Home/Legal & Compliance

Privacy Policy & Data Protection

Detailed disclosure of data governance, security architectures, and statutory privacy rights under Indian and International Law.

Effective Date: September 8, 2026
01

Statutory & Regulatory Framework

This Privacy Policy (“Policy”) governs the collection, processing, storage, transfer, and protection of personal data by MANZA (“MANZA”, “we”, “our”, or “us”) via our website (manza.in), subdomains (*.manza.in), and web application dashboards.

This Policy is published in strict compliance with the statutory requirements of:

  • Digital Personal Data Protection Act, 2023 (“DPDPA 2023”) of the Republic of India;
  • Section 43A of the Information Technology Act, 2000 (“IT Act”);
  • Rule 3 & 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”);
  • Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“IT Rules 2021”); and
  • The General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) for individuals within the European Economic Area (EEA) and the United Kingdom.

02

Role Separation: Data Fiduciary vs. Data Processor

To maintain legal precision under Indian data protection jurisprudence and global standards, MANZA acts in two distinct capacities:

MANZA as Data Fiduciary / Controller

We determine the purpose and means of processing with respect to registered workspace owners, administrators, billing contacts, and platform account credentials.

MANZA as Data Processor

When tenant workspaces upload subscriber lists, capture leads through custom funnels, or broadcast campaigns, the tenant workspace acts as the Data Fiduciary, and MANZA processes customer data solely on the tenant's lawful instructions.


03

Categories of Personal Data Collected

Depending on your relationship with MANZA, we collect and process the following categories of information:

A. Account & Identity Data

Full name, corporate email address, encrypted authentication hashes (Bcrypt), phone number, company name, workspace subdomain, and designated team member profiles.

B. Integration & BYO Credentials (Encrypted at Rest)

Bring-Your-Own (BYO) credentials provided by tenants, including Meta WhatsApp Cloud API Permanent System Tokens, WhatsApp Business Account IDs (WABA), Phone Number IDs, and custom SMTP server hostnames, ports, and authorization secrets. All integration secrets are stored using hardware-grade AES-256 encryption.

C. Tenant End-User Lead & Campaign Data

Subscriber contact names, phone numbers, email addresses, custom tags, funnel stage progress, opt-in timestamps, campaign delivery statuses, email open tracking events, and link click redirects collected on behalf of tenant organizations.

D. Technical & Diagnostic Logs

IP addresses, browser type, operating system metadata, session identifiers, referral URLs, access timestamps, and error traces for performance monitoring and distributed denial-of-service (DDoS) mitigation.


04

Data Retention and Diagnostic Logs

In alignment with data minimization principles under Section 8(7) of DPDPA 2023 and Article 5(1)(e) of GDPR, MANZA enforces differentiated retention schedules based on data classification:

Customer Account & Workspace Data

All user-generated assets—including customer relationship data (CRM contacts, phone numbers, email addresses), published landing pages, funnel steps, tags, and campaign metrics—are stored securely and retained for the duration of your active subscription, or until manually deleted by the workspace owner.

API & Webhook Delivery Logs (30-Day Operational Window)

To ensure platform performance, security, and compliance with data minimization principles, temporary diagnostic data (such as incoming and outgoing webhook delivery receipts, transient API payload traces, and delivery event logs) is retained for an operational window of thirty (30) days. After 30 days, these raw technical trace logs are automatically and permanently purged.

Account Deletion & Data Export

Workspace administrators may export their CRM lists, contact records, and analytics at any time. Upon account termination, all associated personal and workspace data is queued for permanent purging in accordance with applicable statutory timelines.


05

Lawful Grounds for Processing

We process personal data only when substantiated by valid legal grounds under Section 6 of DPDPA 2023 and Article 6 of GDPR:

  • Consent: Given explicitly at registration or when subscribing to communications, with the right to withdraw at any time.
  • Contractual Performance: Processing required to provision workspace subdomains, deliver WhatsApp messages via Meta Cloud API, execute automated workflows, and generate billing statements.
  • Compliance with Legal Obligations: Retaining financial transaction records under the Companies Act, 2013 and responding to lawful statutory notices under the IT Act, 2000.
  • Legitimate Uses: Security monitoring, fraud detection, credential abuse prevention, and network uptime reliability.

06

Multi-Tenant Isolation & Security Measures

In satisfaction of the Reasonable Security Practices prescribed by Rule 5 of the SPDI Rules, 2011 and Section 8(5) of DPDPA, MANZA employs multi-layered architectural safeguards:

  • Logical & Cryptographic Multi-Tenancy: Strict tenant boundary enforcement at the database and application layer. Organization records are segregated such that cross-tenant data leaks are programmatically impossible.
  • Data in Transit: 100% of network requests are enforced with Transport Layer Security (TLS 1.3) with HSTS preloading and high-grade cipher suites.
  • Data at Rest: Automated database backups and disks are encrypted using AES-256 keys managed in secure key vaults.
  • Zero Advertising Monetization: We do not sell, rent, broker, or monetize your customer lists, broadcast data, or funnel traffic to third-party ad networks.

07

Third-Party Sub-Processors & Transfers

MANZA engages audited infrastructure partners to deliver platform services. Current authorized sub-processors include:

Sub-ProcessorService CategoryLocation
Supabase / PostgreSQLPrimary Relational Database & StorageAWS Region (Singapore / Mumbai)
Meta Platforms, Inc.WhatsApp Cloud API DispatcherGlobal Cloud Edge
Cloudflare, Inc.Edge Routing, DNS, S3 R2 Storage & SSLGlobal Anycast Network
Vercel Inc.Next.js Edge Compute HostingGlobal Edge Network

08

Data Principal Rights

Under Sections 11, 12, and 13 of DPDPA 2023 and Chapter III of GDPR, individuals (“Data Principals”) have enforceable rights:

  • Right to Access: Request a summary of your personal data held and identities of third parties with whom it has been shared.
  • Right to Correction & Erasure: Rectify inaccurate records or request permanent deletion of your account and contacts (“Right to be Forgotten”).
  • Right to Grievance Redressal: Seek timely remedy from our designated Grievance Redressal Officer before approaching the Data Protection Board of India.
  • Right to Nominate: Nominate an individual to exercise your privacy rights in the event of death or incapacity.
  • Right to Withdraw Consent: Revoke consent easily at any time through workspace settings or email.

09

Statutory Grievance Redressal Officer

In accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Digital Personal Data Protection Act, 2023, the details of our designated Grievance Redressal Officer and Data Protection Lead are provided below:

PN

Phani Nirola

Grievance Redressal Officer & Data Protection Lead

Physical Headquarters:MANZA HQ, Guwahati, Assam – 781001, India
Statutory Turnaround Commitments: All complaints or privacy concerns submitted to the Grievance Officer will be acknowledged within forty-eight (48) hours of receipt, and substantively investigated and resolved within thirty (30) calendar days in accordance with Rule 3(2) of the IT Rules, 2021.

10

Policy Amendments

We may update this Policy periodically to reflect technological changes, product updates, or statutory amendments. Significant modifications will be communicated via in-app banner or email notifications to workspace owners prior to taking effect.