privacy

Wafi Privacy Policy Effective date: 10 October 2026 Last updated: 10 October 2026 About Wafi and this policy Wafi is a business messaging platform operated by CDN Technologies, a trading name of wafi.in, based at 1st floor, Lubana Complex, Medical College Road, Jalandhar, Punjab, India 144002. Wafi is available at https://wafi.in/. This policy explains how we collect, use, disclose, retain and delete personal information when you visit our website, create an account, connect a WhatsApp Business Account or use our messaging services. This policy covers business customers, their authorised team members, website visitors and individuals whose information is processed through Wafi. Privacy enquiries and deletion requests can be sent to technologiescdn@gmail.com. Our business website is https://cdntechnologies.in/. Our role and client responsibilities We determine how personal information is used for operating Wafi accounts, handling subscriptions, providing support and protecting the service. For contacts, conversations and campaign information that a business customer uploads or processes through Wafi, we generally act as a service provider processing that information on the customer’s instructions. Each business customer determines the purpose of its messages, the recipients, the information collected and the lawful basis for processing. Customers must provide appropriate privacy notices, obtain required permissions and messaging opt-ins, honour opt-outs, and comply with applicable law and WhatsApp policies. Connecting a WhatsApp account to Wafi does not establish consent from message recipients. Information we collect Account and business information: names, business names, email addresses, telephone numbers, login information, team roles, business addresses, subscription details and information supplied to support. Where needed for billing or account verification, this may include tax and business registration details. Connected account information: WhatsApp Business Account identifiers, business portfolio identifiers, connected phone numbers and their identifiers, display names, business profiles, message templates, account status and the permissions and credentials needed to maintain an authorised connection. If Meta sign-in or Embedded Signup is enabled, we receive the account and asset information authorised through that flow. The exact information depends on the permissions requested and granted. Messaging and contact information: names, WhatsApp numbers, uploaded contact lists, contact labels and custom fields, message text, attachments, campaign instructions, chatbot responses, conversation assignments, opt-in and opt-out records, timestamps, message identifiers, delivery and read status, and related webhook events. We process the conversations routed through connected business numbers; connecting Wafi does not give us access to unrelated personal WhatsApp chats. Technical information: IP addresses, browser and device information, session identifiers, account activity, API and webhook logs, error reports and security events. Billing information may include invoice records and payment transaction status. [PAYMENT PROVIDER AND WHETHER WAFI RECEIVES OR STORES ANY PAYMENT CARD DATA]. How we use information We use information to create and manage accounts; connect authorised WhatsApp business assets; send and receive messages on customers’ instructions; manage templates, campaigns, shared inboxes and automation; provide delivery reports; administer billing; answer support requests; and troubleshoot the service. We also use necessary account and technical information to protect accounts, investigate abuse, enforce service terms, maintain reliable operations and meet legal obligations. Our communications about subscriptions, security and support are separate from promotional communications. Where promotional communications require consent, we seek that consent and provide a way to withdraw it. Our authority to process personal information depends on the purpose and applicable law. It may arise from providing a requested service, complying with legal obligations, consent where required, or another legally permitted basis. This policy itself does not substitute for any required consent. WhatsApp and Meta integration Wafi uses the WhatsApp Business Platform to provide messaging features. We access connected assets only within the permissions granted and for the features described in this policy. WhatsApp management access may be used to manage business account settings, numbers and templates; messaging access may be used to send messages and receive messaging events. Meta and WhatsApp process information under their own terms and privacy policies. When a customer sends a message through Wafi, the message and the information necessary for delivery are transmitted through WhatsApp’s infrastructure. Messages and attachments that become available to the customer’s connected business account may also be processed and stored by Wafi to provide the inbox, automation and reporting features. Customers can withdraw integration permissions through the applicable Meta business integration settings or request disconnection by contacting us. Disconnection stops future authorised access through that connection; it does not automatically erase information already stored. To request deletion, follow the process below. Meta’s privacy policy is available at https://www.facebook.com/privacy/policy/ and WhatsApp’s at https://www.whatsapp.com/legal/privacy-policy. Who can receive information Customer organisations and their authorised users can access information associated with their own workspace according to their configured permissions. Message recipients receive the communications addressed to them. Our authorised support personnel may access information where necessary to provide support, investigate an issue or secure the service. We use service providers for activities such as hosting, backups, email delivery, payment processing and technical support. Providers receive information needed for their services, subject to applicable agreements and safeguards. Our relevant providers and processing locations are: Hostinger.in. Software support providers receive customer information only when authorised and necessary for their support services. Customer-enabled integrations may receive information as instructed by that customer. If an optional AI feature sends message content to an external AI