1. Who we are
Quibly Tech ("Quibly", "we", "us") operates Quibly, a software platform that lets a business connect its WhatsApp Business Account to an AI assistant that reads incoming customer messages and helps the business reply, qualify leads, and manage bookings.
We are registered in India and act as a technology provider on the WhatsApp Business Platform (Cloud API), operated by Meta Platforms, Inc.
| Legal entity | Quibly Tech |
|---|---|
| Registered address | K501, Green Valley Apartments, Plot 18, Sector 22, Dwarka, New Delhi, South West Delhi, Delhi 110077 |
| Udyam / MSME | UDYAM-DL-10-0027919 |
| Shop & Establishment | 2026074250 |
| Privacy contact | privacy@quiblytech.in |
| Telephone | +91 78383 63463 |
2. Our role and yours
There are two kinds of people whose information passes through Quibly, and our responsibilities differ for each.
Business customers
The business that signs up for Quibly and connects its WhatsApp Business Account. For their account data we are the data fiduciary (controller) — we decide what we collect and why.
WhatsApp users who message that business
End customers who send a WhatsApp message to a Quibly-connected business number. For their messages we are a data processor acting on the business's instructions. The business is the controller of that conversation; we handle it on their behalf and do not use it for our own purposes.
If you messaged a business on WhatsApp and want your data removed, contact that business directly — they control it. You can also write to us at privacy@quiblytech.in and we will pass the request on and act on their instruction.
3. Information we collect
a. Business account information
- Name, email address and phone number of the person signing up
- Business name, category, address, operating hours and service details you provide
- Login credentials (passwords are stored only as salted hashes — never in plain text)
b. WhatsApp connection information
- Your WhatsApp Business Account (WABA) ID and business phone number ID
- Display name and verification status of the connected number
- Access tokens issued by Meta that authorise Quibly to send and receive messages on your behalf, stored encrypted at rest
c. Message content and metadata
When a WhatsApp user messages your connected number, Meta delivers that event to Quibly. We receive and store:
- The message body — text, and for media messages the caption and a reference to the media
- The sender's WhatsApp phone number and WhatsApp profile name
- Message identifiers, timestamps, and delivery/read status of replies
- Replies generated or sent through Quibly
d. Technical and usage information
- Server logs — IP address, request paths, timestamps, error traces
- Product usage — features accessed, conversations handled, message volumes
We do not collect payment card details. We do not run advertising trackers or sell data to anyone, ever.
4. WhatsApp Business app coexistence
Quibly supports Meta's coexistence mode, which lets a business keep using the WhatsApp Business app on a phone while the same number is also connected to the Cloud API through Quibly. This is optional and only happens if you choose it during onboarding.
When you enable coexistence, Meta synchronises additional data from your WhatsApp Business app to Quibly. You are consenting to that synchronisation. Specifically we may receive:
| What syncs | Why |
|---|---|
| Contact list from your WhatsApp Business app | So Quibly recognises returning customers and does not treat them as new enquiries |
| Message history — up to six months of past conversations | So the assistant has context on prior conversations and does not ask a customer something they have already answered |
| Message echoes — copies of messages you send from the WhatsApp Business app by hand | So Quibly does not duplicate or contradict a reply you have already sent yourself |
This historical data is stored on the same terms as all other message content described in this policy, and is deleted on the same schedule. If you disconnect coexistence, we stop receiving new syncs; previously synced history is deleted when you delete your account or on request.
Important for coexistence users: synced history may contain conversations with people who never interacted with Quibly directly. We process that data solely to provide the service to you, never for our own purposes, and never to train models available to anyone else.
5. Automated processing and AI
Quibly's core function is automated. Message content is sent to third-party large-language-model providers to generate suggested or automatic replies. Currently those providers are:
- OpenAI — reply generation and text analysis
- Google (Gemini) — reply generation and content assistance
We use these providers under their enterprise/API terms, which prohibit using submitted content to train their general-purpose models. We do not send them your access tokens or login credentials — only the conversation content needed to produce a reply.
