Privacy Policy
Last updated: 3 September 2026
1. Who we are
This website and the Rikaja messaging dashboard are operated by Rikaja Automation, trading as Rikaja, a business registered in India.
- Privacy contact: contact@rikajaautomation.com
- Support: support@rikajaautomation.com
- Jurisdiction: India
In this policy, "we", "us" and "Rikaja" mean Rikaja Automation. "Client" means a business that signs up for our dashboard or engages us for software or automation work. "End customer" means a person whom a Client messages through our platform.
2. Two categories of data
We handle two clearly separate categories of personal data, and our role differs for each.
(a) Data about our Clients
Information about the businesses that sign up for our dashboard and the people who administer those accounts. For this data we are the data fiduciary (controller): we decide why and how it is used.
(b) Data our Clients process through our platform about their own end customers
Message recipients, message content and delivery results belonging to a Client's own audience. For this data we are a data processor acting on the Client's instructions. The Client is the data fiduciary (controller) and decides what is sent, to whom, and on what legal basis.
3. Data we handle
Client account and billing data
- Business name and, where applicable, GSTIN and other registration identifiers
- Contact person's name and job role
- Email address and phone number
- Billing details, invoice records and payment status
- Login credentials (passwords are stored only as salted hashes) and account activity logs
WhatsApp Business Platform data
- WhatsApp Business Account (WABA) ID
- Phone number ID and the display phone number connected to the account
- Access tokens issued by Meta for the connected account
- Message templates, their categories, languages and approval status
- Message content sent through the platform, and the delivery status returned by Meta (sent, delivered, read, failed, with failure reasons)
- End-recipient phone numbers supplied by the Client, and inbound replies from those recipients
Website data
This website is a set of static pages. It has no contact form, no analytics script and no advertising or tracking pixels. Standard server access logs (IP address, timestamp, page requested, user agent) are kept by our hosting provider for security and troubleshooting.
4. How we use this data
- To create and administer Client accounts and provide the dashboard
- To connect a Client's WhatsApp Business Account and send messages on their instruction
- To submit templates for Meta's approval and return the result to the Client
- To show delivery and failure reports
- To issue invoices and collect payment
- To provide support, investigate faults and prevent abuse of the platform
- To meet legal, tax and regulatory obligations in India
We do not use Client message content or end-recipient data to build profiles, to market to those recipients ourselves, or to train machine-learning models.
5. Access to Meta and WhatsApp Business Account data
We access a Client's Meta and WhatsApp Business Account data only after that Client has explicitly authorised it by completing Meta's official Embedded Signup flow. The authorisation is granted by the Client directly to Meta; we receive only the scoped access it produces.
We use that access solely to operate the service the Client signed up for — connecting the number, managing templates, sending messages and retrieving delivery status. We do not use it for any other purpose, and we do not share the resulting access with anyone else. A Client can revoke our access at any time from their Meta Business settings, or by writing to support@rikajaautomation.com. Revoking access stops the service.
6. Our role as processor, and the Client's responsibilities
For end-customer data, we act only on the Client's documented instructions. The Client is responsible for:
- Obtaining valid, recorded opt-in consent from every recipient before messaging them
- Having a lawful basis for uploading recipient phone numbers to our platform
- The content of its templates and messages
- Honouring opt-out and stop requests from its recipients
- Publishing its own privacy notice to its end customers
If an end customer contacts us directly about data a Client sent through our platform, we will refer them to that Client and, where we can identify the account, notify the Client of the request.
7. Who we share data with
We share data only with the parties below, and only to the extent needed to run the service.
- Meta Platforms, Inc. (WhatsApp Business Platform) — message content, recipient phone numbers, templates and account identifiers are transmitted to Meta in order to deliver messages, and delivery status is returned to us. Meta's own handling of that data is governed by Meta's terms and privacy policy.
- Our hosting and infrastructure provider — stores and serves the application and its database under contract.
- Our payment processor — handles Client payments. Card details are entered with the processor and are not stored on our systems.
- Government or law-enforcement authorities — only where we are legally required to disclose.
We do not sell personal data, and we do not rent, trade or share it for anyone else's marketing.
8. Retention and deletion
- Message content and delivery status: retained for 90 days so Clients can view reports, then deleted from active systems.
- End-recipient phone numbers and contact lists: retained while the Client's account is active. Deleted within 30 days of the Client deleting them or closing the account.
- Client account data: retained while the account is active and for 30 days after closure, then deleted.
- Meta access tokens: deleted immediately on disconnection, account closure or revocation.
- Invoices and tax records: retained for 8 years as required by Indian tax law. This is the one category we cannot delete on request.
- Server access logs: retained for 30 days.
To request deletion, follow the instructions on our Data Deletion page.
9. Security
- All traffic to our website and dashboard is encrypted in transit using HTTPS/TLS.
- Access tokens and passwords are stored encrypted or hashed, never in plain text.
- Access to production systems is restricted to authorised personnel, on a need-to-know basis, protected by individual accounts and multi-factor authentication.
- Each Client's data is logically separated so one Client cannot see another's.
- Access to production data is logged.
No system is completely secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.
10. Your rights
Subject to Indian law, you may:
- Ask what personal data we hold about you and get a copy of it
- Ask us to correct data that is inaccurate, incomplete or out of date
- Ask us to delete your data (see Data Deletion)
- Withdraw consent you previously gave, including by disconnecting your WhatsApp Business Account
- Nominate another person to exercise these rights on your behalf if you are incapacitated or deceased
- Raise a grievance with us, and escalate to the Data Protection Board of India if you are not satisfied
Write to contact@rikajaautomation.com. We respond within 30 days. If you are an end customer of one of our Clients, please contact that Client — they control the data.
11. Compliance
We process personal data in accordance with India's Digital Personal Data Protection Act, 2023 and the rules made under it. Our processing of WhatsApp Business Platform data also follows Meta's platform terms, the WhatsApp Business Messaging Policy and the WhatsApp Business Solution Terms. Data is stored on servers located in India.
12. Cookies
This public website sets no cookies and runs no third-party scripts. The Rikaja dashboard sets a single first-party session cookie, which exists only to keep you signed in. It is strictly necessary for the service, carries no advertising or analytics identifier, and expires when your session ends. We do not use third-party advertising or tracking cookies anywhere.
13. Children
Our services are for businesses. We do not knowingly collect personal data of children under 18. Clients must not use the platform to message children in breach of applicable law.
14. Changes to this policy
If we change this policy we will update the "Last updated" date at the top of this page. For changes that materially affect how we handle personal data, we will additionally email the registered contact address of every active Client at least 14 days before the change takes effect. Continuing to use the service after that date means you accept the updated policy.
15. Contact us
Privacy questions, requests or complaints
Email contact@rikajaautomation.com and we will respond within 30 days. If your question is about an account you hold with us, write from the address registered on that account.