Privacy Policy
Last updated: 21 September 2026
Effective: 21 September 2026
1. Who we are
CyberFunnels is a customer-communication and marketing-automation platform operated by Cybersync Technologies Private Limited, a company incorporated in India ("we", "us"). This policy explains what personal data the platform handles, why, and what you can do about it.
CIN: U62099AS2023PTC025199
GSTIN: 18AALCC3095R1ZS
Registered office: Block Road, Ramkrishna Nagar, Karimganj, Assam 788166, India
2. Two different groups of people — and our role for each
This distinction decides who controls your data and who you should contact, so it comes before everything else.
- Our customers — businesses that hold an account, and their staff. For their account data we are the data controller.
- People who contact our customers — anyone who sends a WhatsApp, Instagram, Messenger or SMS message to a business using CyberFunnels, submits one of their forms, comments on their posts, or speaks to their AI voice agent. For this data the business you contacted is the controller and we are a data processor acting on its instructions.
If you messaged a business and want your data corrected or erased, that business decides. We will help you reach them, and we act on their instruction — see Data Deletion Instructions.
3. Data we receive from Meta platforms
When a business connects its WhatsApp Business account, Facebook Page or Instagram professional account, it authorises us — through Meta's official login and permissions screen — to receive and send messages on its behalf. We then receive from Meta ("Platform Data"):
- The content of messages sent to or from the connected account, including attachments
- The sender's platform-scoped ID, username or display name, and profile picture where Meta provides it
- Conversation and thread identifiers, timestamps, delivery and read events, and message reactions
- Comments and replies on the connected Page or Instagram account's posts, where comment automation is enabled
- Facebook lead-form submissions, where lead ads are connected
- The connected account's own identifiers, name and access tokens
- Aggregate advertising and page performance statistics, where ads reporting is enabled
We use Platform Data only to provide the messaging and automation features to the business that authorised it. Specifically, we do not:
- Sell, rent or licence Platform Data to anyone
- Use it for advertising, ad targeting, or to build advertising profiles
- Use it to train machine-learning models of our own
- Combine it with data from other businesses, or share it between accounts
- Transfer it to data brokers, information resellers or analytics services
Our handling of Platform Data is additionally governed by the Meta Platform Terms and Developer Policies. Where this policy and those terms differ in respect of Platform Data, those terms prevail.
4. Other data we handle
4.1 Account data
- Name, work email address, phone number and password (stored hashed)
- Organisation name, branch and role assignments
- Billing details and payment records — card data is handled by our payment providers and never reaches our servers
4.2 Contact and lead records
- Name, phone number, email address and enquiry details submitted to a customer's form, landing page or connected channel
- Notes, tags, pipeline stage, assignment and activity history recorded by that business
- