vedhasAI

Privacy Policy

What {{brand}} collects, why, who we share it with, how long we keep it, and how to get it deleted.

Last updated: 17 September 2026 · Effective: 17 September 2026

Who we are

TODO_LEGAL_ENTITY_NAME operates vedhasAI, an AI sales and CRM platform for businesses that sell through conversations on WhatsApp, Instagram, Facebook Messenger and their own websites.

This policy covers the vedhasAI website at https://vedhasai.com, the vedhasAI application at https://vedhasai.com, our APIs, and the support we provide around them. It does not cover other companies' websites or services that we link to.

Our role: your data and your customers' data

Two different sets of people appear in this policy, and our responsibilities differ for each.

You, the business. When you visit this website or hold a vedhasAI account, we decide what data is collected and why. Under India's Digital Personal Data Protection Act, 2023 we are the Data Fiduciary for that data. In GDPR language, we are the controller.

Your customers. When someone messages your business on WhatsApp, Instagram, Messenger or your website chat, that conversation belongs to your business. You decide what is collected, what the AI is allowed to do and how long the data stays. We process it on your instructions, as your Data Processor. Our Data Processing Addendum sets out those terms.

A concrete example: a customer in Noida messages a laptop shop about a ThinkPad. The shop is the Data Fiduciary for that customer's phone number, messages and budget. vedhasAI stores and processes them so the shop's AI agent can reply and its CRM can keep a record. If that customer asks for their data to be deleted, we act on the shop's instruction, and we will help the shop respond.

Information we collect

| Category | Examples | Source | Purpose | Basis | Retention | |---|---|---|---|---|---| | Account information | Name, email, mobile number, business name, website, password (stored hashed, never in plain text) | You | Create and secure your account | Contract, consent | Account life + 90 days | | Google sign-in data | Name, email address, profile picture, Google account ID | Google, when you choose Sign in with Google | Identify you and create or match your account | Consent | Account life + 90 days | | Verification and security | One-time codes (short-lived), login history (date, time, IP address, device and browser) | You, your device | Verify it is you; investigate abuse | Legitimate use, legal duty | Codes: minutes. Logs: 180 days | | Business configuration | Business profile, team members, roles, prompts, lead fields, follow-up settings | You | Run the service the way you configured it | Contract | Workspace life | | WhatsApp Business Platform data | WhatsApp Business Account ID, phone number IDs, message templates, catalogue data, customer messages and media, customer WhatsApp profile name and number, message delivery status | Meta, on your instruction | Send and receive messages on the numbers you connect | Your instruction (we are processor) | Until you delete it or close the workspace | | Messenger and Instagram data | Messages and media, page-scoped and Instagram-scoped user IDs, Page and Instagram account IDs | Meta, on your instruction | Reply on the pages and accounts you connect | Your instruction | Until you delete it or close the workspace | | Ad referral data | For chats started from Click-to-WhatsApp, Messenger or Instagram ads: ad ID, ad headline and body, campaign and ad set names and IDs, click ID | Meta | Show which ad produced each lead | Your instruction | Until you delete it or close the workspace | | Facebook Lead Ads | Form answers submitted by people who fill your lead forms (for example name, phone, email, UTM fields), form ID, ad ID | Meta | Create leads automatically from your lead forms | Your instruction | Until you delete it or close the workspace | | Google Ads data (early access) | Customer ID and name; campaign, ad group, ad and keyword names, IDs and statuses; cost, impressions, clicks, conversions, conversion value | Google, after you connect an account | Show spend beside your real leads and sales | Consent | Deleted within 30 days of disconnecting | | Meta ads data (early access) | Ad account ID and name; campaign, ad set and ad names, IDs and statuses; spend, impressions, reach, clicks, leads, conversions | Meta, after you connect an account | Same as above | Consent | Deleted within 30 days of disconnecting | | Website tracking script data | A random reference ID stored in a cookie, UTM parameters, page URL; optionally approximate location from IP address, or precise location only if the visitor grants browser permission | Your website visitors' browsers | Tie a website visit to the chat it produced | Your instruction; visitor consent where required | Until you delete it or close the workspace | | Website chat widget data | Visitor ID, page URL, referrer, browser type, messages, and name or mobile number if the visitor provides them | Your website visitors | Run the chat widget on your site | Your instruction | Until you delete it or close the workspace | | Lead capture webhooks | The fields your forms or tools send (for example name, phone, email, UTM values) | Your systems | Create leads from your own forms, Zapier or Pabbly | Your instruction | Until you delete it or close the workspace | | Inventory and catalogue | Products or services, prices, specifications and images you upload | You | Let the AI answer from real stock | Contract | Workspace life | | AI-generated data | Replies, conversation summaries, extracted lead details, follow-up decisions, usage and token logs | Generated by the service | Provide the AI features and show you what they cost | Contract | Workspace life | | Our website visitors | Contact form details; cookie and analytics data | You, your browser | Answer your enquiry; understand which pages help | Consent | Enquiries: 24 months. Cookies: see the Cookie Policy |

We do not ask for, and the service is not designed to hold, government identity numbers, payment card numbers, health records or other special-category data. Do not put them into lead fields or prompts.

