Privacy Policy
Effective date | Last updated | Contact
17 September 2026 | 17 September 2026 | [email protected] | +91 95581 33552
AiToolkit respects privacy and is committed to handling personal data in a transparent, secure and responsible manner. This Privacy Policy explains what information AiToolkit collects or receives, why it is processed, how it may be shared, how long it is retained, and the choices available to users of the AiToolkit website, WhatsApp API CRM, web application, mobile application, support channels and related services (collectively, the “Services”).
By using the Services, you acknowledge this Privacy Policy. If you use AiToolkit on behalf of a company or other organization, you also confirm that you are authorized to provide information to AiToolkit and to configure the Services for that organization.
1.1 Privacy roles: AiToolkit, business customers and contacts
AiToolkit may act in different privacy roles depending on the information involved:
- For account registration, subscription, billing, security, support, website usage and AiToolkit’s own business operations, AiToolkit generally determines why and how personal data is processed and acts as the relevant controller/data fiduciary where those concepts apply.
- For contacts, message content, CRM records, customer lists, campaign data and other information uploaded or generated by a business customer for its own communications, the business customer generally decides the purpose of processing. AiToolkit normally processes that information on the customer’s instructions as a processor/service provider.
- A business using AiToolkit remains responsible for having a lawful basis to collect, upload, use and communicate with its contacts, including obtaining valid consent or opt-in where required and honoring opt-out requests.
If you are an individual who receives a WhatsApp message from a business that uses AiToolkit, the business that contacted you may be the primary controller of your data. You may contact that business directly for rights requests. AiToolkit will assist its business customer where required and will separately handle any information that AiToolkit controls directly.
1.2 Information we collect or receive
A. Account and profile information
- Name, business name, email address, mobile or WhatsApp number, login identifier, role, team membership, profile settings, language and account preferences.
- Authentication and security information such as hashed passwords, verification status, login timestamps, session identifiers, device/session records and two-factor authentication status when enabled.
B. Business and CRM information
- Contacts, names, phone numbers, tags, custom fields, notes, lead information, consent or opt-out status, conversation assignments, internal comments, workflow status and CRM activity created or uploaded by authorized users.
- WhatsApp messaging data made available through authorized integrations, which may include message content, media, template details, message IDs, sender/recipient identifiers, timestamps, delivery/read status, replies, campaign or automation events and aggregated messaging metrics.
- Business profile details, WhatsApp Business Account information, phone-number configuration and permissions that a user authorizes through Meta/WhatsApp or another supported provider.
C. AI and automation data
- Prompts, instructions, knowledge-base content, conversation context, workflow inputs and outputs when a customer enables AI, chatbot, classification, summarization, drafting or automation features.
- AiToolkit does not treat customer WhatsApp message content as permission to train a general-purpose AI model. Customer data will not be used to train or improve third-party general-purpose AI models unless a separate, explicit lawful arrangement allows it and the applicable WhatsApp/Meta terms permit it.
D. Device, application and technical information
- – IP address, approximate network-derived location, browser type, operating system, app version, device model, language, time zone, crash reports, diagnostics, log data, feature usage, pages/screens viewed and security events.
- Device permissions such as notifications, contacts, camera, microphone or file/media access are requested only when relevant to a feature. The exact permissions depend on device, app version and enabled functionality. Users can manage most permissions through device settings.
E. Payments, subscriptions and transaction information
- Plan, invoice, subscription status, billing address if supplied, tax information where required, transaction amount, currency, payment status, refund status and payment reference.
- If payment is handled by a third-party payment processor, AiToolkit may receive a token, transaction reference or limited card descriptor rather than the full card number or security code.
F. Support and communications
- Information you send to support through email, phone or other support channels, including attachments, screenshots, issue descriptions and communications. AiToolkit can be contacted at [email protected] or +91 95581 33552.
G. Website cookies and similar technologies
- Essential session/security cookies and, where enabled, preference or analytics technologies as described in the Cookie Policy. Optional non-essential cookies are used subject to applicable consent requirements.
1.3 Why we process information
Purpose | Examples
Provide the Services: Create accounts, operate CRM features, sync authorized integrations, route conversations, run workflows, display analytics and maintain user settings.
Communications: Send service notices, verification messages, security alerts, invoices, renewal notices and support responses.
Security and abuse prevention: Authenticate users, detect suspicious activity, prevent fraud, enforce access controls, investigate misuse and protect users and systems.
Customer-requested automation: Execute campaigns, scheduled actions, chatbots, AI-assisted workflows or integrations configured by the customer.
Improve reliability: Troubleshoot errors, measure feature performance, maintain logs, understand product usage and improve usability.
Billing and administration: Process subscriptions, reconcile payments, manage taxes, handle refunds and maintain required financial records.
Legal compliance: Respond to lawful requests, preserve records when legally required, enforce agreements and protect legal rights.
Marketing with appropriate choice: Send product news or offers to business users where permitted, with unsubscribe/opt-out mechanisms where required.
