Fonabit India Private Limited ("Fonabit", "we", "us") operates the Fonabit.AI platform, comprising Aibit (an AI workspace) and Netbit (a communications platform delivering WhatsApp, SMS, Voice, Email and RCS messaging). The domains fonabit.com and fonabit.ai are operated by the same business — Fonabit India Private Limited. This policy applies to both.
1.Who we are
We are the entity responsible for the personal data described in this policy.
Fonabit India Private Limited
Unit No. 762, 7th Floor, JMD Megapolis, Sector 48, Gurugram, Haryana 122018, India
CIN: U62099HR2023PTC116552 · GSTIN: 06AAFCF7056H1ZK · PAN: AAFCF7056H
Privacy contact: info@fonabit.com
Fonabit is incorporated in India under the Companies Act, 2013 and is registered for Goods and Services Tax in the State of Haryana.
2.Scope and your role
Your rights and our obligations depend on how you interact with us. We distinguish three groups:
| You are | Meaning | Our role |
|---|---|---|
| A visitor | You browse fonabit.ai or fonabit.com, or contact our sales team. | We are the data controller (a "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023). |
| A customer | You hold a Fonabit account and use Aibit or Netbit. | We are the controller of your account, billing and usage data. |
| A message recipient | A Fonabit customer sent you a WhatsApp, SMS, voice, email or RCS message through Netbit. | We are a processor acting on our customer's instructions. That customer is the controller and is responsible for obtaining your consent. |
Fonabit does not choose who is messaged, what is sent, or when. Our customer does. Reply STOP to the message to opt out immediately, and contact info@fonabit.com — we will identify the sending customer, action your request, and require them to suppress your contact details. See section 11.
3.Data we collect
3.1 Data you give us directly
- Account data — name, work email address, phone number, company name, job role, password (stored only as a salted hash).
- Billing data — billing address, GSTIN (where you claim input tax credit), purchase order references and payment-method tokens. Full card numbers are handled by our payment processor and never stored on Fonabit systems.
- KYC and onboarding data — business registration documents, authorised-signatory details and sender-identity evidence that regulators, carriers or Meta require before a channel can be enabled.
- Support and sales correspondence — the content of enquiry forms, support tickets and email threads.
3.2 Data we process on your behalf (customer content)
- Recipient identifiers — phone numbers, email addresses, WhatsApp IDs and contact lists you upload or send via the API.
- Message content — the body of outbound messages, approved templates, media attachments, and inbound replies from recipients.
- Conversation metadata — timestamps, delivery and read receipts, failure codes, routing path, country, channel and cost per message.
- Voice data — call audio and, where you have enabled it, transcripts generated by our Voice AI.
- Aibit workspace content — prompts, chat history, uploaded files, documents and agent configurations you create in the AI workspace.
3.3 Data collected automatically
- Technical data — IP address, browser and device type, operating system, and pages viewed.
- Usage and audit logs — API calls, authentication events, console actions, and administrative changes, retained for security and billing integrity.
- Cookies — see section 14.
We do not intentionally collect special-category or sensitive personal data (such as health, biometric, financial-account or government-identifier data) through our platform. If you transmit such data as message content, you do so as controller and must have a lawful basis for it.
4.Why we process personal data
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and administering your account | Account data | Performance of a contract |
| Delivering messages across WhatsApp, SMS, Voice, Email and RCS | Customer content, recipient identifiers | Performance of a contract; our customer's consent from the recipient |
| Generating AI responses, summaries, transcripts and agent actions in Aibit | Workspace content | Performance of a contract |
| Billing, invoicing and GST compliance | Billing and usage data | Legal obligation; performance of a contract |
| Preventing fraud, spam, abuse and platform-policy violations | Usage logs, message metadata | Legitimate interests; legal obligation |
| Security monitoring and incident response | Technical and audit data | Legitimate interests; legal obligation |
| Responding to sales enquiries and support requests | Correspondence | Legitimate interests; steps prior to a contract |
| Meeting telecom, tax and law-enforcement obligations | As required by the relevant authority | Legal obligation |
| Product marketing to business contacts | Name, work email | Consent; legitimate interests (you may opt out at any time) |
We do not sell personal data, and we do not share personal data for cross-context behavioural advertising.
5.WhatsApp Business Platform and Meta
Netbit delivers WhatsApp messaging through the WhatsApp Business Platform operated by Meta. When you use the WhatsApp channel, personal data is necessarily shared with Meta in order to deliver the message.
