Overview
Thatmatters Technologies Pvt. Ltd. ("Thatmatters", "we", "our") operates an AI-powered WhatsApp Business Automation platform. This Privacy Policy governs how we collect, process, store, and protect data from our users ("you", "Customer", "User") in connection with our services.
By using Thatmatters, you consent to the data practices described in this policy. This policy is compliant with applicable Indian data protection laws, including the Digital Personal Data Protection Act, 2023 (DPDPA).
Thatmatters Technologies Pvt. Ltd. is the data controller for all personal data collected through the platform. For data-related queries, contact: support@thatmatters.in
Data We Collect
We collect several categories of data to operate and improve our services:
How We Use Your Data
We use collected data strictly for the purposes below:
- Providing, operating, and maintaining the Thatmatters platform
- Processing and delivering WhatsApp messages on your behalf
- Managing your account, wallet credits, and billing
- Responding to support tickets and customer queries
- Sending transactional emails (invoices, credit alerts, service notifications)
- Detecting and preventing fraud, abuse, and policy violations
- Improving platform features and performance through analytics
- Complying with legal obligations and regulatory requirements
We do not use your data for third-party advertising or sell your data to any third party. Promotional communications from Thatmatters are only sent with your explicit consent.
WhatsApp Message Data
When you use Thatmatters to send messages, the following applies:
- Message content is processed through our servers solely for delivery purposes
- Recipient phone numbers are stored to track delivery status and campaign analytics
- Message content is not read, analysed, or used for any purpose other than delivery
- Delivery logs (sent, delivered, read, failed) are retained for 90 days by default
- You are responsible for ensuring you have valid consent from recipients before sending messages
- Thatmatters is not liable for messages sent to invalid or opted-out numbers
You are the data controller for your contacts' data. You must maintain valid opt-in consent records for all recipients as required under applicable law and Meta's WhatsApp Business Policy.
Payment & Billing Data
Thatmatters uses PCI-DSS compliant third-party payment processors (such as Razorpay or Stripe) to handle payment transactions. We do not store full card numbers, CVVs, or bank account credentials on our servers.
- Transaction amounts and timestamps are stored for billing records
- Wallet top-up history is retained for the lifetime of your account
- Invoices are stored for a minimum of 7 years as required by Indian tax laws
- For postpaid customers, signed contracts and deposit records are stored for the contract duration plus 5 years
Background Verification (BGV) Data
For postpaid and Enterprise customers who undergo Business Verification, we collect and process sensitive documents. This data is handled with enhanced security:
- BGV documents are stored in encrypted, access-controlled storage
- Access is restricted to authorized Thatmatters personnel and approved verification partners
- Documents are not shared with third parties beyond the scope of verification
- BGV records are retained for the duration of your contract plus 5 years
- You may request deletion of BGV data after account closure, subject to legal retention requirements
Government-issued identity documents and business registration certificates are classified as sensitive personal data under the DPDPA and are processed with explicit consent and appropriate safeguards.
Data Sharing & Disclosure
We do not sell, rent, or trade your personal data. We may share data only in the following circumstances:
- Service Providers: Payment processors, cloud hosting providers, and analytics tools operating under strict data processing agreements
- Meta / WhatsApp: Message content and recipient numbers are transmitted to Meta's API for delivery purposes only
- Verification Partners: For postpaid BGV, documents may be shared with authorized third-party verification agencies
- Legal Obligations: We may disclose data if required by law, court order, or government authority
- Business Transfer: In the event of a merger or acquisition, data may be transferred with prior notice to users
Data Retention
We retain data only as long as necessary for the purposes described in this policy:
- Account data: retained for the lifetime of the account and 2 years post-closure
- Message delivery logs: 90 days by default (extendable on request)
- Payment and invoice records: 7 years (as per Indian tax law)
- BGV and contract documents: contract duration plus 5 years
- Support ticket history: 3 years
- Usage and analytics logs: 12 months rolling
Data Security
We implement industry-standard security measures to protect your data:
- All data in transit is encrypted using TLS 1.2 or higher
- Data at rest is encrypted using AES-256 encryption
- Access to production systems is restricted to authorized personnel via multi-factor authentication
- Regular security audits and vulnerability assessments are conducted
- Incident response procedures are in place for data breaches
In the event of a data breach that materially affects your data, we will notify you within 72 hours as required by applicable law.
Your Data Rights
Under applicable data protection laws, you have the following rights regarding your personal data:
To exercise any of these rights, email support@thatmatters.in. We will respond within 30 days.
Cookies & Tracking
Thatmatters uses cookies and similar technologies for:
- Essential cookies: Authentication sessions and security tokens (required for platform to function)
- Analytics cookies: Understanding how users interact with the platform (can be opted out)
- Preference cookies: Remembering your dashboard settings and preferences
You can manage cookie preferences through your browser settings or our in-app cookie preferences panel. Disabling essential cookies may affect platform functionality.
Children's Privacy
Thatmatters is a business-to-business platform not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that a minor has provided personal data, we will delete it promptly.
Changes to This Policy
Thatmatters may update this Privacy Policy from time to time. Material changes will be communicated via email and in-app notifications at least 14 days before taking effect. The "Effective Date" at the top of this page reflects the latest revision. Continued use of the platform after changes constitute acceptance of the revised policy.
Contact & Grievance Officer
For privacy concerns, data requests, or grievances, contact our Data Protection Officer:
- Email: support@thatmatters.in
- Subject line: "Privacy Request — [Your Account Email]"
- Response time: Within 30 days of receipt
- Address: 2nd Floor, Devanahalli, Bangalore, Karnataka, India
Under the Digital Personal Data Protection Act 2023 (DPDPA), you may also escalate unresolved complaints to the Data Protection Board of India if you are not satisfied with our response.