Privacy Policy

Effective Date: August 24, 2026Last Updated: August 24, 2026

Your Privacy Matters

This Privacy Policy explains how Sellnexia (operated by Megabiz Global Innovations Pvt. Ltd.) collects, uses, stores, and protects your personal data. By using our platform, you consent to the practices described in this policy. Please read it carefully.

1. Introduction and Scope

Megabiz Global Innovations Pvt. Ltd. (referred to as “sellnexia”, “we”, “us”, or “our”) operates the sellnexia AI Revenue Autopilot platform, including sellnexia.com and app.sellnexia.com. This Privacy Policy explains how we collect, use, store, disclose, secure and otherwise process personal data in connection with the platform, our marketing website, customer support, demo and contact forms, WhatsApp communications, the Business Profile and AI features, the API Platform, webhooks, integrations and related services. This Policy applies to Tenants, Team Members, End Customers whose data is processed through a Tenant’s account, website visitors, demo/contact-form users and individuals who communicate with us through supported channels. This Policy should be read together with the Master Terms & Conditions and any applicable Data Processing Agreement or enterprise agreement.

2. Definitions

  • “Personal Data” means information relating to an identified or identifiable natural person.
  • “Tenant” means a business entity or individual subscribing to the platform.
  • “Team Member” means a user invited by a Tenant to access the platform.
  • “End Customer” means an individual whose information is processed through the platform as a result of interacting with a Tenant’s WhatsApp Business number, website, form, application or other connected channel.
  • “Business Profile” means business information and instructions configured by a Tenant so that automation and AI features can understand the Tenant’s business operations.
  • “API Platform” means the developer-facing APIs, webhooks, authentication mechanisms, API logs, usage information and related integration services.
  • “Data Controller” means the entity that determines the purposes and means of processing personal data.
  • “Data Processor” means an entity that processes personal data on behalf of a Data Controller.
  • “WhatsApp Opt-in” means an appropriate consent or other lawful basis authorising WhatsApp communications where required.

3. Personal Data We Collect

We may collect the following categories of personal data, depending on how you use the platform:

  • Tenant Account Data: name, designation, business name, business type and industry, email address, phone number, GST/PAN where provided, billing address, payment-related information, WhatsApp Business number, Meta account identifiers, account preferences and configuration.
  • Team Member Data: name, email address, designation, role, login activity, session information and permission configuration.
  • End Customer Data: WhatsApp phone number, display name, message content, conversation timestamps, message status, lead status, qualification data, notes, tags and opt-in status where supplied or generated through a Tenant’s use of the platform.
  • Contact Import Data: name and phone number, email address, business name, notes, tags, source, opt-in status and import timestamp/method.
  • Business Profile Data: business name, products and services, descriptions, pricing, operating hours, locations, FAQs, policies, offers, qualification rules, escalation instructions, brand tone, contact details and other business information entered or approved by the Tenant.
  • API Data: API requests and responses, webhook payloads, API keys or authentication metadata in protected form, application identifiers, timestamps, usage records, logs, error information and integration configuration.
  • Website and Technical Data: IP address, approximate geographic location, browser and operating system, pages visited, navigation path, device information, cookies and similar technologies.
  • Communication Data: email correspondence, support tickets, chat transcripts, demo requests, contact-form submissions and communications sent through supported channels.

4. How We Use Personal Data

We use personal data to create and manage accounts and subscriptions; provide platform features; process billing; connect and operate supported WhatsApp integrations; route and store messages; manage leads, contacts and conversations; provide Business Profile and AI functionality; process API requests and webhooks; provide integrations and technical support; enforce usage limits and security controls; send service, billing and maintenance notifications; respond to support requests; analyse platform use; debug and improve the service; detect fraud and security incidents; comply with legal obligations; and send marketing communications where required consent or another lawful basis exists.

5. Business Profile and AI Data

Business Profile information is used to provide business-specific context to automation and AI features. The AI may use Business Profile information, conversation context, configured instructions and other authorised platform data to generate responses, classify or qualify leads, summarise conversations, extract information, recommend actions, route conversations or trigger configured workflows. The Tenant is responsible for ensuring that Business Profile information is accurate, current, lawful and appropriate for automated processing. AI outputs may be generated by third-party AI infrastructure providers. We process and disclose the data needed to provide those AI services in accordance with this Policy and applicable agreements. We do not treat AI output as inherently accurate or as a replacement for human review where review is appropriate. The Tenant remains responsible for its business decisions, customer communications and configuration of AI behaviour. The existing policy states that AI response quality may be improved using anonymised conversation patterns and that identifiable personal data is not used for that purpose. Any change to that practice will require an appropriate policy update.

