Skip to content
Janiva Janiva

Privacy Policy

Last updated: 30 July 2026

This policy is provided in good faith and is current as of the date above. A dedicated privacy inbox ([email protected]) and a named Grievance Officer are being finalised; until then, please use the support address below and your request will be routed appropriately.

This Privacy Policy describes how Janiva ("Janiva", "we", "our", or "us"), operated by Janiva Digital Solutions (an Indian limited liability partnership, GSTIN 29BECPN5029M1Z3, with its registered office in Bengaluru, Karnataka), collects, uses, shares, and protects information when you use our WhatsApp-first AI business assistant available on WhatsApp and at https://pa.janiva.bot and our website at https://janiva.bot (together, the "Service"). We are committed to handling personal data in line with applicable law, including India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") and, for individuals in the United Arab Emirates, UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") — see the UAE section below.

1. Our two roles: Fiduciary and Processor

Janiva is a business-to-business (B2B) service, and our responsibility for personal data depends on whose data it is. There are two distinct categories:

  • Account & service data (we are the Data Fiduciary / Controller). For data about our own customers — the businesses and team members who sign in to Janiva — such as account details, business profile, billing information, support correspondence, and usage and telemetry data, we decide why and how the data is processed. For this data we act as the Data Fiduciary (Controller) and are responsible to you under this policy.
  • Customer Data (we are the Data Processor). For the personal data that a business uploads to or processes through Janiva about its own customers, contacts, vendors, and team members — for example phone numbers, names, WhatsApp messages, invoice line items, and ledger entries — the business is the Data Fiduciary and Janiva acts as a Data Processor on that business's behalf. We process such Customer Data only on the customer's documented instructions and only to provide the Service. Our processor commitments are set out in our Data Processing Agreement, available to business customers on request.

Where this policy refers to data we process about you (the account owner or team member), we act as Fiduciary. Where it refers to Customer Data you load into Janiva about third parties, you are the Fiduciary and we are your Processor.

2. Information we collect

Account & business profile

  • Identity and contact details you provide: name, email, phone number, password (stored only as a salted hash), and role.
  • Business profile and tax details: company names, GSTIN(s), addresses, cost-centres, bank-ledger configuration, and other workspace setup.
  • Team members you invite, their roles, and their access permissions.

Content & Customer Data you process

  • WhatsApp messages, contacts, and media (images, documents, voice notes) exchanged with Janiva and with the business numbers you connect.
  • Business records you create or import: invoices, customers, vendors, ledgers, virtual-number usage, CRM deals, tasks, and Tally exports.
  • Social content you compose, schedule, and publish to Instagram and Facebook through the Service.
  • Contact details of people you delegate tasks to, so Janiva can follow up with them on WhatsApp.

Payment metadata

  • Billing details and payment metadata processed through our payment provider, Razorpay — for example transaction identifiers, amounts, plan, GST details, and status.
  • We do not collect or store your full card or bank-account numbers. Card and payment-instrument data is handled directly by Razorpay under its own security and compliance program; we receive only the transaction metadata needed to manage your subscription.

Usage, device & log data

  • Session metadata: login timestamps, IP address, browser/device information, and last-active time.
  • An audit trail of actions taken in the Service (creating invoices, posting ledger entries, scheduling posts, delegating tasks).
  • Diagnostic and error logs, and aggregated usage metrics used to operate and improve the Service.

Integrations you connect

  • Access tokens for connected accounts — for example WhatsApp Business, Instagram, Facebook, and (optionally) Microsoft 365 and Google for email/calendar/drive — encrypted at rest.
  • The account identifiers and display names of the channels you link.

Cookies

  • Essential session cookies needed to sign you in and keep the application working.
  • Minimal first-party analytics on our marketing website to understand aggregate traffic. We do not run advertising trackers in the application.

3. Why we process data & our lawful basis

Under the DPDP Act we process personal data on the basis of your consent and, where applicable, on the basis of certain legitimate uses permitted by law (for example, performing the service you have signed up for, and complying with legal obligations). We process data to:

  • Provide the Service — run your accounting, generate GST invoices and Tally exports, manage virtual numbers and the shared inbox, publish social posts, run your CRM, and chase delegated tasks.
  • Power AI assistant features — interpreting your instructions in plain language and drafting replies, posts, invoices, and summaries (see Section 5 and our AI System Card).
  • Authenticate users and protect accounts (password hashing, session management, rate-limiting, abuse prevention).
  • Send service-related communications (task reminders, approval requests, security and billing notices).
  • Bill your subscription and meter usage where applicable.
  • Maintain, secure, and improve the Service using aggregated, de-identified usage metrics and error monitoring.
  • Comply with legal, tax, and accounting obligations under Indian law.

