🚀 NewAI Voice Agents for COD confirmation — cut RTO before it happens.See how →
01 Legal Notice

Privacy Policy

How Hypersona collects, uses, discloses, retains and protects personal data

OwnerVayce Innovations Private Limited
Last Updated2 August 2026
Effective2 August 2026

Plain-language overview

Hypersona is a business customer-engagement and marketing-automation platform. We process account, billing and website data for our own operations. We process a Client’s customer data mainly on that Client’s instructions. We do not sell personal data or Meta Platform Data.

1. Who we are and scope

This Privacy Policy explains how Vayce Innovations Private Limited, a company incorporated in India and operating the Hypersona platform (“Hypersona”, “we”, “us” or “our”), collects, uses, stores, shares, protects and deletes personal data.

The “Platform” includes https://hypersona.io, https://app.hypersona.io, our APIs, dashboards, integrations, communications, support services and any related feature that links to this Policy.

This Policy applies to: (a) business owners, administrators, marketers, developers, support agents and other authorised users of a Client account (“Client Users”); (b) customers and other individuals whose data a Client uploads, syncs or processes through Hypersona (“End Customers”); and (c) website visitors, prospects, applicants, support contacts and authorised integration users.

This Policy is a privacy notice. Where consent or another specific authorisation is required, Hypersona or the relevant Client will request it separately.

2. Our role for different data

Data or activityHypersona’s roleClient’s role
Client account, billing, website, sales and support dataData Fiduciary / controller for our own business purposesProvides accurate information and controls authorised users
End Customer contacts, commerce events, messages, consent records and segmentsData Processor / processor, except for limited security, legal, fraud-prevention and service-integrity purposesData Fiduciary / controller that decides the purpose, audience, content, lawful basis and retention instructions
Data sent to a channel, store, webhook, API or integration selected by a ClientProcesses and transmits data according to the Client’s configurationSelects and authorises the destination and remains responsible for its use
Aggregated or irreversibly de-identified analyticsMay use independently where individuals and Clients cannot reasonably be identifiedNo ownership in another Client’s data is created

Clients must process End Customer data lawfully, provide required notices, obtain valid permissions, respect communication preferences and issue only lawful instructions. Hypersona may refuse an instruction that we reasonably believe is unlawful, insecure or inconsistent with applicable platform rules.

3. Personal data we collect

3.1 Client User and business-contact data

  • Identity and account data: including name, work email, phone number, business name, role, account and user IDs, team membership, password hash, authentication settings and login history.
  • Business and verification data: including website, industry, company size, registered or billing address, GST/tax identifiers, sender details, WABA or platform IDs, authorised representative details and information required for onboarding, fraud checks or provider verification.
  • Billing data: including plans, wallet balance, top-ups, credits, invoices, usage, taxes, transaction references, failed payments, refunds and disputes. Full card or bank credentials are generally handled by the payment provider and are not stored by Hypersona.
  • Client Content: including templates, campaign copy, automation logic, prompts, knowledge-base files, product catalogues, media, tags, custom fields, API payloads, webhooks and support attachments.
  • Communications: including support tickets, sales and onboarding communications, feedback, complaints, survey responses and call or meeting records where recorded with notice.

3.2 End Customer data processed for Clients

  • Contact and profile data: such as name, phone number, email address, postal address, language, city, tags, custom attributes and store or CRM identifiers.
  • Consent and preference data: such as channel, purpose, opt-in source, notice version, timestamp, proof of consent, withdrawal, opt-out, complaint and suppression status.
  • Commerce and journey data: such as carts, checkouts, orders, products, discounts, order value, payment status, fulfilment, shipping, returns, reviews and attribution events.
  • Messages and conversations: including inbound and outbound content, attachments, delivery/read/failure events, agent actions, AI-generated replies, escalation records and conversation status.
  • Voice data: which may include call metadata, audio, transcript, summary, disposition, consent or notice status and calling-window settings when a Client enables voice features.
  • Engagement and technical data: such as link clicks, campaign source, device/browser signals, IP address and event timestamps where enabled.