6. API Platform and Developer Data

The API Platform processes data submitted through API requests, responses and webhooks to provide the requested integration services. API logs may contain request metadata, timestamps, status information, error details and other technical information needed for security, troubleshooting, billing and service operation. Where message content is included in an API request or response, it may be processed as Customer Data or End Customer Data. API credentials, keys, tokens and webhook secrets are treated as security-sensitive information. Customers are responsible for keeping their credentials confidential and for determining what personal data their applications send through the API. The Customer’s application may send data directly to third-party services or integrations. The Customer is responsible for its own application-level privacy notices, lawful bases and disclosures for such processing. We may process API usage information to enforce rate limits, plan limits, security controls, billing and service reliability.

7. WhatsApp Data and Messaging

When a Tenant connects a WhatsApp Business number, messages sent to and from that number may be processed through the platform. For End Customer data processed on behalf of a Tenant, the Tenant generally determines the purposes of processing and sellnexia acts as a processor to the extent applicable. Message content may be stored to provide conversation history, lead management, automation and AI context. The platform operates through WhatsApp Business infrastructure. Message data may therefore pass through Meta or another applicable authorised provider and is subject to the provider’s applicable privacy terms. Tenants are responsible for obtaining required consent or another lawful basis for messaging End Customers, respecting opt-outs and complying with applicable WhatsApp/Meta policies. For communications sent directly by sellnexia, opt-in records may include timestamp, source page URL, IP address and checkbox status where collected.

8. Legal Bases for Processing

Where applicable, processing may be based on contractual necessity, legitimate interests such as fraud prevention, security and service improvement, consent, or legal obligation. Where processing is based on consent, applicable law may provide a right to withdraw consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

9. Data Sharing and Third Parties

We may share or make data available to service providers required to operate the platform, subject to applicable contracts and instructions. The uploaded policy identifies Meta Platforms Inc. for WhatsApp Business Cloud API, OpenAI for AI language-model processing, Razorpay for payment processing, Amazon Web Services for hosting, MongoDB Atlas for database services, Hostinger for transactional email, and Google for analytics and search-related services. The exact provider used for a particular feature may depend on the Customer’s configuration and the production architecture. We may disclose personal data where required by law, court order or regulatory authority, or where reasonably necessary to prevent or investigate fraud, illegal activity or security threats. In a merger, acquisition or sale of assets, personal data may be transferred to a successor subject to applicable privacy protections and legal requirements. We do not sell, rent or trade personal data to third parties for their own marketing or commercial purposes.

10. Cookies and Tracking

We may use essential cookies for authentication and platform operation, analytics cookies, marketing cookies and preference cookies. The uploaded policy identifies Google Analytics and Meta Pixel on the marketing website and Cloudflare Turnstile for bot protection, together with Google Search Console and Bing Webmaster Tools for website performance monitoring. Cookie availability and identifiers may change as the website evolves. Users can control cookies through browser settings, although disabling essential cookies may affect functionality.

11. Payment Data

Payment processing is handled by the applicable payment provider. The uploaded policy identifies Razorpay as the payment processor and states that sellnexia does not store, transmit or process card numbers. We may retain transaction identifiers, subscription identifiers, payment amounts and dates for billing, accounting, fraud prevention and legal compliance.

12. Data Retention

The uploaded policy specifies the following retention periods: Retention may be extended where required by law, necessary to resolve disputes, prevent fraud, enforce agreements, maintain security records or satisfy legitimate backup requirements.

  • Active Tenant account data: subscription duration plus 30 days after termination.
  • Demo account data: 45 days from account creation, stated as a 14-day demo plus 30-day grace period.
  • End Customer conversation data: duration of the Tenant’s active subscription.
  • Billing and payment records: 7 years as stated in the current policy.
  • Support correspondence: 2 years after the last interaction.
  • Website analytics data: 26 months in aggregated form.
  • Opt-in consent records: 5 years as legal proof of consent.

13. Data Security

The uploaded policy describes technical and organisational safeguards including TLS 1.2 or higher for data in transit, encryption of sensitive data at rest, short-lived JWT access tokens, bcrypt password hashing, authentication rate limiting, MongoDB Atlas network controls, AWS security groups and firewalls, regular security updates, role-based access control, need-to-know access and incident-response procedures. Security controls may evolve as the platform develops. No internet or cloud service can guarantee absolute security.