We do not use your business or Customer Data to train generalised AI models, and we do not sell personal data.

How consent is obtained and withdrawn

Where we rely on consent, we obtain it at sign-up and when you enable optional features or integrations. Your consent request is, or will be made available, in clear and plain language. You may withdraw consent at any time — for example by disconnecting an integration, turning off an optional feature, or contacting us at the address in Section 11. Withdrawing consent is as easy as giving it. Withdrawal does not affect processing carried out before withdrawal, and where consent is necessary to provide the Service, withdrawing it may mean we can no longer provide some or all of the Service.

4. When we share information

  • With sub-processors (listed in Section 6) that operate the Service on our behalf, each bound by confidentiality and data-protection obligations.
  • Within your own workspace — your team members and the contacts you choose to involve (for example a person you delegate a task to).
  • To comply with law when required by a valid legal process, or to protect our rights, users, and the public.
  • On a business transfer (merger, acquisition, or reorganisation), subject to this policy continuing to apply to the transferred data.
  • We do not sell personal data.

5. AI providers

Janiva's assistant features rely on third-party large-language-model (LLM) providers, currently Anthropic, OpenAI, Google, and OpenRouter. When you ask Janiva to do something — for example draft a reply, summarise a thread, or help compose an invoice — the relevant portion of your request and the data needed to fulfil it is sent to one of these providers to generate a response. We select and configure these providers, and use their APIs, under terms that restrict use of your content to delivering the Service, and we do not authorise providers to use your content to train generalised models. We do not send more data than is needed to perform the requested task. The AI System Card documents what data is and is not sent to AI providers for each feature.

6. Sub-processors

We engage the following categories of third parties to provide the Service. Each is bound by contractual confidentiality and data-protection obligations and may process data only as needed to deliver the Service to us:

  • AI / LLM providers — Anthropic, OpenAI, Google, and OpenRouter — for the AI assistant features.
  • Razorpay — payment processing and billing.
  • Meta / WhatsApp Business Platform and the ChatMagnet BSP — WhatsApp messaging and number provisioning.
  • Microsoft 365 and Google — optional, user-connected integrations for email, calendar, and drive.
  • Cloudflare — DNS, CDN, and edge security.
  • DigitalOcean — cloud hosting infrastructure (Bengaluru, India region) for parts of the application and databases.
  • Microsoft OneDrive and Google Drive — encrypted offsite backups of Service databases (backups are encrypted before upload).

We maintain and update this list as our providers change, and we impose confidentiality and data-protection obligations on each sub-processor. The current list is also reflected in our Data Processing Agreement.

7. WhatsApp and messaging

Janiva uses the WhatsApp Business Platform operated by Meta, via our messaging partner (BSP), to send and receive messages. Messages routed through WhatsApp are subject to Meta's and WhatsApp's own terms and privacy practices in addition to this policy. You are responsible for having any consents (recipient opt-in) required to message your contacts through the Service and for honouring opt-out requests.

7A. Facebook and Instagram (Meta Platform Data)

If you connect a Facebook Page or Instagram professional account to Janiva, we receive data from Meta's platform in order to provide the social-media features you use: your Page and Instagram account identifiers and names, access tokens, and — depending on the features you use — the posts, comments, messages, and performance insights of the connected accounts ("Platform Data").

  • How we use it. Platform Data is used solely to provide the features you request — publishing and scheduling posts, moderating comments, replying to messages, and showing insights for your own connected accounts. We do not sell Platform Data, use it for advertising, or share it with third parties except the sub-processors listed in section 6 as needed to run the Service.
  • How it is stored. Access tokens are encrypted at rest. Synced content and insights are stored in your workspace, isolated from other customers.
  • How to disconnect and delete. You can disconnect an account at any time from Social → Accounts in your dashboard, which deletes its access tokens. You can also remove Janiva's access from your Facebook settings under Settings & privacy → Business integrations (or Apps and websites). To have all Platform Data associated with your accounts deleted, disconnect the account and write to the contact in section 12 — we delete or de-identify it within 30 days, subject to section 9.
  • Platform terms. Our use of Meta Platform Data is governed by Meta's Platform Terms and Developer Policies in addition to this policy.

8. International transfers

Some of our sub-processors — in particular certain AI/LLM providers and cloud infrastructure — may process data on servers located outside India. Where personal data is transferred outside India, we do so in accordance with applicable law and impose appropriate contractual protections on the recipient to safeguard the data to a standard consistent with this policy. We do not transfer personal data to any country to which such transfer is restricted under applicable Indian law.

