Gusion Chat LogoChat
Legal

Privacy Policy

Effective date: 1 June 2026  ·  Last updated: 1 June 2026

1. Overview

Om Softwares ("we", "us", "our") operates the Gusion Chat platform at chat.gusion.in. This Privacy Policy explains how we collect, use, share, and protect information in connection with the Service, including information about your business, your employees who use the dashboard, and your end-customers whose data you process through our platform.

We act as a data processor for the personal data of your end-customers that you submit to the Service. You are the data fiduciary / data controller for that data and are responsible for having a lawful basis for its collection and processing. This Policy describes our processing activities as your processor and also our independent processing as a controller of your account and usage data.

2. Data We Collect

2.1 Account & Business Data (Controller)

  • Name, email address, phone number, and password of users who register an account.
  • Business name, GST number, billing address, and payment information (card details are processed by our payment gateway; we store only masked card info and transaction records).
  • WhatsApp Business Account (WABA) credentials, phone number IDs, and associated Meta account information you connect to the Service.

2.2 Customer Data (Processor)

  • Contact data of your end-customers that you import or that is generated through inbound WhatsApp conversations: name, phone number, and any custom attributes you create.
  • Message content: text, media (images, documents, audio, video), and interactive responses exchanged between your business and your end-customers via WhatsApp.
  • Conversation metadata: timestamps, message status (sent/delivered/read/failed), template names, and campaign attribution.

2.3 Usage & Technical Data (Controller)

  • Log data: IP addresses, browser type, pages visited, actions taken in the dashboard, and timestamps.
  • Device information: operating system, screen resolution, and browser version.
  • Performance and error data collected via application monitoring tools.

3. How We Use Data

We use the data we collect for the following purposes:

  • Providing the Service: processing messages, managing campaigns, running automation workflows, and generating analytics.
  • Account management: authentication, billing, plan management, and customer support.
  • Security & fraud prevention: detecting and preventing unauthorized access, abuse, and policy violations.
  • Product improvement: analysing aggregated, anonymised usage patterns to improve features. We do not use message content for training AI models without your explicit consent.
  • Communications: transactional emails (invoices, alerts, OTPs), product updates, and — if you have opted in — marketing communications. You can unsubscribe at any time.
  • Legal compliance: fulfilling obligations under applicable law, including responding to lawful requests from government authorities.

4. WhatsApp Message Data

WhatsApp message content is transmitted over encrypted channels. We store message content and media in encrypted form in our databases in Mumbai, India. Message data is used solely to display conversation history in your inbox, power search, and provide analytics.

We do not read, sell, or use the content of your WhatsApp conversations for any purpose beyond operating the Service and, where necessary, investigating reported policy violations. Our staff may access message content only when required to investigate a support ticket you have raised or a reported abuse complaint, and only to the minimum extent necessary.

Media files (images, documents, audio) are stored in cloud object storage. You can delete message history and media from within the dashboard at any time. Deleted data is permanently removed from our systems within 30 days.

5. Sharing & Disclosure

We do not sell your data or your customers' data. We share data only in the following circumstances:

5.1 Sub-processors

We use the following categories of sub-processors to operate the Service:

Sub-processorPurposeData location
Meta / BSPWhatsApp message routingGlobal / India
MongoDB AtlasPrimary databaseMumbai (ap-south-1)
Redis CloudCache & queuesMumbai
Fly / AWSApplication hostingUS / Singapore (closest AZ)
ResendTransactional emailUS / EU
Razorpay / PayUPayment processingIndia
CloudflareCDN, DDoS protection, DNSGlobal edge

5.2 Legal Disclosures

We may disclose data if required by law, court order, or lawful request from a government authority. We will attempt to notify you before disclosing unless legally prohibited.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity, which will be required to honour this Policy.

6. Data Storage & Retention

Your primary data (account info, contacts, messages) is stored in MongoDB Atlas and Redis Cloud instances deployed in Mumbai, India (ap-south-1). We keep data in India by default, consistent with our DPDP obligations.

  • Account data is retained for the life of your account plus 90 days after closure.
  • Message content & media is retained for as long as your account is active or until you delete it. After account closure, it is deleted within 30 days.
  • Billing records are retained for 7 years as required by Indian accounting law.
  • Log data is retained for 90 days for security and debugging purposes.

7. Security

We implement technical and organisational measures appropriate to the risk to protect data against accidental loss, destruction, alteration, unauthorised disclosure, or access. These measures include:

  • TLS 1.2+ encryption in transit for all API and dashboard traffic.
  • Encryption at rest for databases and media storage.
  • Role-based access controls within our team; production access is limited to engineering leads.
  • Multi-factor authentication enforced for internal systems.
  • Regular dependency audits and automated vulnerability scanning.

No method of transmission over the internet is 100% secure. If you discover a security vulnerability, please report it responsibly to sales@omsoftwares.in.

8. Your Rights Under the DPDP Act, 2023

If you are an individual whose personal data we process as a data fiduciary (e.g., a registered user), you have the following rights under India's Digital Personal Data Protection Act, 2023:

  • Right to access — you may request a summary of the personal data we hold about you and the purposes for which it is processed.
  • Right to correction & erasure — you may request correction of inaccurate data or erasure of data that is no longer necessary for the purpose for which it was collected.
  • Right to grievance redressal — you may contact our Grievance Officer (see Section 14) with any privacy complaint; we will respond within 30 days.
  • Right to nominate — you may nominate another individual to exercise these rights on your behalf in the event of death or incapacity.

To exercise these rights, email sales@omsoftwares.in with the subject "DPDP Data Request". We may ask you to verify your identity before processing the request.

9. EEA / GDPR Rights

If you are located in the European Economic Area (EEA) or UK, you may also have rights under the General Data Protection Regulation (GDPR) or UK GDPR, including the rights of access, rectification, erasure, restriction of processing, data portability, and to object to processing. Our lawful bases for processing are typically: contract performance (providing the Service), legitimate interests (security and fraud prevention), and legal obligation (tax records).

To exercise GDPR rights or lodge a complaint, contact us at sales@omsoftwares.in. You also have the right to lodge a complaint with your local supervisory authority.

10. Cookies & Tracking

We use the following types of cookies and similar technologies:

  • Strictly necessary cookies: session tokens and CSRF tokens required to keep you logged in and to secure your session. These cannot be disabled.
  • Analytics cookies: aggregated, anonymised page-view data to understand how the dashboard is used and where we can improve. We do not share this with advertising networks.
  • Preference cookies: remembering your theme (light/dark) and UI settings.

We do not use third-party advertising or tracking cookies. You can manage cookie preferences in your browser settings, though disabling necessary cookies will prevent the Service from functioning correctly.

11. Children

The Service is not directed to children under 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected data from a child under 18, we will promptly delete it. If you believe we have inadvertently collected such data, please contact us at sales@omsoftwares.in.

12. Third-Party Links

The Service may contain links to third-party websites or services. This Policy does not apply to those external sites. We recommend reading the privacy policies of any third-party sites you visit. We are not responsible for the privacy practices of third parties.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by a prominent notice within the Service at least 14 days before the changes take effect. The "last updated" date at the top of this page reflects when the Policy was last revised. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.

14. Contact & Grievance Officer

For privacy questions, data requests, or complaints, please contact our Grievance Officer. We aim to respond to all requests within 30 days.

Grievance Officer — Om Softwares

Nangal, Punjab — 140 124, India

Email: sales@omsoftwares.in

Phone: +91-62398-62469

Subject line: "Privacy Request" or "DPDP Data Request"