Last Updated: 17 July 2026
This Privacy Policy explains how MinaTech Labs Private Limited ("we," "our," or "us") collects, uses, discloses, and protects information when you use 1MarketingSolution (the "Service"). It is designed to comply with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and related rules in force in India.
1MarketingSolution is a software-as-a-service ("SaaS") platform owned and operated by MinaTech Labs Private Limited, a company incorporated under the Companies Act, 2013, with its registered office at WARD NO. 14, BALDEV BAG, Rajnandgaon, Chhattisgarh 491441, India (GSTIN: 22AATCM1540R1ZZ; PAN: AATCM1540R).
The Service enables our customers to send updates, reminders, and marketing/transactional communications to their own end-recipients through channels including voice calls, SMS, email, and WhatsApp.
We offer WhatsApp through two distinct paths, and this Policy covers both. The first is outbound campaign sending, routed through our messaging aggregator (Fast2SMS), where we transmit the messages you compose to the recipients you select. The second is our optional WhatsApp chatbot add-on, described in Section 3.5, which holds two-way conversations with your customers on a WhatsApp number you connect and control, routed through the Meta WhatsApp Cloud API directly. The two paths collect and store different data; where this Policy distinguishes them, the distinction is deliberate.
Depending on the data in question, we act in one of two capacities:
Where this Policy refers to "you," it primarily refers to the subscriber and their authorised users. Recipients of communications sent through the Service should contact the subscriber (the sender) for any privacy-related queries about their personal data; we will assist the subscriber in responding.
If you enable our WhatsApp chatbot add-on, the Service holds two-way conversations with your customers on your own WhatsApp Business number. This section describes that processing specifically. You remain the Data Fiduciary for those conversations; we act as your processor, as set out in Section 2.
How your number is connected. You authorise us to act on your behalf through Meta's Embedded Signup flow, under which we operate as a Meta Tech Provider. You connect a WhatsApp Business Account that you own and control, and you may revoke that authorisation at any time through your Meta account or by contacting us. Messages sent through the chatbot are routed through the Meta WhatsApp Cloud API directly, rather than through our SMS aggregator. We never share or expose a WhatsApp number, conversation, or contact between subscribers.
What we collect and store. For the chatbot we process:
Most questions are answered without any external AI provider seeing your content.
The technology that matches a customer's question to your FAQs and your uploaded documents — a form of semantic search — runs entirely on our own servers. No third-party AI provider receives your content in order to perform that matching, and the majority of questions are answered at this stage without contacting any external AI service at all.
Only where your FAQs and knowledge base do not already answer a question do we call an external AI provider (Groq, Inc. — see Section 5) to compose a reply. In that case Groq receives only the customer's question and the relevant extract of your own uploaded content. It does not receive phone numbers, recipient names, or conversation history.
Deleting a document removes its indexed content immediately, so the chatbot stops using it at once. You can delete individual documents, FAQs, form submissions, or the whole knowledge base from your dashboard at any time.
We process personal data for the following purposes. Under the DPDP Act, our principal legal bases are (i) the certain legitimate uses recognised by law (such as performance of a contract you have entered into with us), and (ii) your consent, which we collect at the point you provide the data or activate a feature.
To run the Service we use carefully selected third-party providers ("sub-processors"). We share only the personal data each sub-processor needs to perform its function, and we require each to maintain appropriate safeguards. The principal sub-processors as of the date of this Policy are:
| Provider | Purpose | Hosting region |
|---|---|---|
| Amazon Web Services (AWS) — SES, S3 | Email delivery and media/file storage | Asia Pacific (Mumbai) |
| Razorpay Software Pvt. Ltd. | Payment processing and invoicing | India |
| Fast2SMS / aggregator partners | SMS and WhatsApp Business message routing | India |
| Twilio Inc. | Voice calls and call telephony | United States and global |
| Meta Platforms (WhatsApp Business) | WhatsApp message transport, templates, opt-in management | Global |
| Groq, Inc. | AI-generated chatbot replies | United States |
| Supabase / managed PostgreSQL hosting | Application database | Asia Pacific (Mumbai) |
| Email and helpdesk providers | Customer support, internal communications | India / United States |
A qualification on Groq. Groq is used only by the WhatsApp chatbot add-on (Section 3.5), and only for the subset of questions your FAQs and knowledge base do not already answer. Groq receives only the customer's question and the relevant extract of the subscriber's own uploaded content. It does not receive phone numbers, recipient names, or conversation history. The semantic matching that answers most questions runs on our own servers and does not involve Groq or any other external AI provider. If you do not enable the chatbot add-on, no data of yours reaches Groq at all.
We may update this list from time to time. A current list of sub-processors is available on request from the contact below. We do not sell or rent personal data to third parties for their own marketing purposes. We do not use your Customer Data, your conversations, or your uploaded documents to train any AI model.
Personal data is processed primarily within India. Some of our sub-processors (notably Twilio, Meta, Groq and certain AWS services) may process data outside India. In particular, where the WhatsApp chatbot add-on calls Groq to compose a reply (Section 3.5), the customer's question and the relevant extract of your uploaded content are processed in the United States. Where such a transfer happens, it is performed only to the extent permitted under the DPDP Act and we rely on the data-protection commitments these providers have published (including standard contractual terms and certifications such as ISO 27001 and SOC 2).
We retain personal data only for as long as needed for the purposes set out in this Policy or as required by law.
We implement reasonable security practices and procedures as required by Indian law, including encryption of data in transit using TLS, encryption of sensitive data at rest, role-based access controls, audit logging, secret rotation, regular dependency updates, and least-privilege access for our staff. Our infrastructure providers maintain certifications such as ISO 27001 and SOC 2.
Two safeguards are worth stating specifically, because they protect data belonging to your customers:
No service can guarantee absolute security. If we become aware of a personal-data breach that is likely to result in risk to affected individuals, we will notify you and the Data Protection Board of India within the timelines prescribed by law.
Subject to applicable law and verification of your identity, you have the right to:
Subscribers can exercise most of these rights directly from their account settings. For any other requests, please contact our Grievance Officer.
The Service is intended for use by businesses and adults. We do not knowingly collect personal data from any individual under the age of 18. If you believe a child has provided personal data to us, please contact our Grievance Officer and we will delete it.
We and our sub-processors use cookies, local storage, and similar technologies to authenticate you, remember preferences, and improve the Service. Full details — including the categories of cookies in use and how to control them — are set out in our Cookie Policy.
We may send you product updates, newsletters, and promotional offers about 1MarketingSolution. You can opt out at any time by clicking "unsubscribe" in any marketing email or by writing to our Grievance Officer. Transactional communications about your account (billing, security, service updates) are not optional while you remain a subscriber.
Our Service may contain links to third-party websites or integrations. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies before sharing personal data with them.
In accordance with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act, 2023, we have designated the following person to address privacy queries and grievances:
Grievance Officer / Data Protection Contact
MinaTech Labs Private Limited
WARD NO. 14, BALDEV BAG, Rajnandgaon, Chhattisgarh 491441, India
Email: minatechlabs@gmail.com
Phone: +91-8878777786
We will acknowledge grievances within 48 hours and aim to resolve them within 30 days of receipt, in line with applicable timelines.
We may update this Privacy Policy from time to time. The "Last Updated" date at the top of this page reflects the most recent revision. For material changes, we will notify you through the Service or by email before the changes take effect. Your continued use of the Service after the effective date of the updated Policy constitutes acceptance of the changes.