Privacy Policy
Your Privacy Matters
This Privacy Policy explains how Sellnexia (operated by Megabiz Global Innovations Pvt. Ltd.) collects, uses, stores, and protects your personal data. By using our platform, you consent to the practices described in this policy. Please read it carefully.
1. Introduction and Scope
1.1
Megabiz Global Innovations Pvt. Ltd. (referred to as "Sellnexia", "we", "us", or "our") operates the Sellnexia AI Revenue Autopilot platform accessible at app.sellnexia.com and sellnexia.com.
1.2
This Privacy Policy applies to all personal data collected, processed, and stored in connection with use of the Sellnexia platform by Tenants and their Team Members, visits to our marketing website at sellnexia.com, communications with us via email, WhatsApp, or other channels, End Customer data processed through the platform on behalf of Tenants, and data collected through opt-in forms, demo requests, and contact forms.
1.3
This Policy is to be read in conjunction with our Terms and Conditions available at sellnexia.com/terms. We are committed to complying with applicable data protection laws including the Digital Personal Data Protection Act, 2023 (India).
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Tenant" means a business entity or individual who subscribes to the Sellnexia platform.
- "Team Member" means a user invited by a Tenant to access the platform.
- "End Customer" means any individual whose data is processed through the platform as a result of interacting with a Tenant's WhatsApp Business number.
- "Data Controller" means the entity that determines the purposes and means of processing personal data.
- "Data Processor" means the entity that processes personal data on behalf of the Data Controller.
- "WhatsApp Opt-in" means explicit consent given by an individual to receive WhatsApp communications from a Tenant.
3. Data We Collect
3.1 Tenant Account Data
When a business registers on Sellnexia, we collect: full name and designation of the account holder, business name, type, and industry, email address and phone number, GST number and PAN number (where provided), billing address and payment information (processed by Razorpay — we do not store card details), WhatsApp Business number and Meta account identifiers, and account preferences and configuration settings.
3.2 Team Member Data
When Tenants invite team members, we collect full name and email address, designation and role within the Tenant's organisation, login activity and session data, and permission configurations set by the Tenant.
3.3 End Customer Data
When End Customers interact with a Tenant's WhatsApp Business number through the platform, we process: WhatsApp phone number and display name, message content (inbound and outbound), conversation timestamps and message status, lead status and qualification data, notes and tags added by Tenant team members, and opt-in consent status and date.
3.4 Contact Import Data
When Tenants import contacts via CSV upload, we collect and store name and phone number (required), email address, business name, notes and tags (optional), source of the contact and opt-in status, and import timestamp and method.
3.5 Website and Technical Data
When you visit sellnexia.com or app.sellnexia.com, we automatically collect IP address and approximate geographic location, browser type and operating system, pages visited and navigation path, device type and screen resolution, and cookies and similar tracking technologies.
3.6 Communication Data
When you contact us directly, we collect email correspondence, WhatsApp messages sent to our business number, support tickets and chat transcripts, and demo request form submissions including WhatsApp opt-in consent.
4. How We Use Your Data
4.1 Platform Operation
To create and manage Tenant accounts and subscriptions, process payments and manage billing cycles, provide access to platform features, facilitate WhatsApp Business API connections and message routing, power the AI engine for automated response generation, enable team collaboration and permission management, and enforce usage limits and credit quotas.
4.2 Service Improvement
To analyse platform usage patterns, debug technical issues, develop new features, train and improve AI response quality using anonymised data only, and conduct internal research and analytics.
4.3 Communication
To send service notifications, billing alerts, and usage warnings, deliver platform updates and maintenance notices, respond to support queries, send marketing communications (only with explicit consent), and send WhatsApp messages to individuals who have opted in via our website forms.
4.4 Legal and Compliance
To comply with applicable Indian laws, respond to lawful requests from government authorities, enforce our Terms and Conditions, detect and prevent fraud or security incidents, and maintain records required by law.
5. Legal Basis for Processing
5.1
We process personal data on the following legal bases: Contractual necessity — processing required to fulfil our contractual obligations to Tenants; Legitimate interests — processing for fraud prevention, platform security, and product improvement; Consent — processing for marketing communications and WhatsApp opt-in communications; Legal obligation — processing required to comply with applicable Indian laws and regulatory requirements.
5.2
Where processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
6. WhatsApp Data and Messaging
6.1 WhatsApp Opt-in Communications
We collect WhatsApp numbers from individuals who explicitly opt in through our website contact forms, demo request forms, or other opt-in pages. By checking the WhatsApp opt-in checkbox on our forms, you consent to receive WhatsApp messages from Sellnexia about our platform, features, offers, and updates. We will only send WhatsApp messages using Meta-approved message templates to opted-in contacts. You can opt out at any time by replying STOP to any message. We store the following consent proof: timestamp of opt-in, source page URL, IP address, and checkbox status.
