Skip to content

Legal

Privacy Policy

Last updated: 6 October 2026

On this page
  1. 1. Data we collect
  2. 2. How we use WhatsApp, Instagram and other Meta data
  3. 3. How we share data
  4. 4. Sub-processors
  5. 5. Data retention
  6. 6. Your rights under India's DPDP Act
  7. 7. Security and breach notification
  8. 8. International transfers and children
  9. 9. Cookies and analytics
  10. 10. Changes to this policy
  11. 11. Grievance Officer
  12. 12. Contact us

This Privacy Policy explains how Fliok, a unit of Zusta Autonetic Private Limited (CIN U62099WB2023PTC262445), 2/164A VC, Naktala, Kolkata, West Bengal 700047, India (“we”, “us”, “our”; the product is the “Service”), collects, uses, shares, retains, and protects information when you use our WhatsApp Business messaging platform. By using the Service you agree to the practices described here.

1. Data we collect

  • Account data: your name, email address, WhatsApp number, workspace details, and authentication identifiers used to create and secure your account.
  • WhatsApp Business data: WhatsApp Business Account IDs, phone number IDs, display names, message templates, and flow definitions you connect to the Service.
  • Data from other Meta accounts you connect: your Instagram professional account and its messages, comments, posts and insights; your ad accounts, Pages, ads and their results; your product catalogs and the orders customers send from them; and your WhatsApp Pay payment requests and their status (section 2).
  • Message data: the content, metadata, delivery status, and timestamps of messages sent and received through your connected WhatsApp numbers, and the contacts you message.
  • Lead and CRM data: details of leads you add or that reach you through the Service, for example from your website forms, lead portals or click-to-WhatsApp ads, and the notes, tasks and payment-link records your team keeps on them.
  • Billing data: your plan, subscription and AI usage wallet records. Card and bank details are handled by our payment processor (Razorpay), not stored by us.
  • Usage and technical data: log data, IP addresses, device/browser information, and diagnostic information needed to operate and secure the Service.

2. How we use WhatsApp, Instagram and other Meta data

We access the WhatsApp Business Platform and Meta APIs solely to provide the Service to you: to send and receive messages on your behalf, manage templates and flows, deliver inbound messages to your team, report delivery and quality status, and meter usage for billing.

Instagram. When you connect an Instagram professional account (through the Facebook Page it is linked to), we read the account’s name, ID and Page; the direct messages people send it; the comments and mentions on its posts; its posts, stories and reels; and its insights, which are totals Meta reports about the account, its posts and its audience (such as reach, views and followers). We use them only to show them to your team, to send the replies and comment replies your team or the AI writes, to publish and schedule the posts you create, and to show you those insights.

Ads, catalog and payments. When you connect an ad account, we read the ad accounts and Pages you choose, your Click-to-WhatsApp campaigns, ad sets and ads, and their results (such as spend, reach and conversations started), and we create and change ads only when you ask. When a customer messages you from an ad, we record which ad it was. When you connect a product catalog, we read and update its products and receive the orders customers send from it. When you send a WhatsApp Pay request, we keep its items, amount and payment status; the payment itself is handled by the payment provider you set up with Meta, and we never see card or bank details. We use this data only to provide these features to you.

We use information obtained through the Meta platform only as permitted by, and in compliance with, the Meta Platform Terms and the WhatsApp Business Messaging Policy. We do not sell your data, and we do not use Meta or WhatsApp data for advertising or for any purpose unrelated to operating the Service.

3. How we share data

We share data only with the sub-processors listed in the next section, and only as far as each needs it to operate the Service.

AI features. AI features, including the Zusta AI Assistant (the assistant in the dashboard), send the content they need to our AI model providers to produce their output — the Zusta AI Assistant does so whether or not the AI agent that replies to customers is switched on. For an AI reply that is the customer’s messages, your business instructions and the relevant history; for the Zusta AI Assistant it is your request and whatever it reads for you in your workspace, such as chats, contacts and leads. When a customer sends a voice note that an AI feature needs to read, the recording is sent to a speech-to-text provider. When the AI looks something up to answer a customer, the search words, which can come from the customer’s message, are sent to a web search provider; when a customer shares a link, the AI may open that public page. We send this content only to produce that output.

Integrations you connect yourself, such as an online store or another CRM, receive the data you choose to send them; they are your providers, and their own terms apply. We may also disclose data when required by law or to protect the rights, safety, and security of our users and the Service.

