Legal
Privacy Policy
This policy explains what personal data Scafell Tech Private Limited processes, why, on whose instructions, for how long, who else is involved, and what rights the people whose data it is can exercise.
1. Who we are and our role
Scafell Tech Private Limited is a private company limited by shares, registered in India, with its registered office at A 406, Om Decora 9 Square, Nana Mava Road, Mota Mava, Rajkot 360005, Gujarat, India. We build and operate messaging-first operational systems on the WhatsApp Business Platform for client organisations such as municipal corporations, public utilities and enterprises.
Our role differs depending on whose data is involved. This distinction determines who is accountable for what, and it is used throughout this policy.
Data we process for a client organisation — we are a data processor
When a person sends a WhatsApp message to a client organisation’s business number, or when that organisation’s staff use a dashboard we operate, the client organisation decides why and how that data is processed. Under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”), the client organisation is the Data Fiduciary and Scafell Tech Private Limited is its Data Processor.
As a data processor we act only on the client organisation’s documented instructions, recorded in a written contract. We do not decide the purposes of that processing, we do not use the data for our own purposes, we do not sell it, and we do not use it for advertising or for training models for unrelated purposes.
Data we process for ourselves — we are a data fiduciary
For a small set of data we decide the purpose ourselves and act as Data Fiduciary: business enquiries sent to us, correspondence with people at client and prospective client organisations, our own employment and contractor records, and standard server logs for this website.
2. Personal data we process
The table below lists every category of personal data the services handle, what it consists of, where it comes from and the role in which we process it.
| Category | What it consists of | Source | Our role |
|---|---|---|---|
| WhatsApp phone numbers | The mobile number a person uses to message the client organisation, the WhatsApp profile name where WhatsApp supplies it, and the identifier assigned to the conversation. | Received from the WhatsApp Business Platform when the person messages the organisation. | Processor |
| Message content | The text of messages exchanged in both directions, including the person’s description of the complaint or request, replies made by staff, and automated status updates. | Sent by the person, by the organisation’s staff, or generated by the workflow. | Processor |
| Media — photographs, video, voice notes | Images, video and audio recordings attached to a report as evidence, together with the technical metadata WhatsApp supplies with them (such as media type, size and timestamp). | Sent by the person reporting the issue, or by field staff when recording work done. | Processor |
| Location data | Coordinates from a location shared through WhatsApp’s location attachment, and any address or landmark the person types. Derived from these: the ward, zone or administrative boundary the report falls in. | Shared deliberately by the person, or entered by staff. We do not collect continuous or background location. | Processor |
| Staff account records | Name, official role and department, work email address or mobile number, assigned area, login credentials in hashed form, and an audit trail of actions taken in the dashboard. | Provided by the client organisation for its own officers and field staff. | Processor |
| Delivery and technical records | Message delivery, read and failure statuses returned by the WhatsApp Business Platform; application and security logs; IP addresses of dashboard sessions. | Generated by the WhatsApp Business Platform and by our systems. | Processor |
| Business contact data | Name, organisation, email address, telephone number and correspondence with people who contact us about our services. | Provided directly by the person who contacts us. | Fiduciary |
We do not ask for and do not require Aadhaar numbers, PAN, bank or payment details, health records or biometric data in order to accept a complaint. Where a person volunteers such information inside a message or a photograph, it is handled as message content or media under the client organisation’s instructions and retention rules.
3. Purposes and lawful basis
Each category is processed for a stated purpose. Under the DPDP Act, personal data may be processed for a lawful purpose with the Data Principal’s consent, or for one of the “certain legitimate uses” the Act sets out — which include data voluntarily provided by the person for a specified purpose, and processing by the State or its instrumentalities to provide a service, benefit, licence, permit or certificate.
Where we act as processor, the client organisation determines and records the basis it relies on. The table states the basis that ordinarily applies to that category.
| Category | Purpose | Basis ordinarily relied on |
|---|---|---|
| WhatsApp phone numbers | To identify who reported an issue, to reply to them on the same channel, to notify them of progress and closure, and to prevent duplicate and abusive submissions. | Voluntary provision by the person when they choose to message the organisation; consent for any subsequent business-initiated messages; or, where the client is a State instrumentality delivering a service, the corresponding legitimate use under the DPDP Act. |
| Message content | To record what was reported, classify it, route it to the responsible department and officer, and maintain a record of how it was handled. | Voluntary provision for the specified purpose of having the complaint dealt with; or the applicable legitimate use for service delivery by a State instrumentality. |
| Media — photographs, video, voice notes | To evidence the reported issue, allow field teams to assess it before attending, and evidence the work carried out at closure. | As for message content. Media is processed only because the person or officer attached it deliberately. |
| Location data | To place the report at the location it concerns, resolve it to the correct ward or zone, and assign it to the officer responsible for that area. | Deliberate sharing by the person for that purpose; or the applicable legitimate use for service delivery. |
| Staff account records | To authenticate officers, control what each can see and do, assign work, and maintain an attributable audit trail of actions taken. | Employment and administrative relationship between the officer and the client organisation, on that organisation’s instructions. |
| Delivery and technical records | To confirm whether messages were delivered, diagnose faults, protect the service against abuse and unauthorised access, and support audit. | Necessary for the security, integrity and continuity of the service provided to the client organisation. |
| Business contact data | To answer the enquiry, and to carry on correspondence about a possible or existing engagement. | Voluntary provision by the person who contacts us for that purpose. |
We do not carry out advertising, profiling for advertising, automated decision-making with legal effect, or sale of personal data. Classification and routing decide which department and officer a request goes to; they do not decide entitlement to a benefit or any other legal outcome, and a request that cannot be classified confidently is sent for human triage.
