Legal
Privacy Policy
What Growcord collects, why we hold it, who we share it with, how long we keep it, and how you exercise your rights under the Digital Personal Data Protection Act, 2023.
In effect from 7 August 2026. Issued by Growcord, a trade name of Idrishi, First Floor, Plot No. 39, Block R-5, Mohan Garden, New Delhi, Delhi 110059, India. GSTIN 07AESPW3016N1ZS.
This policy is written to be read, not filed. If you only want one thing from it: we do not sell personal data, we do not use your message content to train AI models, and your customers' data belongs to you rather than to us.
1. What this policy covers
It covers personal data handled by Idrishi, a sole proprietorship trading as Growcord, of First Floor, Plot No. 39, Block R-5, Mohan Garden, New Delhi, Delhi 110059, India, GSTIN 07AESPW3016N1ZS, when you visit our website, create a workspace, use the dashboard or the API, or contact us for support.
It is issued under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, and alongside the Information Technology Act, 2000 with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which continue to apply to sensitive personal data. It forms part of our Terms of Service.
2. Who is responsible for which data
Growcord handles two different kinds of personal data, under two different roles. Almost every question about rights and responsibilities comes down to which one you are asking about.
- Your data
- The account you hold with us: your name, work email, phone number, business details and billing records. Here we are the Data Fiduciary. We decide why and how it is processed, and this policy is our notice to you.
- Your customers' data
- The contacts you upload and the conversations you have with the people you message. Here you are the Data Fiduciary and we are a Data Processor acting on your instructions. Your own privacy notice governs that data, not ours.
3. What we collect
3.1 Account and business information
Your name, work email address, phone number, password in hashed form, business name, GSTIN and billing address, your role in the organisation, and the team members you invite. We need this to open the account, raise a valid tax invoice and tell one user apart from another.
3.2 Payment information
Plan, billing cycle, invoice history, payment status, wallet balance and transaction references. Card details are entered on Razorpay's checkout and are never sent to or stored on our servers. We keep the last four digits and the payment method type where Razorpay returns them, which is enough to reconcile a payment and not enough to make one.
3.3 Data you put into the platform
Contacts and their phone numbers, names, tags and custom fields. Message content in both directions, including media you upload or receive. Chatbot flows, message templates, product catalogues, order data from a connected store, notes on a conversation and pipeline stages. We hold this to run the service for you. We do not mine it.
3.4 Technical and usage data
IP address, browser and device type, operating system, referring page, the pages you open in the dashboard, timestamps, API request logs, delivery and error responses from Meta, and session identifiers. Some of this is collected automatically as a normal part of serving a web application, and it is what lets us answer the question "why did that message fail" a week after it failed.
3.5 Support and marketing
The content of tickets you raise, emails you send us, WhatsApp messages to our business number, and any screenshots or logs you attach. If you asked to hear from us, your marketing preferences and whether you opened or clicked.
3.6 What we do not want
Do not put card numbers, CVVs, passwords, Aadhaar or PAN numbers, biometric data, health records or financial account credentials into contact fields, template variables, bot variables or message content. The platform is not built to hold sensitive personal data of that kind, and putting it there creates risk for your customers that neither of us needs to carry.
4. Why we process it, and on what basis
Under the DPDP Act we process personal data either with consent, or for a legitimate use the Act recognises. Where the basis is consent, you can withdraw it and we explain how in clause 11.
| What we do | Why | Basis |
|---|---|---|
| Create and run your account | You cannot use a platform you have no account on. | Performance of the contract you asked for |
| Send messages to your contacts through Meta | It is the service you bought. | Contract, on your instructions as Data Fiduciary |
| Take payment and raise GST invoices | We are required to invoice and to keep books. | Contract and legal obligation |
| Service emails and in-app notices | Payment failures, expiring cards, security notices, downtime. | Contract and legitimate use |
| Support and troubleshooting | You asked us a question and we need the context to answer it. | Contract |
| Security, fraud prevention and abuse detection | Protecting the platform and other customers. | Legitimate use under Section 7 of the DPDP Act |
| Product analytics in aggregate | Working out which screens are confusing. | Legitimate use, on aggregated data |
| Marketing emails and product announcements | Telling you about things we have built. | Consent, withdrawable at any time |
| Meeting legal and tax obligations | Records we are required to retain. | Legal obligation |
We do not sell personal data, we do not rent or trade contact lists, and we do not carry out automated decision making that produces legal effects for you.
5. Cookies and analytics
We use a small number of cookies and similar storage. Strictly necessary ones keep you signed in, remember your workspace and protect against cross site request forgery. These cannot be turned off without breaking the application. Preference storage remembers things like your theme choice.
