Privacy Policy
SD Ventures ("we", "us", "our") operates an AI receptionist platform that helps businesses ("Clients") answer their customers ("End Customers") on WhatsApp. This policy explains what personal data we handle, why, and what rights you have under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
Two kinds of people this policy covers
We handle two categories of personal data, differently:
- Clients — the businesses (and their staff) who sign up to use our dashboard. For this data, we act as the Data Fiduciary.
- End Customers — people who message a Client's WhatsApp number. For this data, we act as a Data Processor on behalf of the Client, who remains responsible for their own customer relationships.
What we collect
From Clients: name, email address, a securely hashed password (we never store or log plaintext passwords), and the business information a Client chooses to provide — address, hours, product catalog, FAQs, and similar content used to answer their customers.
From End Customers: WhatsApp phone number, display name (if shared via WhatsApp), and the content of messages exchanged with the Client's AI receptionist, including any images or files sent.
How we use it
We use this data to operate the service: answering End Customer questions (first from the Client's own stored business data, then from Claude, an AI model, grounded only in that same data — never inventing prices, policies, or facts not present in it), routing conversations, scheduling follow-ups, and providing Clients with analytics about their own conversations.
Who else sees it
We share data only with the service providers necessary to run the platform, each acting under contract:
- Meta / WhatsApp, via our Business Solution Provider — to deliver and receive WhatsApp messages.
- Anthropic (Claude API) — to generate AI responses. Only the specific business data retrieved for a given question is sent; conversation content is not used to train Anthropic's models.
- Cloud storage and hosting providers — to store files/images and run the application.
We do not sell personal data, and we do not use End Customer conversation content for advertising.
How we protect it
Every Client's data is isolated at the database level using PostgreSQL Row-Level Security, so one Client's data is never returned by a query scoped to another. Data is encrypted at rest and in transit (HTTPS/TLS). Our public webhook endpoint verifies a cryptographic signature on every incoming message before processing it, and is rate-limited.
How long we keep it
We retain personal data only as long as necessary to provide the service or as required by law. [A specific retention period for conversation data is still being finalized — this section will be updated once set.]
Your rights
Under the DPDP Act, you have the right to access, correct, and request erasure of your personal data, and to withdraw consent where consent is the basis for processing. To exercise these rights, or to raise a grievance, contact our Grievance Officer at info@sdventure.in.
If you are an End Customer, you can also make this request through the Client business you messaged — we will act on instructions from the Client as the primary point of contact for their own customers.
Cookies
Our customer-facing product does not use advertising or tracking cookies. Our dashboard uses only the minimal session cookies necessary to keep you logged in.
Children's data
Our service is intended for use by businesses and their adult customers. We do not knowingly direct this service at children.
Changes to this policy
We may update this policy as the service evolves. Material changes will be reflected here with an updated revision date.
Contact
Questions about this policy or how your data is handled: info@sdventure.in.
SD Ventures
Kh-16, Sabarmati Colony, Kota, Rajasthan 324006, India