Automated replies can be wrong. Quibly is an assistant, not a substitute for human judgement, and you remain responsible for what is sent from your number. Where a decision could materially affect a customer, review it before it goes out.
6. How we use information
- To deliver the service — receive messages, generate replies, send them via the WhatsApp Business Platform
- To authenticate you and keep your account secure
- To maintain conversation context so the assistant behaves sensibly across a conversation
- To provide dashboards, reporting and analytics to you about your own account
- To diagnose faults, monitor reliability and prevent abuse
- To meet legal obligations and enforce our terms
We do not use your messages or your customers' messages for advertising, for resale, or to train models offered to third parties.
7. Who we share it with
| Recipient | Purpose |
|---|---|
| Meta Platforms, Inc. | Message delivery over the WhatsApp Business Platform. Meta's own handling is governed by Meta's terms and privacy policy. |
| OpenAI | Generating replies and analysing message text |
| Generating replies (Gemini) and content assistance | |
| Hosting and infrastructure providers | Running our servers and databases |
| Law enforcement or regulators | Only where legally compelled, and only to the extent required |
We do not sell personal data. We do not share it with data brokers or advertising networks.
8. Meta platform terms
Because Quibly integrates with the WhatsApp Business Platform, our handling of data obtained through Meta's APIs is additionally governed by Meta's Platform Terms and Developer Policies. Where those terms are stricter than this policy, they prevail. That includes limits on how long we may retain platform data and an obligation to delete it on request or when it is no longer needed for the purpose it was obtained.
9. Retention
| Data | Retained for |
|---|---|
| Business account and profile | While your account is active |
| Conversation content and metadata | Up to 24 months from the message date, unless you ask for shorter |
| Coexistence-synced history | Same as conversation content |
| Access tokens | Until you disconnect WhatsApp or the token is revoked |
| Server and audit logs | Up to 12 months |
| Records we must keep by law | As long as the law requires |
When you close your account we delete or irreversibly anonymise your data within 30 days, except where retention is legally required.
10. Security
- All traffic to and from Quibly is encrypted in transit over HTTPS/TLS
- Access tokens and two-step verification PINs are encrypted at rest
- Passwords are stored as salted hashes only
- Every inbound webhook from Meta is verified using an HMAC-SHA256 signature before it is processed
- Access to production systems is restricted and logged
- Each business's data is logically separated by tenant and never mixed across accounts
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the relevant authorities as required by law, without undue delay.
11. Where data is stored
Quibly's servers are located in India. Where a WhatsApp Business Account is eligible, we set Meta's data localisation region to India (IN) so that message data is stored locally by Meta as well.
Some of our sub-processors — notably Meta, OpenAI and Google — operate globally and may process data outside India. Where that happens, we rely on the contractual protections in those providers' enterprise terms.
12. Your rights
Under India's Digital Personal Data Protection Act, 2023 and other applicable law, you may:
- Ask what personal data we hold about you and get a copy
- Ask us to correct data that is wrong or incomplete
- Ask us to delete your data
- Withdraw a consent you previously gave, including consent to coexistence synchronisation
- Nominate someone to exercise these rights on your behalf
- Raise a grievance with us, and escalate to the Data Protection Board of India if unresolved
Write to privacy@quiblytech.in. We respond within 30 days and may need to verify your identity first.
13. Deleting your data
Full instructions, including what is deleted and how long it takes, are on our Data Deletion page.
14. Children
Quibly is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached us, write to privacy@quiblytech.in and we will delete it.
15. Changes
We may update this policy as the product or the law changes. The effective date at the top always reflects the current version. For material changes affecting how we use your data, we will notify account holders by email at least 14 days before the change takes effect.
16. Contact us
Grievance Officer — Quibly Tech
K501, Green Valley Apartments, Plot 18, Sector 22, DwarkaNew Delhi, South West Delhi, Delhi 110077
Email: privacy@quiblytech.in
Phone: +91 78383 63463