8A. Users in the United Arab Emirates (PDPL)

Where we process personal data of individuals in the UAE — for example when a UAE business uses Janiva, or when we process messages its customers send to its WhatsApp number — the UAE PDPL applies in addition to this policy. For that processing:

  • Roles. For a UAE business's account data we act as controller; for the business's own customer data handled through the Service we act as processor on the business's instructions, mirroring the Fiduciary/Processor split in section 1.
  • Legal bases. We process personal data with consent, or where processing is necessary to perform our contract with the business, to comply with legal obligations, or for our legitimate interests in operating, securing and improving the Service.
  • Your rights. Subject to the PDPL's conditions, individuals in the UAE may request access to, correction or erasure of their personal data, restriction of or objection to processing (including direct marketing), and portability. Write to us at the contact below; we respond within the timelines the PDPL requires.
  • Cross-border transfers. The Service is operated from India, so personal data of UAE users is transferred to and processed in India (and by the sub-processors listed above). We make such transfers with appropriate contractual protections consistent with the PDPL's cross-border transfer requirements, holding recipients to a standard consistent with this policy.
  • Complaints. If you are unsatisfied with our response, you may complain to the UAE Data Office as the competent authority under the PDPL.

9. Retention and deletion

  • We retain your account and business data for as long as your account is active and as needed to provide the Service.
  • We retain certain records for longer where required by applicable law — for example tax, GST, and accounting records that must be kept under Indian law.
  • Integration access tokens are deleted when you disconnect the integration or close your account.
  • As a business customer, you can export or delete the Customer Data within your workspace using the Service, subject to the integrity of records you are legally required to keep.
  • You can request deletion of your personal data or closure of your account at any time; we will delete or de-identify it within a reasonable period, subject to any legal holds or retention obligations.

10. Security

  • Encryption in transit (TLS) and encryption at rest for sensitive credentials and access tokens.
  • Passwords stored as salted hashes and never logged.
  • Account-level isolation so each workspace's data is kept separate.
  • Access controls, rate-limiting, and an audit trail of administrative and sensitive actions.

We apply reasonable, industry-standard technical and organisational safeguards appropriate to the nature of the data we process. No online service can guarantee absolute security. In the event of a personal-data breach, we will take reasonable steps to mitigate it and will notify affected users and the relevant authority where required by applicable law, including the DPDP Act.

10A. Government and legal requests

If a public authority requests personal data we hold, we follow a documented process:

  • Every request is reviewed for legality — its legal basis, scope, and the authority's competence — before any response.
  • We challenge requests we consider unlawful or overbroad through the available legal channels, and reject requests that do not carry a valid legal basis.
  • We apply data minimisation — where a response is legally required, we disclose the minimum information necessary to comply.
  • We document each request, our legal assessment, the actors involved, and our response.
  • Where the law permits, we notify affected users before disclosing their data.

11. Your rights as a Data Principal

Subject to applicable law, including the DPDP Act, you may have the right to:

  • Access a summary of the personal data we process about you and how we process it.
  • Correction and erasure — to have inaccurate or incomplete data corrected, updated, or completed, and to have your data erased where it is no longer required for the purpose it was collected, subject to legal retention obligations.
  • Withdraw consent for optional processing at any time (see Section 3).
  • Grievance redressal — to a readily available means of raising and resolving a grievance with us (see below).
  • Nomination — to nominate another individual to exercise your rights in the event of your death or incapacity.
  • Complain to the Data Protection Board of India or other competent authority.

For Customer Data where we act as Processor, requests from the relevant individuals should be directed to the business that controls that data (the Fiduciary); we will assist that business in responding as set out in our DPA.

12. Grievance Officer & contact

Data Fiduciary for our own processing:
Janiva Digital Solutions
No. 6, 3rd Floor, 14/3, Varanasi Jinkethimmanahalli, Bangalore, Karnataka 560036, India
GSTIN 29BECPN5029M1Z3

Grievance Officer (under the DPDP Act):
Name: to be appointed
Email: [email protected] (being finalised)
Until the dedicated inbox is live, please contact us at [email protected] and mark your message "Privacy / Grievance".

We will acknowledge and respond to grievances and rights requests within the time limits required by applicable law.

13. Children

The Service is intended for businesses and their authorised personnel. It is not directed to, and we do not knowingly collect personal data from, individuals under the age of 18. If you believe a minor has provided us personal data, please contact us so we can take appropriate action.

14. Changes to this policy

We may update this policy from time to time. Material changes will be announced in the Service and reflected in the "Last updated" date above. Your continued use of the Service after an update takes effect constitutes acceptance of the revised policy. See also our Terms of Service and Data Processing Agreement.