Privacy Policy
Last Updated: June 26, 2026
1. Introduction
Welcome to NeetiCRM (“we,” “our,” or “us”). We are committed to protecting your privacy and ensuring the security of your personal data and the data of your leads. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our SaaS Customer Relationship Management (CRM) platform, services, and website (collectively, the “Service”).
Under the Digital Personal Data Protection Act, 2023 (India) (“DPDP Act”) and other international privacy frameworks such as the General Data Protection Regulation (“GDPR”), NeetiCRM acts as a Data Processor with respect to the customer leads, contacts, and WhatsApp/SMS message logs you import or collect through the platform. NeetiCRM acts as a Data Fiduciary (or Data Controller) only with respect to your account administration, billing, and system usage information.
In Plain English
2. Information We Collect
We collect information in three ways: information you provide directly, information collected automatically, and information received from third-party integrations.
A. Information You Provide to Us
- Account Information: When you register an account, we collect your name, email address, password, company name, phone number, and physical address in India.
- Payment Information: We collect billing details and tax identification numbers (GSTIN for Indian companies). Actual transactions are processed securely through our payment processors (Razorpay and Stripe); we do not store raw credit card numbers or banking credentials.
B. Lead Data You Upload or Capture
You may upload, import, or automatically sync customer and lead data into the Service. This data (collectively, “Customer Lead Data”) may include:
- Names, email addresses, phone numbers, and job titles of your prospects.
- Interaction history, custom pipeline stages, lead scores, and qualification criteria.
- Any other custom metadata fields you define for your lead tracking.
3. WhatsApp Business Platform & Lead Ads Data
NeetiCRM integrates directly with the Meta Graph API (including WhatsApp Cloud API, Facebook Lead Ads, and Instagram Leads).
- WhatsApp Messages: To provide CRM messaging inbox and automated flows, NeetiCRM accesses, processes, and stores the content of WhatsApp chats, media attachments, template status updates, and delivery confirmations exchanged between your business and your leads. This data is handled in strict compliance with the Meta WhatsApp Business Terms and developer guidelines.
- Meta Lead Ads: When you link your Facebook page or Instagram professional account, we sync lead data generated from your campaigns in real time. We process this information to trigger automated workflows and push conversion events back to Meta via the Conversions API.
In Plain English
4. AI Lead Qualification & Call Tracking
NeetiCRM features AI-driven calling, qualification bots, and communication tools.
- Voice Recordings and Transcripts: When you enable AI voice qualification, calls between our AI agent and your leads are recorded. We transcribe these calls and generate structured summaries (identifying intent, budget, timeline) for your dashboard.
- Lead Consent: You represent and warrant that you have obtained all necessary consents, legal approvals, and registrations under applicable law (including Indian TRAI telecommunication and DND rules) before initiating automated voice calls, SMS, or WhatsApp campaigns to your leads.
5. How We Use Collected Information
We use the information we collect to operate, manage, and improve NeetiCRM, including:
- Providing, maintaining, and developing the CRM features and automation builders.
- Processing subscription fees, managing billing profiles, and collecting GST taxes.
- Sending system alerts, security notices, service changes, and support updates.
- Aggregating anonymized performance metrics (e.g., email open rates, average bot qualification time) to optimize our AI algorithms and platform capacity. We do not sell or monetize raw lead data.
6. Third-Party Sub-processors
We share data with verified third-party sub-processors to assist in delivering NeetiCRM services. These sub-processors are legally bound to protect your data under confidentiality agreements equivalent to ours.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Infrastructure hosting and database storage | Asia Pacific (Mumbai, India) |
| Meta Platforms, Inc. | WhatsApp Cloud API & Lead Ad sync | Global / US |
| Razorpay / Stripe | Payment processing and transaction billing | India / Global |
| OpenAI, LLC | AI qualification text and voice summary APIs | Global / US |
| Google Analytics | Website usage analytics | Global |
7. Data Retention & Deletion
We retain account and administrative data for as long as your subscription is active, and for a reasonable period thereafter to comply with audit, tax, and legal requirements.
For Customer Lead Data and communication logs, we store this information according to your subscription tier and account configuration. You may export or request deletion of your lead data directly from the dashboard. Upon subscription cancellation or non-payment, we store lead data for up to 90 days before permanent deletion from active servers and database backups.
8. DPDP Act (India) & User Rights
In accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act, India), you are designated as the Principal (Data Principal) for your account information, and you act as the Data Fiduciary for your customer leads. We support your rights under this Act, including:
- Right to Access & Correction: You can access, update, or rectify your account data inside the CRM portal.
- Right to Erasure (Right to be Forgotten): You can request complete erasure of your business contact information from our marketing directories.
- Right to Grievance Redressal: You have the right to register complaints regarding data handling. We will resolve DPDP grievances within the statutory timeline.
If you are an individual whose data is held in NeetiCRM as a lead of one of our customers, please contact the respective customer (who acts as the Data Fiduciary) to exercise your rights. We will assist our customers in fulfilling these requests.
9. Data Security
We implement rigorous administrative, technical, and physical security measures to safeguard data:
- Encryption of data in transit using industry-standard TLS 1.3.
- Encryption of data at rest inside our AWS database instances using AES-256 keys.
- Role-based access controls for internal operations teams, coupled with regular security audits.
- Secure password hashing using salted bcrypt hashing algorithms.
10. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your rights under the DPDP Act, or have a data grievance, you may contact our Grievance Officer:
NeetiCRM Data Operations
Grievance Officer: Rahul Sonawane
Email: legal@neeticrm.com
Address: Mumbai, Maharashtra, India