Legal

Privacy Policy

This policy explains what personal data Fonabit India Private Limited collects when you use fonabit.ai, fonabit.com, Aibit and Netbit, why we collect it, who we share it with, how long we keep it, and the rights you can exercise over it.

Effective  11 September 2026 Last updated  11 September 2026 Controller  Fonabit India Private Limited CIN  U62099HR2023PTC116552

Fonabit India Private Limited ("Fonabit", "we", "us") operates the Fonabit.AI platform, comprising Aibit (an AI workspace) and Netbit (a communications platform delivering WhatsApp, SMS, Voice, Email and RCS messaging). The domains fonabit.com and fonabit.ai are operated by the same business — Fonabit India Private Limited. This policy applies to both.

1.Who we are

We are the entity responsible for the personal data described in this policy.

Fonabit India Private Limited

Unit No. 762, 7th Floor, JMD Megapolis, Sector 48, Gurugram, Haryana 122018, India

CIN: U62099HR2023PTC116552 · GSTIN: 06AAFCF7056H1ZK · PAN: AAFCF7056H

Privacy contact: info@fonabit.com

Fonabit is incorporated in India under the Companies Act, 2013 and is registered for Goods and Services Tax in the State of Haryana.

2.Scope and your role

Your rights and our obligations depend on how you interact with us. We distinguish three groups:

You areMeaningOur role
A visitor You browse fonabit.ai or fonabit.com, or contact our sales team. We are the data controller (a "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023).
A customer You hold a Fonabit account and use Aibit or Netbit. We are the controller of your account, billing and usage data.
A message recipient A Fonabit customer sent you a WhatsApp, SMS, voice, email or RCS message through Netbit. We are a processor acting on our customer's instructions. That customer is the controller and is responsible for obtaining your consent.
If you received a message you did not ask for

Fonabit does not choose who is messaged, what is sent, or when. Our customer does. Reply STOP to the message to opt out immediately, and contact info@fonabit.com — we will identify the sending customer, action your request, and require them to suppress your contact details. See section 11.

3.Data we collect

3.1 Data you give us directly

  • Account data — name, work email address, phone number, company name, job role, password (stored only as a salted hash).
  • Billing data — billing address, GSTIN (where you claim input tax credit), purchase order references and payment-method tokens. Full card numbers are handled by our payment processor and never stored on Fonabit systems.
  • KYC and onboarding data — business registration documents, authorised-signatory details and sender-identity evidence that regulators, carriers or Meta require before a channel can be enabled.
  • Support and sales correspondence — the content of enquiry forms, support tickets and email threads.

3.2 Data we process on your behalf (customer content)

  • Recipient identifiers — phone numbers, email addresses, WhatsApp IDs and contact lists you upload or send via the API.
  • Message content — the body of outbound messages, approved templates, media attachments, and inbound replies from recipients.
  • Conversation metadata — timestamps, delivery and read receipts, failure codes, routing path, country, channel and cost per message.
  • Voice data — call audio and, where you have enabled it, transcripts generated by our Voice AI.
  • Aibit workspace content — prompts, chat history, uploaded files, documents and agent configurations you create in the AI workspace.

3.3 Data collected automatically

  • Technical data — IP address, browser and device type, operating system, and pages viewed.
  • Usage and audit logs — API calls, authentication events, console actions, and administrative changes, retained for security and billing integrity.
  • Cookies — see section 14.

We do not intentionally collect special-category or sensitive personal data (such as health, biometric, financial-account or government-identifier data) through our platform. If you transmit such data as message content, you do so as controller and must have a lawful basis for it.

4.Why we process personal data

PurposeData usedLawful basis
Creating and administering your accountAccount dataPerformance of a contract
Delivering messages across WhatsApp, SMS, Voice, Email and RCSCustomer content, recipient identifiersPerformance of a contract; our customer's consent from the recipient
Generating AI responses, summaries, transcripts and agent actions in AibitWorkspace contentPerformance of a contract
Billing, invoicing and GST complianceBilling and usage dataLegal obligation; performance of a contract
Preventing fraud, spam, abuse and platform-policy violationsUsage logs, message metadataLegitimate interests; legal obligation
Security monitoring and incident responseTechnical and audit dataLegitimate interests; legal obligation
Responding to sales enquiries and support requestsCorrespondenceLegitimate interests; steps prior to a contract
Meeting telecom, tax and law-enforcement obligationsAs required by the relevant authorityLegal obligation
Product marketing to business contactsName, work emailConsent; legitimate interests (you may opt out at any time)

We do not sell personal data, and we do not share personal data for cross-context behavioural advertising.

5.WhatsApp Business Platform and Meta

Netbit delivers WhatsApp messaging through the WhatsApp Business Platform operated by Meta. When you use the WhatsApp channel, personal data is necessarily shared with Meta in order to deliver the message.