4. Sub-processors

These are the service providers that process personal data on our behalf, by category, with what they do for the Service and where they process it:

  • Meta Platforms (WhatsApp, Instagram and Facebook): Sends and receives your WhatsApp messages, templates and media and reports their delivery; carries Instagram messages, comments, posts and insights; runs the Click-to-WhatsApp ads, catalogs and WhatsApp Pay requests you create. Where: Meta's own data centres, which may be outside India.
  • Razorpay: Processes subscription, wallet top-up and other payments to us. Card and bank details are entered with Razorpay and are not stored by us. Where: India.
  • Cloudflare: Network, DNS and content delivery in front of the website and the Service; storage for our encrypted off-site backups; forwarding of email sent to our fliok.com addresses. Where: Cloudflare's global network, which may be outside India.
  • Server hosting provider: Runs the virtual private server that holds the Service, its database and stored files. Where: India.
  • Email delivery provider: Delivers sign-in codes, team invitations and account notices by email. Where: May be outside India.
  • AI model providers that process message text to draft replies: Also produce Zusta AI Assistant answers, summaries, lead details and other AI output from the content each AI feature needs. More than one is used: a second takes over when the first is unavailable. Where: May be outside India.
  • Speech-to-text provider: Turns a customer's voice note into text when an AI feature needs to read it. Where: May be outside India.
  • Web search provider: Runs a search when the AI looks something up to answer a customer. The search words can come from the customer's message. Where: May be outside India.
  • Google (Google Analytics): Measures how the website and the dashboard are used (section 9). Never message content, names, phone numbers or email addresses. Where: Google's data centres, which may be outside India.
  • Microsoft (Microsoft Clarity): Heatmaps and session recordings of the public website only, with form entries masked (section 9). Never used in the dashboard. Where: Microsoft's data centres, which may be outside India.
  • Meta Platforms (Meta Pixel and Conversions API): Measures which of our ads lead to enquiries, sign-ups and paid subscriptions, with email address and phone number hashed (section 9). Public website and our own server only; never in the dashboard. Where: Meta's own data centres, which may be outside India.

If you turn on browser or app notifications, the notification is delivered through your browser’s or device’s own push service. We update this list when a sub-processor is added or replaced.

5. Data retention

Your workspace’s data (account, contacts, conversations, messages, media, templates, leads and settings) is kept for as long as the workspace is active. Deleting a contact deletes that contact’s conversations and messages with it at once, and their stored media (photos, voice notes, documents and files attached to their lead) is erased from the Service within minutes. A file your team also sent to someone else stays while that other chat still shows it.

When a workspace is closed by its owner (Settings → Danger zone, or by email), it stops sending and receiving at once, and its data, including its stored media, is permanently erased from the Service 30 days later. Until then the closure can be stopped by contacting us. The login of each member who belongs to no other workspace is deleted with it. See Delete your account for the steps and for deleting only your login.

Meta data-deletion requests: if you connected a WhatsApp number, an ad account, a product catalog or an Instagram account to Fliok through Facebook, you can remove Fliok in your Facebook settings and ask Meta to delete your data. We then disconnect what you connected, delete the access you gave and your Meta user ID, and tell the workspace. The workspace’s own records (its chats, contacts and settings) belong to the business and are not deleted by your request; the workspace owner can close the workspace. Meta gives you a code to follow the request.

Shopify stores. When you install Fliok from the Shopify App Store, Shopify sends Fliok your store’s orders, fulfilments, checkouts and products, and the customers who agreed to WhatsApp marketing, so Fliok can message your customers and answer them. When your team asks it to, Fliok also creates checkout links (draft orders), discount codes and short order notes in your store. Fliok keeps this data while the app is installed. When you uninstall the app, order messages stop at once and, 48 hours later, when Shopify asks, Fliok deletes the store’s connection, its order records, abandoned checkouts and back-in-stock requests, and its record of the store. When a customer asks Shopify to erase their data, Fliok removes what it copied from Shopify about them: their store link, tags and order totals, their order records and back-in-stock requests, and payments recorded from store orders. Conversations on WhatsApp are your business’s own record and stay until you delete the contact.

Operational records are deleted automatically once they reach these ages:

  • Notifications Meta sends us about messages, templates and account changes: 14 days.
  • Payment notifications from Razorpay: 90 days.
  • Records of Meta data-deletion and app-removal requests: 365 days after the request is processed.
  • In-app notifications: 90 days once read, 180 days if never read.
  • Chatbot sessions with no set expiry: 30 days after their last activity. Sessions with an expiry are removed once it passes.
  • Abandoned-cart records that have been reminded, recovered or expired: 60 days.
  • Finished automation runs: 180 days, except the most recent run of each automation for each lead.
  • AI drafts that were stopped before sending: 90 days.
  • Zusta AI Assistant conversations, including what the assistant read to answer: 90 days.
  • Expired sign-in sessions and sign-in codes: removed daily.

Kept after deletion: invoices, credit notes and payment and wallet records are kept, as Indian tax law requires, no longer linked to the deleted workspace; they are not deleted on a schedule. The audit log, a record of who did what in an account (including deletion requests), is not deleted on a schedule; when a workspace is erased its entries are detached from it.

Backups: we keep encrypted off-site backups of the database, daily copies for 30 days and one copy a month for 12 months, and a backup copy of stored media. Backups are used only to restore the Service after a failure. Data erased from the database stays in a database backup until that backup is deleted on this schedule. A file erased from the Service (a deleted contact’s media, a closed workspace’s files) is removed from the media backup 35 days after it was erased; until then it can still be restored if it was deleted by mistake.