3.3 Data received from integrations

Depending on the Client’s configuration and permissions, Hypersona may receive data from Meta and WhatsApp Business, Facebook Pages, Instagram, Shopify, WooCommerce, payment processors, logistics providers, review platforms, email and telecom providers, spreadsheets, CRMs, webhooks and other applications connected by the Client.

We request and use permissions reasonably required for the enabled feature. A Client can disconnect an integration through Hypersona or the provider’s settings. Disconnection stops future access but does not automatically delete information that must be retained for security, billing, legal compliance, suppression or a pending request.

3.4 Data collected automatically

  • Technical data: including IP address, browser, operating system, device type, app version, language, time zone and approximate location derived from IP.
  • Usage and audit data: including logins, pages, actions, API calls, configuration changes, exports, deletion requests, campaign sends, errors, timestamps and administrator activity.
  • Cookie and similar-technology data: used for sessions, security, preferences and product analytics.
  • Security and abuse signals: including failed logins, threat indicators, spam complaints, malware scans, rate-limit events and incident-response records.

4. How we use personal data

  1. Create, authenticate, administer and support Client accounts and authorised users.
  2. Provide messaging, inbox, automation, cart-recovery, template, analytics, attribution, wallet, AI, voice, API and integration features selected by the Client.
  3. Process and route communications and End Customer data on a Client’s documented instructions.
  4. Onboard and verify businesses, senders, phone numbers, domains, templates, connected assets and integrations.
  5. Calculate usage, deduct wallet charges, process payments, issue GST invoices, prevent duplicate or fraudulent transactions and resolve billing disputes.
  6. Provide support, troubleshoot errors, communicate service notices, manage incidents and respond to privacy or deletion requests.
  7. Protect the Platform, recipients and Clients; enforce consent and opt-outs; detect abuse, spam, fraud and unlawful activity; and maintain audit records.
  8. Analyse performance and improve features using aggregated, statistical or de-identified data where reasonably possible.
  9. Comply with applicable law, binding legal process and channel/provider policies; and establish, exercise or defend legal claims.
  10. Send product, educational or marketing communications to Client Users where permitted, with an unsubscribe option for non-essential messages.

5. Legal grounds, consent and messaging responsibility

The applicable legal ground depends on the person, purpose and jurisdiction. Under Indian law, personal data is processed for a lawful purpose with consent or another permitted use where and when applicable. Account, billing and essential service data may also be processed to take steps requested by a Client User, perform our agreement, protect the Platform, prevent fraud and comply with law.

For individuals in the EEA or United Kingdom, where applicable, we rely on performance of a contract, legitimate interests, consent and legal obligations. A person may contact privacy@hypersona.io for information about the ground used for a particular activity.

For End Customer communications, the Client is the sender and is responsible for valid channel-specific consent, DND and telecom compliance, message content, frequency, timing, audience selection and proof of permission. Clients must not upload purchased, scraped, rented or unlawfully obtained contact lists. Hypersona’s consent and suppression features assist compliance but do not transfer the Client’s legal responsibility to us.

6. AI, automation and voice processing

When a Client enables an AI or voice feature, relevant prompts, knowledge-base content, customer inputs, conversation context and call data may be sent to an AI, speech or telephony provider to generate a reply, transcription, summary, classification, recommendation or call response.

Hypersona does not use Client Content or End Customer personal data to train general-purpose models for other customers unless the Client expressly agrees in writing or through a clearly described opt-in feature. We require service providers to process data for the contracted service and apply confidentiality and security obligations appropriate to their role.

AI output can be inaccurate, incomplete or unsuitable. Clients are responsible for testing prompts and knowledge sources, configuring human escalation, reviewing high-risk uses and not using Hypersona to make solely automated decisions that create legal or similarly significant effects unless the Client has independently assessed and implemented the required safeguards.

Clients enabling recorded or automated voice calls must provide all legally required notices, obtain consent where required, comply with permitted calling windows and honour DND, opt-out and sector-specific restrictions.