What is shared with Meta
  • Recipient phone numbers and WhatsApp IDs, so that Meta can route the message.
  • Message content, including templates, text, media and interactive components.
  • Delivery metadata — sent, delivered, read and failure signals returned by Meta.
  • Business account data — your WhatsApp Business Account ID, display name, verified business details and phone-number registration data submitted during onboarding.
  • Quality signals — recipient blocks and reports, which Meta uses to compute your sender quality rating and messaging limits.

Meta processes this data as an independent controller under its own terms. Meta's handling of that data is governed by:

If you connect your WhatsApp Business Account to Netbit through Meta's Embedded Signup flow, you authorise Fonabit to act as your Business Solution Provider and to access your WhatsApp Business Account on your behalf for the purposes of registering phone numbers, submitting message templates for Meta's approval, sending and receiving messages, and retrieving quality and delivery metrics. You may revoke that authorisation at any time from Meta Business Manager or by contacting us.

Other channels involve equivalent disclosures to their own operators: SMS, Voice and RCS messages are handed to licensed telecom carriers and, for RCS, to Google; email is delivered through our sending infrastructure to the recipient's mail provider. Those operators receive the recipient identifier and message content necessary to complete delivery.

7.AI processing and model training

Aibit routes requests to large language models, some run on our own infrastructure and some operated by third-party model providers. Voice AI additionally performs speech-to-text transcription.

  • We do not train our models on your content. Customer content, message bodies and workspace data are not used to train or fine-tune Fonabit models or any third-party model.
  • Third-party model providers process content under zero-retention terms where the provider offers them. Content sent to a third-party model is used only to generate your response and is not retained for training by that provider.
  • Automated outputs are not solely automated decisions with legal or similarly significant effects. Aibit generates drafts, summaries and suggested actions; a human or your own configured workflow decides what is acted on.
  • AI output can be wrong. Do not rely on it for legal, medical, financial or safety-critical decisions without human review.

Enterprise customers may request a list of the model providers in scope for their account, and may restrict processing to in-house models only.

8.Who we share data with

We share personal data only with the categories of recipient below, and only as far as is necessary.

RecipientWhyWhat they receive
Meta Platforms (WhatsApp Business Platform)To deliver WhatsApp messagesRecipient numbers, message content, delivery and quality metadata
Licensed telecom carriers and aggregatorsTo deliver SMS and voice trafficRecipient numbers, message content, call audio, routing metadata
Google (RCS)To deliver RCS messagesRecipient numbers, message content, delivery metadata
Cloud infrastructure providersHosting, storage and networkingEncrypted platform data
AI model providersTo generate AI responses in AibitPrompt content, under zero-retention terms
Payment processorsTo collect paymentBilling contact and payment details
Professional advisers and auditorsLegal, tax and compliance advice; SOC 2 auditLimited data under confidentiality obligations
Courts, regulators and law-enforcement agenciesWhere legally compelledOnly what the lawful order requires
An acquirerIn a merger, acquisition or asset saleData transfers subject to this policy; we will notify you

All processors act under written contracts that restrict them to our documented instructions and impose confidentiality and security obligations.

9.International transfers

Fonabit is established in India, and our primary processing takes place there. Delivering global messaging necessarily involves cross-border transfers — a message to a recipient in Germany must reach a carrier in Germany.

  • EU and UK customer data may be held in our Frankfurt (AWS eu-central-1) region where a data-residency commitment has been agreed.
  • Transfers out of the EEA and UK rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and a transfer risk assessment.
  • Transfers from India are made in accordance with the Digital Personal Data Protection Act, 2023 and any restrictions notified by the Central Government.
  • Carrier routing may transit intermediate jurisdictions determined by the destination number. We use direct routes wherever available to minimise this.

A copy of the safeguards applying to a specific transfer is available on request from info@fonabit.com.

10.How long we keep data

CategoryRetentionReason
Message content and media90 days by default, configurable down to 0 daysDelivery troubleshooting and customer audit
Message metadata (delivery receipts, cost records)24 monthsBilling disputes and carrier reconciliation
Call audio and transcripts30 days, or as configured by the customerQuality assurance
Aibit workspace contentFor the life of the account, then 30 daysService delivery
Account and contact dataLife of the account, then 90 daysService delivery and reactivation
Invoices, tax and GST records8 yearsCompanies Act, 2013 and GST law
Security and audit logs12 monthsIncident investigation
Opt-out and suppression recordsIndefinitelySo that an opt-out is never lost

Suppression records are deliberately kept forever. Deleting them would let a recipient who has opted out be messaged again.

11.Data deletion requests

You can ask us to delete your personal data. How we handle the request depends on who you are.

