Privacy Policy
In short
- Two different things are going on: information about you, which we decide how to use, and your customers' conversations, which we only hold on your behalf.
- Your data lives on a server in Mumbai, India. Backups are encrypted before they leave that server.
- We do not sell data, and we do not train any AI on your conversations.
- Four outside companies are involved, each for one specific job. They are all named below.
- You can ask for a copy of your data, ask us to correct it, or ask us to delete it, and we will do it.
01 The two kinds of data
This policy is written by Mosorb India LLP, trading as Endelir. Our registered particulars are on the legal and company details page.
Most privacy policies blur together two situations that are legally and practically very different. We have separated them, because the answer to “who decides what happens to this data?” is different in each.
| Information about you | Your customers' data | |
|---|---|---|
| For example | Your name, work email, phone number, billing details, how you use the dashboard | Your customers' phone numbers and names, the messages they send you and you send them, the files exchanged |
| Who decides how it is used | We do. We are the Data Fiduciary and this policy explains our decisions. | You do. You are the Data Fiduciary; we are your Data Processor and act on your instructions. |
| Who a customer of yours should complain to | Us | You first. We will help you answer, but the relationship is yours. |
The terms “Data Fiduciary”, “Data Processor” and “Data Principal” come from India's Digital Personal Data Protection Act, 2023, which is the law we have written this policy to satisfy.
02 Information about you
This is what we hold about you and the people on your team, and why.
| What | Why we have it |
|---|---|
| Name, work email, phone number, role — for you and each agent you add | To create accounts, let people sign in, show who replied to which customer, and contact you about your account |
| Business name, address, GSTIN | To issue a valid tax invoice, which we are legally required to do |
| Payment records — what you paid and when | Accounting, tax and answering billing questions. We do not store your card or bank details; if and when we take online payments, the payment provider handles those directly. |
| Sign-in records — time, IP address, browser | Security. It is how we tell your login from someone else's, and how we investigate if an account is compromised. |
| Activity in the dashboard — what was changed and by whom | An audit trail, so a question like “who deleted that template?” has an answer |
| Emails and messages you send us | To answer you, and to keep a record of what was agreed |
Our lawful basis is that we need this to provide a service you have asked for and to meet our legal obligations. Where the Act requires consent for something outside that — for example, using your logo as a customer reference — we ask you first, and you can say no or change your mind later.
We do not sell your information, and we do not use it to market anything other than Endelir to you.
03 Your customers' data
When your business uses Endelir, your customers' conversations pass through and are stored in our system. That includes their phone number, the display name WhatsApp provides, the content of messages in both directions, any images, documents, audio or location they send, the times of everything, and the contact details and tags you add yourself.
We hold this only to run the service for you. Specifically: to deliver messages to and from Meta, to show them in your inbox, to run the automations you have configured, to produce your reports, to keep encrypted backups, and to help you when you ask us to look at a problem. We do not use it for anything else.
You are responsible for having permission. Because you are the Data Fiduciary for your customers' data, it is your job to have a lawful basis for holding their details and for messaging them, to give them the notice the law requires, and to answer their requests. Endelir records consent, honours opt-outs and can export or delete on demand — but the software cannot supply the permission itself.
We will not sell your customers' data, will not contact your customers for our own purposes, and will not disclose it to anyone except the sub-processors named in section 5, or where we are legally compelled. If we are compelled by a court or an authority, we will tell you before we comply unless the law forbids us from doing so.
If you need a signed data processing agreement for your own compliance or for a customer of yours, ask and we will sign one.
04 Where your data is kept
The Endelir application and its database run on a private server in a Mumbai, India data centre. That was a deliberate choice: your customers and your agents are in India, and every other region adds delay to every page and every message.
Backups. We take an encrypted backup every night. It is encrypted on our server, before it goes anywhere, and a copy is stored with Cloudflare's object storage, which may hold it outside India. The storage provider holds an encrypted file and does not have the key, so it cannot read the contents. This transfer is permitted under the Digital Personal Data Protection Act, 2023, which allows transfers except to countries the Government has restricted.
WhatsApp itself is not in India, and we cannot make it be. Messages travel over Meta's WhatsApp Business Platform — the Cloud API — and Meta stores and processes them in its own data centres, outside India, under its own terms. We have no control over that, no ability to localise it, and no visibility into it beyond what Meta shows you.
This is true of every provider built on the WhatsApp Business Platform, including all of our competitors. We say it plainly because a business handling sensitive information — a clinic, a lender, a school — should decide with that fact in front of them, not discover it later. What we control is our own copy: that is in Mumbai.
