Privacy Policy
This policy explains what personal data Nucleus Ai collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. We have written it to be read, not survived.
1. Who we are
Nucleus Ai Automation Private Limited ("Nucleus Ai", "we", "us", "our") is a company incorporated in India and operating from Noida, Uttar Pradesh. We provide WhatsApp Business API, RCS business messaging, chatbot automation, SEO, website development and SaaS product development services.
Nucleus Ai Automation Private Limited (trading as Nucleus Ai)
Unit-603 604, Floor 6th, Tower B, Bhutani Alphathum, Sector 90, NEPZ Post Office, Noida, Gautam Buddha Nagar- 201305, Uttar Pradesh
CIN — U63111UW2026PTC255078
Email — hello@nucleusaiautomation.com · Phone — 8139 933 933
For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we act as a Data Fiduciary for personal data we collect in our own right — website visitors, enquiries, clients and their staff. Where we operate messaging, chatbot or analytics systems on behalf of a client, we act as a Data Processor for the end-customer data flowing through those systems, and we process it only on that client's documented instructions.
2. Scope
This policy covers:
- this website and any subdomain we operate;
- the on-site assistant ("Nucleus" chat widget);
- enquiries you send us by WhatsApp, email, telephone or a form;
- the commercial relationship if you become a client, including onboarding, billing and support.
It does not cover third-party platforms we integrate with on your behalf — WhatsApp and Meta, Google and RCS carrier infrastructure, your payment gateway, your CRM. Those are governed by their own privacy terms, and by the agreement between you and them.
3. What we collect
3.1 Information you give us
- Contact and enquiry data — your name, business name, phone number, email address, and whatever you choose to tell us about your requirement when you message us on WhatsApp, email us, call us or talk to the on-site assistant.
- Client and engagement data — the business, technical and brand information needed to deliver the service: account credentials or delegated access you grant us, brand assets, campaign copy, website content and product catalogues.
- Billing data — billing name and address, GSTIN, PAN where legally required, purchase orders and payment references. We do not store full card numbers or UPI credentials; payments are handled by regulated payment providers.
- Messaging opt-in records — if you opt in to receive WhatsApp, RCS or SMS messages from us, the opt-in message you send us, your mobile number, the channels you selected and the date and time of that message. Each channel is consented separately: WhatsApp under Meta's Business Messaging Policy, and RCS and SMS under the TRAI Telecom Commercial Communications Customer Preference Regulations and the DLT framework. The form on our messaging opt-in page does not submit anything to our servers; it opens WhatsApp with the message ready for you to send, and your sent message is the consent record. See that page for what we send, how often, and how to stop each channel.
- Recruitment data, if you apply to work with us — CV, contact details and the contents of your application.
3.2 Information collected automatically
- Technical and log data — IP address, browser and device type, operating system, referring page, pages viewed and timestamps. This is generated by our hosting infrastructure as an ordinary part of serving the site securely.
- On-device storage — the assistant widget stores your conversation locally in your browser so it survives page navigation and reloads. It stays on your device. See our Cookie Policy for the full inventory.
3.3 Information we process on behalf of clients
When we run messaging, chatbot or automation systems for a client, end-customer data — phone numbers, message content, order and delivery details, opt-in records — passes through those systems. We process it as a Processor, under the client's instructions and the agreement signed with them. The client is the Data Fiduciary for that data and is responsible for having a valid legal basis, including opt-in consent, before any message is sent.
4. Why we use it, and on what basis
Under the DPDP Act we process personal data either with your consent or for a legitimate use permitted by Section 7 — chiefly, where you have voluntarily provided data for a purpose and have not indicated you object.
| What we do | Data used | Basis |
|---|---|---|
| Reply to your enquiry, send a proposal, arrange a call | Contact and enquiry data | Consent / voluntary provision (s.7(a)) |
| Deliver the service you engaged us for | Client and engagement data | Performance of our contract with you |
| Raise invoices, collect payment, meet tax and company-law obligations | Billing data | Legal obligation |
| Keep the site available, secure and free of abuse | Technical and log data | Legitimate use — security and fraud prevention |
| Improve our services and the website | Aggregated, de-identified usage data | Legitimate use |
| Send service updates, offers or newsletters | Contact data | Consent — withdrawable at any time |
We do not sell personal data. We do not use your data, or your customers' data, to train third-party AI models.
