Skip to content

Security & Compliance

How your data is actually protected.

Your clients trust you with their conversations. You need to trust us with that data. No marketing language, no vague promises — exactly what we do, in plain terms.

Data hosted in IndiaTLS 1.3 in transitAES-256 at restDPDP Act compliantGST-registered entityAudit-logged access

Infrastructure

Data Residency

Database
PostgreSQL on Hetzner VPS
Bangalore, India. Your data never leaves Indian territory.
Application
Next.js on Hetzner
Same India-based VPS. No multi-region replication to foreign servers.
Backups
Daily encrypted dumps
pg_dump (cluster + per-DB) at 02:00 UTC daily, retained 30 days on-VPS and uploaded to an off-site Google Drive remote via rclone. Restore procedure documented and tested.

AI inference (via Anthropic Claude) is processed in the US — this is unavoidable for current LLM providers. Only the conversation context needed to generate a reply is sent; no PII is transmitted beyond what's in the message itself. Anthropic's enterprise agreement explicitly prohibits using API data for model training.

Data Protection

Encryption

In Transit
TLS 1.3

All API calls, dashboard sessions, and WhatsApp webhooks use TLS 1.3. Older protocols (TLS 1.0, 1.1) are disabled at the nginx layer.

At Rest
AES-256

Hetzner VPS disk encryption via LUKS (AES-256-XTS). Database passwords, API keys, and tokens are stored hashed (bcrypt/HMAC-SHA256), never plaintext.

HTTPS is enforced site-wide via HSTS with a 2-year max-age. Certificates are auto-renewed via Let's Encrypt / Certbot.

Regulation

DPDP Act 2023 Compliance

India's Digital Personal Data Protection Act 2023 governs how we collect, use, and delete personal data. Here's our posture on each relevant obligation:

Compliant
Lawful purpose & consent

Data is collected only to deliver the contracted WhatsApp first-responder service. Clients explicitly consent via our Terms of Service at signup.

Compliant
Data minimisation

We collect: phone number, business name, conversation history, and usage events. No location tracking, no device fingerprinting, no third-party ad pixels.

Compliant
Retention limit

Conversation data and leads are retained for 24 months from last activity. Clients can request earlier deletion (see below).

Compliant
Deletion on request

Clients and their end-customers can request full deletion via /data-deletion. We process all requests within 14 days and confirm via email.

In progress
Data fiduciary registration

Registration with the Data Protection Board is in progress post-incorporation (INC-20A expected Q2 2026).

Designated
Grievance officer

Ashish Dubey, Grievance Officer (Niyog AI). Email grievance@niyogai.com or write to 103 Diamond Harbour Road, Kolkata 700038, India. Acknowledged within 48 hours; resolved within 30 days, in line with IT Rules 2021 and DPDP Act 2023.

Access Controls

Who Can Read Your Data

Default: zero Niyog employees can read your conversations.

Access to production data requires explicit admin credentials held by a single designated administrator. Every admin action is logged with timestamp, IP, and action type. Logs are immutable and retained for 12 months.

Dashboard access

Each client workspace is isolated by client_id at the database row level. A dashboard token (HMAC-SHA256) scoped to your workspace is required. Tokens expire after 7 days.

API access

Your mobile app and API integrations authenticate via an app_secret (32-byte random string) + owner phone pair. Secrets are hashed before storage.

Support access

If you contact support and explicitly request investigation, we may access your workspace data only for that specific support case and only for the duration needed.

Audit log

Every agent action, message sent, and data modification is logged in whatsapp_audit_log and agent_runs tables. You can request a full export at any time.

Third Parties

Subprocessors

We use a minimal set of third-party services. Each one is listed below with what data they touch and a link to their own privacy policy.

SubprocessorPurposeData touchedLocation
AnthropicAI inference (Claude models)Conversation context — no customer data used for model trainingUSA
Meta (WhatsApp Business API)WhatsApp message deliveryPhone numbers, message content in transitUSA / Global
RazorpayPayment processing & subscriptionsBilling name, email, payment method tokens — no raw card dataIndia
Hetzner OnlineCloud hosting & VPS infrastructureAll application data including databaseIndia (Bangalore)
SentryError monitoring & performanceStack traces, non-PII request metadataUSA

We will notify clients of any new subprocessors at least 30 days before they process data. Last updated: May 2026.

Breach Response

Incident Response

0–1 hr

Contain the incident. Revoke compromised credentials. Isolate affected systems.

1–24 hrs

Notify all affected clients directly via WhatsApp + email. Provide initial impact assessment.

24–72 hrs

Notify CERT-In (per DPDP Act obligation). File report with Data Protection Board once operational.

Post-incident

Full post-mortem published to affected clients. Corrective measures documented and implemented.

To report a suspected vulnerability: security@niyogai.com. We aim to acknowledge all reports within 24 hours.

Roadmap

Certifications & Compliance Roadmap

GST Registration
Active

Registered under Dubey Electronics (bridge entity). Niyog AI Pvt Ltd registration in progress.

Udyam (MSME)
Active

UDYAM-WB-10-0103548. Recognised small enterprise under the Ministry of MSME.

INC-20A (Company)
In progress

Niyog AI Pvt Ltd incorporation underway. Target: Q2 2026.

DPDP Registration
Post-incorporation

Data fiduciary registration with Data Protection Board once INC-20A clears.

SOC 2 Type I
Target Q1 2027

Scoped and planned. Audit firm evaluation begins Q3 2026.

ISO 27001
Evaluating

Under evaluation. Intent confirmed; implementation timeline post-Series A.

Legal

Data Processing Agreement

Need a Data Processing Agreement?

Enterprise and mid-market clients requiring a signed DPA (Data Processing Agreement) or MSA (Master Service Agreement) can request one directly. We typically turn these around within 5 business days.

Security questions?

We'll answer any security question before you sign. No pressure, no sales pitch.

hello@niyogai.com →
WhatsApp