๐Ÿ›ก๏ธ Privacy Policy

Privacy Policy

We are committed to protecting your personal data in accordance with the Digital Personal Data Protection Act 2023 (India), GDPR, and all applicable laws.

๐Ÿ“… Effective: 1 July 2025 ๐Ÿ”„ Last Reviewed: 1 July 2025 ๐Ÿ“Œ Version 1.0
๐Ÿ‡ฎ๐Ÿ‡ณ DPDPA 2023 ๐Ÿ‡ช๐Ÿ‡บ GDPR ๐Ÿ‡บ๐Ÿ‡ธ CCPA IT Act 2000 & SPDI Rules 2011
๐Ÿข
Data Fiduciary / Data Controller WhizzAct Private Limited ("WhizzAct", "we", "us", "our") is the Data Fiduciary under the DPDPA 2023 and the Data Controller under GDPR for personal data processed through WhizzMeet. Our registered office is in India.

Table of Contents

  1. Who This Policy Applies To
  2. Data We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing
  5. Consent Management
  6. Data Sharing & Third Parties
  7. Cross-Border Data Transfers
  8. Data Retention
  9. Data Security
  10. Your Rights (DPDPA)
  11. Your Rights (GDPR)
  12. Children's Privacy
  13. Grievance Officer
  14. Changes to This Policy
  15. Contact Us

1 Who This Policy Applies To

This Privacy Policy applies to all individuals who:

Under the DPDPA 2023, you are a Data Principal. Under GDPR, you are a Data Subject.

2 Data We Collect

2.1 Data You Provide Directly

2.2 Data Collected Automatically

2.3 Data from Third Parties

๐Ÿ’ก
Data Minimisation We collect only the minimum data necessary to provide WhizzMeet services. We do not sell your personal data.

3 How We Use Your Data

PurposeData UsedLegal Basis
Provide meeting & workspace servicesAccount info, meeting metadataContract performance / Consent
Billing & subscription managementEmail, org name, payment infoContract performance / Legal obligation
Authentication & account securityEmail, IP address, device infoLegitimate interests / Legal obligation
Product improvement & analyticsUsage data, anonymised telemetryLegitimate interests / Consent
Customer supportAccount info, support historyContract performance
Sending transactional emailsEmail addressContract performance
Sending marketing communicationsEmail, nameConsent (opt-in only)
Compliance with legal obligationsAs required by lawLegal obligation
Fraud detection & securityIP, device, usage patternsLegitimate interests

4 Legal Basis for Processing

Under DPDPA 2023 (India)

We process personal data on the following grounds permitted by the Digital Personal Data Protection Act 2023:

Under GDPR (EEA/UK)

Under IT Act 2000 & SPDI Rules 2011 (India)

Sensitive Personal Data or Information (SPDI) โ€” including financial data, health data and biometrics โ€” is collected only with explicit consent and protected under stricter controls per Rule 5 of the SPDI Rules 2011.

5 Consent Management

Under the DPDPA 2023, consent must be free, specific, informed, unconditional and unambiguous. We honour this by:

โš ๏ธ
Withdrawal of Consent Withdrawing consent for essential processing (e.g., account authentication) will result in your account being deactivated, as we cannot provide the service without that data.

6 Data Sharing & Third Parties

We do not sell your personal data. We share data only with:

RecipientPurposeLocationSafeguard
Cashfree PaymentsPayment processing & subscription billingIndiaPCI-DSS compliant; DPDPA Data Processor agreement
Amazon Web Services (AWS)Cloud hosting & infrastructureIndia (ap-south-1)Data Processing Addendum; ISO 27001
Google Fonts / CDNFont deliveryGlobalNo personal data shared; GDPR-compliant
Email delivery providerTransactional & marketing emailsIndia / USData Processor agreement; SCCs
Law enforcement / regulatorsCompliance with court orders, MEITY directionsIndiaLegal obligation only; minimised disclosure

All third-party processors are bound by Data Processing Agreements and may only process personal data on our documented instructions.

7 Cross-Border Data Transfers

WhizzMeet primarily processes and stores data in India. Where data is transferred outside India or the EEA, we apply the following safeguards:

๐Ÿ‡ฎ๐Ÿ‡ณ
Data Residency Commitment All meeting data, recordings and user account data are stored on servers physically located in India by default.

