1. Preamble & Regulatory Scope
This Privacy Policy (“Policy”) outlines the practices of DialText Infotech Private Limited (operating as “DialText”, “Company”, “we”, “our”, or “us”) regarding the collection, use, processing, transfer, storage, and erasure of Personal Data through our website (dialtext.com), developer REST APIs, and enterprise CPaaS services.
This Policy is published pursuant to and in compliance with:
- Section 43A of the Information Technology Act, 2000;
- Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
- The Digital Personal Data Protection Act, 2023 (“DPDP Act 2023”); and
- Rule 3(1) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
2. Relationship of Parties (Data Fiduciary vs. Data Processor)
Under the DPDP Act 2023:
- When you interact with our website or submit inquiries: DialText acts as a Data Fiduciary in respect of your corporate contact details (name, business email, mobile number, company name).
- When you utilize our CPaaS APIs, WhatsApp Cloud API, Bulk SMS, or Voice IVR engines: You (the enterprise customer) are the Data Fiduciary with respect to your end-users' recipient data. DialText operates strictly as a Data Processor on your documented instructions and in accordance with your master service agreement.
3. Categories of Data Collected
We collect and process personal data solely to the extent necessary for lawful commercial and statutory purposes:
| Data Category | Examples | Lawful Purpose & Retention |
|---|---|---|
| Account & Commercial Data | Name, business email, mobile number, company GSTIN, billing address. | KYC verification, invoicing, MSME/GST statutory audits. Retained for 7 years under Indian tax laws. |
| Transmission Telemetry (CDR) | Source Sender ID, destination MSISDN (hashed), timestamp, delivery receipt status (DLR), error code. | Telecommunication routing and TRAI regulatory compliance. Retained for 2 years as mandated by DoT/TRAI licenses. |
| Message Body Payloads | Template parameters (e.g. OTP digits, customer names in notifications). | Ephemeral transit only. Encrypted in memory and permanently purged within 72 hours of terminal delivery. |
| Technical & Device Telemetry | IP address, browser user-agent, API request rate, TLS handshake metadata. | Rate limiting, DDoS defense, intrusion prevention. Retained in rolling 90-day security logs. |
4. Sub-Processors & Platform Ecosystem Disclosures
To deliver global enterprise messaging, DialText engages vetted technical sub-processors under strict data protection agreements:
- Meta Platforms, Inc. / Meta Platforms Ireland Limited: As an official Meta Tech Provider ecosystem participant, WhatsApp Cloud API message payloads are transmitted directly to Meta's infrastructure for delivery to WhatsApp end-user devices. Meta processes data in accordance with the Meta Business Terms and WhatsApp Business Data Processing Terms.
- Tier-1 Indian Telecom Operators: Including Bharti Airtel, Reliance Jio Infocomm, Vodafone Idea, and BSNL for SMS transmission and TRAI DLT registry scrubbing.
- Domestic Cloud Infrastructure Providers: ISO 27001 / SOC-2 certified tier-4 datacenters located strictly within the territory of India (Mumbai and Pune regions) ensuring data residency.
5. User Rights Under the DPDP Act 2023
As a Data Principal under Indian law, you have the following enforceable statutory rights:
- Right to Access: You may request a summary of your personal data processed by us, along with the identities of all third parties with whom it has been shared.
- Right to Correction & Updating: You may request the rectification of inaccurate or outdated personal data.
- Right to Erasure: You may request the deletion of your personal data when the lawful purpose for which it was collected has ceased to exist, subject to statutory retention obligations under TRAI / tax regulations. Visit our dedicated Data Deletion Policy to initiate this process.
- Right to Grievance Redressal: You have the right to expeditious grievance redressal through our designated Grievance Officer.
- Right to Nominate: You may nominate any other individual to exercise your data rights in the event of death or incapacity.
6. Security Measures & Cryptographic Controls
DialText maintains comprehensive technical and organizational security controls:
- Encryption in Transit: All web and API communications are enforced over TLS 1.3 with modern cipher suites.
- Encryption at Rest: Database volumes, backup archives, and configuration stores are encrypted using AES-256.
- Role-Based Access Control (RBAC): Strict least-privilege administrative access with multi-factor authentication (MFA) and immutable audit logging.
- Annual Vulnerability Assessments: Periodic CERT-In certified third-party VAPT audits.
7. Governing Venue & Dispute Resolution
This Policy shall be governed by and construed in accordance with the laws of the Republic of India. Any dispute, claim, or controversy arising under or relating to this Policy shall be subject to the exclusive jurisdiction of the competent courts situated in Mumbai, Maharashtra, India.