Legal
Privacy Policy
1. Who we are
RecoverRail ("we", "our", "us") is a product of Siphalion Private Limited, a company incorporated under the Companies Act, 2013 in India. We act as a Data Fiduciary as defined under the Digital Personal Data Protection Act, 2023 ("DPDP Act"). We provide a WhatsApp-powered invoice collection platform for Indian businesses ("the Service"). By using the Service you agree to this Privacy Policy.
2. Information we collect
Information you give us
- Account details: name, business name, email address, and mobile number when you register.
- Invoice data: client names, phone numbers, invoice amounts, due dates, and any other details you upload or enter.
- Payment details: billing name and payment method for your subscription (card details are processed by our payment gateway and never stored on our servers).
Information collected automatically
- Usage data: pages visited, features used, and actions taken within the platform.
- Device and log data: IP address, browser type, operating system, and timestamps.
- WhatsApp delivery data: message delivery status and read receipts returned by the WhatsApp Business API.
3. Lawful basis and consent
Under the DPDP Act, 2023 (Section 4 and 6), we process your personal data only for lawful purposes on the basis of your free, specific, informed, unconditional, and unambiguous consent. By creating an account and clicking "I agree" at registration, you provide consent for the processing described in this Policy.
You may withdraw consent at any time by emailing siphalion@gmail.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Note that withdrawing consent may result in loss of access to parts of the Service.
4. How we use your information
- To send WhatsApp payment reminders on your behalf to your clients.
- To provide, maintain, and improve the Service.
- To process your subscription payments.
- To send you transactional emails (account alerts, receipts, and critical service notices).
- To detect and prevent fraud and abuse.
- To comply with applicable Indian law, including requests from government authorities.
We do not sell your data or your clients' data to any third party for marketing purposes.
5. WhatsApp and the Meta Business API
The Service uses the WhatsApp Business Platform (provided by Meta Platforms, Inc.) to send messages. By using our platform you authorise us to send WhatsApp messages to your clients' numbers on your behalf. You confirm that:
- You have a legitimate business relationship with each recipient.
- You will not use the Service to send unsolicited messages or spam.
- Message delivery and read-receipt data is subject to Meta's Privacy Policy in addition to ours.
6. Data sharing and disclosure
We share data only in these limited circumstances:
- Service providers: cloud hosting (AWS/GCP), payment gateways (Razorpay), and analytics tools operating under confidentiality agreements and bound to process data only on our instructions.
- Legal requirements: when required by Indian courts, regulators, or law enforcement under the Information Technology Act, 2000, the DPDP Act, 2023, or other applicable law.
- Business transfers: in the event of a merger or acquisition, with notice to you in advance and with the successor bound to honour this Policy.
7. Data storage and security
Your data is stored on servers located in India. Where we use service providers whose infrastructure is outside India, we transfer data only to countries that the Central Government has notified as providing adequate personal data protection under Section 16 of the DPDP Act, or where contractual protections are in place.
We implement industry-standard safeguards: TLS encryption in transit, AES-256 encryption at rest, role-based access controls, and regular security audits, in compliance with Section 8(5) of the DPDP Act.
8. Data breach notification
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in the manner prescribed under Section 8(6) of the DPDP Act and the rules thereunder. If you believe your account or data may have been compromised, please contact us immediately at siphalion@gmail.com.
9. Data retention
We retain your account and invoice data for as long as your account is active, and for up to 5 years after closure to comply with Indian financial record-keeping requirements. WhatsApp message logs are retained for 90 days and then permanently deleted. We erase personal data as soon as the purpose for which it was collected is no longer served, in accordance with Section 8(4) and Section 8(7) of the DPDP Act.
10. Your rights as a Data Principal
Under the DPDP Act, 2023, you have the following rights:
- Right to access information (Section 11): request a summary of the personal data we hold about you and the purposes for which it is processed.
- Right to correction and erasure (Section 12): request correction of inaccurate or incomplete data, or erasure of data that is no longer necessary for the stated purpose, subject to applicable retention obligations.
- Right to grievance redressal (Section 13): raise a grievance with our Grievance Officer and receive a response within 30 days.
- Right to nominate (Section 14): nominate another individual to exercise your rights in the event of your death or incapacity.
- Right to withdraw consent: withdraw your consent for processing at any time (see Section 3 above).
To exercise any of these rights, email siphalion@gmail.com from your registered email address. We will respond within 30 days.
11. Cookies
We use strictly necessary cookies for session management and authentication, and optional analytics cookies to understand platform usage. You may disable analytics cookies in your browser settings without affecting core functionality.
12. Children's privacy
The Service is intended for businesses and individuals aged 18 and above. In accordance with Section 9 of the DPDP Act, we will not process personal data of a child (a person under 18 years of age) without verifiable parental or guardian consent. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete it promptly.
13. Changes to this policy
We may update this policy from time to time. We will notify you by email and by a banner on the platform at least 7 days before material changes take effect. Continued use after the effective date constitutes acceptance.
14. Grievance Officer and contact
In accordance with Section 13 of the DPDP Act, 2023 and Rule 7 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have designated a Grievance Officer to address complaints and queries regarding personal data processing:
Grievance Officer
Siphalion Private Limited
Email: siphalion@gmail.com
Response time: within 30 days of receipt of complaint.
If you are not satisfied with our response, you may approach the Data Protection Board of India once it is constituted and operational under the DPDP Act, 2023.