Legal
Privacy Policy
Last updated: August 2026
1. Introduction
Axilrate ("Axilrate," "we," "us," or "our") is committed to protecting personal data and ensuring transparency in how such data is collected, used, and processed.
This Privacy Policy describes how we process personal data in connection with our marketing automation platform ("Platform") and is designed to comply with applicable data protection laws, including the Digital Personal Data Protection Act, 2023 ("DPDP"), and, where applicable to a given Customer or End User, the General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA"). See Section 8 for how these frameworks apply to you specifically.
2. Scope and Roles
This Privacy Policy applies to:
- Customers using the Platform
- Personal data processed on behalf of Customers
- Visitors to our website
For the purposes of applicable data protection laws:
- Customers act as Data Controllers (Data Fiduciaries under DPDP)
- Axilrate acts as a Data Processor
Axilrate does not determine the purposes or means of processing End User data.
3. Categories of Personal Data We Process
3.1 Customer Account Data
Name, email, contact details; organization and billing information.
3.2 End User Data (Customer-Controlled)
Customers may upload and process phone numbers and identifiers, message content and communication history, and campaign and targeting data. Axilrate processes this data solely on Customer instructions.
3.3 Device, Network, and Technical Data
Device type, operating system, and screen resolution; mobile network and carrier information; IP address and approximate location (such as city-level location); browser type and device configuration.
3.4 Usage and Behavioral Data
Time and frequency of access; interaction events (message opens, clicks, and responses); activity on Customer-integrated platforms; session logs and engagement patterns.
3.5 Payment and Transaction Data
Payment method type (e.g., card, UPI, wallet); transaction status and metadata. Full payment credentials are handled by third-party providers and are not stored or accessed by Axilrate.
3.6 Log and Audit Data
API activity and request/response data; user actions within the Platform; access timestamps and system events.
4. Purpose of Processing
Axilrate processes personal data solely to provide the Platform and related services as instructed by Customers, and not for independent purposes except for security, compliance, and operational integrity. This includes providing and operating the Platform, delivering communications via third-party messaging and communication services, monitoring usage and detecting abuse, providing analytics and reporting, and complying with legal and regulatory obligations.
4A. How Personal Data Is Used
(a) Communication Delivery. Personal data such as phone numbers and identifiers are used to deliver messages through third-party platforms (including WhatsApp, SMS, and email) as initiated by the Customer, including transactional, support, and marketing communications, sent solely on the Customer's instructions. Customers are required to ensure End Users have opted in and are informed of the purpose of communications, and every communication must include a clear opt-out mechanism. Axilrate does not independently contact End Users and does not control the consent lifecycle.
(b) Message Processing and Routing. Personal data is processed to format, queue, and route messages, and to manage retries, failures, and delivery confirmations.
(c) Analytics and Performance Measurement. Personal data and interaction data may be used to measure delivery, open, and engagement rates, analyze campaign effectiveness, and provide Customers with reporting and insights.
(d) Personalization and Segmentation (Customer-Controlled). The Platform enables Customers to segment End Users and personalize communications based on behavioral, device, and engagement data. Axilrate provides the tools but does not independently profile End Users.
(e) Platform Security and Abuse Prevention. Personal data may be used to detect and prevent spam, fraud, or misuse, monitor suspicious activity, and enforce Platform usage policies.
(f) System Optimization and Reliability. Technical and usage data may be used to improve delivery performance, maintain reliability and uptime, and diagnose technical issues.
(g) Compliance and Legal Obligations. Personal data may be processed to comply with applicable law, respond to lawful requests from authorities, and enforce contractual obligations.
(h) No Independent Use by Axilrate. Axilrate does not sell personal data, does not contact End Users directly, and does not use End User data outside Customer instructions or for its own independent marketing, advertising, or profiling.
4B. AI and Automated Processing
4B.1 The Platform incorporates AI/machine-learning functionality (as described in the Terms & Conditions) to support features such as message drafting and suggestions, personalization, segmentation, and conversational responses.
4B.2 Where personal data is processed through this functionality, it is processed solely to provide the relevant feature to the Customer, using Axilrate's own systems and/or infrastructure operated by third-party AI providers acting as subprocessors under Section 7.
4B.3 Axilrate does not use Customer or End User personal data to train AI models shared with, or made available to, other customers, without the Customer's separate written consent.
4B.4 Customers remain solely responsible for reviewing AI-generated output before it is sent to any End User, and for ensuring such output complies with applicable law and this Policy.
4C. Data Minimization and Purpose Limitation
Axilrate processes only such personal data as is necessary to provide the Platform and associated services. Personal data is not used for purposes incompatible with those described in this Policy and is not retained longer than required, except where required for legal, security, or audit purposes.
5. Lawful Use by Customers
Customers represent, warrant, and undertake that they have obtained valid, informed, and legally compliant consent from End Users prior to collecting or processing personal data; that they have provided appropriate notices regarding data collection, tracking, and analytics; and that their use of the Platform complies with applicable law, including DPDP, telecom regulations, and third-party platform policies (including WhatsApp/Meta policies).