How we use information

  • Create your account, verify it, and keep it secure.
  • Send and receive messages on the channels you connect.
  • Generate AI replies, conversation summaries and extracted lead details for your workspace.
  • Create and update leads, and remove duplicates.
  • Run follow-ups at the intervals you set, and stop them when your rules say to stop.
  • Show which ad, page or form produced each lead, and (in early access) what each campaign cost.
  • Provide support when you ask for it.
  • Detect and prevent abuse, fraud and security incidents.
  • Meet legal, tax and regulatory obligations.
  • Improve the service using aggregated or de-identified usage metrics that do not identify any person.

We do not sell personal data. We do not use customer conversation content, Google user data or Meta Platform Data for advertising, including retargeting or personalised advertising.

How AI is used

To generate a reply, a summary or an extracted lead field, we send the relevant part of the conversation and the business data it needs (for example matching catalogue items) to our AI model provider, listed in the sub-processors table below. The provider returns the output to your workspace.

  • We do not use your data, or your customers' data, to train generalised AI or machine-learning models, and our agreements require our providers not to train on it either.
  • AI output can be wrong. Your team can read every chat, correct any field and take over a conversation at any time. You decide which actions the AI is allowed to take.
  • Usage and token logs record how much AI was used, so you can see the cost. They do not add any new category of personal data.

Google user data

This section applies when you use Sign in with Google or connect a Google Ads account.

What we receive. From Sign in with Google: your name, email address, profile picture and Google account ID. From the Google Ads API (early access, only after you connect an account and choose which accounts to read): your Google Ads customer ID and name; campaign, ad group, ad and keyword names, IDs and statuses; and daily cost, impressions, clicks, conversions and conversion value.

Why we need it. Sign-in data identifies you and creates or matches your vedhasAI account. Google Ads data is what makes cost per lead, cost per sale and ROAS per campaign possible, shown beside the leads and sales already in your CRM.

What we do not do. We do not create, edit or pause your campaigns. We do not change budgets or bids. We do not read anything from your Google account beyond the scopes you grant.

How it is stored. OAuth tokens are encrypted at rest. Synced metrics and names are stored in your workspace database while the account stays connected. Access is limited to staff who need it to run or support the service.

Who it is shared with. Only the sub-processors listed below, and only as needed to run the service. Never with advertisers, data brokers or anyone buying data.

How long we keep it. Tokens are deleted immediately when you disconnect. Synced Google Ads data is deleted within 30 days of disconnecting, or sooner on request.

How to revoke access. In the app, go to Settings → Integrations → Google Ads → Disconnect. You can also revoke access at myaccount.google.com/permissions at any time.

vedhasAI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain language, the Limited Use requirements mean:

  • Google user data is used only to provide or improve user-facing features that are prominent in vedhasAI: ads reporting, cost per lead and cost per sale, campaign comparison, and — if you turn it on in future — conversion sync.
  • It is transferred to others only when necessary to provide those features (the named sub-processors below), to comply with law, or as part of a merger or acquisition, with notice to you.
  • It is not used or transferred for serving advertisements, including retargeting, personalised or interest-based advertising.
  • Humans do not read it, unless you give affirmative consent for specific data (for example when you attach it to a support ticket), it is necessary for security or abuse investigation, or the law requires it.
  • It is not sold, not used to determine creditworthiness or for lending, and not used to build or train generalised AI or machine-learning models. Where an AI feature produces insights from your ads data, that processing exists only to produce that output for you.

A standalone summary is at Google API disclosure.

Meta Platform Data

This section applies when you connect WhatsApp, a Facebook Page, an Instagram account, Facebook Lead Ads or a Meta ad account.

What we receive. WhatsApp Business Account and phone number IDs, message templates and catalogue data, customer messages and media, customer WhatsApp profile names and numbers, and delivery status; Messenger and Instagram messages, media and scoped user IDs; Click-to-WhatsApp, Messenger and Instagram ad referral details; Facebook Lead Ads form submissions; Page and Instagram account IDs; and (early access) ad account, campaign, ad set and ad names, IDs, statuses and performance metrics.

How it is used. Only to provide the features your business turned on: replying to customers, creating and updating leads, running follow-ups, showing lead sources, and reporting on ad spend.

How it is protected and shared. Tokens are encrypted at rest. Data is stored in your workspace's own database. We share it only with the sub-processors below as needed to run the service, or where the law requires. We do not sell it and we do not use it for advertising.

Deletion. Disconnecting a channel or ad account stops the flow immediately and deletes the stored tokens. Message and lead data is deleted when you delete it, when you close the workspace, or on a verified request, as described in Requesting data deletion.

We handle Meta Platform Data in line with the Meta Platform Terms and Meta's developer policies.