- Recipient phone numbers and WhatsApp IDs, so that Meta can route the message.
- Message content, including templates, text, media and interactive components.
- Delivery metadata — sent, delivered, read and failure signals returned by Meta.
- Business account data — your WhatsApp Business Account ID, display name, verified business details and phone-number registration data submitted during onboarding.
- Quality signals — recipient blocks and reports, which Meta uses to compute your sender quality rating and messaging limits.
Meta processes this data as an independent controller under its own terms. Meta's handling of that data is governed by:
- WhatsApp Business Terms of Service
- WhatsApp Business Messaging Policy
- WhatsApp Commerce Policy
- WhatsApp Business Data Transfer Addendum
- WhatsApp Privacy Policy
If you connect your WhatsApp Business Account to Netbit through Meta's Embedded Signup flow, you authorise Fonabit to act as your Business Solution Provider and to access your WhatsApp Business Account on your behalf for the purposes of registering phone numbers, submitting message templates for Meta's approval, sending and receiving messages, and retrieving quality and delivery metrics. You may revoke that authorisation at any time from Meta Business Manager or by contacting us.
Other channels involve equivalent disclosures to their own operators: SMS, Voice and RCS messages are handed to licensed telecom carriers and, for RCS, to Google; email is delivered through our sending infrastructure to the recipient's mail provider. Those operators receive the recipient identifier and message content necessary to complete delivery.
6.Consent, opt-in and opt-out
Messaging through Netbit is permission-based. Our customers must obtain a valid opt-in from every recipient before the first message is sent, and must keep records proving it.
- Opt-in must be explicit. The recipient must have affirmatively agreed to receive messages from the identified business on the specific channel. Purchased, scraped or inferred lists are prohibited.
- Opt-out must always work. Every recipient may reply STOP, UNSUBSCRIBE or the local-language equivalent. Netbit detects these keywords automatically, suppresses the contact, and blocks further sends to that number on that channel.
- Suppression is enforced at the platform level. Once a recipient opts out, Netbit rejects subsequent API calls targeting that contact. Customers may not circumvent suppression by re-uploading the contact or routing through another sender ID.
- Recipients can reach us directly. If an opt-out is not honoured, email info@fonabit.com. We will suppress the contact ourselves and investigate the customer.
Failure to obtain or honour consent is a material breach of our Terms of Service and of the WhatsApp Business Messaging Policy, and may result in immediate suspension.
7.AI processing and model training
Aibit routes requests to large language models, some run on our own infrastructure and some operated by third-party model providers. Voice AI additionally performs speech-to-text transcription.
- We do not train our models on your content. Customer content, message bodies and workspace data are not used to train or fine-tune Fonabit models or any third-party model.
- Third-party model providers process content under zero-retention terms where the provider offers them. Content sent to a third-party model is used only to generate your response and is not retained for training by that provider.
- Automated outputs are not solely automated decisions with legal or similarly significant effects. Aibit generates drafts, summaries and suggested actions; a human or your own configured workflow decides what is acted on.
- AI output can be wrong. Do not rely on it for legal, medical, financial or safety-critical decisions without human review.
Enterprise customers may request a list of the model providers in scope for their account, and may restrict processing to in-house models only.
9.International transfers
Fonabit is established in India, and our primary processing takes place there. Delivering global messaging necessarily involves cross-border transfers — a message to a recipient in Germany must reach a carrier in Germany.
- EU and UK customer data may be held in our Frankfurt (AWS eu-central-1) region where a data-residency commitment has been agreed.
- Transfers out of the EEA and UK rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and a transfer risk assessment.
- Transfers from India are made in accordance with the Digital Personal Data Protection Act, 2023 and any restrictions notified by the Central Government.
- Carrier routing may transit intermediate jurisdictions determined by the destination number. We use direct routes wherever available to minimise this.
A copy of the safeguards applying to a specific transfer is available on request from info@fonabit.com.
