๐ก๏ธ Privacy Policy
Privacy Policy
We are committed to protecting your personal data in accordance with the Digital Personal Data Protection Act 2023 (India), GDPR, and all applicable laws.
๐
Effective: 1 July 2025
๐ Last Reviewed: 1 July 2025
๐ Version 1.0
๐ฎ๐ณ DPDPA 2023
๐ช๐บ GDPR
๐บ๐ธ CCPA
IT Act 2000 & SPDI Rules 2011
๐ข
Data Fiduciary / Data Controller
WhizzAct Private Limited ("WhizzAct", "we", "us", "our") is the Data Fiduciary under the DPDPA 2023 and the Data Controller under GDPR for personal data processed through WhizzMeet. Our registered office is in India.
1 Who This Policy Applies To
This Privacy Policy applies to all individuals who:
- Workspace Admins โ organisations and individuals who create a WhizzMeet workspace.
- Members โ employees, contractors or guests added to a workspace.
- Meeting Participants โ anyone who joins a WhizzMeet video session.
- Website Visitors โ anyone who browses our platform or marketing pages.
Under the DPDPA 2023, you are a Data Principal. Under GDPR, you are a Data Subject.
2 Data We Collect
2.1 Data You Provide Directly
- Name, email address, phone number (for account registration)
- Organisation name, billing address, GST/tax identification number
- Payment details (processed by our payment processor โ not stored by us)
- Profile photo (optional)
- Meeting content you choose to record, transcribe, or share
2.2 Data Collected Automatically
- IP address and approximate geolocation (country/city)
- Browser type, operating system, device identifiers
- Meeting metadata: join/leave timestamps, duration, participant count
- Usage analytics: features used, session frequency
- Cookies and similar tracking technologies (see Cookie Policy)
2.3 Data from Third Parties
- Organisation details from payment processors (Cashfree Payments)
- SSO identity data if you log in via Google or Microsoft (with your consent)
๐ก
Data Minimisation
We collect only the minimum data necessary to provide WhizzMeet services. We do not sell your personal data.
3 How We Use Your Data
| Purpose | Data Used | Legal Basis |
| Provide meeting & workspace services | Account info, meeting metadata | Contract performance / Consent |
| Billing & subscription management | Email, org name, payment info | Contract performance / Legal obligation |
| Authentication & account security | Email, IP address, device info | Legitimate interests / Legal obligation |
| Product improvement & analytics | Usage data, anonymised telemetry | Legitimate interests / Consent |
| Customer support | Account info, support history | Contract performance |
| Sending transactional emails | Email address | Contract performance |
| Sending marketing communications | Email, name | Consent (opt-in only) |
| Compliance with legal obligations | As required by law | Legal obligation |
| Fraud detection & security | IP, device, usage patterns | Legitimate interests |
4 Legal Basis for Processing
Under DPDPA 2023 (India)
We process personal data on the following grounds permitted by the Digital Personal Data Protection Act 2023:
- Consent โ explicit, informed, specific and revocable consent obtained before processing.
- Legitimate Uses โ including purposes specified by the Central Government, employment-related processing, and compliance with Indian law.
Under GDPR (EEA/UK)
- Article 6(1)(a) โ Consent
- Article 6(1)(b) โ Performance of a contract
- Article 6(1)(c) โ Compliance with a legal obligation
- Article 6(1)(f) โ Legitimate interests (security, fraud prevention, analytics)
Under IT Act 2000 & SPDI Rules 2011 (India)
Sensitive Personal Data or Information (SPDI) โ including financial data, health data and biometrics โ is collected only with explicit consent and protected under stricter controls per Rule 5 of the SPDI Rules 2011.
5 Consent Management
Under the DPDPA 2023, consent must be free, specific, informed, unconditional and unambiguous. We honour this by:
- Presenting a clear consent notice before collecting personal data.
- Never bundling consent with Terms of Service acceptance for optional processing.
- Allowing you to withdraw consent at any time via your account settings or by emailing privacy@whizzact.com.
- Maintaining a verifiable consent record with timestamp and mechanism.
โ ๏ธ
Withdrawal of Consent
Withdrawing consent for essential processing (e.g., account authentication) will result in your account being deactivated, as we cannot provide the service without that data.
6 Data Sharing & Third Parties
We do not sell your personal data. We share data only with:
| Recipient | Purpose | Location | Safeguard |
| Cashfree Payments | Payment processing & subscription billing | India | PCI-DSS compliant; DPDPA Data Processor agreement |
| Amazon Web Services (AWS) | Cloud hosting & infrastructure | India (ap-south-1) | Data Processing Addendum; ISO 27001 |
| Google Fonts / CDN | Font delivery | Global | No personal data shared; GDPR-compliant |
| Email delivery provider | Transactional & marketing emails | India / US | Data Processor agreement; SCCs |
| Law enforcement / regulators | Compliance with court orders, MEITY directions | India | Legal obligation only; minimised disclosure |
All third-party processors are bound by Data Processing Agreements and may only process personal data on our documented instructions.
7 Cross-Border Data Transfers
WhizzMeet primarily processes and stores data in India. Where data is transferred outside India or the EEA, we apply the following safeguards:
- DPDPA 2023: Transfers to countries notified by the Central Government as permissible under Section 16. Until such notification, we default to data residency in India.