05 Who else touches it
We keep this list short on purpose, and every entry is here because it does one specific job that the service cannot do without.
| Who | What they do | What they can see |
|---|---|---|
| Meta Platforms (WhatsApp Business Platform) |
Carries every WhatsApp message to and from your customers | The messages themselves, phone numbers, and delivery information — under Meta's own terms |
| Hostinger | Runs the physical server in Mumbai, and hosts this website | Nothing in normal operation. As the infrastructure provider it has physical access to the machine. |
| Cloudflare | Stores the off-site copy of our nightly backups | Encrypted files only. It does not hold the key and cannot read them. |
| Hostinger (email) | Runs the @endelir.com mailboxes and sends account emails such as password resets and invoices |
The email address and the contents of those emails |
| Expo | Relays push notifications to the Endelir mobile app, and delivers app updates | The push token issued by your phone, and the text of the alert — which carries a customer’s name, not their number or their message. Applies only if you use the app. |
| Apple | Delivers the notification to an iPhone | The same alert text, in transit. Applies only if you use the app on an iPhone. |
| Deepgram | Turns a voice note or a dictated reply into text | The audio of that recording. Not retained by them for training. |
| Google Fonts | Serves the typeface used on this website | Your browser's IP address and browser version when a page loads. No account data. This affects visitors to endelir.com only. |
Every company in this table is bound by a written contract that holds them to the same protection of your data that we give it, and to using it only for the purpose named beside them — never for their own. None of them may pass it on further without us agreeing, and none of them may use it to build a profile of you or your customers. We do not sell data to anyone, and no company in this table is an advertising network.
If we add a sub-processor that handles personal data, we will update this table and, where the change is material, tell account holders before it takes effect. Optional integrations with third parties — online shops, payment gateways, calling providers and AI providers — exist in the software and are off until you switch them on in your own dashboard. Each one names what it will send before you enable it, and the AI assistant is described in the section below.
06 How long we keep it
| What | Kept for |
|---|---|
| Conversations, contacts and media | As long as your account is open, unless you delete them sooner. You control this. |
| Everything in a deleted account | Destroyed when we action your request, within 7 days of asking. Copies inside encrypted backups age out within 30 days. Nothing is recoverable afterwards — not by you and not by us. |
| Encrypted backups | On a rolling cycle, then destroyed. Deleted data disappears from backups as the cycle turns. |
| Sign-in and security logs | Up to 12 months |
| Invoices and tax records | As long as Indian tax law requires, currently up to 8 years |
| Emails between us | 3 years, so that we can both check what was agreed |
06b Deleting your account
Email hello@endelir.com from the address the account is registered to, with delete my account in the subject. A person replies, and we ask you to confirm once before anything is destroyed — a single mistaken email should not be able to erase a business’s records.
Everything belonging to the workspace is destroyed: every contact and conversation, the messages and their photos, documents and voice notes, templates, campaigns, automations, saved replies, uploaded documents, and your team’s logins. It is destroyed rather than hidden, and there is no recovery afterwards, by you or by us. Your WhatsApp number itself is yours and Meta’s — deleting here disconnects it from Endelir and changes nothing on Meta’s side.
We action requests within 7 days and usually the same working day. Copies inside encrypted backups disappear as the backup cycle turns, within 30 days, as described above.
Two things survive, both because the law requires them: invoices and payment records, which Indian tax law obliges us to keep and which carry the billing name, amount and date rather than your customers; and a record that the deletion happened, without which we could not show we had done what you asked.
You do not have to delete anything merely to stop paying — see Refunds and Cancellation. Full detail is on the Delete your account page.
06c The Endelir mobile app
The app is the same product as the dashboard, on a phone, for the same business users. It asks for four permissions and none of them are for advertising or analytics:
- Camera — only to take a photo you are about to send to a customer in a conversation.
- Microphone — only to record a voice note, or to dictate a reply.
- Photo library — only to choose an existing photo to send. We see the photo you pick and nothing else in your library.
- Face ID or Touch ID — to unlock the app so your customers’ conversations stay private on a phone someone else picks up. This happens entirely on the device. Your face and fingerprint never leave it and are never sent to us; iOS answers yes or no and that is all we receive.
Notifications. To alert you to a new message we hold a push token issued by your phone, and the alert travels through Apple’s notification service and through Expo, who operate the relay. The alert carries the customer’s name and the reason, so that it is useful on a lock screen; it does not carry their phone number or the contents of their message.
Dictation. When you dictate a reply, or when a customer’s voice note is turned into text for you to read, the audio is sent to a speech-to-text provider (Deepgram) to transcribe and is not kept by them for training.
Dictation also uses AI, and this one is not optional. After the audio becomes text, that text and the last ten messages of that conversation are sent to an AI provider to tidy the wording — the surrounding messages are what let it get names, products and amounts right. Unlike the AI assistant described further down, this happens whenever you use the dictate button, whether or not you have switched the assistant on; and if you have not configured your own AI provider it runs on ours. If you would rather no message content went to an AI provider at all, do not use the dictate button — typing sends nothing anywhere but to us and to WhatsApp.
Deleting the app removes nothing from our side; see 06b.
07 How we protect it
- Separate workspaces. Each business's data is isolated in the database, and the isolation is enforced at the lowest level of the software rather than page by page. It is covered by automated tests that run before every release.
- Encrypted in transit. Every connection to the application and to Meta uses HTTPS. The site will not serve an unencrypted page.
- Encrypted at rest. Sensitive fields, including access tokens and the contents of submitted forms, are encrypted in the database.
- Encrypted backups. Backups are encrypted with a passphrase held separately from the server, so a copy of the backup file alone is useless.
