Privacy Policy
How Creware collects, uses, shares and protects personal data in Creware CallDesk and the WhatsApp Business Platform services we operate for client businesses.
Last updated 20 September 2026 · Creware Technologies Private Limited
1. Who we are
Creware Technologies Private Limited (CIN U72200KA2015PTC084326), trading as Creware, is a company registered in India with its registered office at Flat No. O-508, Ittina Mahaveer Neeladri Vihar, Electronic City, Bengaluru, Karnataka 560100, India. We operate the Creware CallDesk platform and provide WhatsApp Business Platform and cloud telephony services to business clients.
This policy explains what we do with personal data. It applies to https://creware.tech, to the Creware CallDesk application, and to the messaging services we operate on behalf of client businesses. You can reach us about privacy at archit@creware.tech or +91 78294-13575.
2. Our two roles: controller and processor
Our responsibilities depend on whose data is involved, and this distinction matters for understanding your rights.
- We are a data controller for our client relationships: the accounts of the client staff who log in to our platform, our billing records, our website visitors, and our own security and audit logs.
- We are a data processor for end-customer data: the phone numbers, profile names, messages and media belonging to the people who contact our client businesses on WhatsApp or by phone. The client business is the controller of that data and decides why it is collected and how long it is kept. We process it only on that client's instructions.
- If you are an end customer who messaged or called a business that uses our platform, and you want your data accessed, corrected or deleted, please contact that business directly. They control the record. We will support them in fulfilling your request.
3. Data we collect
We collect the following categories. We do not collect special category data such as health, biometric or financial account data, and we ask clients not to send it through the platform.
- Client user accounts: full name, work email address, role, profile photo if uploaded, and a one-way bcrypt hash of the password. We never store passwords in a readable form.
- Session and security records: session identifiers, sign-in and sign-out times, device and browser information, and an audit log of significant actions taken in the platform.
- WhatsApp Business Account configuration: WhatsApp Business Account (WABA) identifiers, phone number identifiers, display phone numbers, access credentials issued by Meta, and your message template definitions and their approval status.
- WhatsApp conversation data: end-customer phone numbers and WhatsApp identifiers, WhatsApp profile names, the content of messages sent and received, attached media such as images, video, audio and documents, message identifiers, and delivery, read and failure receipts with their timestamps.
- Voice call data: calling and receiving phone numbers, call direction, duration, outcome and disposition, IVR menu selections, and call recordings where recording is enabled for that line.
- AI-derived data: transcripts and written summaries generated from call recordings, where a client has enabled that feature.
- Lead and CRM records: contact names, phone numbers, notes written by agents, lead status and follow-up dates.
- Website data: pages requested, referring URL, approximate location derived from IP address, and standard server log information.
4. Why we use it
- To deliver the service: sending and receiving WhatsApp messages and calls, maintaining the shared inbox, running automated replies, and managing message templates through Meta's approval process.
- To operate campaigns that a client has configured, sending only approved template messages to recipients the client has confirmed have opted in.
- To provide reporting on delivery, response times, call volumes and messaging spend.
- To authenticate users, protect accounts, detect abuse, and investigate security incidents.
- To provide support, respond to your questions, and communicate service and billing notices.
- To meet legal, tax and regulatory obligations, and to enforce our Terms of Service.
5. Legal bases for processing
Where India's Digital Personal Data Protection Act, 2023 applies, we process personal data on the basis of consent obtained by the client business, or for legitimate uses permitted by that Act. Where the UK or EU GDPR applies, we rely on the following.
- Performance of a contract - to provide the platform to our clients and their authorised users.
- Legitimate interests - to secure our systems, prevent abuse and improve reliability, balanced against the rights of the people concerned.
- Consent - for end-customer messaging, which the client business is responsible for obtaining before any message is sent.
- Legal obligation - for retention of financial records and responses to lawful requests.
6. Consent for messaging
WhatsApp requires that a business hold a person's phone number and their permission before messaging them. Our client businesses are contractually responsible for obtaining and evidencing that opt-in, for honouring opt-out and stop requests promptly, and for complying with the WhatsApp Business Messaging Policy.
We support clients in meeting these obligations, and we may suspend messaging where we have reason to believe consent has not been obtained or an opt-out has been ignored.
7. Who we share data with
We do not sell personal data. We do not share it with advertising networks, data brokers or unrelated third parties. We do not use WhatsApp message content for advertising, for building profiles of individuals, or for training our own or third-party machine learning models.
We share data with the following service providers, each engaged under contract to process data only on our instructions.
- Meta Platforms, Inc. - WhatsApp Business Cloud API - message delivery, templates, media. Data shared: End-customer phone numbers, message content, media, template definitions. Processing region: United States and global edge infrastructure.
- Twilio Inc. - Outbound and inbound voice calling, SMS. Data shared: Caller and recipient phone numbers, call audio, call metadata. Processing region: United States.
- Plivo Inc. - Indian voice calling and IVR routing. Data shared: Caller and recipient phone numbers, call audio, call metadata. Processing region: India and United States.
- Resend, Inc. - Transactional and report email delivery. Data shared: Recipient work email addresses, report contents. Processing region: United States.
