Privacy policy
How DAM Networks LLP collects, uses and protects personal data in Clevar, our WhatsApp Business messaging console.
Who we are
Clevar is operated by DAM Networks LLP ("we", "us"), an Indian limited liability partnership. It is a business messaging console built on Meta's WhatsApp Business Platform, used by us and by our clients to hold conversations with their own customers.
Two different relationships
This matters for understanding your rights, so we state it plainly rather than burying it.
- When a client uses Clevar, that client decides what data is collected and why. They are the data controller and we act as their data processor, handling data on their instructions under a written agreement.
- When DAM Networks messages its own customers, we are the controller ourselves.
If you received a WhatsApp message from a business using Clevar and want your data corrected or deleted, that business is the right first point of contact. Write to us anyway if you cannot reach them and we will help.
What we hold
| Data | Why |
|---|---|
| Your WhatsApp phone number | To send and receive messages. It is how WhatsApp identifies you |
| Your WhatsApp profile name | So an agent sees who they are talking to rather than a number |
| Message content, including photos, documents and voice notes you send | To display the conversation and let an agent answer it |
| Delivery and read receipts | To show whether a message arrived, and for billing accuracy |
| Contact details and attributes a client imports | Names, emails and fields such as order number, supplied by the client |
| Whether you have opted out | To make sure you are never sent marketing again once you ask us to stop |
| Sign-in records and IP addresses of platform users | Security and accountability. This is our clients' staff, not their customers |
We do not buy contact lists, we do not build advertising profiles, and we do not sell personal data to anyone.
How to stop hearing from us
Reply STOP to any WhatsApp message. It takes effect immediately and permanently: the contact is marked opted out and excluded from every future campaign automatically. Reply START if you later change your mind.
An opt-out is never removed by a later data import, and it is retained even if the rest of the contact record is deleted — otherwise deleting your data would quietly re-enable marketing to you.
How long we keep things
| Data | Retained |
|---|---|
| Raw delivery logs from Meta | 30 days |
| Messages and attachments | 24 months |
| Campaign recipient records | 12 months |
| Security and activity logs | 24 months |
| Contact records | Until the client deletes them |
| Opt-out records | Indefinitely, deliberately |
Deletion is automatic. A scheduled job removes expired data nightly, and attachments are deleted from storage along with the messages that referenced them.
Who else is involved
- Meta Platforms — WhatsApp itself. Messages travel through Meta's WhatsApp Business Platform, subject to their own terms and privacy policy.
- DigitalOcean — hosting. Our servers and database run in DigitalOcean's Bangalore, India region, so day-to-day personal data stays in India.
We add no analytics trackers, advertising pixels or third-party scripts to the console.
How we protect it
- Everything travels over HTTPS; the site refuses plain HTTP.
- WhatsApp access tokens are encrypted at rest with AES-256-GCM and are never written to logs.
- Incoming data from Meta is cryptographically verified before it is processed, so forged traffic is rejected.
- Each client's data is isolated; one client can never see another's conversations or contacts.
- Sign-in attempts are rate limited, sessions expire after 12 hours, and signing out or changing a password invalidates existing sessions.
- Consequential actions — sign-ins, campaign sends, imports, account changes — are recorded in an activity log.
- Databases are not reachable from the public internet.
No system is perfectly secure. If a breach affects your personal data we will notify the relevant authority and the people affected, as India's Digital Personal Data Protection Act 2023 requires, and — where the GDPR applies — within 72 hours.
Your rights
Under the DPDP Act 2023, and the GDPR where it applies, you may ask us to:
- tell you what personal data we hold about you;
- correct anything inaccurate;
- delete your data;
- stop using it for marketing, at any time, for any reason;
- provide it in a portable form;
- nominate someone to exercise these rights on your behalf.
We respond within 30 days. Where we hold data on behalf of a client, we will pass the request to them and support them in answering it.
Children
Clevar is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. Tell us if you believe we have, and we will delete it.
Changes
If we change this policy we will update the date at the top of this page. Material changes affecting how your data is used will be communicated to clients directly rather than left here to be discovered.
Contact
Email harshit.damani@damnw.com for any privacy question, data request or complaint. If you are not satisfied with our response you may complain to the Data Protection Board of India, or to your local supervisory authority where the GDPR applies.