Legal & Privacy Assurance

Privacy Policy

Last Updated: August 5, 2026. This policy explains how we collect, process, secure, and manage your data within the Blyno Solutions WhatsApp CRM platform.

Introduction

Welcome to Blyno Solutions (“Blyno Solutions”, “we”, “us”, or “our”). We operate the Blyno Solutions - WA Suite, a unified customer relationship management (CRM) platform designed specifically for Indian enterprises to manage team inboxes, sales pipelines, broadcast marketing campaigns, and conversational automations using the Meta WhatsApp Business Cloud API.

Your privacy and data security are core priorities for us. We are committed to protecting the personal data of our users (the “CRM Users”) as well as the individuals whose information is handled through our systems (the “End Customers”). This Privacy Policy outlines how we collect, process, share, secure, and delete data in compliance with standard regulations, including the Digital Personal Data Protection (DPDP) Act, 2023 of India and Meta's Developer & WhatsApp Policies.

1. Information We Collect

We collect and process various categories of data depending on how you interact with the WA Suite CRM:

CRM User Account & Billing

  • Profile Details: Full name, business email address, phone number, and password credentials.
  • Business Information: Company name, registration status, Indian GSTIN (for tax compliance), and billing address.
  • Billing History: Transaction history denominated in Indian Rupees (INR ₹), subscription tiers, and payment status details (we do not store raw credit card numbers).

WhatsApp Integration Data

  • Meta Developer Credentials: WhatsApp Business Account (WABA) IDs, system user access tokens, and scoped API keys.
  • CRM Contact Database: Names, phone numbers, labels, custom fields, and CSV lists uploaded for broadcast campaigns.
  • Conversational History: Message logs, files, voice notes, images, PDF documents, templates sent/received, and read statuses.

Automation & RAG Documents

If you use the AI Knowledge Base Auto-Reply or visual flows, the system stores:

  • Knowledge-grounding document files (FAQs, PDF manuals, product lists) uploaded to build the RAG (Retrieval-Augmented Generation) context.
  • Configuration metadata for automation trigger nodes, keyword rules, and custom webhooks.

2. How We Use Information

We use the collected information to operate, monitor, and improve the WhatsApp CRM suite, specifically:

  • Core Functionality: Activating the shared multi-agent inbox, synchronization of WhatsApp chats, rendering pipeline kanban stages, and triggering webhooks.
  • Campaign Execution: Dispatching approved Meta template messages to saved contact segments, validating numbers, and recording read rates.
  • AI Auto-Replies: Processing incoming End Customer queries against your organization's knowledge base documents to generate automated replies.
  • Billing & Administration: Generating tax invoices, verifying GST registration details, administering subscription billing in INR (₹), and handling customer support tickets.
  • Security & Monitoring: Enforcing role-based access control, monitoring webhook integrity (HMAC signatures), detecting API rate limits, and ensuring compliance.

3. Sharing & Integrations

We do not sell, rent, or trade your data. In order to provide the CRM services, your data is processed through specific third-party integration partners:

Meta Platforms, Inc. (WhatsApp API)

Incoming and outgoing chat messages, templates, and delivery updates travel through official Meta Cloud API endpoints.

Primary Integration

Supabase Cloud Infrastructure

Our databases, authentication directories, and storage buckets run on Supabase, ensuring enterprise-grade isolation, automated backups, and encrypted tables.

Database Hosting

AI API Providers (OpenAI & Anthropic)

If CRM Users activate the AI Auto-Reply feature, customer messages and matching document chunks are sent to selected models to synthesize responses.

Optional Feature API

4. Security & Data Isolation

Blyno Solutions applies rigorous security controls to maintain integrity across all organizations:

  • Multi-Tenant Data Isolation: Every workspace uses strict Row-Level Security (RLS) policies within Supabase. An organization's agents cannot access chats, contacts, or pipelines of another organization.
  • Role-Based Access Control (RBAC): Access limits are configured automatically per user role:
    • Admins: Full config control, API keys, pricing plans, billing, and team manager settings.
    • Managers: Lead flow designs, CRM pipeline automation rules, and contact segments.
    • Agents: Shared inbox chats, contact records, and direct chat interactions only.
  • Data Encryption: Sensitive integration tokens (e.g. system user Meta tokens) are stored encrypted at rest. Communication with the dashboard and webhooks uses SSL/TLS encryption.
  • Data Deletion: Upon organization deletion or request, we delete account details, integration credentials, and RAG document data within 30 days.

5. India DPDP Act & Legal Rights

As an application built for Indian businesses, we act as a Data Processor when handling the personal data of your End Customers, and a Data Fiduciary when managing your account profiles under the Digital Personal Data Protection (DPDP) Act, 2023 of India.

Key Rights Under DPDP Act 2023

  • Right to Access & Correction: Users can request summary details of active personal data and update inaccuracies instantly from the Profile Settings tab.
  • Right to Erasure: Organizations can trigger a complete erasure of contact databases, chat records, and integration configurations.
  • Consent Withdrawal: You may revoke Meta API access tokens, which stops all outgoing broadcasts and incoming webhook processing.
  • Nomination & Grievance: You have the right to nominate an individual to act on your behalf in case of incapacity. Grievances will be addressed within 7 days.

6. Meta Policy & Opt-Outs

Blyno Solutions strictly respects Meta's WhatsApp Commercial Policy. We enforce features to protect End Customers:

  • Opt-In Verification: CRM Users are required to obtain verified opt-in consent before dispatching broadcast templates to prevent WhatsApp numbers from being marked as spam.
  • Opt-Out Commands: We recommend adding an opt-out choice (e.g. “Reply STOP to unsubscribe”) in broadcast templates. If a customer replies with opt-out keywords, our visual flow builder can be configured to unsubscribe them automatically.
  • Official APIs Only: All workflows operate exclusively through the official Meta Cloud API infrastructure. Scraping tools, unauthorized emulators, or unofficial WhatsApp APIs are strictly prohibited on our platform.

7. Contact Information

If you have questions about this Privacy Policy, your rights under India's DPDP Act, or want to raise a grievance, please contact our dedicated Data Officer:

Blyno Solutions Privacy Team

Email: support@blynosolutions.com

Response Time: Within 7 business days