Skip to main content
Legal

Privacy Policy

This policy explains what personal data Nucleus Ai collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. We have written it to be read, not survived.

Nucleus Ai Automation Private LimitedCIN U63111UW2026PTC255078Last updated — 26 July 2026

1. Who we are

Nucleus Ai Automation Private Limited ("Nucleus Ai", "we", "us", "our") is a company incorporated in India and operating from Noida, Uttar Pradesh. We provide WhatsApp Business API, RCS business messaging, chatbot automation, SEO, website development and SaaS product development services.

Nucleus Ai Automation Private Limited (trading as Nucleus Ai)

Unit-603 604, Floor 6th, Tower B, Bhutani Alphathum, Sector 90, NEPZ Post Office, Noida, Gautam Buddha Nagar- 201305, Uttar Pradesh

CIN — U63111UW2026PTC255078

Email — hello@nucleusaiautomation.com · Phone — 8139 933 933

For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we act as a Data Fiduciary for personal data we collect in our own right — website visitors, enquiries, clients and their staff. Where we operate messaging, chatbot or analytics systems on behalf of a client, we act as a Data Processor for the end-customer data flowing through those systems, and we process it only on that client's documented instructions.

2. Scope

This policy covers:

  • this website and any subdomain we operate;
  • the on-site assistant ("Nucleus" chat widget);
  • enquiries you send us by WhatsApp, email, telephone or a form;
  • the commercial relationship if you become a client, including onboarding, billing and support.

It does not cover third-party platforms we integrate with on your behalf — WhatsApp and Meta, Google and RCS carrier infrastructure, your payment gateway, your CRM. Those are governed by their own privacy terms, and by the agreement between you and them.

3. What we collect

3.1 Information you give us

  • Contact and enquiry data — your name, business name, phone number, email address, and whatever you choose to tell us about your requirement when you message us on WhatsApp, email us, call us or talk to the on-site assistant.
  • Client and engagement data — the business, technical and brand information needed to deliver the service: account credentials or delegated access you grant us, brand assets, campaign copy, website content and product catalogues.
  • Billing data — billing name and address, GSTIN, PAN where legally required, purchase orders and payment references. We do not store full card numbers or UPI credentials; payments are handled by regulated payment providers.
  • Messaging opt-in records — if you opt in to receive WhatsApp, RCS or SMS messages from us, the opt-in message you send us, your mobile number, the channels you selected and the date and time of that message. Each channel is consented separately: WhatsApp under Meta's Business Messaging Policy, and RCS and SMS under the TRAI Telecom Commercial Communications Customer Preference Regulations and the DLT framework. The form on our messaging opt-in page does not submit anything to our servers; it opens WhatsApp with the message ready for you to send, and your sent message is the consent record. See that page for what we send, how often, and how to stop each channel.
  • Recruitment data, if you apply to work with us — CV, contact details and the contents of your application.

3.2 Information collected automatically

  • Technical and log data — IP address, browser and device type, operating system, referring page, pages viewed and timestamps. This is generated by our hosting infrastructure as an ordinary part of serving the site securely.
  • On-device storage — the assistant widget stores your conversation locally in your browser so it survives page navigation and reloads. It stays on your device. See our Cookie Policy for the full inventory.

3.3 Information we process on behalf of clients

When we run messaging, chatbot or automation systems for a client, end-customer data — phone numbers, message content, order and delivery details, opt-in records — passes through those systems. We process it as a Processor, under the client's instructions and the agreement signed with them. The client is the Data Fiduciary for that data and is responsible for having a valid legal basis, including opt-in consent, before any message is sent.

We do not knowingly collect sensitive personal data such as health, biometric, financial-account or caste/religion data through this website, and we ask you not to send it to us over chat or email. We do not access your camera or microphone.

4. Why we use it, and on what basis

Under the DPDP Act we process personal data either with your consent or for a legitimate use permitted by Section 7 — chiefly, where you have voluntarily provided data for a purpose and have not indicated you object.

What we doData usedBasis
Reply to your enquiry, send a proposal, arrange a callContact and enquiry dataConsent / voluntary provision (s.7(a))
Deliver the service you engaged us forClient and engagement dataPerformance of our contract with you
Raise invoices, collect payment, meet tax and company-law obligationsBilling dataLegal obligation
Keep the site available, secure and free of abuseTechnical and log dataLegitimate use — security and fraud prevention
Improve our services and the websiteAggregated, de-identified usage dataLegitimate use
Send service updates, offers or newslettersContact dataConsent — withdrawable at any time

We do not sell personal data. We do not use your data, or your customers' data, to train third-party AI models.

5. Who we share it with

We share personal data only where it is needed to run the service, and only with recipients bound by confidentiality and data-protection obligations:

  • Communication platforms — Meta Platforms (WhatsApp Business Platform), Google and RCS aggregators, SMS and DLT-registered telecom providers, where the service you have engaged requires it.
  • Cloud, hosting and infrastructure providers who store and serve our systems.
  • Google Analytics, but only if you have accepted analytics cookies on this website. If you decline, no data reaches Google at all. See our Cookie Policy.
  • Payment and accounting providers, and our auditors and tax advisers.
  • Professional advisers — lawyers, insurers — where necessary and under a duty of confidentiality.
  • Government, law-enforcement and regulatory authorities, where we are legally compelled to disclose, or where disclosure is necessary to protect our rights, safety or property.
  • An acquirer, if the business or its assets are merged, acquired or restructured. You will be told before your data becomes subject to a different privacy policy.

