Privacy Policy
Last updated 9 October 2026
This policy explains what personal data Dakiya ("we") handles when you use Dakiya at https://dakiya.smartaccounts.in, and why.
1. Two kinds of data
- Account data: details of the people who use Dakiya (our customers and their team members). For this data we decide how it is used.
- Customer content: the contact lists, phone numbers, messages and media that our customers put into Dakiya or receive through it. For this data our customer decides the purpose and is responsible for consent; we only process it on their instructions to run the service.
2. What we collect
- Account data: name, email address, password (stored only as a one-way hash), business name, plan and payment records, IP address at sign-up and log-in.
- Customer content: contact names, WhatsApp numbers, emails, tags and custom fields; message text and media sent and received; delivery and read status; opt-out status.
- Connection details: your WhatsApp Business Account ID, phone number ID and access token. Tokens and secrets are stored encrypted.
- Technical data: logs of API calls and errors, kept for a short time to run and secure the service.
We use one essential cookie to keep you logged in. We do not use advertising or tracking cookies.
3. How we use it
- To provide the service: sending and receiving WhatsApp messages on your behalf, showing reports, running your automations and API requests.
- To manage your account: billing, plan limits, service emails such as password resets and renewal reminders.
- To keep the service secure and to fix problems.
We do not sell personal data, and we do not use your contacts or messages for our own marketing.
4. Who receives it
- Meta Platforms (WhatsApp): messages, numbers and templates are sent to Meta to deliver them. Meta's own terms and privacy policy apply to that processing.
- Our hosting provider, which stores the data on our behalf.
- Our payment provider, for plan payments. We do not see or store card details.
- Any address you configure yourself, such as a webhook to your CRM.
- Authorities, where the law requires it.
5. How long we keep it
Customer content is kept while the account is active. After an account is closed we delete it within 90 days unless the law requires longer. Technical logs are kept for up to 14 days. Payment records are kept as tax law requires.
6. Security
Access is by password over an encrypted connection, tokens and secrets are encrypted at rest, each workspace's data is separated from every other workspace, and incoming events from Meta are signature-checked. No system is perfectly secure; we will tell affected customers without undue delay if we learn of a breach involving their data.
7. Your choices
- Account holders can see and correct their details in the app, export contacts and reports, and ask us to delete the account.
- People who receive messages from one of our customers can reply STOP to opt out, and should contact that business to see, correct or erase their data. If they write to us, we pass the request to the business concerned.
- You can withdraw consent to service emails that are not essential by writing to us.
8. Grievances
Questions and complaints about personal data: The Grievance Officer, Dakiya, . Email: . We aim to respond within 15 days.
9. Children
The service is for businesses. It is not meant for anyone under 18.
10. Changes
We will post any change to this policy here and, for significant changes, tell account owners by email.