provider, we will identify the provider, the data sent, the purpose and any relevant retention or training practices before that feature is activated. Use of AI is governed by the respective providers like openai and we are no way affiliated with them. we take no responsibility of merchantability of the ai used and are just facilitating the services on customers behalf. We may disclose information when required by law or a valid legal process, or when necessary and legally permitted to protect rights, safety or the service. If the business is transferred, personal information may be transferred subject to applicable law, appropriate confidentiality arrangements and any required notice. We do not sell personal information or use customer contact lists or message content for unrelated advertising. We do not use that information to train general-purpose AI models but the AI models we use have a complex working and how they use the information is beyond our control and customer is advised to share any information of misuse if he find so. Cookies and similar technologies We use cookies or similar storage where necessary for sign-in, session management, preferences and security. Blocking essential cookies may prevent parts of the service from working. Where required, optional technologies are activated only after the relevant choice or consent. You can also manage cookies through your browser settings. Retention and deletion We retain information only for the purposes described in this policy, the period required to provide the service, or applicable legal obligations. Customer content is subject to the customer’s instructions and the retention settings supported by Wafi. Credentials that are no longer needed for an authorised connection are revoked or removed. Our standard retention schedule is: customer contacts, conversations and attachments until customer deletes it; operational and security logs as per required for smooth running of the software, we periodically remove unwanted log files and clear them time to time; backup copies might exist but we are not obliged to provide the user that data and it is for recovery purpose only; and billing or tax records stays as long as the account stays with us and insome cases we can keep those for records. Where a valid deletion request applies, we remove the relevant information from active systems and arrange for backup copies to expire under the backup schedule. Backups pending expiry are not used for ordinary service operations. Information retained to meet a legal obligation or resolve a dispute is restricted to that purpose. Deletion from Wafi does not automatically delete copies held independently by the customer, message recipients, Meta or other services. Your choices and data deletion requests Depending on applicable law and our role, you may request information about your data, access, correction, deletion, withdrawal of consent, or other rights available to you. An authorised account administrator may also request account closure or disconnection of an integration. Some service features will stop working if the information or permissions they require are withdrawn. To request deletion of Wafi account data or information received through Meta, email technologiescdn@gmail.com with the subject “Wafi Data Deletion Request”. Include the email used for your Wafi account, your business or workspace name, the connected WhatsApp number or account identifier if relevant, and whether you want particular information deleted or the whole account closed. Do not send passwords, OTPs, access tokens or payment card details. We may ask for proportionate information to verify your identity and authority before acting. We will acknowledge the request, explain any lawful retention exceptions, and respond within applicable legal deadlines. Our normal response target is 2 working days; deletion from active systems is normally completed within 7 working days after verification, subject to any legally required shorter period. If you received a message from a business using Wafi, you should contact that business to withdraw messaging permission or exercise rights concerning its customer records. You may also contact us with the sending number and enough information to identify the relevant business. We will assist or refer the request to the responsible business without disclosing another customer’s information. A marketing opt-out and a data deletion request are separate choices. Security and international processing We use reasonable technical and organisational measures appropriate to the information and risks, including controls over authorised access and the handling of integration credentials. Customers must protect their credentials and manage team access responsibly. No online service can guarantee absolute security. We will respond to security incidents and provide notifications where required by applicable law. We operate from India. Hosting providers, Meta and other authorised service providers may process information in other countries as identified above. Where applicable law requires safeguards or restricts transfers, we apply the required safeguards and restrictions. Children and changes to this policy Wafi account registration is intended for adults authorised to act for a business. We do not knowingly invite children to create Wafi accounts. Business customers must comply with any additional requirements that apply when their communications involve children. If you believe information about a child has been processed unlawfully, contact us. We may update this policy when our services, data practices or legal requirements change. We will publish the updated version with a revised date and give additional notice or obtain fresh consent where required. Materially different processing will not be justified solely by changing the wording of this policy. Contact and privacy complaints For privacy questions, rights requests or complaints, contact CDN Technologies at technologiescdn@gmail.com or +91 7710614900. Postal address: 1st floor, Lubana Complex, Medical College Road, Jalandhar, Punjab, India 144001. Privacy or grievance contact: Naveen Goel, Founder. Please explain the concern and provide enough information to identify the relevant account or interaction. We will investigate and respond within applicable legal time limits. Where applicable law provides a right to approach a regulator or other competent authority, this policy does not limit that right.