately 30 days).
  • WhatsApp access credentials are stored encrypted at rest using AES-256-GCM.
  • WhatsApp messaging is subject to Meta's own privacy terms as the underlying platform operator.

2.4 Technical and Operational Data

  • Error & Diagnostic reports: captured when something fails so we can diagnose faults.
  • Server logs: recording API requests, IP addresses, and timestamps for security and abuse prevention.
  • Billing records: subscription status, plan, invoices, and payment reference identifiers. We do not store card numbers, CVVs, UPI PINs or bank credentials. Payments are handled entirely by Razorpay (Section 5).

2.5 What We Do NOT Do

❌ We do NOT sell personal data.
🔒 We do NOT share Lead data between businesses.
🤖 We do NOT train AI/ML models on Lead data.
🚫 We do NOT serve third-party ads in the Service.

3. How We Use Personal Data

We process personal data for the following specific operational purposes:

  1. Create and operate your account and authenticate you.
  2. Provide core CRM functionality — capturing, assigning, tracking and reporting on leads.
  3. Send operational notifications: follow-up reminders, missed follow-up alerts, daily summaries and team invitations.
  4. Deliver and receive WhatsApp messages on behalf of a connected business.
  5. Import leads from connected sources you authorise, such as Meta Lead Ads, website forms and Google Sheets.
  6. Process subscription payments and maintain billing records.
  7. Maintain security, detect abuse, and diagnose faults.
  8. Comply with legal obligations and enforce our terms.
Lawful Basis: Our lawful basis for account data is the consent you give at sign-up and the necessity of performing our contract with you. For Lead data, the lawful basis is established by the subscribing business that collected it.

4. Notifications and Communications

We send service emails and push notifications that are necessary to operate the Service — sign-in codes, follow-up reminders, alerts and billing notices. These cannot be fully disabled while your account is active, though push notifications can be turned off on each device and reminder timing can be configured.

Reminder and alert emails respect configured quiet hours and are not sent overnight.

If we ever send product or marketing email, it will carry an unsubscribe link and opting out will not affect your use of the Service.

5. Sub-processors and Third Parties

We rely on the following providers. Each processes data only to deliver its specific function, and we remain accountable for account data throughout.

ProviderFunctionData Involved
SupabaseManaged PostgreSQL database and file storageAll application data and uploaded attachments
Amazon Web ServicesApplication hosting (Lambda, API Gateway), secrets management — region ap-south-1, MumbaiAll application data in transit and at rest
Meta PlatformsWhatsApp Cloud API; Meta Lead Ads importWhatsApp messages and media; lead form submissions
GoogleFirebase Cloud Messaging for push; Google Sheets API for optional lead syncDevice tokens, notification content; synced lead rows
RazorpayPayment processing and subscription billingBilling contact details and payment data (card details go directly to Razorpay)
SentryError monitoringDiagnostic context in failing requests
AWS SESTransactional email deliveryRecipient email address and message content

Our primary infrastructure is located in India (AWS ap-south-1, Mumbai). Some providers listed above operate globally and may process data outside India. Where that happens we rely on contractual safeguards, and transfers are made only to countries not restricted by the Government of India under Section 16 of the DPDP Act.

We may also disclose personal data where legally required — to comply with a valid legal order, enforce our terms, or protect rights and safety. In a business merger or asset sale, data may be transferred with prior notice.

6. Retention and Deletion

6.1 Lead Data

Each business configures its own retention period, which defaults to 365 days. Businesses may erase individual Leads at any time. When a Lead is erased on request, we retain a non-identifying proof-of-erasure record — a hashed reference, the business ID, timestamp and reason — so the business can demonstrate DPDP Act compliance. This record contains no personal data.

6.2 Account Deletion

You may request deletion of your account from within the application or via our web portal. When you submit a request:

  • Deletion is scheduled 30 days in the future, not performed immediately.
  • During those 30 days nothing is destroyed, and signing in again cancels the request.
  • Businesses you solely own are deactivated during the window so scheduled emails stop.
  • After 30 days a background process permanently deletes your profile, solely-owned businesses, and all associated leads, conversations, messages, attachments, memberships and invitations. This cascade is irreversible.
Initiate account deletion in the app (Settings -> Profile -> Delete Account) or visit our dedicated web page.
Account Deletion Portal ↗

6.3 Other Retention

  • Sign-in OTPs and refresh tokens expire automatically.
  • Billing and transaction records are retained as required by Indian tax law, typically eight years.
  • Server diagnostic logs are retained for a limited operational period and then purged.

7. Your Rights Under the DPDP Act

Under the Digital Personal Data Protection Act, 2023, as a Data Principal whose account data we hold as Data Fiduciary, you have the right to:

🔍 AccessObtain a summary of personal data processed about you and third-party identities with whom it was shared.
✏️ Correction & CompletionHave inaccurate or incomplete data updated. Most profile fields can be edited directly in the app.
🗑️ ErasureRequest deletion of your personal data, subject to legal and tax retention mandates.
📩 Grievance RedressalRaise a complaint with our Grievance Officer and receive a prompt response within 30 days.
👤 NominationNominate another individual to exercise your privacy rights in the event of death or incapacity.
↩️ Consent WithdrawalWithdraw consent at any time. Withdrawal does not affect prior lawful processing.

Converso also provides subscribing businesses with tools to export data and execute erasure requests from their own customers. We respond to verified requests within prescribed DPDP Act timelines.

8. Security Safeguards

We enforce strict enterprise security controls to safeguard all personal data:

🔒 Transit Encryption: HTTPS/TLS 1.3 for all API traffic.
🔑 At-Rest Encryption: AES-256-GCM for credentials.
🛡️ Passwordless Auth: One-time passcodes eliminate breach risks.
👥 RBAC Control: Role-based access per business team.
🏢 Tenant Isolation: Queries scoped strictly per business.
✍️ Webhook Verification: HMAC signatures on Meta/Razorpay.

In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in accordance with the DPDP Act and its rules.

9. Children's Data

The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal data of any individual under 18 years of age. Businesses using Converso must not enter data about children without verifiable parental consent as required by Section 9 of the DPDP Act. If we learn that we hold a child's data without such consent, we will delete it immediately.

10. Obligations for Subscribing Businesses

If you use Converso to store data about other people, you are the Data Fiduciary for that data. You are responsible for:

  • Giving your customers a clear notice and obtaining valid consent before entering their details.
  • Publishing your own privacy policy (Converso provides a settings field to record your policy URL).
  • Designating a contact for privacy queries (Converso provides fields for DPO name and contact email).
  • Responding to access, correction and erasure requests from your customers.
  • Using WhatsApp messaging only with recipients who have opted in, adhering to Meta's WhatsApp Business Messaging Policy.
  • Setting a lead retention period appropriate to your specific business purpose.

11. Changes to This Policy

We may update this Policy as the Service changes or legal regulations evolve. The "Last updated" date at the top of this document will be updated accordingly. For material changes, we will provide advance notice through the Service or by email before changes take effect. Continued use after the effective date constitutes acceptance of the revised Privacy Policy.

12. Contact and Grievance Redressal

For any privacy questions, rights requests, or complaints regarding personal data processing:

Grievance Officer:Grievance Officer, Thinkraft Technologies
Postal Address:Thinkraft Technologies, India

⏱️ We aim to acknowledge every grievance within 72 hours and resolve it within 30 days.

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.