6. Storage and cross-border transfer
Our primary systems are hosted in India. Some of the platforms we rely on — Meta, Google, cloud and email providers — process data outside India as part of their global infrastructure. Where personal data is transferred outside India, we do so in accordance with Section 16 of the DPDP Act and any restrictions the Central Government notifies, and under contractual safeguards with the recipient.
7. How long we keep it
We keep personal data only as long as the purpose it was collected for requires, and then delete or de-identify it.
| Category | Retention |
|---|---|
| Enquiries that do not become engagements | Up to 24 months from the last contact |
| Messaging opt-in and opt-out records (WhatsApp, RCS, SMS) | While you remain opted in, plus 3 years — so we can evidence consent |
| Client records and correspondence | The term of the engagement plus 3 years |
| Invoices, tax and statutory records | 8 years, as required by the Companies Act, 2013 and the Income-tax Act, 1961 |
| Server and security logs | Up to 180 days |
| Data processed on behalf of a client | As instructed by that client; deleted or returned on termination |
| Recruitment data for unsuccessful applicants | 12 months, unless you ask us to keep it longer |
Where a legal claim, investigation or statutory obligation requires it, we may retain data for longer — but only for that purpose.
8. How we protect it
We implement reasonable security safeguards as required by Section 8(5) of the DPDP Act and Rule 8 of the SPDI Rules, 2011, including:
- encryption in transit (TLS) across our website and client systems, and encryption at rest for data stores that support it;
- role-based access control, least-privilege access and multi-factor authentication on administrative accounts;
- network and application logging, monitoring and periodic review;
- vendor due diligence and written data-protection terms with sub-processors;
- confidentiality obligations binding on every employee and contractor;
- a documented process for receiving and acting on external vulnerability reports — see our Responsible Disclosure Policy.
No system is perfectly secure. If a personal data breach occurs, we will notify each affected Data Principal without delay and report the breach to the Data Protection Board of India within the timelines prescribed under the DPDP Rules, 2025, alongside any CERT-In reporting obligation that applies.
9. Your rights
As a Data Principal under the DPDP Act, you have the right to:
- Access — obtain a summary of the personal data we process about you, the processing activities, and the identities of others it has been shared with.
- Correction and completion — have inaccurate or misleading data corrected, incomplete data completed and out-of-date data updated.
- Erasure — have your personal data deleted, unless retention is required for a legal purpose.
- Withdraw consent — as easily as you gave it. Withdrawal does not affect processing already carried out lawfully.
- Nominate — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
- Grievance redressal — a readily available means of raising a complaint with us, before escalating to the Board.
To exercise any of these, write to hello@nucleusaiautomation.com from the email address or phone number on record. We may ask for information to verify your identity. We respond within 30 days.
If we process your data as a Processor on behalf of a client, we will forward your request to that client — they are the Data Fiduciary and control the decision.
Note that the DPDP Act also places duties on Data Principals: do not impersonate someone else, suppress material information, or file false or frivolous complaints.
10. Children
Our services are directed at businesses, not children. We do not knowingly collect the personal data of anyone under 18 without verifiable consent from a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided us data, write to hello@nucleusaiautomation.com and we will delete it.
11. Grievance redressal
For any question or complaint about this policy or how we handle your data, contact our Grievance Officer, designated under Rule 5(9) of the SPDI Rules, 2011 and Rule 3(2) of the IT (Intermediary Guidelines) Rules, 2021:
The Grievance Officer, Nucleus Ai Automation Private Limited
Unit-603 604, Floor 6th, Tower B, Bhutani Alphathum, Sector 90, NEPZ Post Office, Noida, Gautam Buddha Nagar- 201305, Uttar Pradesh
Email — hello@nucleusaiautomation.com
We acknowledge complaints within 24 hours and resolve them within 15 days of receipt.
If you are not satisfied with our response, you may complain to the Data Protection Board of India under the DPDP Act, or to the appropriate authority under the Consumer Protection Act, 2019.
12. Changes to this policy
We update this policy when our practices or the law change. The revision date at the top always reflects the current version. Material changes will be notified on this page, and by email or WhatsApp where we hold your contact details and the change affects you. Continuing to use the site or our services after a change takes effect means you accept the updated policy.
This page is provided for transparency and does not constitute legal advice. Where a signed agreement between us says something different, that agreement governs.
Connect. Automate. Grow.
Every day without it is a conversation your competitor is having instead. Talk to us on the channel we sell — reply time: instant.
Start the conversation →Get updates on your channel
Service notices, project updates and the occasional offer — on the channels you pick, and only if you ask. Reply STOP to stop any of them. Full opt-in terms →