Privacy Policy

Effective Date: June 1, 2026Last Updated: June 1, 2026

Your Privacy Matters

This Privacy Policy explains how Sellnexia (operated by Megabiz Global Innovations Pvt. Ltd.) collects, uses, stores, and protects your personal data. By using our platform, you consent to the practices described in this policy. Please read it carefully.

1. Introduction and Scope

1.1

Megabiz Global Innovations Pvt. Ltd. (referred to as "Sellnexia", "we", "us", or "our") operates the Sellnexia AI Revenue Autopilot platform accessible at app.sellnexia.com and sellnexia.com.

1.2

This Privacy Policy applies to all personal data collected, processed, and stored in connection with use of the Sellnexia platform by Tenants and their Team Members, visits to our marketing website at sellnexia.com, communications with us via email, WhatsApp, or other channels, End Customer data processed through the platform on behalf of Tenants, and data collected through opt-in forms, demo requests, and contact forms.

1.3

This Policy is to be read in conjunction with our Terms and Conditions available at sellnexia.com/terms. We are committed to complying with applicable data protection laws including the Digital Personal Data Protection Act, 2023 (India).

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Tenant" means a business entity or individual who subscribes to the Sellnexia platform.
  • "Team Member" means a user invited by a Tenant to access the platform.
  • "End Customer" means any individual whose data is processed through the platform as a result of interacting with a Tenant's WhatsApp Business number.
  • "Data Controller" means the entity that determines the purposes and means of processing personal data.
  • "Data Processor" means the entity that processes personal data on behalf of the Data Controller.
  • "WhatsApp Opt-in" means explicit consent given by an individual to receive WhatsApp communications from a Tenant.

3. Data We Collect

3.1 Tenant Account Data

When a business registers on Sellnexia, we collect: full name and designation of the account holder, business name, type, and industry, email address and phone number, GST number and PAN number (where provided), billing address and payment information (processed by Razorpay — we do not store card details), WhatsApp Business number and Meta account identifiers, and account preferences and configuration settings.

3.2 Team Member Data

When Tenants invite team members, we collect full name and email address, designation and role within the Tenant's organisation, login activity and session data, and permission configurations set by the Tenant.

3.3 End Customer Data

When End Customers interact with a Tenant's WhatsApp Business number through the platform, we process: WhatsApp phone number and display name, message content (inbound and outbound), conversation timestamps and message status, lead status and qualification data, notes and tags added by Tenant team members, and opt-in consent status and date.

3.4 Contact Import Data

When Tenants import contacts via CSV upload, we collect and store name and phone number (required), email address, business name, notes and tags (optional), source of the contact and opt-in status, and import timestamp and method.

3.5 Website and Technical Data

When you visit sellnexia.com or app.sellnexia.com, we automatically collect IP address and approximate geographic location, browser type and operating system, pages visited and navigation path, device type and screen resolution, and cookies and similar tracking technologies.

3.6 Communication Data

When you contact us directly, we collect email correspondence, WhatsApp messages sent to our business number, support tickets and chat transcripts, and demo request form submissions including WhatsApp opt-in consent.

4. How We Use Your Data

4.1 Platform Operation

To create and manage Tenant accounts and subscriptions, process payments and manage billing cycles, provide access to platform features, facilitate WhatsApp Business API connections and message routing, power the AI engine for automated response generation, enable team collaboration and permission management, and enforce usage limits and credit quotas.

4.2 Service Improvement

To analyse platform usage patterns, debug technical issues, develop new features, train and improve AI response quality using anonymised data only, and conduct internal research and analytics.

4.3 Communication

To send service notifications, billing alerts, and usage warnings, deliver platform updates and maintenance notices, respond to support queries, send marketing communications (only with explicit consent), and send WhatsApp messages to individuals who have opted in via our website forms.

4.4 Legal and Compliance

To comply with applicable Indian laws, respond to lawful requests from government authorities, enforce our Terms and Conditions, detect and prevent fraud or security incidents, and maintain records required by law.

5. Legal Basis for Processing

5.1

We process personal data on the following legal bases: Contractual necessity — processing required to fulfil our contractual obligations to Tenants; Legitimate interests — processing for fraud prevention, platform security, and product improvement; Consent — processing for marketing communications and WhatsApp opt-in communications; Legal obligation — processing required to comply with applicable Indian laws and regulatory requirements.

5.2

Where processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

6. WhatsApp Data and Messaging

6.1 WhatsApp Opt-in Communications

We collect WhatsApp numbers from individuals who explicitly opt in through our website contact forms, demo request forms, or other opt-in pages. By checking the WhatsApp opt-in checkbox on our forms, you consent to receive WhatsApp messages from Sellnexia about our platform, features, offers, and updates. We will only send WhatsApp messages using Meta-approved message templates to opted-in contacts. You can opt out at any time by replying STOP to any message. We store the following consent proof: timestamp of opt-in, source page URL, IP address, and checkbox status.