Analytics cookies help us see which pages convert and where people give up. Where we run advertising on search or social platforms, those platforms may set their own cookies on the marketing pages to measure whether a click became a signup. You can block or clear cookies in your browser. Blocking the strictly necessary ones will log you out.
6. Who we share data with
We share personal data only with the processors listed below, only for the purpose stated, and only under a contract that binds them to protect it. This is our current sub-processor list. We will update it here before adding a new processor that handles personal data.
| Who | What they process | Why |
|---|---|---|
| Meta Platforms (WhatsApp Business Platform) | Phone numbers and message content you send and receive | Delivering the messages. This is the service itself. |
| Razorpay Software Private Limited | Name, email, phone, billing address, payment details | Taking payment and processing refunds. |
| DigitalOcean (Spaces object storage) | Media files you upload to the gallery or send | Storing and serving images, documents and video. |
| Cloud hosting and database provider | All platform data at rest | Running the application and the database. |
| Email delivery provider | Email address and the content of the email | Sending verification, billing and service email. |
| AI model provider you choose | The prompt, which may include recent conversation text | Generating a reply or summary, only when you enable an AI feature. |
| Shopify, WooCommerce, Zapier | Order and customer data from your store | Only if you connect that store yourself. |
| Professional advisers, auditors and authorities | Whatever the specific matter requires | Legal, tax and regulatory obligations. |
We will also disclose data where a court, a regulator or a law enforcement agency lawfully requires it. Where we are permitted to tell you about such a request, we will. If the business is ever sold or reorganised, data may transfer to the acquirer, and this policy or one at least as protective will continue to apply.
7. Where data is stored and transferred
Platform data is held in data centres operated by our hosting provider. Some of the processors above operate outside India, so personal data may be transferred and processed abroad. Section 16 of the DPDP Act permits transfer to any country the Central Government has not restricted, and we will stop transferring to a restricted country if one is notified.
Where data leaves India, it is transferred under contractual protections at least equivalent to the standards in this policy, and it stays subject to Indian law in our hands.
8. How long we keep it
We keep personal data only as long as the purpose needs it, or as long as a law requires, whichever is longer. When neither applies, it is erased.
| Data | Kept for | Then |
|---|---|---|
| Account and profile data | While the account is open | Erased 90 days after closure, apart from what tax law requires us to keep |
| Contacts, conversations and media | While the account is open, or until you delete them | Erased 90 days after closure. You can export before then. |
| Invoices, GST records and payment history | 8 years from the end of the relevant financial year | Erased. This period is set by tax law, not by us. |
| AI conversation transcripts | The retention window set in your AI settings, 30 days by default | Purged automatically. You can purge them immediately from the dashboard. |
| Message delivery logs | While the account is open | Erased with the account. Needed to answer delivery disputes. |
| Application error samples | 30 days, or 90 days once the underlying error is resolved | Pruned automatically |
| Administrative audit trail | Retained for the life of the platform | Append only by design. It is the record of who changed what. |
| Support tickets and email | 3 years from closure of the ticket | Erased |
| Marketing contact data | Until you unsubscribe | Erased, apart from a suppression record so we do not email you again |
Backups are kept on a rolling cycle and are overwritten in the ordinary course. Data deleted from the live system may persist in a backup for a short period before it is overwritten.
9. How we protect it
We follow reasonable security practices and procedures as required by Section 43A of the Information Technology Act, 2000 and Rule 8 of the SPDI Rules, 2011, and the security safeguards required by Rule 6 of the DPDP Rules, 2025. In concrete terms:
- All traffic to the platform and the API is encrypted in transit using TLS.
- Passwords are stored only as salted bcrypt hashes. Nobody at Growcord can read them.
- API keys are shown once at creation and stored hashed. A lost key is revoked and reissued, not recovered.
- Access to production data is limited to staff who need it for a specific task, and administrative actions are written to an append only audit log.
- Provider credentials and access tokens are encrypted at rest, and secrets are redacted from application logs and error reports.
- Data is segregated by organisation, and every query is scoped to the caller's account.
- Rate limits and abuse detection protect against credential stuffing and scraping.
- Backups are taken regularly and restores are tested.
No system is perfectly secure and we will not pretend otherwise. What we commit to is keeping these controls in place, fixing weaknesses when we find them, and telling you honestly if something goes wrong. If you believe you have found a vulnerability, please write to [email protected] before disclosing it publicly. We will not pursue anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it.
10. If there is a data breach
Rule 7 of the DPDP Rules, 2025 sets a two stage obligation and we follow it. On becoming aware of a personal data breach we intimate the Data Protection Board of India without delay, describing the nature, extent, timing and likely impact of the breach. Within 72 hours we follow up with the fuller account the Rules require: the circumstances, the remedial and mitigation measures taken, and our findings on the cause.
We also notify every affected person, in plain language and without delay, telling them what happened, what data was involved, what they can do to protect themselves, and who to contact with questions.
