Privacy Policy
Last updated: 25 July 2026
This Privacy Policy explains how Kryta Labs LLP ("Kryta Labs", "we", "us", "our") collects, uses, shares, retains and protects personal data in connection with our website at kryta.in and our WhatsApp automation platform for transport and logistics businesses (the "Service").
We are a company registered in India and we comply with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the rules made under it.
The Service is currently provided free of charge. We do not sell personal data, and we do not use data from WhatsApp conversations for advertising.
If you do not agree with this Policy, please do not use the Service.
1. Two different roles we play
This distinction matters, so we set it out first.
When we act as a Data Fiduciary (controller)
For data about our own users and prospects — the transport businesses that sign up with us, their staff who administer an account, and visitors to our website — we decide why and how the data is processed. This Policy governs that processing.
When we act as a Data Processor
Our users use the Service to communicate with their own contacts: consignors, consignees, drivers, fleet owners, brokers and staff. The personal data in those conversations belongs to the user's business. We process it only on that business's instructions, under our Terms of Service.
If you received a WhatsApp message from a transport business using our platform and want your data corrected or deleted, please contact that business directly — they control that data. If you are unsure who to contact, write to us at admin@kryta.in and we will route your request.
2. Data we collect
2.1 Account data
- Business name, address and statutory identifiers such as GSTIN
- Name, designation, email address and mobile number of authorised users
- Login credentials and authentication data
- Support tickets, emails and correspondence with our team
We do not collect payment card details, because the Service is currently free. If we introduce paid plans in future, we will update this Policy before doing so.
2.2 Data received through the WhatsApp Business Platform
When a business runs automation flows through our platform, the following may pass through or be stored on our systems:
- WhatsApp phone number and WhatsApp profile name of the person messaging
- Message content sent to and from the business, including text, images, documents, location and other media
- Data submitted inside an automation flow — for example consignment or booking references, LR / bilty numbers, vehicle registration numbers, driver names and contact numbers, pickup and delivery addresses, cargo descriptions, freight details, proof-of-delivery images, and e-way bill or invoice documents
- Location data, where a person voluntarily shares their location in a chat
- Message metadata: timestamps, delivery and read status, the template or automation flow used
We receive this data on behalf of the business that operates the WhatsApp Business Account. We do not use it for our own purposes.
2.3 Data from Meta permissions
Our application requests the following permissions on the Meta platform, and uses the resulting data only for the purposes stated:
| Permission | What we access | Why |
|---|---|---|
| whatsapp_business_messaging | Send and receive messages on the business's WhatsApp Business Account | To deliver the automation flows the business has configured |
| whatsapp_business_management | WhatsApp Business Account settings, phone numbers, message templates | To register numbers, create and manage message templates, and configure webhooks |
| business_management | Business portfolio identifiers and asset relationships | To link the business's WhatsApp assets to their Kryta Labs account |
We do not request or access personal Facebook profile data, friend lists, photos, or Instagram content. We do not use Meta platform data for advertising, for building profiles of individuals, or for any purpose other than operating the Service.
2.4 Data collected automatically
- IP address, browser type, device type, operating system
- Pages visited, features used, referring URL
- Cookies and similar technologies (see Section 8)
- Application logs and error reports
3. Why we process data
| Purpose | Legal basis under the DPDP Act |
|---|---|
| Creating and administering user accounts | Performance of contract / consent |
| Delivering the WhatsApp automation Service | Performance of contract; instruction of the business |
| Sending and receiving messages via the WhatsApp Business Platform | Instruction of the business; consent of the recipient |
| User support and troubleshooting | Contract; legitimate use |
| Platform security, fraud prevention and abuse detection | Legitimate use; legal obligation |
| Improving the reliability and performance of the Service | Legitimate use |
| Complying with law, court orders and regulatory requests | Legal obligation |
| Product update emails to account administrators | Consent, withdrawable at any time |
4. WhatsApp and Meta
The Service operates on the WhatsApp Business Platform provided by Meta Platforms, Inc. and its affiliates.
- Messages sent and received through the Service pass through Meta's infrastructure and are subject to Meta's own terms and privacy policies, which we do not control.