6.2 Tenant WhatsApp Data

When Tenants connect their WhatsApp Business number to Sellnexia, all messages sent to and from that number are processed through our platform. Sellnexia acts as a data processor for all End Customer data collected through Tenant WhatsApp interactions — the Tenant is the data controller for this data. Message content is stored to enable conversation history, lead management, and AI response context. Messages are not used for advertising purposes.

6.3 Meta Platform Data Sharing

The Platform operates through Meta's WhatsApp Business Cloud API. Message data necessarily passes through Meta's infrastructure, subject to Meta's Privacy Policy. We do not sell or share WhatsApp communication data with any third party beyond what is required to operate the platform.

7. Cookies and Tracking Technologies

7.1 Types of Cookies We Use

Essential cookies (required for platform function, authentication and session management), Analytics cookies (Google Analytics — to understand visitor behaviour), Marketing cookies (Meta Pixel — to measure advertising effectiveness), and Preference cookies (to remember your settings).

7.2 Cookie Management

You can control cookies through your browser settings. Disabling essential cookies may affect platform functionality. Our website uses Google Analytics (G-B8KDZ22DSZ) and Meta Pixel (ID: 1096872276841847). We use Cloudflare Turnstile for bot protection on forms, which may collect technical data for security purposes. You can opt out of Google Analytics tracking via the Google Analytics Opt-out Browser Add-on at tools.google.com/dlpage/gaoptout.

8. Data Sharing and Third Parties

8.1 Service Providers

We share data with the following carefully selected service providers: Meta Platforms Inc. (WhatsApp Business Cloud API — message routing and delivery), OpenAI (AI language model — response generation using anonymised conversation context), Razorpay (payment processing — subscription billing), Amazon Web Services (cloud hosting — infrastructure and data storage), MongoDB Atlas (database services), Hostinger (email delivery — transactional emails), and Google (analytics and search console). Each provider is bound by contractual obligations to process data only as instructed.

8.2 Legal Disclosure

We may disclose personal data if required by law, court order, or regulatory authority, and to law enforcement agencies where necessary to prevent or investigate fraud, illegal activity, or security threats. We will notify affected individuals of such disclosure requests where legally permitted.

8.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity subject to equivalent privacy protections. We will notify Tenants of any such transfer and provide an opportunity to opt out where legally required.

8.4 No Sale of Data

We do not sell, rent, or trade personal data to third parties for their own marketing or commercial purposes. This applies to all categories of personal data we collect.

9. Data Retention

We retain personal data for as long as necessary to fulfil the purposes for which it was collected. Specific retention periods are as follows:

  • Active Tenant account data: Duration of subscription plus 30 days after termination
  • Demo account data: 45 days from account creation (14-day demo + 30-day grace period), then permanently deleted
  • End Customer conversation data: Duration of the Tenant's active subscription
  • Billing and payment records: 7 years as required by Indian tax law
  • Support correspondence: 2 years after the last interaction
  • Website analytics data: 26 months in aggregated form
  • Opt-in consent records: 5 years as legal proof of consent

10. Data Security

10.1 Technical Measures

Encryption of all data in transit using TLS 1.2 or higher, encryption of sensitive data at rest, JWT authentication with short expiry windows (15 minutes for access tokens), bcrypt password hashing with salt factor 12, rate limiting on all authentication endpoints (5 attempts per 15 minutes), MongoDB Atlas network access controls and encryption, AWS security groups and firewall configurations, and regular security patches and dependency updates.

10.2 Organisational Measures

Access to personal data is restricted to authorised personnel on a need-to-know basis, with role-based access control within the platform, regular review of access permissions, and incident response procedures for data breaches.

10.3 Breach Notification

In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will notify affected parties and relevant authorities within 72 hours of becoming aware of the breach. Notifications will include the nature of the breach, categories of data affected, likely consequences, and measures taken to address the breach.

11. International Data Transfers

11.1

The Sellnexia platform is operated from India. However, some service providers operate internationally, which may involve transferring personal data outside India. Key international transfers include: OpenAI (United States — AI processing), Meta Platforms Inc. (United States — WhatsApp message routing), and Amazon Web Services (primary region: ap-south-1 Mumbai, India).

11.2

Where data is transferred internationally, we ensure appropriate safeguards are in place including contractual data processing agreements with service providers. By using our platform, you consent to the transfer of your data to these providers as necessary for platform operation.

12. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

Right of Access

You have the right to request a copy of the personal data we hold about you. We will respond to access requests within 30 days.

Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data. Many corrections can be made directly within the platform settings.

Right to Erasure

You have the right to request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to legal retention requirements.

Right to Restriction

You have the right to request that we restrict processing of your personal data in certain circumstances, such as while the accuracy of the data is contested.

Right to Data Portability

You have the right to receive your personal data in a structured, machine-readable format. The platform provides CSV export functionality for leads, contacts, and conversation data.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests. We will cease such processing unless we can demonstrate compelling legitimate grounds.

Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw consent at any time by contacting us at hello@sellnexia.com or by using the opt-out mechanisms provided.

WhatsApp Opt-out

You can opt out of WhatsApp communications at any time by replying STOP to any WhatsApp message from us. We will process your opt-out within 24 hours.

Exercising Your Rights

To exercise any of the above rights, please contact our privacy team at hello@sellnexia.com with the subject line: PRIVACY REQUEST. We will respond within 30 days and may require verification of your identity before processing the request.

13. Tenant Responsibilities as Data Controller

13.1

Tenants are the data controllers for all End Customer data processed through the platform. Tenants bear primary responsibility for obtaining valid legal basis for collecting and processing End Customer personal data, providing End Customers with appropriate privacy notices, honouring End Customer data subject rights requests, ensuring imported contacts have consented to WhatsApp communications, complying with all applicable data protection laws, and immediately removing contacts who have opted out.

13.2

Sellnexia acts as a data processor on behalf of Tenants for End Customer data. We process such data only as instructed by the Tenant and as described in this policy. Tenants indemnify Sellnexia against any claims arising from the Tenant's failure to comply with data protection obligations.

14. Children's Privacy

14.1

The Sellnexia platform is designed for business use and is not intended for individuals under the age of 18. We do not knowingly collect personal data from individuals under 18 years of age.

14.2

If we become aware that we have collected personal data from a person under 18 without parental consent, we will take steps to delete such information promptly. Tenants must ensure their use of the platform does not involve collecting data from or communicating with individuals under 18 without appropriate parental consent.

15. AI and Automated Decision Making

15.1

The Sellnexia platform uses artificial intelligence to generate automated responses to WhatsApp messages. AI-generated responses are produced by large language model technology based on the Tenant's configured business context and conversation history.

15.2

We do not use automated decision-making that produces legal or similarly significant effects on individuals without human oversight. AI response data is not used to profile individuals for advertising purposes.

15.3

To improve AI response quality, we may analyse anonymised conversation patterns. This analysis does not involve identifiable personal data. Tenants and their team members retain the ability to review and override AI-generated responses at any time through manual reply functionality.

16. Analytics and Tracking

16.1

We use Google Analytics (G-B8KDZ22DSZ) on our website to understand how visitors interact with our content. This involves collecting anonymised usage data through cookies.

16.2

We use Meta Pixel (ID: 1096872276841847) to measure the effectiveness of our advertising campaigns. This may involve sharing anonymised event data with Meta. We also use Google Search Console and Bing Webmaster Tools for website performance monitoring.

16.3

Platform usage analytics are collected to understand feature adoption and identify areas for improvement. This data is aggregated and anonymised where possible.

17. Payment Data

17.1

Payment processing is handled entirely by Razorpay, a PCI DSS compliant payment gateway. Sellnexia does not store, transmit, or process credit card or debit card numbers.

17.2

We retain transaction identifiers, subscription IDs, payment amounts, and dates for billing and accounting purposes. Billing records are retained for 7 years as required by Indian financial regulations.

18. Changes to This Privacy Policy

18.1

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated to Tenants via email at least 14 days before the changes take effect.

18.2

The updated Privacy Policy will be published at sellnexia.com/privacy with the effective date clearly indicated. Continued use of the platform following notification of changes constitutes acceptance of the updated Privacy Policy. We maintain an archive of previous Privacy Policy versions available upon request.

19. Grievance Officer

19.1

In accordance with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we have appointed a Grievance Officer.

19.2

Any grievances related to the processing of personal data may be directed to the Grievance Officer at Megabiz Global Innovations Pvt. Ltd. — Email: hello@sellnexia.com — Subject line: PRIVACY GRIEVANCE — Response time: Within 30 days of receipt. If you are not satisfied with our response, you may escalate to the relevant data protection authority or seek legal redress through the appropriate courts.

20. Governing Law

This Privacy Policy is governed by the laws of India including the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and all rules and regulations made thereunder. Any disputes arising from this Privacy Policy shall be subject to the exclusive jurisdiction of the courts in Bengaluru, Karnataka, India.

21. Contact Us

For any questions, concerns, or requests related to this Privacy Policy or our data practices, please contact our Privacy Team at Megabiz Global Innovations Pvt. Ltd. — CIN: U15122KA2026PTC215834 — Email: hello@sellnexia.com — Website: sellnexia.com/privacy. Please use the following subject lines for faster response: Data access request — PRIVACY REQUEST — ACCESS; Data deletion request — PRIVACY REQUEST — DELETION; Opt-out request — PRIVACY REQUEST — OPT OUT; General privacy query — PRIVACY QUERY; Grievance — PRIVACY GRIEVANCE.

This document is maintained by Megabiz Global Innovations Private Limited. For any questions, contact us at support@sellnexia.com