- GDPR: Standard Contractual Clauses (SCCs โ 2021 EU Commission version) or adequacy decisions under Article 45 GDPR.
- SPDI Rules: Transfers only to countries with equivalent data protection levels, under contract.
๐ฎ๐ณ
Data Residency Commitment
All meeting data, recordings and user account data are stored on servers physically located in India by default.
8 Data Retention
| Data Type | Retention Period | Reason |
| Account & profile data | Duration of account + 90 days | Service delivery; account recovery |
| Meeting metadata (logs) | 12 months | Analytics; dispute resolution |
| Recordings (if enabled) | Until deleted by admin (max 1 year) | Customer control |
| Billing & invoice records | 7 years | Legal obligation โ Indian Companies Act; GST |
| Support tickets | 3 years | Quality assurance; legal disputes |
| Consent records | 3 years after last interaction | DPDPA compliance; audit trail |
| Security & access logs | 180 days | Security monitoring; IT Act compliance |
| Anonymised analytics | Indefinite | Product improvement (not personal data) |
After the applicable retention period, data is securely deleted or anonymised using industry-standard methods.
9 Data Security
We implement technical and organisational measures (TOMs) appropriate to the risk:
- Encryption in transit: TLS 1.2+ for all data in transit; DTLS for WebRTC media streams.
- Encryption at rest: AES-256 for stored data and database backups.
- Access control: Role-based access; multi-factor authentication for admin accounts.
- Network security: Firewalls, DDoS protection, intrusion detection.
- Employee training: All staff handling personal data receive mandatory data protection training.
- Penetration testing: Periodic security audits and vulnerability assessments.
- Breach response: Incident response plan; notification within 72 hours of discovery (GDPR Art. 33; DPDPA breach notification obligations).
โ ๏ธ
Report a Security Issue
If you discover a vulnerability or suspect a data breach, contact us immediately at
security@whizzact.com.
10 Your Rights Under DPDPA 2023
As a Data Principal under the Digital Personal Data Protection Act 2023, you have the following rights:
๐
Right to Information (ยง11)
Know what personal data we hold about you, how it is processed and with whom it is shared.
โ๏ธ
Right to Correction (ยง12)
Request correction, completion or updating of inaccurate or incomplete personal data.
๐๏ธ
Right to Erasure (ยง12)
Request deletion of your personal data where consent is withdrawn and retention is not required by law.
๐
Right to Grievance Redressal (ยง13)
Lodge a complaint with our Grievance Officer. If unresolved, approach the Data Protection Board of India.
๐งโ๐ผ
Right of Nomination (ยง14)
Nominate a person who may exercise your rights on your behalf in the event of death or incapacity.
โฉ๏ธ
Right to Withdraw Consent
Withdraw previously given consent at any time. Processing prior to withdrawal remains lawful.
To exercise any right, email privacy@whizzact.com. We will respond within 30 days as required by the DPDPA.
11 Your Rights Under GDPR (EEA/UK Users)
๐๏ธ
Right of Access (Art. 15)
Obtain a copy of the personal data we hold about you.
โ๏ธ
Right to Rectification (Art. 16)
Correct inaccurate or incomplete data without undue delay.
๐๏ธ
Right to Erasure (Art. 17)
Request deletion ("right to be forgotten") where no lawful basis for continued processing exists.
โธ๏ธ
Right to Restriction (Art. 18)
Restrict processing while accuracy is contested or objection is pending.
๐ฆ
Right to Portability (Art. 20)
Receive your data in a structured, machine-readable format (JSON/CSV).
๐ซ
Right to Object (Art. 21)
Object to processing based on legitimate interests, including profiling and direct marketing.
EEA/UK users may also lodge a complaint with your local supervisory authority (e.g., ICO in the UK, CNIL in France). We will respond to requests within 30 days (extendable to 90 days for complex requests).
12 Children's Privacy
WhizzMeet is not directed at children under the age of 18 years. Under the DPDPA 2023:
- We do not knowingly collect personal data from individuals under 18 without verifiable parental or guardian consent.
- Organisations deploying WhizzMeet for educational purposes involving minors must obtain appropriate consent and inform us at privacy@whizzact.com.
- We will not process data of a child for behavioural monitoring, targeted advertising, or any purpose that may be detrimental to the well-being of the child (DPDPA ยง9).
โ ๏ธ
EdTech & Schools
If you are an educational institution using WhizzMeet and your users include students under 18, please contact us to execute a supplementary Data Protection Agreement.
13 Grievance Officer
In accordance with the Information Technology Act 2000, the SPDI Rules 2011, the DPDPA 2023, and the IT (Intermediary Guidelines & Digital Media Ethics Code) Rules 2021, we have appointed a Grievance Officer:
14 Changes to This Policy
We may update this Privacy Policy to reflect changes in law, our services, or data practices. When we make material changes, we will:
- Post the updated policy on this page with a revised "Last Reviewed" date.
- Send an email notification to all active workspace admins at least 14 days before the changes take effect.
- Display an in-dashboard notification for significant changes.
Continued use of WhizzMeet after the effective date constitutes acceptance of the revised policy.