We engage sub-processors under written terms that impose obligations no weaker than those in this policy. A current list is available on request from hello@nucleusaiautomation.com.

6. Storage and cross-border transfer

Our primary systems are hosted in India. Some of the platforms we rely on — Meta, Google, cloud and email providers — process data outside India as part of their global infrastructure. Where personal data is transferred outside India, we do so in accordance with Section 16 of the DPDP Act and any restrictions the Central Government notifies, and under contractual safeguards with the recipient.

7. How long we keep it

We keep personal data only as long as the purpose it was collected for requires, and then delete or de-identify it.

CategoryRetention
Enquiries that do not become engagementsUp to 24 months from the last contact
Messaging opt-in and opt-out records (WhatsApp, RCS, SMS)While you remain opted in, plus 3 years — so we can evidence consent
Client records and correspondenceThe term of the engagement plus 3 years
Invoices, tax and statutory records8 years, as required by the Companies Act, 2013 and the Income-tax Act, 1961
Server and security logsUp to 180 days
Data processed on behalf of a clientAs instructed by that client; deleted or returned on termination
Recruitment data for unsuccessful applicants12 months, unless you ask us to keep it longer

Where a legal claim, investigation or statutory obligation requires it, we may retain data for longer — but only for that purpose.

8. How we protect it

We implement reasonable security safeguards as required by Section 8(5) of the DPDP Act and Rule 8 of the SPDI Rules, 2011, including:

  • encryption in transit (TLS) across our website and client systems, and encryption at rest for data stores that support it;
  • role-based access control, least-privilege access and multi-factor authentication on administrative accounts;
  • network and application logging, monitoring and periodic review;
  • vendor due diligence and written data-protection terms with sub-processors;
  • confidentiality obligations binding on every employee and contractor;
  • a documented process for receiving and acting on external vulnerability reports — see our Responsible Disclosure Policy.

No system is perfectly secure. If a personal data breach occurs, we will notify each affected Data Principal without delay and report the breach to the Data Protection Board of India within the timelines prescribed under the DPDP Rules, 2025, alongside any CERT-In reporting obligation that applies.

9. Your rights

As a Data Principal under the DPDP Act, you have the right to:

  • Access — obtain a summary of the personal data we process about you, the processing activities, and the identities of others it has been shared with.
  • Correction and completion — have inaccurate or misleading data corrected, incomplete data completed and out-of-date data updated.
  • Erasure — have your personal data deleted, unless retention is required for a legal purpose.
  • Withdraw consent — as easily as you gave it. Withdrawal does not affect processing already carried out lawfully.
  • Nominate — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
  • Grievance redressal — a readily available means of raising a complaint with us, before escalating to the Board.

To exercise any of these, write to hello@nucleusaiautomation.com from the email address or phone number on record. We may ask for information to verify your identity. We respond within 30 days.

If we process your data as a Processor on behalf of a client, we will forward your request to that client — they are the Data Fiduciary and control the decision.

Note that the DPDP Act also places duties on Data Principals: do not impersonate someone else, suppress material information, or file false or frivolous complaints.

10. Children

Our services are directed at businesses, not children. We do not knowingly collect the personal data of anyone under 18 without verifiable consent from a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided us data, write to hello@nucleusaiautomation.com and we will delete it.

11. Grievance redressal

For any question or complaint about this policy or how we handle your data, contact our Grievance Officer, designated under Rule 5(9) of the SPDI Rules, 2011 and Rule 3(2) of the IT (Intermediary Guidelines) Rules, 2021:

The Grievance Officer, Nucleus Ai Automation Private Limited

Unit-603 604, Floor 6th, Tower B, Bhutani Alphathum, Sector 90, NEPZ Post Office, Noida, Gautam Buddha Nagar- 201305, Uttar Pradesh

Email — hello@nucleusaiautomation.com

We acknowledge complaints within 24 hours and resolve them within 15 days of receipt.

If you are not satisfied with our response, you may complain to the Data Protection Board of India under the DPDP Act, or to the appropriate authority under the Consumer Protection Act, 2019.

12. Changes to this policy

We update this policy when our practices or the law change. The revision date at the top always reflects the current version. Material changes will be notified on this page, and by email or WhatsApp where we hold your contact details and the change affects you. Continuing to use the site or our services after a change takes effect means you accept the updated policy.

This page is provided for transparency and does not constitute legal advice. Where a signed agreement between us says something different, that agreement governs.

Connect. Automate. Grow.

Every day without it is a conversation your competitor is having instead. Talk to us on the channel we sell — reply time: instant.

Start the conversation →
Messaging opt-in

Get updates on your channel

Service notices, project updates and the occasional offer — on the channels you pick, and only if you ask. Reply STOP to stop any of them. Full opt-in terms →

Send me messages on *

Opens WhatsApp with your opt-in message ready to send — that is how we record it, whichever channels you picked. Free; carrier data charges apply. v2.0