- OpenAI, L.L.C. - AI voice agent and call summarisation. Data shared: Live call audio, transcripts, call context sent for completion. Processing region: United States.
- Groq, Inc. - Speech-to-text and AI call summaries. Data shared: Call recordings and transcripts submitted for summarisation. Processing region: United States.
- DigitalOcean, LLC - Application servers, PostgreSQL database, media storage. Data shared: All platform data at rest. Processing region: India (Bengaluru).
8. Additional disclosures
- With the client business whose account the data belongs to, and with the users they have authorised.
- With professional advisers such as auditors and lawyers, bound by confidentiality.
- With authorities where we are required to do so by law, or to establish, exercise or defend legal claims. We assess each request and disclose the minimum necessary.
- With an acquirer in connection with a merger, acquisition or sale of assets, subject to this policy continuing to apply.
9. How your WhatsApp data is handled
Because we act as a technology provider on the WhatsApp Business Platform, we want to be explicit about this data.
- Your business owns its WhatsApp Business Account, its phone numbers and its conversation history. Our access is granted by you and can be withdrawn by you at any time through your Meta Business Settings.
- We access your WhatsApp Business Account solely to provide the services you have engaged us for: sending and receiving messages, managing templates, and configuring webhooks and automation.
- We do not access, use or disclose your WhatsApp data for any purpose other than providing those services to you.
- Message media received through WhatsApp is downloaded and stored on our servers so that your team can view it in the inbox after Meta's own retention window has passed.
- Credentials issued by Meta are held in server-side configuration, restricted to the systems that need them, and are never exposed to browsers or to other clients.
10. Where data is stored and how long we keep it
Platform data is stored in a PostgreSQL database, and message media is stored on the file systems of our application servers. Access is restricted to authorised personnel who need it to operate the service.
We retain conversation, call and lead records for as long as the client's account remains active, because that history is the working record their team relies on. We do not currently apply an automatic expiry to conversation history; clients control retention by asking us to delete records.
- Client businesses request deletion of stored records by emailing archit@creware.tech, as described on our data deletion page. The customer portal does not include in-product Delete chat controls.
- On a verified account deletion request we delete platform data within 30 days, and deleted records age out of encrypted backups within a further 35 days.
- We retain invoices, tax records and other statutory documents for the period required by law, even after account closure.
- Security and audit logs are retained for a limited period for incident investigation.
- Full instructions are on our data deletion page at https://creware.tech/data-deletion.
11. International transfers
Our service providers listed above process data outside India, including in the United States and the European Union. Where we transfer personal data internationally we rely on the recipient's contractual commitments, including standard contractual clauses where applicable, to keep the data protected to the standard described in this policy.
12. Security
We apply the following measures. We describe them plainly rather than claiming a level of protection we do not provide.
- All traffic to our website and platform is encrypted in transit using TLS.
- Passwords are stored only as bcrypt hashes and are never recoverable.
- Sessions use signed, HTTP-only cookies with a limited lifetime, and can be revoked per device by the user or an administrator.
- Access within the platform is restricted by role, and administrative actions are recorded in an audit log.
- Credentials for Meta, telephony and other providers are held in server-side configuration and are not accessible from client browsers.
- Database and file storage rely on the disk-level encryption and access controls provided by our hosting environment. We are progressively adding application-level encryption for stored third-party credentials.
- No system is completely secure. If a breach affects your personal data we will notify you and the relevant authority as required by law.
13. Your rights
Subject to the law that applies to you, and subject to our role as controller or processor as described in section 2, you may exercise the following rights by writing to archit@creware.tech. We will verify your identity before acting and will respond within 30 days.
- Access - obtain confirmation of what personal data we hold about you and a copy of it.
- Correction - have inaccurate or incomplete data corrected.
- Erasure - request deletion where we have no continuing lawful reason to retain the data.
- Portability - receive your data in a structured, machine-readable format.
- Withdraw consent - where processing relies on consent, withdraw it at any time. This does not affect processing already carried out.
- Object or restrict - object to processing based on legitimate interests, or ask us to restrict processing while a dispute is resolved.
- Complain - raise a concern with your data protection authority, or with the Data Protection Board of India.
14. Cookies
Creware CallDesk sets a single essential cookie that holds your signed session so you stay logged in. It is strictly necessary for the platform to function and cannot be switched off while you are using it.
We do not use advertising cookies, third-party tracking pixels or cross-site analytics on our website or in the platform.
15. Children
The platform is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached us, contact us and we will delete it.
16. Changes to this policy
We may update this policy as the service or the law changes. The revision date is shown at the top of this page. Where a change materially affects how we handle personal data we will notify affected clients directly, and where required we will obtain fresh consent.
17. Contact and grievance officer
For privacy questions or to exercise a right, write to archit@creware.tech.
In accordance with the Digital Personal Data Protection Act, 2023, our grievance officer is Archit Soni. Write to archit@creware.tech, call +91 78294-13575, or write by post to Creware Technologies Private Limited, Flat No. O-508, Ittina Mahaveer Neeladri Vihar, Electronic City, Bengaluru, Karnataka 560100, India. We acknowledge grievances promptly and aim to resolve them within 30 days.
To report a suspected security vulnerability, write to archit@creware.tech.