Customers further agree that they shall not use unlawfully obtained data (including scraped or purchased datasets); that they are solely responsible for determining the purposes and means of processing; and that they shall handle End User rights requests, including access, correction, and deletion, as further described in our Data Deletion Instructions & User Data Handling Policy.
Axilrate shall not be responsible for the Customer's compliance with applicable laws.
6. Advanced Analytics and Profiling
The Platform enables Customers to analyze and segment End Users based on behavioral and technical data. Axilrate does not independently perform profiling for its own purposes. Customers are responsible for ensuring lawful use of such capabilities.
7. Data Sharing and Subprocessors
We share data with the following categories of subprocessors, each contractually required to protect personal data:
| Category | Example Provider(s) | Purpose |
|---|---|---|
| Cloud infrastructure | Oracle Cloud Infrastructure (OCI) | Hosting, storage, compute |
| Messaging delivery | Meta / WhatsApp Business Platform, SMS and email gateway providers | Message transmission |
| Payment processing | Razorpay | Billing and subscription payments |
| AI/ML functionality | OpenAI, Anthropic | Content generation, automation features (see Section 4B) |
| Resend | Email sending | |
| Push Notifications | Google, Apple | For sending push notifications |
| CDN | Cloudflare | Content Delivery |
We do not sell personal data.
Where a Customer is subject to GDPR or an equivalent framework, we will provide reasonable advance notice before adding or replacing a subprocessor materially involved in processing that Customer's personal data, and the Customer may raise concerns on reasonable data-protection grounds, in accordance with the data processing terms set out in Section 23 of our Terms & Conditions.
8. Cross-Border Transfers and Applicable Frameworks
8.1 Personal data may be processed outside India, including by subprocessors listed in Section 7, subject to appropriate contractual and technical safeguards.
8.2 Where a Customer or its End Users are located in the European Economic Area or United Kingdom, transfers of personal data outside those regions are made subject to Standard Contractual Clauses or another lawful transfer mechanism recognized under GDPR.
8.3 Where a Customer or End User is a California resident, Axilrate processes personal data as a "service provider" under CCPA/CPRA, and does not sell or share personal data as those terms are defined under that law.
> **Callout:** Sections 8.2–8.3 should only be published as-is if Axilrate genuinely has EU/UK or California-based Customers or End Users today, or anticipates them imminently. If not, consider softening to "may apply, depending on where your business and End Users are located" rather than asserting a specific compliance posture you haven't operationally built out yet.
9. Data Retention
Personal data is retained only for as long as necessary to provide services, comply with legal obligations, and maintain security and audit records. Different categories of data may be retained for different durations depending on operational and legal requirements. Deletion requests are processed in accordance with our separate Data Deletion Instructions & User Data Handling Policy, which sets out standard processing timeframes.
10. Security Measures
We implement appropriate technical and organizational safeguards, including encryption in transit and at rest, role-based access controls, and monitoring, logging, and alerting systems. While we strive to protect data, no system is completely secure.
10A. Transparency to End Users
End Users receiving communications through the Platform should be aware that the communication is sent by or on behalf of a Customer, that Axilrate acts solely as a service provider facilitating delivery, and that requests relating to personal data should be directed to the relevant Customer. Axilrate may assist Customers in responding to such requests where required.
11. Data Subject Rights
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, or port their personal data, withdraw consent, and (under CCPA/CPRA) opt out of the sale or sharing of personal data. Because Customers act as Data Controllers, such requests should be directed to the relevant Customer in the first instance. Where a request is directed to Axilrate in error, we will forward it to the relevant Customer and/or provide reasonable assistance as required by law.
12. Cookies and Tracking
We use cookies and similar technologies for authentication, performance, and analytics on our website, as described in our separate Cookie Policy.
13. Data Breach Notification
We will notify affected Customers of a data breach involving their data without undue delay and in accordance with applicable law, to enable Customers to meet their own notification obligations to End Users and regulators.
14. Children's Data
The Platform is not intended for use by, or in relation to, individuals under the age of 18 ("Minors"), except that where the law of a jurisdiction in which an End User is located sets the age of legal majority above 18 years, that higher age applies as the threshold for that jurisdiction in place of 18. We do not knowingly collect or process personal data relating to Minors, and Customers are prohibited from using the Platform to target or collect data from Minors, as further described in our Acceptable Use Policy. If we become aware that we have inadvertently processed personal data relating to a Minor, we will take reasonable steps to delete that data promptly.
15. Grievance Officer
In accordance with the Digital Personal Data Protection Act, 2023, we have designated a Grievance Officer to address privacy-related concerns:
- Grievance Officer
- Akarai Technologies LLP
- Email: [email protected]
16. Updates
This Policy may be updated periodically. The "Last updated" date at the top of this page will reflect any changes. Material changes will be notified to Customers through the Platform or by email where reasonably practicable.
17. Contact
- For privacy-related queries: [email protected]