Your data — and your customers' — protected by design
Vyapnova handles real customer conversations on the channels your business runs on. Security, privacy, and responsible AI are built into the platform, not bolted on — and Vyapnova never touches the money.
Trust pillars
The controls that keep your merchant data isolated, your access governed, and your AI answers grounded.
Data encryption
Conversations, requests, and catalogue records are encrypted in transit (TLS 1.2+) and at rest. Channel access tokens and secrets are stored encrypted — never in plaintext, never in logs.
Access control & roles
Role-based access control with least-privilege defaults, short-lived signed sessions, and audit logging on sensitive actions — who did what, and when.
Official platform APIs
Vyapnova connects to Instagram and WhatsApp only through Meta's official APIs — the Instagram Messaging API and the WhatsApp Business Platform. We request the minimum scopes needed, and you can disconnect a channel at any time.
Tenant isolation
Your data is logically isolated per merchant, and every query is scoped to your tenant by design — one business cannot read another's conversations, customers, or catalogue.
Data ownership
Your data stays yours. Export your knowledge base, customers, and requests, and ask for erasure on demand — including per-customer erasure, in line with India's DPDP Act 2023 and the GDPR.
Responsible AI
Answers are grounded in the knowledge you provide — catalogue, prices, policies, FAQs. The agent mirrors the customer's language, escalates to a human when it is unsure, and you can take over or switch it off for any conversation. Your data is never used to train foundation models.
Compliance & data rights
Vyapnova Technologies Private Limited is built from India for businesses worldwide. We are building to India's Digital Personal Data Protection (DPDP) Act 2023 and align with GDPR principles for merchants and customers outside India. You stay in control of personal data — yours and your customers'.
Exactly what we collect, every sub-processor we use, and our retention schedule are published in our Privacy Policy. No hidden processors, no undisclosed data use.
Data export
Pull a structured export of a customer's data — profile, conversations, and requests — or request a full account export, yours to keep and to move.
Erasure on request
Request deletion of a customer's personal data or your full account. Erasure is honoured across live systems within 30 days, and expires from encrypted backups within 90 days.
Documented retention
Data is kept only as long as the purpose requires, on the retention schedule published in our Privacy Policy — no indefinite hoarding, and deletion timelines you can point your own customers to.
Report a vulnerability
Found a security issue? We take it seriously and will work with you in good faith. Please report it privately so we can fix it before any disclosure. We support good-faith research: report privately, avoid harming data or availability, allow us reasonable time to fix — and we will not pursue legal action over research conducted that way.