- Restricted access. The server takes no password logins at all, only cryptographic keys. Administrative access is limited to the people in section 8.
- Least privilege. The application's database account has only the permissions it needs, and cannot alter the database structure.
- Monitoring. Failed login attempts are rate-limited and repeat offenders are blocked automatically.
No system is perfectly secure, and we will not claim otherwise. What we can say is that these are real controls, they are documented, and they are tested rather than asserted.
08 Who at Endelir can see your data
Being straight about this. Endelir has a platform administrator account, held by the Designated Partner of Mosorb India LLP. That account can access any workspace, including its conversations and media. It exists so that we can restore your account, investigate a fault, or answer a legal demand.
We use it for support and troubleshooting only, we do not read conversations out of curiosity or for any commercial purpose, and actions taken in the dashboard are recorded in the audit trail. As the company grows, this access will be narrowed and put behind a formal approval and logging process. Every provider in this market has an equivalent capability; most do not mention it.
Within your own account, you control who sees what. Agents see the conversations in your workspace; account owners can add and remove them at any time.
09 Your rights
Under the Digital Personal Data Protection Act, 2023, in relation to the information we hold about you, you can:
- Ask what we hold and get a summary of it and of who we have shared it with;
- Ask us to correct anything inaccurate, incomplete or out of date;
- Ask us to erase it, where we are not required by law to keep it;
- Withdraw consent you gave us, as easily as you gave it — this does not undo anything done before you withdrew it;
- Nominate someone to exercise these rights for you if you die or become unable to;
- Complain to our Grievance Officer, and then to the Data Protection Board of India if we have not resolved it.
Write to hello@endelir.com. We acknowledge within 24 hours and answer within 15 days, or sooner. We may need to confirm who you are before we act, which is a protection for you rather than an obstacle.
10 Your customers' rights
If one of your customers asks us directly for a copy of their data or for its deletion, we will pass the request to you rather than acting on it ourselves, and we will tell them we have done so. That is not us avoiding it: you are the business they gave their details to, you know the context, and acting behind you could destroy a record you are legally required to keep.
We will help you answer, and the software can export or delete a contact's data along with their conversation history when you decide to.
11 Cookies and tracking
This website (endelir.com) sets no cookies and carries no analytics, no advertising pixels and no tracking of any kind. It does load its typeface from Google Fonts, which means Google's servers see your IP address when a page loads. If we add analytics later, we will update this section before it goes live.
The application (dashboard.endelir.com) uses cookies that are strictly necessary to make it work: one to keep you signed in, and one to protect forms against cross-site request forgery. They are not used to track you and are not shared with anyone. It also loads a typeface from Google Fonts and one interface library from a public code network, which see your IP address in the same way.
12 Artificial intelligence
We do not use your conversations or your customers' data to train any machine-learning model, ours or anyone else's, and we do not permit our providers to.
The software contains an AI assistant that can draft or send replies on your behalf. It is off until you switch it on in your dashboard, under AI Brain, and only the workspace owner can do it. When it is on, the customer’s message and the business details you have given the assistant — your prompt, your policies, your product list — are sent to the AI provider you have chosen in order to compose the reply. You choose the provider, and you may use your own account with them instead of ours. Inbound voice notes are additionally sent to a speech-to-text provider to be transcribed, as described in 06c.
Separately, you can connect an AI assistant of your own choosing to your workspace, using the Model Context Protocol. It is off until you switch it on: nothing can connect until you generate an access token on your settings page and give it to the assistant. Once you do, that assistant can list your conversations, read the messages in them, search your contacts, see your message templates, and send messages to your customers as you.
We should be plain about what that means. Whatever you connect receives your customers' messages and their phone numbers, and it does so on your instruction, not ours. We do not choose the assistant, we cannot see what it does with what it reads, and we have no agreement with whoever runs it — that relationship is yours, and so is the responsibility for it under the Act. Before you connect one, satisfy yourself about where it sends data and how long it keeps it, exactly as you would for any other processor you appoint. You can cut it off at any time by regenerating the token, which stops the old one working immediately.
13 Children
Endelir is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 18, and we do not knowingly process the personal data of a child as a Data Principal in their own right. If you become aware that a child's data has reached us through your account in a way that requires verifiable parental consent under the Act, tell us and we will help you deal with it.
14 If something goes wrong
If we discover a breach of personal data, we will notify the Data Protection Board of India and every affected Data Fiduciary without delay, in the form and within the time the Act requires. Our notice to you will say what happened, what data was involved, what we have done about it, and what we suggest you do — in plain language, as soon as we know it, rather than a polished statement weeks later.
15 Changes to this policy
The date at the top says when this last changed. If a change materially affects how we handle personal data, we will email account holders at least 30 days before it takes effect. We keep previous versions and will send you one on request.
16 How to contact us
For anything in this policy — a question, a request about your data, or a complaint — write to hello@endelir.com.
Our Grievance Officer, who is also our contact point for personal data questions, is named with a postal address and response times on the legal and company details page. If we have not resolved your complaint, you may take it to the Data Protection Board of India.