Special Launch1,000 Free WhatsApp Conversations on Signup • Zero Setup FeeClaim Free Trial →
AsanConnectWhatsApp Cloud API
AsanPay Group ComplianceMeta Cloud API VerifiedDPDP Act 2023 India

Privacy Policy & Data Protection

Effective: 18 September 2026Version 2.4Ref: AC-LEGAL-2025

This Privacy Policy outlines how AsanConnect (an enterprise communications subsidiary of AsanPay Innovation Pvt. Ltd.) collects, safeguards, and processes personal data. Formulated under India's Digital Personal Data Protection (DPDP) Act 2023 and Meta Platform policies, this document provides complete transparency regarding your communications metadata and security.

Privacy Guarantees at a Glance

Zero Data Selling: We never sell, monetize, or broker personal information to third-party ad networks.
End-to-End Encryption:All WhatsApp Cloud API messages travel encrypted across Meta's global network.
User Control: 1-click data deletion and opt-out rights provided under Indian DPDP Act guidelines.
Fintech-Grade Isolation: Sensitive financial credentials are never logged or exposed in WhatsApp chat logs.

1. Corporate Identity & Group Relationship

AsanConnect provides mission-critical enterprise customer-communication services for the AsanPay Innovation Pvt. Ltd. group, including one-time passwords (OTP), automated WhatsApp notifications, and customer support infrastructure.

The parent company is AsanPay Innovation Pvt. Ltd. (fintech portal: https://asanpay.in). For legal or compliance concerns, our Grievance Desk can be reached at support@asanpay.in.

2. Categories of Information Collected

Depending on your interaction with AsanConnect, we may collect and process:

  • Contact Attributes: Name, work email address, and company name provided during demo or trial onboarding.
  • Telecommunication Identifiers: Mobile number used for WhatsApp messaging, OTP authentication, or fallback SMS routing.
  • Authentication Metadata: One-time password cryptographic tokens and verification timestamps (never plaintext OTP codes).
  • Transactional Signals: High-level transaction statuses (e.g. Success, Pending, Failed) required to trigger order status alerts. Full payment card numbers or CVVs are never processed on AsanConnect.
  • Technical Diagnostics: IP address, user agent, and API latency metrics for fraud prevention and Meta Cloud API uptime monitoring.

3. Purpose and Legal Grounds for Processing

We process personal information solely for legitimate enterprise purposes, including:

  • Delivering critical account authentication (1-tap WhatsApp OTPs).
  • Sending requested transactional alerts (e.g. shipping updates, payment receipts).
  • Multi-agent customer support routing via the Shared Team Inbox.
  • Preventing bot spam, abuse, phishing attempts, and unauthorized account access.

4. WhatsApp Cloud API & Meta Processing

Messages sent via AsanConnect utilize the Official Meta WhatsApp Cloud API. Templates conform strictly to Meta's category rules (Authentication, Utility, Service, and Marketing).

Meta operates as an independent infrastructure processor governed by Meta Business Platform Terms and GDPR / DPDP adequacy standards.

5. Data Retention & Erasure

We retain personal data only as long as necessary to fulfill operational obligations or satisfy Indian regulatory standards (such as statutory financial audit trails).

You may exercise your right to erasure at any time. For detailed instructions on removing your telephone number or logs, visit our User Data Deletion Portal.

6. Security & Encryption Standards

All data in transit is protected using TLS 1.3 protocol with 256-bit encryption. System secrets, Meta API tokens, and webhooks reside in hardware-security-module (HSM) backed key vaults with automated rotation.

Corporate Structure

AsanConnect Communications

AsanConnect operates as the specialized enterprise communications technology subsidiary of AsanPay Innovation Pvt. Ltd.

Parent Company: AsanPay Innovation Pvt. Ltd.

https://asanpay.in

Grievance & DPO Desk

Data Protection Officer

For privacy inquiries, rights enforcement, or statutory notices under the Digital Personal Data Protection Act:

Average legal response: < 48 business hours

Security Enforced

TLS 1.3 in-transit, 256-bit AES encryption at rest, and zero storage of plain text OTPs or payment card credentials.