8 Data Retention

Data TypeRetention PeriodReason
Account & profile dataDuration of account + 90 daysService delivery; account recovery
Meeting metadata (logs)12 monthsAnalytics; dispute resolution
Recordings (if enabled)Until deleted by admin (max 1 year)Customer control
Billing & invoice records7 yearsLegal obligation โ€” Indian Companies Act; GST
Support tickets3 yearsQuality assurance; legal disputes
Consent records3 years after last interactionDPDPA compliance; audit trail
Security & access logs180 daysSecurity monitoring; IT Act compliance
Anonymised analyticsIndefiniteProduct improvement (not personal data)

After the applicable retention period, data is securely deleted or anonymised using industry-standard methods.

9 Data Security

We implement technical and organisational measures (TOMs) appropriate to the risk:

โš ๏ธ
Report a Security Issue If you discover a vulnerability or suspect a data breach, contact us immediately at security@whizzact.com.

10 Your Rights Under DPDPA 2023

As a Data Principal under the Digital Personal Data Protection Act 2023, you have the following rights:

๐Ÿ“„

Right to Information (ยง11)

Know what personal data we hold about you, how it is processed and with whom it is shared.

โœ๏ธ

Right to Correction (ยง12)

Request correction, completion or updating of inaccurate or incomplete personal data.

๐Ÿ—‘๏ธ

Right to Erasure (ยง12)

Request deletion of your personal data where consent is withdrawn and retention is not required by law.

๐Ÿ™‹

Right to Grievance Redressal (ยง13)

Lodge a complaint with our Grievance Officer. If unresolved, approach the Data Protection Board of India.

๐Ÿง‘โ€๐Ÿ’ผ

Right of Nomination (ยง14)

Nominate a person who may exercise your rights on your behalf in the event of death or incapacity.

โ†ฉ๏ธ

Right to Withdraw Consent

Withdraw previously given consent at any time. Processing prior to withdrawal remains lawful.

To exercise any right, email privacy@whizzact.com. We will respond within 30 days as required by the DPDPA.

11 Your Rights Under GDPR (EEA/UK Users)

๐Ÿ‘๏ธ

Right of Access (Art. 15)

Obtain a copy of the personal data we hold about you.

โœ๏ธ

Right to Rectification (Art. 16)

Correct inaccurate or incomplete data without undue delay.

๐Ÿ—‘๏ธ

Right to Erasure (Art. 17)

Request deletion ("right to be forgotten") where no lawful basis for continued processing exists.

โธ๏ธ

Right to Restriction (Art. 18)

Restrict processing while accuracy is contested or objection is pending.

๐Ÿ“ฆ

Right to Portability (Art. 20)

Receive your data in a structured, machine-readable format (JSON/CSV).

๐Ÿšซ

Right to Object (Art. 21)

Object to processing based on legitimate interests, including profiling and direct marketing.

EEA/UK users may also lodge a complaint with your local supervisory authority (e.g., ICO in the UK, CNIL in France). We will respond to requests within 30 days (extendable to 90 days for complex requests).

12 Children's Privacy

WhizzMeet is not directed at children under the age of 18 years. Under the DPDPA 2023:

โš ๏ธ
EdTech & Schools If you are an educational institution using WhizzMeet and your users include students under 18, please contact us to execute a supplementary Data Protection Agreement.

13 Grievance Officer

In accordance with the Information Technology Act 2000, the SPDI Rules 2011, the DPDPA 2023, and the IT (Intermediary Guidelines & Digital Media Ethics Code) Rules 2021, we have appointed a Grievance Officer:

Grievance Officer

Name
Grievance Officer, WhizzAct Private Limited
Response Time
Within 30 days of receipt
Escalation
Data Protection Board of India (once constituted)

14 Changes to This Policy

We may update this Privacy Policy to reflect changes in law, our services, or data practices. When we make material changes, we will:

Continued use of WhizzMeet after the effective date constitutes acceptance of the revised policy.

15 Contact Us

Get in Touch

Company
WhizzAct Private Limited
Privacy Queries
Grievance Officer
Security Issues
General Support