Where the breach affects your customers' data rather than your own, you are the Data Fiduciary and the duty to notify those individuals is yours. We will give you everything you need to do it, promptly and without charge, and we will not delay telling you while we work out whose fault it was.
11. Your rights, and how to use them
As a Data Principal under the DPDP Act you have the following rights over the personal data we hold about you as Data Fiduciary:
- Access
- A summary of the personal data we hold about you, what we are doing with it, and who we have shared it with.
- Correction and completion
- Have inaccurate data corrected, incomplete data completed and out of date data updated. Most of this you can do yourself in the dashboard.
- Erasure
- Have your personal data erased, unless we are required by law to keep it or need it for the purpose you gave it for.
- Withdraw consent
- Withdraw consent where consent is the basis, as easily as it was given. Withdrawing marketing consent does not affect your account.
- Grievance redressal
- Complain to our grievance officer about how we have handled your data, and escalate if the answer does not satisfy you.
- Nominate
- Name someone to exercise these rights on your behalf if you die or become incapable of exercising them yourself.
To exercise any of them, write to [email protected] from the email address on your account, or use the account settings in the dashboard. We may ask you to confirm your identity, which protects you rather than us. We answer within 30 days, and sooner where we can. There is no charge.
Along with these rights, the Act places a duty on you not to make a false or frivolous complaint and not to impersonate someone else when making a request.
12. Your duties if you are a Data Fiduciary
When you use Growcord to message your customers, the DPDP Act treats you as their Data Fiduciary. That carries obligations we cannot discharge for you:
- Give your customers a clear notice, in plain language, saying what you collect and why, and offering it in English and in the languages listed in the Eighth Schedule to the Constitution where the Rules require it.
- Obtain and keep evidence of free, specific, informed and unambiguous consent before you message them on WhatsApp, and honour withdrawal as easily as you obtained it.
- Answer access, correction and erasure requests from your own customers.
- Publish a working grievance contact of your own.
- Notify your customers and the Data Protection Board if a breach affects their data, following the same two stage timeline described in clause 10.
This policy sets out our processing terms as your Data Processor. We act only on your documented instructions, we require confidentiality from anyone who touches the data, we apply the security measures in clause 9, and we return or delete the data when your account closes. If you need a separate signed data processing agreement for your own compliance file, ask us at [email protected] and we will provide one at no cost.
13. Children and persons with disabilities
The platform is sold to businesses and is not intended for anyone under 18. We do not knowingly collect personal data from a child. If we learn that we have, we delete it.
Section 9 of the DPDP Act prohibits processing a child's personal data without verifiable consent from a parent or lawful guardian, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. If your business messages people under 18, that obligation is yours, and you must have verifiable parental consent before you send anything. The same applies to a person with a disability who has a lawful guardian.
14. AI features and your data
AI replies, summaries and drafting are optional and off unless you turn them on. When they are on, the prompt sent to the model provider can include recent conversation text so the model has context to answer with.
- You choose the provider. Anthropic, OpenAI, Google, DeepSeek, Qwen or a model you host.
- Where you supply your own API key, the provider's terms apply to that traffic and their retention practices govern it.
- We do not use your conversations, contacts or message content to train any model, ours or anyone else's.
- Transcripts stored for context are kept for the retention window you set, 30 days by default, and you can purge them at any time from the dashboard.
- If you would rather no conversation text left the platform, leave the AI features off. The rest of the product works without them.
15. Grievance officer and escalation
We have appointed a grievance officer under Rule 9 of the DPDP Rules, 2025 and Rule 3(2) of the IT (Intermediary Guidelines) Rules, 2021. Contact them about anything in this policy, a rights request that was not answered properly, or a complaint about how we handled your data.
- Name
- Mohd Wasim
- Designation
- Grievance Officer and Data Protection Contact
- [email protected]
- Phone
- +91 88003 17861
- Address
- First Floor, Plot No. 39, Block R-5, Mohan Garden, New Delhi, Delhi 110059, India
- Acknowledgement
- Within 24 hours of receipt.
- Resolution
- Within 15 days for complaints under the IT Rules, and within 90 days at the outside for complaints under the DPDP Rules. In practice most are closed in under a week.
If our answer does not satisfy you, you may complain to the Data Protection Board of India. You must raise the complaint with us first. That is a requirement of the Act, and it also means most problems are fixed without anyone needing to involve a regulator.
16. Changes to this policy
We update this policy when the law changes, when we add a processor, or when the product starts handling data differently. The date it took effect is at the top of the page. For a material change we notify you by email or in the dashboard at least 30 days before it takes effect. Continuing to use the platform after that means you accept the updated policy.
Questions about this document
Write to [email protected] or call +91 88003 17861. Full contact details, including the named grievance officer, are on the contact page.
