Privacy Policy
Effective date: 1 June 2026 · Last updated: 1 June 2026
1. Overview
Om Softwares ("we", "us", "our") operates the Gusion Chat platform at chat.gusion.in. This Privacy Policy explains how we collect, use, share, and protect information in connection with the Service, including information about your business, your employees who use the dashboard, and your end-customers whose data you process through our platform.
We act as a data processor for the personal data of your end-customers that you submit to the Service. You are the data fiduciary / data controller for that data and are responsible for having a lawful basis for its collection and processing. This Policy describes our processing activities as your processor and also our independent processing as a controller of your account and usage data.
2. Data We Collect
2.1 Account & Business Data (Controller)
- Name, email address, phone number, and password of users who register an account.
- Business name, GST number, billing address, and payment information (card details are processed by our payment gateway; we store only masked card info and transaction records).
- WhatsApp Business Account (WABA) credentials, phone number IDs, and associated Meta account information you connect to the Service.
2.2 Customer Data (Processor)
- Contact data of your end-customers that you import or that is generated through inbound WhatsApp conversations: name, phone number, and any custom attributes you create.
- Message content: text, media (images, documents, audio, video), and interactive responses exchanged between your business and your end-customers via WhatsApp.
- Conversation metadata: timestamps, message status (sent/delivered/read/failed), template names, and campaign attribution.
2.3 Usage & Technical Data (Controller)
- Log data: IP addresses, browser type, pages visited, actions taken in the dashboard, and timestamps.
- Device information: operating system, screen resolution, and browser version.
- Performance and error data collected via application monitoring tools.
3. How We Use Data
We use the data we collect for the following purposes:
- Providing the Service: processing messages, managing campaigns, running automation workflows, and generating analytics.
- Account management: authentication, billing, plan management, and customer support.
- Security & fraud prevention: detecting and preventing unauthorized access, abuse, and policy violations.
- Product improvement: analysing aggregated, anonymised usage patterns to improve features. We do not use message content for training AI models without your explicit consent.
- Communications: transactional emails (invoices, alerts, OTPs), product updates, and — if you have opted in — marketing communications. You can unsubscribe at any time.
- Legal compliance: fulfilling obligations under applicable law, including responding to lawful requests from government authorities.
4. WhatsApp Message Data
WhatsApp message content is transmitted over encrypted channels. We store message content and media in encrypted form in our databases in Mumbai, India. Message data is used solely to display conversation history in your inbox, power search, and provide analytics.
We do not read, sell, or use the content of your WhatsApp conversations for any purpose beyond operating the Service and, where necessary, investigating reported policy violations. Our staff may access message content only when required to investigate a support ticket you have raised or a reported abuse complaint, and only to the minimum extent necessary.
Media files (images, documents, audio) are stored in cloud object storage. You can delete message history and media from within the dashboard at any time. Deleted data is permanently removed from our systems within 30 days.
6. Data Storage & Retention
Your primary data (account info, contacts, messages) is stored in MongoDB Atlas and Redis Cloud instances deployed in Mumbai, India (ap-south-1). We keep data in India by default, consistent with our DPDP obligations.
- Account data is retained for the life of your account plus 90 days after closure.
- Message content & media is retained for as long as your account is active or until you delete it. After account closure, it is deleted within 30 days.
- Billing records are retained for 7 years as required by Indian accounting law.
- Log data is retained for 90 days for security and debugging purposes.
7. Security
We implement technical and organisational measures appropriate to the risk to protect data against accidental loss, destruction, alteration, unauthorised disclosure, or access. These measures include:
- TLS 1.2+ encryption in transit for all API and dashboard traffic.
- Encryption at rest for databases and media storage.
- Role-based access controls within our team; production access is limited to engineering leads.
- Multi-factor authentication enforced for internal systems.
- Regular dependency audits and automated vulnerability scanning.
No method of transmission over the internet is 100% secure. If you discover a security vulnerability, please report it responsibly to sales@omsoftwares.in.
8. Your Rights Under the DPDP Act, 2023
If you are an individual whose personal data we process as a data fiduciary (e.g., a registered user), you have the following rights under India's Digital Personal Data Protection Act, 2023:
- Right to access — you may request a summary of the personal data we hold about you and the purposes for which it is processed.
- Right to correction & erasure — you may request correction of inaccurate data or erasure of data that is no longer necessary for the purpose for which it was collected.
- Right to grievance redressal — you may contact our Grievance Officer (see Section 14) with any privacy complaint; we will respond within 30 days.
- Right to nominate — you may nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
To exercise these rights, email sales@omsoftwares.in with the subject "DPDP Data Request". We may ask you to verify your identity before processing the request.
9. EEA / GDPR Rights
If you are located in the European Economic Area (EEA) or UK, you may also have rights under the General Data Protection Regulation (GDPR) or UK GDPR, including the rights of access, rectification, erasure, restriction of processing, data portability, and to object to processing. Our lawful bases for processing are typically: contract performance (providing the Service), legitimate interests (security and fraud prevention), and legal obligation (tax records).
To exercise GDPR rights or lodge a complaint, contact us at sales@omsoftwares.in. You also have the right to lodge a complaint with your local supervisory authority.
11. Children
The Service is not directed to children under 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected data from a child under 18, we will promptly delete it. If you believe we have inadvertently collected such data, please contact us at sales@omsoftwares.in.
12. Third-Party Links
The Service may contain links to third-party websites or services. This Policy does not apply to those external sites. We recommend reading the privacy policies of any third-party sites you visit. We are not responsible for the privacy practices of third parties.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by a prominent notice within the Service at least 14 days before the changes take effect. The "last updated" date at the top of this page reflects when the Policy was last revised. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.
14. Contact & Grievance Officer
For privacy questions, data requests, or complaints, please contact our Grievance Officer. We aim to respond to all requests within 30 days.
Grievance Officer — Om Softwares
Nangal, Punjab — 140 124, India
Email: sales@omsoftwares.in
Phone: +91-62398-62469
Subject line: "Privacy Request" or "DPDP Data Request"