4. Processing over WhatsApp
Messages are carried by the WhatsApp Business Platform, operated by Meta Platforms, Inc. and its affiliates. The following points describe how that affects your data.
- The organisation can read what you send. When you message a business or government account, your messages are available to that organisation and to the technology provider that operates the account on its behalf — in this case, Scafell Tech Private Limited. This is how business messaging on WhatsApp works, and it is described in WhatsApp’s own Privacy Policy.
- Meta processes the message in transit. Meta transmits and delivers the message and returns delivery status. Meta’s handling of your data is governed by its own terms and policies, not by this policy.
- You start the conversation. The service is designed so that the person reports an issue first. Business-initiated messages — for example a status update or closure notice sent later — use message templates approved through the WhatsApp Business Platform and are sent only where the client organisation has an opt-in for that person, in line with WhatsApp’s Business Messaging Policy.
- Template management. We create, submit and maintain those message templates on the client organisation’s behalf. Templates contain the wording of the message and placeholders for case-specific values such as a reference number or a status.
- Your WhatsApp copy is yours. Deleting data from our systems does not remove the conversation from your own device or from WhatsApp’s systems. WhatsApp’s Help Centre explains the controls available to you inside the app, including deleting a chat and blocking or reporting a business.
WhatsApp and Meta are trademarks of Meta Platforms, Inc. References to them are descriptive only and do not imply any partnership, endorsement or affiliation.
5. How long data is kept
Retention for data we hold as processor is set by the client organisation in its contract with us, and reflects its own record-keeping obligations. Each contract fixes the period for which case data is kept after a case is closed, and we delete on that schedule.
| Category | Retained for | Then |
|---|---|---|
| Message content and case records | As specified in the client organisation’s contract. | Deleted, or irreversibly anonymised for statistical reporting where the client organisation has instructed that. |
| Media — photographs, video, voice notes | As specified in the client organisation’s contract. | Deleted from our storage. |
| Location data | As specified in the client organisation’s contract. | Deleted or reduced to ward or zone level only. |
| WhatsApp phone numbers | As specified in the client organisation’s contract, unless the person asks for erasure earlier and the client organisation agrees. | Deleted or replaced with a non-identifying reference. |
| Staff account records | For as long as the officer holds an account, then as specified in the client organisation’s contract. | Account disabled and record deleted; audit entries are retained in the case record. |
| Delivery, technical and security logs | A limited period, on a rolling rotation. | Deleted on rotation. |
| Business contact data | For as long as the enquiry is live, and then deleted. | Deleted. |
Data may be kept beyond these periods only where a law, a court or a statutory authority requires it, and only for as long as that requirement lasts.
On termination of a client contract we return or delete the personal data we hold for that client, as the contract directs, and delete remaining copies within the period the contract specifies. Backups are deleted on their own rotation cycle, after which the data is no longer recoverable.
6. Sub-processors
We use a small number of sub-processors to deliver the service. Each is bound by contract to protect the data and to process it only for the purpose we engage them for.
| Sub-processor | Function | Data involved | Processing location |
|---|---|---|---|
| Meta Platforms, Inc. and its affiliates (including WhatsApp LLC) | Provider of the WhatsApp Business Platform: transmission and delivery of messages between the person and the client organisation’s business number, media transfer, and delivery status reporting. | Phone numbers, message content, media, shared locations, delivery status. | Global infrastructure operated by Meta. |
| Cloud hosting provider | Hosting of the application, database and media storage for the operations system and dashboards. | All categories listed in section 2 that we hold as processor. | Named, with its processing location, in the current sub-processor list — see below. |
| Other sub-processors | Any further sub-processor engaged for a specific function, such as transactional email or error monitoring. | Limited to what the function requires. | Named, with its processing location, in the current sub-processor list — see below. |
The current sub-processor list is provided to client organisations under their contract, and is available on request from privacy@scafelltech.com. Client organisations are notified before a new sub-processor with access to their personal data is engaged, as their contract provides.
7. Transfers outside India
WhatsApp messages are transmitted through Meta’s global infrastructure, so message content, media and phone numbers may be processed outside India in the course of delivery. Application data that we hold is stored with the hosting provider named in our current sub-processor list, in the region stated there.
Section 16 of the DPDP Act permits transfer of personal data outside India except to countries the Central Government restricts by notification. Where a client organisation requires that data remain within India, that is agreed in its contract and configured accordingly; note that messages carried by the WhatsApp Business Platform remain subject to Meta’s infrastructure and terms.