6.2 Tenant WhatsApp Data
When Tenants connect their WhatsApp Business number to Sellnexia, all messages sent to and from that number are processed through our platform. Sellnexia acts as a data processor for all End Customer data collected through Tenant WhatsApp interactions — the Tenant is the data controller for this data. Message content is stored to enable conversation history, lead management, and AI response context. Messages are not used for advertising purposes.
6.3 Meta Platform Data Sharing
The Platform operates through Meta's WhatsApp Business Cloud API. Message data necessarily passes through Meta's infrastructure, subject to Meta's Privacy Policy. We do not sell or share WhatsApp communication data with any third party beyond what is required to operate the platform.
7. Cookies and Tracking Technologies
7.1 Types of Cookies We Use
Essential cookies (required for platform function, authentication and session management), Analytics cookies (Google Analytics — to understand visitor behaviour), Marketing cookies (Meta Pixel — to measure advertising effectiveness), and Preference cookies (to remember your settings).
7.2 Cookie Management
You can control cookies through your browser settings. Disabling essential cookies may affect platform functionality. Our website uses Google Analytics (G-B8KDZ22DSZ) and Meta Pixel (ID: 1096872276841847). We use Cloudflare Turnstile for bot protection on forms, which may collect technical data for security purposes. You can opt out of Google Analytics tracking via the Google Analytics Opt-out Browser Add-on at tools.google.com/dlpage/gaoptout.
8. Data Sharing and Third Parties
8.1 Service Providers
We share data with the following carefully selected service providers: Meta Platforms Inc. (WhatsApp Business Cloud API — message routing and delivery), OpenAI (AI language model — response generation using anonymised conversation context), Razorpay (payment processing — subscription billing), Amazon Web Services (cloud hosting — infrastructure and data storage), MongoDB Atlas (database services), Hostinger (email delivery — transactional emails), and Google (analytics and search console). Each provider is bound by contractual obligations to process data only as instructed.
8.2 Legal Disclosure
We may disclose personal data if required by law, court order, or regulatory authority, and to law enforcement agencies where necessary to prevent or investigate fraud, illegal activity, or security threats. We will notify affected individuals of such disclosure requests where legally permitted.
8.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity subject to equivalent privacy protections. We will notify Tenants of any such transfer and provide an opportunity to opt out where legally required.
8.4 No Sale of Data
We do not sell, rent, or trade personal data to third parties for their own marketing or commercial purposes. This applies to all categories of personal data we collect.
9. Data Retention
We retain personal data for as long as necessary to fulfil the purposes for which it was collected. Specific retention periods are as follows:
- Active Tenant account data: Duration of subscription plus 30 days after termination
- Demo account data: 45 days from account creation (14-day demo + 30-day grace period), then permanently deleted
- End Customer conversation data: Duration of the Tenant's active subscription
- Billing and payment records: 7 years as required by Indian tax law
- Support correspondence: 2 years after the last interaction
- Website analytics data: 26 months in aggregated form
- Opt-in consent records: 5 years as legal proof of consent
10. Data Security
10.1 Technical Measures
Encryption of all data in transit using TLS 1.2 or higher, encryption of sensitive data at rest, JWT authentication with short expiry windows (15 minutes for access tokens), bcrypt password hashing with salt factor 12, rate limiting on all authentication endpoints (5 attempts per 15 minutes), MongoDB Atlas network access controls and encryption, AWS security groups and firewall configurations, and regular security patches and dependency updates.
10.2 Organisational Measures
Access to personal data is restricted to authorised personnel on a need-to-know basis, with role-based access control within the platform, regular review of access permissions, and incident response procedures for data breaches.
10.3 Breach Notification
In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will notify affected parties and relevant authorities within 72 hours of becoming aware of the breach. Notifications will include the nature of the breach, categories of data affected, likely consequences, and measures taken to address the breach.
11. International Data Transfers
11.1
The Sellnexia platform is operated from India. However, some service providers operate internationally, which may involve transferring personal data outside India. Key international transfers include: OpenAI (United States — AI processing), Meta Platforms Inc. (United States — WhatsApp message routing), and Amazon Web Services (primary region: ap-south-1 Mumbai, India).
11.2
Where data is transferred internationally, we ensure appropriate safeguards are in place including contractual data processing agreements with service providers. By using our platform, you consent to the transfer of your data to these providers as necessary for platform operation.
12. Your Rights
Subject to applicable law, you have the following rights regarding your personal data:
Right of Access
You have the right to request a copy of the personal data we hold about you. We will respond to access requests within 30 days.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data. Many corrections can be made directly within the platform settings.
Right to Erasure
You have the right to request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to legal retention requirements.
Right to Restriction
You have the right to request that we restrict processing of your personal data in certain circumstances, such as while the accuracy of the data is contested.