6. Your rights under India’s DPDP Act

Under the Digital Personal Data Protection Act, 2023, you have the right to:

  • Access: a summary of the personal data we process about you, how we process it, and who we have shared it with. A workspace owner can also download the workspace’s data from Settings → Your account → Your data.
  • Correction: have inaccurate or incomplete personal data corrected, completed or updated. Most account and contact details can be edited directly in the Service.
  • Erasure: have your personal data erased when it is no longer needed for the purpose it was collected for, or when you withdraw consent, unless the law requires us to keep it. A workspace owner can close the workspace from Settings, and anyone can ask us to delete their login (see Delete your account).
  • Withdraw consent: as easily as you gave it. Withdrawing consent does not affect processing already done.
  • Grievance redressal: raise a complaint with our Grievance Officer (section 11). If you are not satisfied with the response, you may complain to the Data Protection Board of India.
  • Nominate: name another person to exercise these rights for you in the event of your death or incapacity.

To exercise a right, contact us as described in section 11 or 12. We verify that a request comes from the person the data belongs to, or the workspace owner, before acting on it.

If you are a customer of a business that uses Fliok: that business decides why and how your messages are processed, and we process them on its behalf. Send your request to the business; we help it respond. You can also contact us directly and we will pass your request on. You can stop a business’s messages at any time by replying STOP, and opt-outs are honoured automatically. When a business deletes you as a contact, your chats, messages and the files you sent are erased as described in section 5.

7. Security and breach notification

We protect sensitive credentials and access tokens using encryption at rest, encrypt traffic to and from the Service, restrict access on a least-privilege basis, and verify the authenticity of webhook traffic from Meta and our payment processor. No method of transmission or storage is completely secure, but we take reasonable measures to safeguard your data.

If a personal data breach happens, we will tell each affected business (its workspace owner) without undue delay, with what happened, what data was involved, what we are doing about it and what they can do, and help them meet their own duties to the people concerned. For personal data we are responsible for ourselves, such as your login, we will inform the Data Protection Board of India and the affected people as the Digital Personal Data Protection Act, 2023 and its rules require.

8. International transfers and children

The servers that hold the Service and its database are in India. Some of the sub-processors in section 4 (Meta, Cloudflare, Google, Microsoft, and the email, AI model, speech-to-text and web search providers) may process data outside India, so your data may be processed in countries other than your own. We transfer personal data outside India only as Indian law allows, and only to the extent each provider needs it to do its job for the Service.

The Service is not directed to children and is intended for business use only.

9. Cookies and analytics

Strictly necessary cookies keep you signed in and secure and remember your theme, your currency, your country code (used only to decide whether to ask for your consent below) and your cookie choice. They are always on.

On our public website (the pages about Fliok, pricing, help, guides, these legal pages, and sign-in and sign-up) we use, subject to your choice:

  • Google Analytics (Google): which pages are visited and how (for example which buttons are clicked, how far a page is scrolled, searches in the Help Center), the device and browser, an approximate location derived from the IP address (Google Analytics does not store the address itself), and a random identifier kept in the _ga cookies. We keep Google Analytics data for 14 months.
  • Microsoft Clarity (Microsoft): heatmaps and session recordings of how the public pages are used (clicks, scrolling, mouse movement). Everything typed into a form is masked before it leaves your browser, so no name, number, email address or code is recorded. Cookies _clck and _clsk. Microsoft keeps recordings for about 30 days and aggregated reports for up to 13 months.
  • Meta Pixel and Conversions API (Meta Platforms): the Pixel tells Meta which page was viewed and when you take a step we advertise for — viewing a product, integration or pricing page, choosing a plan, sending the enquiry or walkthrough form, completing sign-up, or opening a chat with us on WhatsApp — with the _fbp / _fbc cookies. Our server also reports the same key steps directly (the Conversions API): an enquiry sent, a sign-up completed, and a paid subscription, add-on or wallet payment (never a free trial or a card check), with your email address, phone number and account identifier only in hashed (one-way SHA-256) form, plus your IP address and browser details, so Meta can measure which of our ads work. We do not use this to show you ads in the Service, and Meta handles it under its own terms.

In the dashboard (everything you see after signing in) we use Google Analytics only, to learn which features are used: the page type (never the address of a chat, contact or record), the actions taken, a one-way coded account identifier, your plan, your role and how long ago the workspace was created. No names, phone numbers, email addresses, message content or template text are ever sent, no sessions are recorded, and neither Microsoft Clarity nor the Meta Pixel is loaded there.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by notifying you within the Service.

11. Grievance Officer

Complaints about how we handle personal data, and requests to exercise the rights in section 6, are handled by our Grievance Officer:

  • Krishnendu Karmakar, Grievance Officer, Zusta Autonetic Private Limited (Fliok)
  • Address: 2/164A VC, Naktala, Kolkata, West Bengal 700047, India
  • Email: info@fliok.in, with “Grievance” or “Privacy request” in the subject
  • Online: the form on our contact page; start your message with “Grievance” or “Privacy request”
  • WhatsApp: +91 62903 26663

We acknowledge a grievance within 72 hours of receiving it and resolve it within 30 days. If a request needs longer, for example because we must first confirm who is asking, we tell you why and when to expect an answer.

12. Contact us

For any other privacy question, email support@fliok.com, write to us through our contact page, or message us on WhatsApp at +91 62903 26663.