7. Meta Platform Data

When a Client connects Meta, WhatsApp Business, Facebook or Instagram assets, Hypersona may receive business portfolio IDs, WABA IDs, phone-number details, page or Instagram account IDs, message templates, quality and messaging-limit information, access tokens, webhooks, delivery/read/failure events and inbound messages needed for the connected features.

  • We use Meta Platform Data only for connected onboarding, account management, messaging, templates, inbox, analytics, support, security and deletion purposes disclosed to the Client.
  • We do not sell, rent, license or broker Meta Platform Data, use it to create unrelated advertising profiles, or disclose it to data brokers or advertising networks.
  • We logically separate Client environments and do not use one Client’s Meta Platform Data to benefit another Client except through aggregated, non-identifying service metrics.
  • Access tokens and credentials are restricted, protected and used only for authorised actions.
  • A Client may revoke access through Hypersona or Meta settings. We then stop new access and delete or de-identify associated tokens and Platform Data according to Section 11 and the Data Deletion Policy, subject to legal and security exceptions.
  • We process valid user-data deletion requests received through Meta’s required mechanisms and provide confirmation or status information where required.

8. How we share personal data

8.1 Service providers

We use providers for cloud hosting, databases, storage, security, messaging, WhatsApp/Meta connectivity, SMS/RCS, voice and telephony, AI, email delivery, payment processing, analytics, error monitoring, support and professional services. They receive only information reasonably required for their function and are subject to contractual confidentiality, security and data-protection obligations.

8.2 Client-directed disclosures

We transmit data to recipients, channels, stores, webhooks, APIs and applications selected or configured by a Client. The Client is responsible for the destination, permissions, third-party terms and onward use of data after it reaches that destination.

8.3 Legal, safety and corporate events

We may disclose information to authorities, courts, advisers, auditors, insurers or other parties where required by law or reasonably necessary to investigate fraud or abuse, protect rights or safety, enforce agreements, respond to legal process, or complete a merger, financing, restructuring, acquisition or sale of assets. Where legally permitted, affected Clients will receive appropriate notice of a material corporate transfer.

We do not sell personal data. We do not share personal data for cross-context behavioural advertising as defined by certain US privacy laws unless a future feature expressly states otherwise and provides required choices.

9. International processing and data location

The Platform may process data in India and in other countries where our providers operate. Those countries may have different privacy laws. We use contractual, organisational and technical safeguards appropriate to the transfer and provider relationship. Clients are responsible for assessing any localisation or restricted-transfer requirement specific to their industry, customers or jurisdiction.

For EEA or UK restricted transfers, where applicable, the parties may use approved mechanisms such as Standard Contractual Clauses, the UK Addendum or another lawful transfer tool.

10. Data retention

We retain personal data only for the period reasonably necessary for the purpose described below, a Client’s valid instruction, security and dispute resolution, or applicable law. Actual retention may be shorter where the Client deletes data or configures a shorter period, and longer where a legal hold or binding requirement applies.

Data categoryTypical retention approach
Client account and workspace dataWhile the account is active; normally deleted or de-identified within 30 days after verified account closure, subject to the exceptions below.
End Customer profiles, attributes and segmentsWhile required by the Client; deleted through Client controls or normally within 30 days after verified workspace deletion.
Messages and conversation contentUp to 24 months from the message date by default, unless the Client configures another available period, requests earlier deletion, or law requires retention.
Consent, opt-out and suppression recordsFor as long as needed to prove permission, honour an opt-out, defend a complaint or satisfy applicable law. A minimal suppression record may be retained after other profile data is deleted.
Meta tokens and integration credentialsAccess is revoked and active credentials are deleted promptly after disconnection; associated integration metadata is normally deleted or de-identified within 30 days unless required for security, billing or law.
Security, audit, traffic and processing logsGenerally up to 12 months, and for at least the minimum period required by applicable law when the relevant requirement is in force.
Support, complaint and incident recordsUsually up to 3 years after closure, or longer for an unresolved dispute, legal claim or security investigation.
Invoices, GST and transaction recordsUp to 8 years or another period required by tax, accounting or corporate law.
Encrypted backupsRemoved through normal rotation, generally within 90 days after live deletion, unless isolated for security, disaster recovery or a legal hold.

