Privacy Policy
Last updated: 11 July 2026
This policy explains what Pleisys Engage (“Pleisys”, “we”) collects, why we collect it, and the choices you have. It applies to our website and the Pleisys Engage platform.
1. Introduction
Pleisys Engage is a conversation automation platform operated by Verdeshell Technologies Pvt. Ltd. We act as a data controller for the account and usage data of our customers, and as a data processor for the contact data our customers import and process through the platform (see our Data Processing Agreement).
2. Information we collect
2.1 Account & registration data
Your name (first and last), work email, mobile phone number, job title, organization name, and authentication identifiers.
2.2 Business & verification data
To operate your account, issue invoices, meet tax and regulatory obligations, and verify your business for WhatsApp, we collect your organization's legal-entity details (legal name, business type, registration number, tax identifiers such as PAN/GSTIN, and registered address), your data-protection / grievance officer contact, and any documents you upload as verification evidence (for example an incorporation certificate, GST/PAN, or address proof).
2.3 Platform usage data
Workflows you build, channels you connect, billing and wallet activity, and audit logs of actions taken in your account.
2.4 Contact data you import
Contact identifiers (e.g. phone numbers), conversation history, and consent records you upload or capture. You are the controller of this data; we process it on your instructions.
2.5 Cookies & technical data
First-party session cookies for authentication, plus IP address, browser, and device information used for security and diagnostics. We do not use third-party advertising or analytics cookies. See our Cookie Policy for details.
3. How we use your information
- Provide, secure, and maintain the platform.
- Deliver messages through the channels you connect.
- Process payments and manage your wallet and subscription.
- Detect, prevent, and investigate abuse and security incidents.
- Comply with legal obligations and respond to lawful requests.
- Communicate service updates and respond to support requests.
4. Lawful bases for processing (GDPR Art. 6)
Where the GDPR applies, we rely on the following lawful bases for the personal data we process as a controller:
| Purpose | Lawful basis |
|---|---|
| Marketing communications and newsletters | Consent — Art. 6(1)(a) |
| Providing the platform, account management, and payments | Performance of a contract — Art. 6(1)(b) |
| Security, fraud and abuse prevention, and service-related messages | Legitimate interests — Art. 6(1)(f) |
| Tax, accounting, and statutory record-keeping | Legal obligation — Art. 6(1)(c) |
For contact data our customers import, the customer is the controller and is responsible for establishing the lawful basis for that processing.
5. Third-party sub-processors
We share data with a small set of vetted sub-processors strictly to operate the service. Each is bound by data-protection terms.
| Sub-processor | Purpose | Region |
|---|---|---|
| Meta Platforms | WhatsApp Cloud API — message delivery | USA / EU |
| Twilio | WhatsApp & SMS delivery | USA |
| Amazon Web Services (SES) | Transactional email delivery | India / USA |
| Amazon Web Services (S3) | Object & file storage | India / USA |
| Razorpay | Payment processing (INR) | India |
| Hostinger (VPS) | Application & database hosting | India |
6. International data transfers
Our primary application and database, and our AWS SES/S3 services in the ap-south-1 (Mumbai) region, are hosted in India. India is not currently the subject of an EU adequacy decision under Art. 45 GDPR.
Where we transfer personal data of individuals in the EU/EEA or the UK to India or to any sub-processor outside those regions, we rely on the European Commission's Standard Contractual Clauses (SCCs), and, for UK personal data, the UK International Data Transfer Addendum / IDTA, together with a transfer impact assessment and supplementary technical measures (such as encryption in transit and at rest). Copies of the relevant transfer mechanisms are available on request.
7. Data retention
We retain your account and usage data for the life of your account. After your account is closed, we retain it for a limited period — up to 24 months — to meet legal, tax, audit, and dispute-resolution obligations, after which it is deleted or crypto-shredded so it becomes permanently unreadable. Backup copies age out on their normal cycle.
Contact data our customers import is retained according to the customer's configured retention policy and is deleted or crypto-shredded on the customer's instruction or on termination of their subscription.
9. Your rights
Depending on your jurisdiction (including India's DPDP Act 2023 and the GDPR), you may request access, correction, deletion, export, or restriction of your personal data. End users can submit a request through our DSAR portal; we verify identity and respond within 30 days.
10. Security
We encrypt data in transit (TLS 1.2+) and at rest (AES-256), hash passwords with a memory-hard function (scrypt), isolate tenants with row-level security, and offer crypto-shred erasure that renders a contact's data permanently unreadable. Access is role-based and audit-logged.
11. Children's privacy
The platform is intended for business use and is not directed to children under 18. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified in-product or by email, and the “last updated” date above will change.
13. Contact, Grievance Officer & EU Representative
Questions about this policy or your data? Email privacy@pleisys.com.
Grievance / Data Protection Officer: Pleisys Legal Team (legal@pleisys.com)
EU Representative (GDPR Art. 27): Pleisys Legal Team (legal@pleisys.com)