1. Roles
The business that uses Navakrit (the “Customer”) decides why and how its customers' personal data is processed and is the Data Fiduciary (controller). Navakrit processes that data only to provide the Service, on the Customer's behalf and on its documented instructions, and is the Data Processor. For data received from Meta platforms, Navakrit acts as a Meta Tech Provider for the Customer.
2. What we process
- Purpose: running the Customer's inbox: receiving, storing, organising and sending messages and comments, contact management, lead forms, and AI features the Customer turns on.
- People: the Customer's own customers and leads, and the Customer's staff who use Navakrit.
- Data: names, phone numbers, platform IDs, message and comment content, files and locations shared in conversations, lead form answers, notes, and delivery status.
- Duration: for as long as the Customer uses Navakrit, then as set out in section 10.
3. The Customer's responsibilities
The Customer is responsible for giving its customers the notices required by law, having a lawful basis (including any required opt-in) to collect and message them, and making sure its instructions to us comply with the law and with the policies of the channels it connects.
4. Our commitments
- We process Customer Data only on the Customer's instructions and to provide the Service.
- We keep each Customer's data separate from every other Customer's.
- Everyone we allow to access Customer Data is bound by confidentiality.
- We never sell Customer Data or use it for advertising.
- We never use Customer Data, or any data received from Meta platforms, to train, develop or improve AI models, and we do not allow our sub-processors to do so.
5. Sub-processors
The Customer authorises us to use the sub-processors below. Each is bound by written terms that protect the data at least as well as this addendum. We will email account owners at least 14 days before adding or replacing a sub-processor. If the Customer objects on reasonable data-protection grounds and we cannot resolve it, the Customer may end the Service.
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Microsoft Azure | Hosting of the platform: servers, database and backups | All Customer Data | United States |
| OpenAI | AI features (suggested and automatic replies, follow-ups), only when a business turns them on | Recent conversation text and the business's own information | United States |
| Vercel | Hosting of this website (navakrit.com) | Website visitor technical data (IP address, browser) | Global edge network |
Meta (WhatsApp, Facebook Messenger, Instagram) is the channel the Customer chooses to use; Meta processes messages under its own terms with the Customer, and may keep WhatsApp message content for up to 30 days to deliver it.
6. Security
We protect Customer Data with encryption in transit (TLS) and at rest, encrypted storage of access tokens, role-based access within each workspace, an activity log of staff actions, daily backups and monitoring. We review these measures as the Service changes.
7. Personal data breaches
If we become aware of a breach affecting Customer Data, we will notify the Customer without undue delay and in any case within 72 hours, with what we know about the breach, the data affected and the steps we are taking, and we will help the Customer meet its own notification duties.
8. Requests from individuals
If someone asks us directly to access, correct or delete their data held for a Customer, we will pass the request to that Customer and help it respond, using the tools in the Service where possible.
9. International transfers
Customer Data is processed in the countries listed in section 5. Such transfers are permitted under the Digital Personal Data Protection Act, 2023; we only use sub-processors bound by written data-protection terms.
10. Deletion and return
The Customer can export its data at any time. When the Service ends, the Customer has 30 days to export it, after which we delete it; encrypted backups are overwritten within a further 14 days. See our Data Deletion Instructions.
11. Information and audits
Once a year, or after a breach, we will answer a reasonable written security questionnaire from the Customer about how we process its data.
12. Order of precedence
If this addendum conflicts with the Terms of Service on how personal data is processed, this addendum applies. Questions: hello@navakrit.com.