- Use of the Service is subject to the WhatsApp Business Messaging Policy and the WhatsApp Business Terms of Service. Businesses using our platform are responsible for obtaining valid opt-in from every person they message, and for honouring opt-out requests.
- Meta may retain message data and metadata according to its own policies, independently of us.
We comply with Meta's Platform Terms and Developer Policies in our handling of platform data, including restrictions on transferring platform data to third parties and on using it for prohibited purposes.
5. Who we share data with
We do not sell personal data. We share it only as set out below.
Sub-processors
We use vetted third parties to operate the Service, each bound by confidentiality and data protection obligations:
- Meta Platforms — WhatsApp Business Platform messaging
- Application hosting and data storage is located in Jaipur, India
- Gmail — transactional and support email
A current list of sub-processors is available on request at admin@kryta.in.
The businesses using our platform
Where you interact with a transport business through our Service, your messages are delivered to and accessible by that business.
Legal and regulatory disclosure
Where required by applicable law, a valid court order, or a lawful request from a government or law enforcement authority.
Business transfer
In connection with a merger, acquisition, financing or sale of assets, subject to the acquirer honouring this Policy.
6. Data retention and deletion
Retention periods
- Account data: for as long as the account is active, and for 30 days after account closure.
- WhatsApp conversation content and media: 365 days by default, or the shorter period configured by the business operating the account.
- Structured automation flow records (for example consignment reference and status history, without message content): for as long as the account is active.
- Application and security logs: 6 months.
We delete or anonymise personal data once it is no longer needed for the purpose it was collected for, unless retention is required by law.
How to request deletion of your data
Anyone may request deletion of their personal data by emailing admin@kryta.in with the subject line "Data Deletion Request", stating the phone number or account concerned. We will verify the request and complete deletion within 30 days, and confirm by email once it is done.
Businesses using the Service can also delete conversation data directly from their dashboard, and can request deletion of their entire account and all associated data by writing to admin@kryta.in.
7. Security
We maintain reasonable security safeguards appropriate to the nature of the data, including:
- Encryption of data in transit (TLS) and at rest
- Role-based access control and the principle of least privilege
- Access logging and monitoring
- Secure storage of access tokens and credentials
- Regular backups
- Confidentiality obligations on all personnel and contractors
- Periodic review of our security posture
No system is perfectly secure. In the event of a personal data breach, we will notify the Data Protection Board of India and affected persons as required under the DPDP Act.
8. Cookies
Our website and dashboard use cookies and similar technologies for authentication and session management, remembering preferences, and understanding how the Service is used. You can control cookies through your browser settings, though disabling essential cookies may prevent the dashboard from functioning.
9. Your rights
Subject to applicable law, you may:
- Access — obtain a summary of the personal data we process about you and the parties it has been shared with
- Correct — have inaccurate or incomplete data corrected, completed or updated
- Erase — request deletion of data that is no longer necessary for the purpose it was collected for
- Withdraw consent — where processing is based on consent, withdraw it at any time; this does not affect processing carried out before withdrawal
- Nominate — nominate another individual to exercise your rights in the event of your death or incapacity
- Grievance redressal — raise a complaint with us and, if unsatisfied with our response, escalate to the Data Protection Board of India
To exercise these rights, write to admin@kryta.in. We will respond within 30 days. We may need to verify your identity before acting on a request.
If your data was provided to us by a transport business using our platform, we will refer your request to them, as they control that data.
10. Children
The Service is intended for business use by adults. We do not knowingly process the personal data of children under 18. If we learn that we have done so without verifiable parental consent, we will delete it.
11. International transfers
Our infrastructure is hosted in Jaipur, Rajasthan. Some of our sub-processors, including Meta, may process data outside India. Where data is transferred internationally, we do so in accordance with the DPDP Act and any restrictions notified by the Central Government, and we require appropriate contractual protections.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified by email to account administrators, or through a notice in the dashboard, at least 14 days before they take effect. The "Last updated" date above reflects the current version.
13. Contact and grievance officer
For any question, request or complaint about this Policy or our handling of personal data:
Email: admin@kryta.in
Address: Plot no. 30, Kishan Nagar, Janpath, Shyam Nagar (Jaipur)
Phone: +91-9251142291
We aim to acknowledge grievances within 48 hours and resolve them within 30 days.
If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.