10.How long we keep data
| Category | Retention | Reason |
|---|---|---|
| Message content and media | 90 days by default, configurable down to 0 days | Delivery troubleshooting and customer audit |
| Message metadata (delivery receipts, cost records) | 24 months | Billing disputes and carrier reconciliation |
| Call audio and transcripts | 30 days, or as configured by the customer | Quality assurance |
| Aibit workspace content | For the life of the account, then 30 days | Service delivery |
| Account and contact data | Life of the account, then 90 days | Service delivery and reactivation |
| Invoices, tax and GST records | 8 years | Companies Act, 2013 and GST law |
| Security and audit logs | 12 months | Incident investigation |
| Opt-out and suppression records | Indefinitely | So that an opt-out is never lost |
Suppression records are deliberately kept forever. Deleting them would let a recipient who has opted out be messaged again.
11.Data deletion requests
You can ask us to delete your personal data. How we handle the request depends on who you are.
If you are a Fonabit customer
Delete individual records from the Netbit or Aibit console, or email info@fonabit.com to request deletion of your whole account. We complete account deletion within 30 days, except for records we must keep by law (see section 10) and suppression lists.
If you are a message recipient
Email info@fonabit.com from, or quoting, the phone number or email address that received the message. Because we process your data on a customer's behalf, we will forward the request to that customer and act on their instruction, while independently suppressing your contact so no further messages are sent. We respond within 30 days.
WhatsApp and Meta data
Data already delivered to Meta is held by Meta under its own policy. Deleting data from Fonabit does not delete it from Meta's systems or from the recipient's device. To request deletion of data held by Meta, use the controls in your WhatsApp account or in Meta Business Manager.
Deletion requests: info@fonabit.com · Opt out of messages: reply STOP · Response time: 30 days · No account or login required to make a request.
12.Your rights
Depending on where you live, you have some or all of the following rights. We do not charge for exercising them, and we will not treat you differently for doing so.
- Access — obtain confirmation of whether we process your data, and a copy of it.
- Correction — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted where we no longer need it.
- Restriction and objection — limit or object to processing based on legitimate interests.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent — at any time, without affecting processing already carried out.
- Nomination — under India's DPDP Act, nominate a person to exercise your rights if you die or become incapacitated.
- Non-discrimination and opt-out of sale or sharing — under the CCPA/CPRA. We do not sell or share personal data as those terms are defined.
- Complain to a regulator — the Data Protection Board of India, your EU supervisory authority, or the UK Information Commissioner's Office.
To exercise any right, email info@fonabit.com. We verify identity before disclosing data and respond within 30 days.
13.How we protect data
- TLS 1.2+ in transit and AES-256 at rest.
- Role-based access control, least-privilege provisioning and mandatory multi-factor authentication for staff.
- Tenant isolation between customer accounts, and scoped API keys that can be rotated or revoked.
- Continuous logging and monitoring, with alerting on anomalous access.
- SOC 2 Type II controls, annual penetration testing and a coordinated vulnerability disclosure process.
- Written processor agreements with every vendor that touches personal data.
No system is perfectly secure. We commit to industry-standard protection, not to a guarantee against every possible compromise. See our Trust Center for detail.
15.Children's data
Fonabit is a business-to-business platform and is not directed at children. We do not knowingly collect personal data from anyone under 18. Customers must not use Netbit to message recipients they know to be children without verifiable parental consent where the law requires it. If you believe a child's data has reached us, contact info@fonabit.com and we will delete it.
16.Breach notification
If a personal data breach occurs, we will notify the Data Protection Board of India and affected customers without undue delay, and in any event within 72 hours of becoming aware of it where the applicable law requires. Notification will describe what happened, what data was involved, what we are doing, and what you should do. Where we act as processor, we notify the customer so they can meet their own notification duties.
17.Changes to this policy
We update this policy when our processing changes. The effective date at the top always reflects the current version. For material changes we will notify account holders by email or in-console notice at least 30 days before the change takes effect. Continuing to use the platform after that date means you accept the updated policy.
18.Contact and grievance redressal
For any privacy question, request or complaint:
Privacy team — info@fonabit.com
EU / UK data protection enquiries — info@fonabit.com
Grievance Officer (Information Technology Rules, 2021 and DPDP Act, 2023) — info@fonabit.com
Fonabit India Private Limited, Unit No. 762, 7th Floor, JMD Megapolis, Sector 48, Gurugram, Haryana 122018, India
The Grievance Officer acknowledges every complaint within 24 hours and resolves it within 15 days. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India or to your local supervisory authority.
This Privacy Policy is published by Fonabit India Private Limited and applies to fonabit.ai and fonabit.com, which are operated by the same business. It should be read together with our Terms of Service. Governing law: India; courts at Gurugram, Haryana.