Right to Data Portability
You have the right to receive your personal data in a structured, machine-readable format. The platform provides CSV export functionality for leads, contacts, and conversation data.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests. We will cease such processing unless we can demonstrate compelling legitimate grounds.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw consent at any time by contacting us at hello@sellnexia.com or by using the opt-out mechanisms provided.
WhatsApp Opt-out
You can opt out of WhatsApp communications at any time by replying STOP to any WhatsApp message from us. We will process your opt-out within 24 hours.
Exercising Your Rights
To exercise any of the above rights, please contact our privacy team at hello@sellnexia.com with the subject line: PRIVACY REQUEST. We will respond within 30 days and may require verification of your identity before processing the request.
13. Tenant Responsibilities as Data Controller
13.1
Tenants are the data controllers for all End Customer data processed through the platform. Tenants bear primary responsibility for obtaining valid legal basis for collecting and processing End Customer personal data, providing End Customers with appropriate privacy notices, honouring End Customer data subject rights requests, ensuring imported contacts have consented to WhatsApp communications, complying with all applicable data protection laws, and immediately removing contacts who have opted out.
13.2
Sellnexia acts as a data processor on behalf of Tenants for End Customer data. We process such data only as instructed by the Tenant and as described in this policy. Tenants indemnify Sellnexia against any claims arising from the Tenant's failure to comply with data protection obligations.
14. Children's Privacy
14.1
The Sellnexia platform is designed for business use and is not intended for individuals under the age of 18. We do not knowingly collect personal data from individuals under 18 years of age.
14.2
If we become aware that we have collected personal data from a person under 18 without parental consent, we will take steps to delete such information promptly. Tenants must ensure their use of the platform does not involve collecting data from or communicating with individuals under 18 without appropriate parental consent.
15. AI and Automated Decision Making
15.1
The Sellnexia platform uses artificial intelligence to generate automated responses to WhatsApp messages. AI-generated responses are produced by large language model technology based on the Tenant's configured business context and conversation history.
15.2
We do not use automated decision-making that produces legal or similarly significant effects on individuals without human oversight. AI response data is not used to profile individuals for advertising purposes.
15.3
To improve AI response quality, we may analyse anonymised conversation patterns. This analysis does not involve identifiable personal data. Tenants and their team members retain the ability to review and override AI-generated responses at any time through manual reply functionality.
16. Analytics and Tracking
16.1
We use Google Analytics (G-B8KDZ22DSZ) on our website to understand how visitors interact with our content. This involves collecting anonymised usage data through cookies.
16.2
We use Meta Pixel (ID: 1096872276841847) to measure the effectiveness of our advertising campaigns. This may involve sharing anonymised event data with Meta. We also use Google Search Console and Bing Webmaster Tools for website performance monitoring.
16.3
Platform usage analytics are collected to understand feature adoption and identify areas for improvement. This data is aggregated and anonymised where possible.
17. Payment Data
17.1
Payment processing is handled entirely by Razorpay, a PCI DSS compliant payment gateway. Sellnexia does not store, transmit, or process credit card or debit card numbers.
17.2
We retain transaction identifiers, subscription IDs, payment amounts, and dates for billing and accounting purposes. Billing records are retained for 7 years as required by Indian financial regulations.
18. Changes to This Privacy Policy
18.1
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated to Tenants via email at least 14 days before the changes take effect.
18.2
The updated Privacy Policy will be published at sellnexia.com/privacy with the effective date clearly indicated. Continued use of the platform following notification of changes constitutes acceptance of the updated Privacy Policy. We maintain an archive of previous Privacy Policy versions available upon request.
19. Grievance Officer
19.1
In accordance with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we have appointed a Grievance Officer.
19.2
Any grievances related to the processing of personal data may be directed to the Grievance Officer at Megabiz Global Innovations Pvt. Ltd. — Email: hello@sellnexia.com — Subject line: PRIVACY GRIEVANCE — Response time: Within 30 days of receipt. If you are not satisfied with our response, you may escalate to the relevant data protection authority or seek legal redress through the appropriate courts.
20. Governing Law
This Privacy Policy is governed by the laws of India including the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and all rules and regulations made thereunder. Any disputes arising from this Privacy Policy shall be subject to the exclusive jurisdiction of the courts in Bengaluru, Karnataka, India.
21. Contact Us
For any questions, concerns, or requests related to this Privacy Policy or our data practices, please contact our Privacy Team at Megabiz Global Innovations Pvt. Ltd. — CIN: U15122KA2026PTC215834 — Email: hello@sellnexia.com — Website: sellnexia.com/privacy. Please use the following subject lines for faster response: Data access request — PRIVACY REQUEST — ACCESS; Data deletion request — PRIVACY REQUEST — DELETION; Opt-out request — PRIVACY REQUEST — OPT OUT; General privacy query — PRIVACY QUERY; Grievance — PRIVACY GRIEVANCE.
This document is maintained by Megabiz Global Innovations Private Limited. For any questions, contact us at support@sellnexia.com