1.4 Lawful bases and consent
Depending on location and the type of processing, AiToolkit may rely on performance of a contract, steps requested before entering a contract, consent, compliance with legal obligations, protection of rights and security, or legitimate interests recognized by applicable law. Where consent is required, it should be specific and informed, and users may withdraw it through available settings or by contacting AiToolkit. Withdrawal does not affect processing that was lawful before withdrawal and may limit features that depend on the relevant data.
Business customers are responsible for ensuring that their own contacts receive legally required notices and that the customer has valid permission to send business communications, especially for marketing, bulk messaging, automated messages and template messages.
1.5 WhatsApp, Meta and other third-party services
AiToolkit may connect with the WhatsApp Business Platform and other third-party services selected by the customer. When a customer authorizes an integration, information may pass between AiToolkit and that third party as needed to provide the requested integration. Third-party platforms process data under their own terms, privacy policies and technical rules. AiToolkit does not control the independent processing performed by Meta, WhatsApp, payment providers, cloud providers or other third-party services outside AiToolkit’s systems.
Customers must comply with the WhatsApp Business Terms, WhatsApp Business Messaging Policy, applicable Meta terms and technical documentation, as amended from time to time. AiToolkit may limit, suspend or modify functionality if required to remain compatible with platform rules or API changes.
1.6 Service providers and disclosures
AiToolkit may share information only as reasonably necessary with categories of recipients such as cloud hosting and infrastructure providers, security and monitoring vendors, communications providers, payment processors, analytics or crash-reporting providers, customer-support tools, authorized AI or automation providers, professional advisers, and integrations specifically chosen by the customer.
AiToolkit may also disclose information when reasonably necessary to comply with law, respond to valid legal process, protect users or the public, investigate fraud or abuse, enforce agreements, or support a merger, financing, acquisition, reorganization or sale of assets subject to appropriate confidentiality and legal safeguards.
AiToolkit does not sell customer CRM data or WhatsApp message content as a data-broker product. If AiToolkit’s business model changes in a way that legally constitutes a sale or targeted-sharing activity, this Policy and applicable choice mechanisms will be updated before that processing is used where required.
1.7 International processing and transfers
AiToolkit, its customers and service providers may operate in different countries. Personal data may therefore be processed outside the country where the user or message recipient is located. Where required, AiToolkit uses appropriate contractual, organizational or legal transfer mechanisms and limits access to what is necessary for the relevant service. Customers should also evaluate cross-border transfer requirements applicable to the data they control.
1.8 Security
AiToolkit uses administrative, technical and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, loss or destruction. Measures may include encryption in transit, controlled access, authentication, session management, logging, monitoring, backups, role-based permissions and secure development practices. No internet service can guarantee absolute security, and users are responsible for protecting credentials, devices and administrator access.
- Use strong, unique passwords and enable additional authentication protections when available.
- Remove team members who no longer need access and review administrator permissions regularly.
- Do not share API keys, access tokens, passwords or verification codes in unsecured channels.
- Report suspected compromise promptly to [email protected].
1.9 Data retention
AiToolkit keeps information only for as long as reasonably necessary for the purpose for which it was collected, to provide the Services, meet contractual obligations, maintain security, resolve disputes and satisfy legal requirements. More detailed default periods appear in the Data Retention Policy. Customer-configurable deletion or export options may shorten retention for certain CRM data.
1.10 Your privacy choices and rights
Depending on applicable law, you may have rights to request access, correction, updating, deletion, restriction, objection, withdrawal of consent, portability, information about processing, or grievance/complaint handling. Rights are subject to identity verification and lawful exceptions.
- Account deletion: use the in-app account-deletion feature where available or follow the Account Deletion page.
- Data deletion without deleting the entire account: follow the Data Deletion Request page.
- Marketing choices: use unsubscribe/opt-out controls in the relevant communication or contact support.
- Device permissions: manage permissions in Android/iOS settings.
- Business contact rights: if a business using AiToolkit contacted you, you may contact that business directly; AiToolkit will support the business when required.
1.11 Children
AiToolkit is designed for business and professional use and is not intended for children. Users must be at least 18 years old or the legal age required to enter a binding business agreement in their jurisdiction. Customers must not intentionally use AiToolkit to collect children’s personal data unless they have a lawful basis, appropriate safeguards and any verifiable parental/guardian permissions required by law.
1.12 Changes to this Privacy Policy
AiToolkit may update this Privacy Policy to reflect changes in the Services, technology, laws, third-party platform requirements or data practices. Material changes will be communicated through the website, app, account notice, email or another reasonable method when required. The “Last updated” date identifies the current version.
1.13 Contact and grievances
Privacy questions, rights requests or grievances may be submitted to AiToolkit at [email protected] or +91 95581 33552. Include enough information to identify the relevant account or relationship, but do not send passwords, one-time passwords or full payment-card details. AiToolkit may request additional verification before acting on a request.