Sharing and sub-processors

We share personal data only with the providers that make the service work, and only as far as each needs.

| Sub-processor | Purpose | Location | |---|---|---| | Meta Platforms, Inc. | WhatsApp Business Platform, Messenger, Instagram, Lead Ads and Marketing API | Global | | Google LLC | Google sign-in and Google Ads API | Global | | Anthropic PBC | AI replies, summaries and lead details (Claude API) | United States | | Akamai Technologies (Linode Object Storage) | Media and file storage | India | | TODO_DATABASE_HOST | Database hosting | TODO | | TODO_VECTOR_SEARCH_HOST | Product search index (Qdrant) | TODO | | TODO_EMBEDDINGS_PROVIDER | Search embeddings | TODO | | TODO_EMAIL_PROVIDER | Transactional email and one-time codes | TODO | | TODO_APP_HOSTING | Application hosting | TODO | | Google Analytics, Meta Pixel | Website analytics and ad measurement on this website only, and only if you accept those cookies | Global |

We may also share data with professional advisers under confidentiality, with authorities where the law requires it, and with a buyer as part of a merger or acquisition, in which case we will tell you before your data becomes subject to a different policy.

International transfers

Some sub-processors process data outside India. Where that happens we rely on the safeguards allowed under applicable law and on contractual commitments requiring an equivalent standard of protection.

How long we keep data

  • Account data: while your account is active, then deleted within 90 days of closure.
  • Connected-account tokens: deleted immediately when you disconnect.
  • Synced ads data: deleted within 30 days of disconnecting.
  • Conversation and lead data: kept for your workspace until you delete it or close the account, then deleted within 30 days.
  • Backups: purged within 90 days as backups rotate.
  • One-time codes: expire within minutes.
  • Security and login logs: 180 days.
  • Legal, tax and accounting records: as long as the law requires, even after account closure.

How we protect data

  • All traffic uses HTTPS/TLS.
  • Third-party access tokens are encrypted at rest.
  • Each business gets a separate database, or connects its own MongoDB.
  • Roles and granular permissions control who on your team sees what.
  • Email and mobile one-time codes verify account actions, and login history is recorded.
  • Staff access is limited to people who need it to run or support the service.
  • We investigate and respond to security incidents, and notify you as described in the Data Processing Addendum.

No system is completely secure. We cannot promise that data will never be accessed without authorisation, and we do not ask you to rely on such a promise.

Your rights

If you hold a vedhasAI account or use this website, you can:

  • Access the personal data we hold about you and a summary of how it is processed.
  • Correct or complete anything inaccurate or incomplete.
  • Erase your data, subject to legal retention duties.
  • Withdraw consent at any time, where processing rests on consent. Withdrawal does not undo processing already carried out.
  • Nominate someone to exercise your rights if you die or become incapacitated (India DPDP).
  • Raise a grievance with our Grievance Officer, who will respond within 30 days.
  • Complain to the Data Protection Board of India if you are not satisfied with our response.

If you are outside India, equivalent rights under your local law — including GDPR rights to portability, restriction and objection — apply where that law applies to us.

To exercise any right, email privacy@vedhasai.com or use the form on the data deletion page. We will verify who you are before acting, and respond within 30 days.

If you are a customer of a business that uses vedhasAI: contact that business first, because it decides what happens to your data. If you contact us, we will pass the request on and help the business respond.

Requesting data deletion

Any user, in any region, can ask us to delete all the data we hold about them, at any time, free of charge. You do not need an account, and you do not need to give a reason.

How to ask:

  1. In the app. Settings → Integrations → disconnect each channel and ad account. Then delete leads, delete the workspace, and delete the account. Each step asks for confirmation.
  2. By email. Write to privacy@vedhasai.com from the email address on the account, or from any address if you are an end customer.
  3. Using the form on our data deletion page.

What is deleted: your account and profile, business configuration, prompts and lead fields, leads, conversations and media, synced ads data, connected-account tokens, and website tracking records tied to you.

What may be kept, and why: records we must retain by law (for example tax invoices), a minimal record of the deletion request itself so we can prove we acted on it, and data inside backups until those backups rotate, within 90 days. Anything retained stays protected under this policy and is not used for any other purpose.

Timeline: we acknowledge within 30 days, and complete deletion within 30 days of verifying the request, except for the backup rotation above. You receive a reference number and an email confirming completion.

Full instructions are on the How to delete your data page.

Cookies

This website uses a small number of cookies. Only the strictly necessary ones are set before you choose. Analytics and marketing cookies load only after you accept them, and you can change your mind at any time through Cookie settings in the footer. The full list, with purposes and durations, is in the Cookie Policy.

Children

vedhasAI is a business tool. It is not directed at children, and accounts are for people aged 18 or over. We do not knowingly collect the personal data of children. If you believe a child's data has reached us, write to privacy@vedhasai.com and we will delete it.

Changes to this policy

We update this policy when the service or the law changes. The "Last updated" date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will email account holders before it takes effect.

Contact and Grievance Officer

If we cannot resolve your grievance, you may complain to the Data Protection Board of India.