Legal

PRIVACY POLICY FOR AGC EVENT OS

Last Updated: August 2, 2026

Agrima Growth Catalyst Pvt Ltd ("Company", "We", "Us", or "Our"), operating the AGC Event OS platform (agceventos.com), respects your privacy and is committed to protecting the personal data of our business Tenants, their authorized personnel, and their End-Users.

This Privacy Policy explains how we collect, use, process, disclose, and secure information when you use AGC Event OS and its integrated communications capabilities, including the WhatsApp Business Platform (Cloud API).

1. Legal Roles Under Data Protection Laws

1.1 Dual Role: Under applicable data protection frameworks, including the Digital Personal Data Protection (DPDP) Act 2023 of India, our role depends on the category of data:

  • Tenant as Data Fiduciary (Controller) — End-User data: The Tenant (event props rental house, planner, or decorator) is the Data Fiduciary in respect of End-User customer data, phone numbers, contact lists, order details, and message content. We act as a Data Processor, processing that data only on the Tenant's documented instructions.
  • Company as Data Fiduciary (Controller) — Tenant data: In respect of Tenant account records, authorized-user credentials, billing and subscription data, authentication events, security logs, and platform usage telemetry, we act as the Data Fiduciary and determine the purposes of processing ourselves.

1.2 End-User Requests: Because the Tenant is the Data Fiduciary for End-User records, an End-User seeking to exercise data rights in relation to notifications sent by a Tenant should direct the request to that Tenant. We will assist the Tenant in responding.

2. Information We Collect

We collect only the information necessary to provide, manage, and secure AGC Event OS.

A. Tenant Account & Administrative Data

  • Business details, business owner/manager name, corporate address, billing details, contact email address, and primary phone numbers.
  • Authorized-user accounts, role assignments, and permission grants.
  • Meta Business Portfolio IDs, WhatsApp Business Account (WABA) IDs, business phone number IDs, and the long-lived Meta System User access token issued to us during WhatsApp onboarding.

B. End-User & Transactional Messaging Data

  • Recipient phone numbers of End-Users (event managers, decorators, rental clients, staff) provided or configured by the Tenant.
  • Transactional metadata, including order status updates, delivery and pickup schedules, rental confirmation references, and per-message delivery status (sent, delivered, read, failed) together with any error reason returned by Meta.
  • Mobile phone numbers submitted for One-Time Password (OTP) login authentication.
  • Generated order and invoice documents (PDF), where the Tenant has enabled notifications that attach them.

C. Data Received Through WhatsApp Coexistence Onboarding

Where a Tenant connects an existing WhatsApp Business app number using Meta's Coexistence onboarding, Meta requires us to initiate a one-time synchronisation within 24 hours of onboarding, failing which the Tenant is disconnected and must repeat the process. As a direct result, Meta transmits the following to our webhook endpoint:

  • Chat history — messages sent to and received from WhatsApp users within the 180 days preceding onboarding, excluding group chats.
  • Contacts— the WhatsApp contacts held in the Tenant's WhatsApp Business app, and subsequent additions, edits, or removals.
  • Message echoes — a copy of each message the Tenant subsequently sends from the WhatsApp Business app or a linked companion device, for as long as the connection remains active.

We do not store, index, analyse, or display any of this data. These transmissions are acknowledged as required by Meta and discarded in the same request; no chat history, message content, or contact record from these sources is written to our databases, logs, or storage. We receive them only because Meta's onboarding process requires the subscription, and we retain only an operational record that a synchronisation was requested.

A Tenant may decline to share chat history when confirming the connection in the WhatsApp Business app. Declining does not prevent the Tenant from using the Platform.

D. Technical & Device Information

  • IP addresses, browser specifications, login timestamps, system activity logs, and device identifiers accessed via agceventos.com.
  • Authentication cookies and session tokens set in your browser to keep you signed in and to maintain workspace context. These are strictly necessary for the Platform to function.

3. How We Use Collected Information

We process personal and operational data exclusively for the following business purposes:

  • Authenticating Tenant and End-User accounts via OTP login dispatch.
  • Processing and transmitting automated order status notifications between Tenants, clients, and internal staff.
  • Establishing and maintaining WhatsApp Business Platform connectivity, provisioning message templates, and monitoring connection and template approval status.
  • Generating catalogue, order, and invoice documents at the Tenant's request.
  • Generating vector representations of inventory imagery and descriptions to power in-platform search.
  • Preventing security breaches, detecting system abuse, and enforcing platform compliance.
  • Responding to customer support requests and billing inquiries.

4. Third-Party Data Sharing, Sub-Processors, and International Transfers

4.1 Meta Cloud API Processing:When an automated order notification or OTP is triggered via AGC Event OS, payload parameters — including recipient phone numbers, message template parameters, and status indicators — are transmitted through Meta's Cloud API infrastructure. Meta processes this information pursuant to the Meta Business Data Processing Terms and WhatsApp Business Terms.