11. Security and personal-data breaches

We maintain reasonable technical and organisational safeguards proportionate to the nature and risk of processing. Controls may include:

  • TLS or equivalent protection for data in transit and protection of stored credentials, access tokens and secrets.
  • Role-based and least-privilege access, authentication controls, tenant separation and personnel confidentiality.
  • Access logging, monitoring, rate limiting, dependency and vulnerability management, malware protection and secure change practices.
  • Backups, recovery procedures, incident response, vendor assessment and contractual processor safeguards.
  • Procedures to detect, investigate, contain, remediate and document personal-data breaches.

No system is completely secure. Clients are responsible for secure devices, strong credentials, appropriate user roles, API-key protection, lawful configuration and prompt reporting of suspected compromise to security@hypersona.io.

If we become aware of a personal-data breach affecting Client data, we will investigate, take reasonable containment and remediation steps, and notify the affected Client without undue delay, taking account of the nature of the processing and available information. Where Hypersona is the Data Fiduciary/controller, we will notify affected individuals and competent authorities within the timeline required by applicable law, including the applicable DPDP Rules timeline where and when that requirement is in force.

12. Rights and choices

Depending on applicable law and our role, an individual may request access to or a summary of personal data, correction, completion, erasure, withdrawal of consent, grievance redressal, nomination of another person where provided by law, objection or restriction, and a copy or export where available. These rights are subject to identity verification, legal exceptions, security requirements and our role as controller or processor.

Client Users may submit a request through available account settings or by emailing privacy@hypersona.io. End Customers should first contact the business that messaged them because that Client controls the purpose and use of their data. If an End Customer contacts us, we will identify and forward the request to the relevant Client and provide reasonable assistance.

Withdrawing consent does not affect processing already carried out lawfully and may prevent delivery of a requested feature. Essential service, security, billing and legal communications cannot be opted out of while the account remains active.

We aim to acknowledge privacy grievances promptly and respond within 30 days, or within another period required by applicable law. Where a person remains dissatisfied, they may use the escalation mechanism available under the applicable data-protection law.

13. Cookies and similar technologies

Hypersona may use: (a) strictly necessary technologies for login, security, load balancing and fraud prevention; (b) preference technologies for language, interface and saved settings; and (c) limited analytics technologies to understand product use and errors. We do not use third-party advertising cookies in the authenticated Platform unless this Policy and the consent interface are updated before doing so.

Browser settings can block or delete cookies. Blocking necessary cookies may prevent login or cause features to fail. Where applicable, a cookie banner or preference centre will provide additional choices. We do not currently respond to “Do Not Track” signals. Where a legally recognised opt-out signal applies to a future activity, we will process it as required.

14. Children

Client accounts are for adults acting for businesses. We do not knowingly allow anyone under 18 to create a Client account. Hypersona is not designed for Clients to intentionally target or profile children. A Client that lawfully processes a child’s data must first obtain verifiable parental consent and implement all required safeguards, notices and restrictions. We may suspend a configuration that presents an unacceptable child-safety or compliance risk.

15. Third-party sites and services

The Platform may link to or connect with third-party services. Their privacy practices and terms apply independently. Hypersona is not responsible for a third party’s independent processing after data is transmitted under the Client’s instruction or when a person leaves our website.

16. Changes to this Policy

We may update this Policy to reflect legal, product, vendor, security or operational changes. We will revise the “Last updated” date and provide reasonable advance notice of material changes through email, dashboard notice or the website, unless an urgent legal or security change requires earlier effect.

17. Contact and grievance channel

ItemDetails
Legal entityVAYCE INNOVATIONS PRIVATE LIMITED
GSTIN24AAMCV4972H1ZW
Registered officeBlock-A, 606, Prahladnagar Trade Center, B/H Titanium City Center, Vejalpur, Ahmedabad, Gujarat 380051, India
Privacy and grievance contactThe person designated by Vayce Innovations Private Limited to handle privacy questions and grievances
Privacy / grievance emailprivacy@hypersona.io
Security reportssecurity@hypersona.io
General supportsupport@hypersona.io
Websitehttps://hypersona.io