8. Security
We apply the following measures to the data we process:
- Data in transit — between the WhatsApp Business Platform, our systems, and dashboards used by staff — is protected with transport-layer encryption (HTTPS/TLS).
- Dashboard access is by individual named account with role-based permissions, so an officer sees only the cases and areas their role covers.
- Actions taken in the system are recorded in an audit trail attributable to the account that took them.
- Access to production systems and to stored media is restricted to authorised personnel who need it to operate or support the service, and is logged.
- Message templates and workflow content are reviewed before release so that personal data is not exposed in message wording beyond what the case requires.
If a personal data breach occurs, we notify the affected client organisation without undue delay after becoming aware of it, with the information that organisation needs to meet its own obligations. Under the DPDP Act it is the client organisation, as Data Fiduciary, that is responsible for giving notice of a breach to the Data Protection Board of India and to affected Data Principals; we support it in doing so.
No claim of an independent security certification or audit is made on this website. Where procurement requires evidence of certification, penetration testing or an independent assessment, the current position can be confirmed by writing to privacy@scafelltech.com.
9. Your rights and how to exercise them
Under the DPDP Act, a Data Principal — the individual the data is about — has the right to:
- Access a summary of the personal data being processed and the processing activities undertaken, and the identities of others with whom it has been shared.
- Correction, completion and updating of inaccurate or incomplete personal data.
- Erasure of personal data that is no longer needed for the purpose it was collected for, unless retention is required by law.
- Grievance redressal — a readily available means of raising a complaint about how data has been handled, and a response to it.
- Nomination of another individual to exercise these rights in the event of death or incapacity.
Where to send a request
These rights are exercised against the Data Fiduciary. For a complaint you made over WhatsApp, that is the organisation you reported it to — the municipal body, utility or company operating the business number — not Scafell Tech Private Limited.
You can nevertheless write to us at privacy@scafelltech.com. We will identify the client organisation concerned, pass the request to it without delay, and act on its instruction. Where we hold the data as Data Fiduciary in our own right — business contact data and our own records — we act on the request ourselves.
To let us locate the right records, include the WhatsApp number you messaged from, the organisation you contacted, and any reference number you were given. We may need to verify your identity before acting, and we will ask only for what is necessary to do so. We acknowledge every request on receipt, respond within the time applicable law allows, and tell you if more time is needed.
Exercising these rights is free of charge.
10. Deletion of data
Deletion has its own page, with step-by-step instructions for end users, for client organisation administrators, and for people who have only corresponded with us: Data Deletion Instructions.
11. This website
- This website sets no cookies. It runs no analytics, no advertising tags, no session tracking and no third-party scripts.
- Fonts are the ones already installed on your device; no font, script or stylesheet is loaded from an external content delivery network.
- There is no contact form and no account. Nothing you type is submitted to us from this site.
- Our hosting provider records standard server request logs — IP address, time, page requested and user agent — to keep the site available and to protect it against abuse. These are kept for a limited period and then deleted on rotation.
- If you email us using an address on this site, your message and address are handled as business contact data under sections 2 and 3.
- Links to external sites, such as WhatsApp’s policies, are provided for reference. We are not responsible for the content or privacy practices of those sites.
12. Children’s data
The services are built for adults reporting issues to an organisation, and are not directed at children. The DPDP Act requires verifiable consent from a parent or lawful guardian before processing the personal data of a child, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. We do not carry out tracking, behavioural monitoring or advertising of any kind.
We do not knowingly process a child’s personal data as Data Fiduciary. Where a client organisation’s service may be used by or on behalf of a child, obtaining and verifying guardian consent is that organisation’s responsibility as Data Fiduciary; we implement what its instructions require. If you believe a child’s data has been submitted, write to privacy@scafelltech.com and we will refer it to the client organisation for erasure.
13. Grievance redressal
Complaints about how Scafell Tech Private Limited has handled personal data can be sent to our grievance contact:
Grievance Officer
Scafell Tech Private Limited
grievance@scafelltech.com
A 406, Om Decora 9 Square, Nana Mava Road, Mota Mava, Rajkot 360005, Gujarat, India
We acknowledge every grievance on receipt and work to resolve it as quickly as we can, keeping you informed of progress.
Where the grievance concerns a complaint you made to a client organisation, the organisation’s own grievance officer is the correct first route, and we will tell you who that is. If you are not satisfied with the outcome, the DPDP Act allows you to complain to the Data Protection Board of India.
14. Changes to this policy
We update this policy when what we do changes — for example when a sub-processor is added or a retention period is revised. The date at the top of the page shows when it was last changed. Client organisations are notified of material changes through the notice route in their contract.
15. How to contact us
Scafell Tech Private Limited
A 406, Om Decora 9 Square, Nana Mava Road, Mota Mava, Rajkot 360005, Gujarat, India
Privacy: privacy@scafelltech.com
General: contact@scafelltech.com
Full contact details are on the Contact page.