Privacy Policy
What we collect, why we collect it, how long we keep it, and who else sees it.
This Privacy Policy explains how DV Connect ("we", "us"), operating dvconnect.in, handles personal data in connection with our SMS, voice, WhatsApp, Telegram and RCS communication services (the "Services"). It applies to our customers, to visitors to this website, and it explains our role in relation to the recipients your messages are sent to.
1. Two Different Roles
This distinction matters throughout this policy.
- For your account data — your name, business details, billing information and usage — we are the data fiduciary. We decide how it is used and this policy governs it.
- For your recipients' data — the mobile numbers you upload, the message content you compose and the personalisation values you supply — you are the data fiduciary and we are a data processor acting on your instructions. You are responsible for having lawful consent to send to those recipients, for your own privacy notice to them, and for responding to their rights requests. We process that data only to deliver your messages and to meet our legal and regulatory obligations.
2. What We Collect
Account and billing data
- Name, business or company name, email address and mobile number.
- Billing address, state, PIN code, country and GSTIN.
- Password, stored only as a bcrypt hash, and two factor authentication settings.
- Invoices, payment references and transaction records. Card and bank details are never stored on our servers; they are handled entirely by our payment gateways.
Service and traffic data
- Recipient mobile numbers, message content, template identifiers and personalisation values submitted for delivery.
- Delivery status, timestamps, message and call identifiers, call duration, keypress responses and error codes.
- Voice call recordings, where you use IVR or a call recording feature.
- Chatbot conversation history for WhatsApp and Telegram services, including any files a customer sends to your bot.
- API keys and panel credentials issued to you.
Technical data
- IP address, browser type, device and operating system, pages viewed and referring URL.
- Login history, including IP address and timestamp, retained for account security.
- Form submission records used to detect and block automated abuse.
3. Why We Use It
- To deliver the Services you have purchased and to route your messages and calls.
- To create your account, issue API keys, apply credits and provide the client area.
- To raise GST compliant invoices and process payments.
- To provide support, investigate delivery problems and answer your tickets.
- To meet obligations under TRAI regulations and the DLT framework, including retaining records of commercial communication and responding to complaints and regulatory directions.
- To detect, prevent and investigate fraud, spam, abuse and security incidents.
- To send you service notices about your account, renewals and platform changes. These are operational messages and are not marketing.
- To send occasional marketing about our own services, where you have not opted out. Every such message carries an unsubscribe option.
4. Cookies
We use a session cookie to keep you logged in and to protect forms against automated submission. We do not use advertising or cross-site tracking cookies. Third party scripts we load, such as Google reCAPTCHA and the payment gateway checkout, may set their own cookies under their own privacy policies. Blocking cookies will prevent login and checkout from working.
5. Who We Share Data With
We do not sell personal data, and we never sell, rent or share your recipient lists. We share data only as follows:
- Telecom operators and SMS or voice aggregators, to route your messages and calls. They receive the recipient number and the message content because delivery is impossible otherwise.
- Meta Platforms, for WhatsApp Business API traffic, and Telegram, for Telegram bot traffic, under their own terms.
- DLT platforms operated by telecom operators, for entity, header and template registration and for scrubbing.
- Payment gateways (Razorpay and CCAvenue), which process payment instruments directly. We receive only a transaction reference and status.
- Google reCAPTCHA, for bot protection on public forms.
- Our email infrastructure, for account, invoice and support email.
- Regulators, law enforcement and courts, where we are legally required to disclose, or where disclosure is necessary to investigate abuse or protect rights and safety.
- A successor entity, in the event of a merger, acquisition or restructuring, subject to equivalent protection.
6. How Long We Keep It
- Account and billing records: for the life of the account and then for eight years, as required by Indian tax and company law.
- Message and call logs: a minimum of six months as required under the TRAI framework, and typically up to 12 months, after which they are deleted or aggregated.
- Call recordings: as configured for your account, and deleted on written request unless a dispute or investigation is open.
- Chatbot conversation history: for the life of the subscription plus 90 days.
- Login and security logs: up to 12 months.
- Form abuse records: 24 hours.
7. Security
Traffic to this site and to our APIs is encrypted with TLS. Passwords are stored as bcrypt hashes and are never recoverable in plain text. Access to production systems is restricted and logged, API access requires a per-account key, and optional two factor authentication is available on every account. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authority as required by law.
8. Your Rights
Subject to our legal and regulatory retention obligations, you may:
- request a copy of the personal data we hold about you;
- ask us to correct data that is inaccurate or incomplete, or update it yourself in your profile;
- ask us to erase data we no longer have a legal basis or obligation to retain;
- withdraw consent to marketing at any time, without affecting service messages;
- ask us to restrict processing while a complaint is being resolved;
- nominate another person to exercise these rights in the event of death or incapacity.
Write to support@dvconnect.in. We respond within 30 days. We may ask you to verify your identity first.
If you are a recipient of a message sent through our platform and want your data removed, please contact the business that sent it, since they control the list. If you cannot identify them, write to us with the sender ID and the date and we will pass your request on and stop delivery to your number where we can.
9. Reporting Unwanted Messages
To report spam, a scam or a message you did not consent to, email support@dvconnect.in with the message text, the sender ID and the date and time. We investigate every report, and we suspend customers who send without consent. You may also register your preferences on the national DND registry through your telecom operator or the TRAI DND application.
10. Children
The Services are intended for businesses and are not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child's data has been provided to us, contact us and we will delete it.
11. International Transfers
Our infrastructure is primarily in India. Some processors, notably Meta for WhatsApp traffic, process data outside India. Where data is transferred internationally, it is done under the terms and safeguards of the relevant platform.
12. Changes to This Policy
We may update this policy as our services, our processors or the law change. The current version is always published here with its effective date. Material changes affecting how we use your data will also be notified by email.
13. Contact
Privacy questions and rights requests: support@dvconnect.in
Sales and general enquiries: sales@dvconnect.in
Phone: 011 6965 3983
Address: 1/10A, Pocket B, Phase 3, Ashok Vihar, Delhi, India