Privacy Policy

Last updated: 21 September 2026

Effective: 21 September 2026

1. Who we are

CyberFunnels is a customer-communication and marketing-automation platform operated by Cybersync Technologies Private Limited, a company incorporated in India ("we", "us"). This policy explains what personal data the platform handles, why, and what you can do about it.

CIN: U62099AS2023PTC025199

GSTIN: 18AALCC3095R1ZS

Registered office: Block Road, Ramkrishna Nagar, Karimganj, Assam 788166, India

2. Two different groups of people — and our role for each

This distinction decides who controls your data and who you should contact, so it comes before everything else.

  • Our customers — businesses that hold an account, and their staff. For their account data we are the data controller.
  • People who contact our customers — anyone who sends a WhatsApp, Instagram, Messenger or SMS message to a business using CyberFunnels, submits one of their forms, comments on their posts, or speaks to their AI voice agent. For this data the business you contacted is the controller and we are a data processor acting on its instructions.

If you messaged a business and want your data corrected or erased, that business decides. We will help you reach them, and we act on their instruction — see Data Deletion Instructions.

3. Data we receive from Meta platforms

When a business connects its WhatsApp Business account, Facebook Page or Instagram professional account, it authorises us — through Meta's official login and permissions screen — to receive and send messages on its behalf. We then receive from Meta ("Platform Data"):

  • The content of messages sent to or from the connected account, including attachments
  • The sender's platform-scoped ID, username or display name, and profile picture where Meta provides it
  • Conversation and thread identifiers, timestamps, delivery and read events, and message reactions
  • Comments and replies on the connected Page or Instagram account's posts, where comment automation is enabled
  • Facebook lead-form submissions, where lead ads are connected
  • The connected account's own identifiers, name and access tokens
  • Aggregate advertising and page performance statistics, where ads reporting is enabled

We use Platform Data only to provide the messaging and automation features to the business that authorised it. Specifically, we do not:

  • Sell, rent or licence Platform Data to anyone
  • Use it for advertising, ad targeting, or to build advertising profiles
  • Use it to train machine-learning models of our own
  • Combine it with data from other businesses, or share it between accounts
  • Transfer it to data brokers, information resellers or analytics services

Our handling of Platform Data is additionally governed by the Meta Platform Terms and Developer Policies. Where this policy and those terms differ in respect of Platform Data, those terms prevail.

4. Other data we handle

4.1 Account data

  • Name, work email address, phone number and password (stored hashed)
  • Organisation name, branch and role assignments
  • Billing details and payment records — card data is handled by our payment providers and never reaches our servers

4.2 Contact and lead records

  • Name, phone number, email address and enquiry details submitted to a customer's form, landing page or connected channel
  • Notes, tags, pipeline stage, assignment and activity history recorded by that business
  • Appointment and site-visit bookings

4.3 Voice calls

Where a business uses the AI voice agent or the dialler, we process call audio, recordings, transcripts and call outcomes. Recording and notice obligations are the calling business's responsibility.

4.4 Website and technical data

  • IP address, browser and device type, pages visited and referring URL
  • Visitor analytics on customer landing pages, where that customer enables it
  • Application logs needed to keep the service running and secure

5. Why we process it

  • To deliver, send and display messages across the connected channels
  • To run the automations, sequences and AI replies a business has configured
  • To maintain each business's contact records, pipeline and calendar
  • To authenticate users, enforce permissions and keep tenants separated
  • To bill for the service and prevent abuse or fraud
  • To provide support, diagnose faults and keep the platform secure
  • To meet legal, tax and regulatory obligations

6. Who we share it with

We do not sell personal data. We share it only with the providers below, each of which receives it solely to perform the function listed, and only when the relevant feature is enabled:

ProviderPurpose
Meta Platforms, Inc.WhatsApp, Instagram and Messenger messaging; Facebook lead forms and ads reporting
Twilio Inc.SMS sending and receiving
Vapi Labs, Inc.AI voice calling and call transcription
Google LLCCalendar scheduling, and Gemini for AI assistant replies and ad copy
Cloudinary Ltd.Image and media hosting
Stripe, Inc.Subscription billing and payments
Razorpay Software Private LimitedSubscription billing and payments in India

The application database is hosted on infrastructure we control. A business may also choose to have its records stored in a database it owns, in which case they are never written to our shared database.

We may also disclose data where required by law or valid legal process, and in a merger or acquisition — in which case this policy continues to apply until you are told otherwise.

7. How long we keep it

  • Message and Platform Data: retained for as long as the business keeps it. Disconnecting a channel stops us receiving anything new and removes the stored access credentials, but it does not by itself erase conversations already received — that history stays until the business deletes the underlying records or asks us to erase it, which we complete within 30 days.
  • Contact and lead records: kept until the business deletes them or closes its account.
  • Account and billing records: kept for as long as the account is open, and afterwards only as long as tax and company law require.
  • Logs: kept for a short operational period, then discarded.

8. Deleting your data

Businesses can delete conversations, contacts, connected channels and entire organisations from within the product. Individuals can ask the business that holds their data, or contact us and we will route the request. Full instructions, including how to remove our app from your Facebook or Instagram account, are on the Data Deletion Instructions page. We respond within 30 days.

9. Security

Data is encrypted in transit using TLS. Access tokens for connected channels are encrypted at rest. Access is restricted by role, and every organisation's data is scoped so that one customer cannot read another's. No system is perfectly secure, and we do not claim otherwise; if a breach affects you we will notify you and the relevant authority as the law requires.

10. Your rights

Subject to the law that applies to you — including India's Digital Personal Data Protection Act and, where relevant, the GDPR — you may:

  • Ask what personal data we hold and get a copy
  • Have inaccurate data corrected or incomplete data completed
  • Have your data erased
  • Object to or restrict processing, and withdraw consent at any time
  • Ask for your data in a portable format
  • Nominate another person to exercise these rights on your behalf
  • Complain to your data protection authority

Where we act as processor for a business, we will forward your request to that business rather than act on it ourselves.

11. International transfers

Some providers listed in section 6 operate outside India. Where data is transferred abroad, we rely on the safeguards offered by those providers, including standard contractual clauses where applicable.

12. Cookies

We use cookies that are strictly necessary to keep you signed in and to keep the application secure. Customer landing pages may set analytics or advertising cookies where that customer has configured them; those choices are the customer's, and their own notice governs them. You can block cookies in your browser, but the application will not work without the necessary ones.

13. Children

CyberFunnels is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child's data has reached us, contact us and we will delete it.

14. Changes to this policy

If we change this policy we will update the date at the top of this page, and tell account holders directly when the change is material.

15. Contact us

For any privacy question, or to exercise a right above, contact our grievance officer:

Cybersync Technologies Private Limited

Email: support@cybersync-technologies.com

Phone: +918472837846

Block Road, Ramkrishna Nagar, Karimganj, Assam 788166, India