4.2 Current Sub-Processors: We engage sub-processors to deliver infrastructure, database, email, and search capabilities. Current sub-processors include:

Sub-processorPurposeData categories
Meta Platforms, Inc.WhatsApp message delivery and account managementRecipient phone numbers, message parameters, WABA identifiers, delivery status
SupabaseApplication database, authentication, and file storageAll Tenant and End-User data stored by the Platform
ResendTransactional email delivery (OTP and alerts)Email addresses, message content
Voyage AIGenerating embeddings for inventory searchInventory item images and descriptions
CloudflareDNS, TLS termination, and content deliveryIP addresses, request metadata
HostingerApplication server hostingAll data processed by the application at runtime

4.3 Engagement of Additional Sub-Processors: We reserve the right to engage additional or replacement sub-processors to support Platform functionality, provided such third parties comply with acceptable industry security standards and applicable laws of India.

4.4 International Transfers: Where personal data is processed or stored outside India by approved sub-processors, such cross-border transfers are conducted in accordance with Section 16 of the Digital Personal Data Protection (DPDP) Act 2023, supported by technical safeguards and standard contractual data processing terms.

4.5 No Commercial Data Sale: We do not sell, rent, monetize, or share Tenant or End-User personal data with third-party advertisers, data brokers, or marketing networks.

5. Data Storage, Retention, and Security

5.1 Database Storage Scope: We store message delivery logs (recipient phone number, event type, delivery status, Meta message ID, category, error reasons), WhatsApp connection metadata, and workspace configuration records. We do not store the body text of messages sent to End-Users.

5.2 Generated Documents and Public Media: Order summaries, invoices, and report documents attached to WhatsApp notifications are generated as files and uploaded to a publicly accessible storage bucket. This is a technical requirement of the Meta Cloud API, which retrieves media from a publicly reachable URL in order to deliver it. Such files are stored under unguessable paths, are not indexed or listed, and are automatically deleted 90 days after creation.

5.3 Data Retention Schedule:

Data CategoryOperational Retention PeriodAction Upon Expiry
Generated Media (Invoices/PDFs)90 daysAutomatically deleted via storage lifecycle rules
WhatsApp Message LogsUp to 180 daysAutomatically purged or anonymized
WhatsApp Connection CredentialsDuration of active connectionRemoved immediately upon tenant disconnection
Tenant Account & Billing RecordsActive subscription + required statutory tax retentionRetained for company accounting compliance
Coexistence Webhook Sync Data0 days (In-memory transient)Discarded immediately after HTTP response

5.4 Security Safeguards: We maintain technical and organizational controls including:

  • Enforced HTTPS/TLS encryption across all web endpoints, and encryption in transit for sub-processor communications.
  • Row-Level Security in the application database, isolating each Tenant's workspace records.
  • Restricted access controls on server-side credentials and API access tokens.
  • Cryptographic verification of inbound Meta webhooks (HMAC-SHA256 signature validation).
  • Automated rate-limiting to prevent unauthorized message flooding.

6. Rights Under the Digital Personal Data Protection (DPDP) Act 2023

In accordance with the DPDP Act 2023 of India, Data Principals possess the following rights:

  • Right to Access & Summary — to request a summary of personal data processed and processing activities.
  • Right to Correction & Erasure — to request correction of inaccurate data or erasure of data no longer required for its original purpose.
  • Right to Nominate — to nominate another individual to exercise data rights in the event of death or incapacity.
  • Right to Grievance Redressal — to seek resolution of data processing concerns through our Grievance Officer before approaching the Data Protection Board of India.

Note: Because Tenants are Data Fiduciaries for End-User records, End-Users seeking to exercise rights regarding notifications sent by a Tenant should direct their requests to that Tenant.

7. Personal Data Breach Management & Notification

In the event of a confirmed personal data breach affecting systems managed by Company:

  • Notification to Tenant: Where the breach impacts End-User data for which Tenant is the Data Fiduciary, Company shall notify Tenant without undue delay (and in no event later than 24 hours after confirmation).
  • Statutory Reporting: Company shall report qualifying cybersecurity incidents to CERT-In within statutory timelines and to the Data Protection Board of India in accordance with the DPDP Act 2023 and rules framed thereunder.

8. Children's Personal Data

AGC Event OS is exclusively a B2B business application. We do not knowingly collect, process, or track personal data of individuals under eighteen (18) years of age ("Children"). Tenants are strictly prohibited from submitting or processing Children's personal data using the Platform.

9. Updates to This Privacy Policy

We may update this Privacy Policy to reflect technical enhancements, changes in Meta API requirements, or updates to Indian privacy legislation. Updated versions will be published at agceventos.com/privacy with a revised "Last Updated" date. Material changes will be notified to Tenants through the Platform or by email.

10. Grievance Redressal & Contact Information

In accordance with the IT Act 2000, IT Rules 2021, and DPDP Act 2023, questions, privacy requests, or grievances should be directed to our Privacy Lead:

Entity Name: Agrima Growth Catalyst Pvt Ltd

Designation: Grievance Officer & Privacy Lead

App Platform: AGC Event OS (agceventos.com)

Company Website: agrimagc.com

Registered Address: Ernakulam, Kerala, India

Privacy Email: [email protected]

Grievance Email: [email protected]

Support Email: [email protected]

Acknowledgement Timeline: Within 24 hours of receipt.

Response / Resolution Timeline: Within 7 to 15 business days.