Statutory & Regulatory Framework
This Privacy Policy (“Policy”) governs the collection, processing, storage, transfer, and protection of personal data by MANZA (“MANZA”, “we”, “our”, or “us”) via our website (manza.in), subdomains (*.manza.in), and web application dashboards.
This Policy is published in strict compliance with the statutory requirements of:
- Digital Personal Data Protection Act, 2023 (“DPDPA 2023”) of the Republic of India;
- Section 43A of the Information Technology Act, 2000 (“IT Act”);
- Rule 3 & 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”);
- Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“IT Rules 2021”); and
- The General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) for individuals within the European Economic Area (EEA) and the United Kingdom.
Role Separation: Data Fiduciary vs. Data Processor
To maintain legal precision under Indian data protection jurisprudence and global standards, MANZA acts in two distinct capacities:
MANZA as Data Fiduciary / Controller
We determine the purpose and means of processing with respect to registered workspace owners, administrators, billing contacts, and platform account credentials.
MANZA as Data Processor
When tenant workspaces upload subscriber lists, capture leads through custom funnels, or broadcast campaigns, the tenant workspace acts as the Data Fiduciary, and MANZA processes customer data solely on the tenant's lawful instructions.
Categories of Personal Data Collected
Depending on your relationship with MANZA, we collect and process the following categories of information:
A. Account & Identity Data
Full name, corporate email address, encrypted authentication hashes (Bcrypt), phone number, company name, workspace subdomain, and designated team member profiles.
B. Integration & BYO Credentials (Encrypted at Rest)
Bring-Your-Own (BYO) credentials provided by tenants, including Meta WhatsApp Cloud API Permanent System Tokens, WhatsApp Business Account IDs (WABA), Phone Number IDs, and custom SMTP server hostnames, ports, and authorization secrets. All integration secrets are stored using hardware-grade AES-256 encryption.
C. Tenant End-User Lead & Campaign Data
Subscriber contact names, phone numbers, email addresses, custom tags, funnel stage progress, opt-in timestamps, campaign delivery statuses, email open tracking events, and link click redirects collected on behalf of tenant organizations.
D. Technical & Diagnostic Logs
IP addresses, browser type, operating system metadata, session identifiers, referral URLs, access timestamps, and error traces for performance monitoring and distributed denial-of-service (DDoS) mitigation.
Data Retention and Diagnostic Logs
In alignment with data minimization principles under Section 8(7) of DPDPA 2023 and Article 5(1)(e) of GDPR, MANZA enforces differentiated retention schedules based on data classification:
Customer Account & Workspace Data
All user-generated assets—including customer relationship data (CRM contacts, phone numbers, email addresses), published landing pages, funnel steps, tags, and campaign metrics—are stored securely and retained for the duration of your active subscription, or until manually deleted by the workspace owner.
API & Webhook Delivery Logs (30-Day Operational Window)
To ensure platform performance, security, and compliance with data minimization principles, temporary diagnostic data (such as incoming and outgoing webhook delivery receipts, transient API payload traces, and delivery event logs) is retained for an operational window of thirty (30) days. After 30 days, these raw technical trace logs are automatically and permanently purged.
Account Deletion & Data Export
Workspace administrators may export their CRM lists, contact records, and analytics at any time. Upon account termination, all associated personal and workspace data is queued for permanent purging in accordance with applicable statutory timelines.
Lawful Grounds for Processing
We process personal data only when substantiated by valid legal grounds under Section 6 of DPDPA 2023 and Article 6 of GDPR:
- Consent: Given explicitly at registration or when subscribing to communications, with the right to withdraw at any time.
- Contractual Performance: Processing required to provision workspace subdomains, deliver WhatsApp messages via Meta Cloud API, execute automated workflows, and generate billing statements.
- Compliance with Legal Obligations: Retaining financial transaction records under the Companies Act, 2013 and responding to lawful statutory notices under the IT Act, 2000.
- Legitimate Uses: Security monitoring, fraud detection, credential abuse prevention, and network uptime reliability.
Multi-Tenant Isolation & Security Measures
In satisfaction of the Reasonable Security Practices prescribed by Rule 5 of the SPDI Rules, 2011 and Section 8(5) of DPDPA, MANZA employs multi-layered architectural safeguards:
- Logical & Cryptographic Multi-Tenancy: Strict tenant boundary enforcement at the database and application layer. Organization records are segregated such that cross-tenant data leaks are programmatically impossible.
- Data in Transit: 100% of network requests are enforced with Transport Layer Security (TLS 1.3) with HSTS preloading and high-grade cipher suites.
- Data at Rest: Automated database backups and disks are encrypted using AES-256 keys managed in secure key vaults.
- Zero Advertising Monetization: We do not sell, rent, broker, or monetize your customer lists, broadcast data, or funnel traffic to third-party ad networks.
Third-Party Sub-Processors & Transfers
MANZA engages audited infrastructure partners to deliver platform services. Current authorized sub-processors include:
| Sub-Processor | Service Category | Location |
|---|---|---|
| Supabase / PostgreSQL | Primary Relational Database & Storage | AWS Region (Singapore / Mumbai) |
| Meta Platforms, Inc. | WhatsApp Cloud API Dispatcher | Global Cloud Edge |
| Cloudflare, Inc. | Edge Routing, DNS, S3 R2 Storage & SSL | Global Anycast Network |
| Vercel Inc. | Next.js Edge Compute Hosting | Global Edge Network |
Data Principal Rights
Under Sections 11, 12, and 13 of DPDPA 2023 and Chapter III of GDPR, individuals (“Data Principals”) have enforceable rights:
- Right to Access: Request a summary of your personal data held and identities of third parties with whom it has been shared.
- Right to Correction & Erasure: Rectify inaccurate records or request permanent deletion of your account and contacts (“Right to be Forgotten”).
- Right to Grievance Redressal: Seek timely remedy from our designated Grievance Redressal Officer before approaching the Data Protection Board of India.
- Right to Nominate: Nominate an individual to exercise your privacy rights in the event of death or incapacity.
- Right to Withdraw Consent: Revoke consent easily at any time through workspace settings or email.
Statutory Grievance Redressal Officer
In accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Digital Personal Data Protection Act, 2023, the details of our designated Grievance Redressal Officer and Data Protection Lead are provided below:
Phani Nirola
Grievance Redressal Officer & Data Protection Lead
Policy Amendments
We may update this Policy periodically to reflect technological changes, product updates, or statutory amendments. Significant modifications will be communicated via in-app banner or email notifications to workspace owners prior to taking effect.