If you are a Fonabit customer

Delete individual records from the Netbit or Aibit console, or email info@fonabit.com to request deletion of your whole account. We complete account deletion within 30 days, except for records we must keep by law (see section 10) and suppression lists.

If you are a message recipient

Email info@fonabit.com from, or quoting, the phone number or email address that received the message. Because we process your data on a customer's behalf, we will forward the request to that customer and act on their instruction, while independently suppressing your contact so no further messages are sent. We respond within 30 days.

WhatsApp and Meta data

Data already delivered to Meta is held by Meta under its own policy. Deleting data from Fonabit does not delete it from Meta's systems or from the recipient's device. To request deletion of data held by Meta, use the controls in your WhatsApp account or in Meta Business Manager.

Quick reference

Deletion requests: info@fonabit.com · Opt out of messages: reply STOP · Response time: 30 days · No account or login required to make a request.

12.Your rights

Depending on where you live, you have some or all of the following rights. We do not charge for exercising them, and we will not treat you differently for doing so.

  • Access — obtain confirmation of whether we process your data, and a copy of it.
  • Correction — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted where we no longer need it.
  • Restriction and objection — limit or object to processing based on legitimate interests.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent — at any time, without affecting processing already carried out.
  • Nomination — under India's DPDP Act, nominate a person to exercise your rights if you die or become incapacitated.
  • Non-discrimination and opt-out of sale or sharing — under the CCPA/CPRA. We do not sell or share personal data as those terms are defined.
  • Complain to a regulator — the Data Protection Board of India, your EU supervisory authority, or the UK Information Commissioner's Office.

To exercise any right, email info@fonabit.com. We verify identity before disclosing data and respond within 30 days.

13.How we protect data

  • TLS 1.2+ in transit and AES-256 at rest.
  • Role-based access control, least-privilege provisioning and mandatory multi-factor authentication for staff.
  • Tenant isolation between customer accounts, and scoped API keys that can be rotated or revoked.
  • Continuous logging and monitoring, with alerting on anomalous access.
  • SOC 2 Type II controls, annual penetration testing and a coordinated vulnerability disclosure process.
  • Written processor agreements with every vendor that touches personal data.

No system is perfectly secure. We commit to industry-standard protection, not to a guarantee against every possible compromise. See our Trust Center for detail.

14.Cookies and tracking

We use a deliberately small set of cookies.

TypePurposeCan you refuse?
Strictly necessarySession management, authentication, load balancing, CSRF protectionNo — the service cannot function without them
PreferenceRemembering language and console layoutYes
AnalyticsAggregate, first-party measurement of page usageYes

We do not use third-party advertising or cross-site tracking cookies. You can block or delete cookies in your browser settings; strictly necessary cookies cannot be disabled without breaking sign-in. We honour Global Privacy Control signals where your browser sends them.

15.Children's data

Fonabit is a business-to-business platform and is not directed at children. We do not knowingly collect personal data from anyone under 18. Customers must not use Netbit to message recipients they know to be children without verifiable parental consent where the law requires it. If you believe a child's data has reached us, contact info@fonabit.com and we will delete it.

16.Breach notification

If a personal data breach occurs, we will notify the Data Protection Board of India and affected customers without undue delay, and in any event within 72 hours of becoming aware of it where the applicable law requires. Notification will describe what happened, what data was involved, what we are doing, and what you should do. Where we act as processor, we notify the customer so they can meet their own notification duties.

17.Changes to this policy

We update this policy when our processing changes. The effective date at the top always reflects the current version. For material changes we will notify account holders by email or in-console notice at least 30 days before the change takes effect. Continuing to use the platform after that date means you accept the updated policy.

18.Contact and grievance redressal

For any privacy question, request or complaint:

Privacy teaminfo@fonabit.com

EU / UK data protection enquiriesinfo@fonabit.com

Grievance Officer (Information Technology Rules, 2021 and DPDP Act, 2023) — info@fonabit.com

Fonabit India Private Limited, Unit No. 762, 7th Floor, JMD Megapolis, Sector 48, Gurugram, Haryana 122018, India

The Grievance Officer acknowledges every complaint within 24 hours and resolves it within 15 days. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India or to your local supervisory authority.

This Privacy Policy is published by Fonabit India Private Limited and applies to fonabit.ai and fonabit.com, which are operated by the same business. It should be read together with our Terms of Service. Governing law: India; courts at Gurugram, Haryana.

© 2026 Fonabit India Private Limited. All rights reserved.
CIN: U62099HR2023PTC116552 · GSTIN: 06AAFCF7056H1ZK · PAN: AAFCF7056H
fonabit.com and fonabit.ai are operated by the same business — Fonabit India Private Limited.

SOC 2HIPAAGDPRCCPADPDP