14. Data Breach and Security Incidents

The existing policy states that, where a personal-data breach poses a risk to individuals’ rights and freedoms, sellnexia will notify affected parties and relevant authorities within 72 hours of becoming aware of the breach. Actual notification obligations and timelines will be governed by applicable law and contractual commitments. Where a Tenant is the responsible controller for End Customer data, sellnexia will provide appropriate cooperation and notifications as required by the applicable agreement and law.

15. International Data Transfers

The uploaded policy states that the platform is operated from India while certain providers may operate internationally. It identifies OpenAI and Meta as international providers and AWS ap-south-1 Mumbai as a primary India region. Where personal data is transferred internationally, we will use appropriate safeguards required by applicable law and relevant contractual arrangements. The actual location and transfer mechanism may vary by provider and service configuration.

16. Tenant Responsibilities

Tenants are responsible for determining the lawful purposes and legal basis for End Customer data processed through their account; providing appropriate privacy notices; obtaining required WhatsApp opt-in or other consent; honouring data-subject rights requests; ensuring imported contacts were collected lawfully; removing or suppressing opted-out contacts; keeping Business Profile information accurate; configuring AI and automation appropriately; securing API credentials; and ensuring their applications and integrations comply with applicable laws and third-party policies. Where sellnexia processes End Customer data on the Tenant’s behalf, sellnexia acts as a processor to the extent applicable.

17. Your Privacy Rights

Subject to applicable law, individuals may have rights to access, rectify, erase, restrict or object to processing, data portability and withdrawal of consent. The uploaded policy provides a 30-day response period for privacy requests and states that identity verification may be required. Requests may be sent to hello@sellnexia.com with the subject line “PRIVACY REQUEST”. The applicable rights, response periods and exceptions will be determined by the law that applies to the request.

18. WhatsApp Opt-Out

For WhatsApp communications sent by sellnexia, individuals may opt out using the available opt-out mechanism, including replying STOP where supported. The uploaded policy states that sellnexia will process such opt-outs within 24 hours. For WhatsApp communications sent by a Tenant, the Tenant remains responsible for maintaining appropriate opt-out and suppression processes.

19. Children’s Privacy

The platform is designed for business use. The uploaded policy states that it is not intended for individuals under 18 and that sellnexia does not knowingly collect personal data from individuals under 18. Tenants must ensure that their use of the platform does not unlawfully collect or process children’s data or send communications to children where prohibited by applicable law.

20. Automated Decision-Making

The platform may use AI to generate responses, classify or qualify leads, summarise conversations, extract information or recommend and automate actions. The uploaded policy states that sellnexia does not use automated decision-making that produces legal or similarly significant effects on individuals without human oversight and does not use AI response data to profile individuals for advertising purposes. Customers remain responsible for reviewing AI-assisted outcomes where decisions may materially affect individuals.

21. Data Portability and Account Export

The uploaded policy states that the platform provides CSV export functionality for leads, contacts and conversation data. Export availability, format, scope and timing may depend on the relevant plan and technical functionality. The Tenant is responsible for securely handling exported data and complying with applicable retention and privacy obligations.

22. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our services, technology, data practices or legal requirements. The uploaded policy states that material changes will be communicated to Tenants at least 14 days before taking effect and that previous versions are maintained on request. The current effective date and last-updated date will be displayed at the top of the published Policy.

23. Grievance Officer and Privacy Contact

Privacy requests, complaints and grievances may be directed to the privacy contact identified by the Company. Privacy requests: hello@sellnexia.com Subject: PRIVACY REQUEST Privacy grievance: hello@sellnexia.com Subject: PRIVACY GRIEVANCE General privacy query: hello@sellnexia.com Subject: PRIVACY QUERY The final published Policy should identify the current Grievance Officer and legally required contact details.

24. Governing Law

The uploaded policy states that the Privacy Policy is governed by the laws of India, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, together with applicable rules and regulations. The uploaded policy identifies Bengaluru, Karnataka, India as the jurisdiction for disputes. This wording should remain consistent with the Master Terms and should be reviewed by legal counsel before publication.

25. Contact Us

Megabiz Global Innovations Pvt. Ltd. Email: hello@sellnexia.com Website: sellnexia.com/privacy The final published version should use the Company’s exact registered legal name and current official contact details consistently across the Privacy Policy, Terms, invoices, website footer and legal notices.

This document is maintained by Megabiz Global Innovations Private Limited. For any questions, contact us at hello@sellnexia.com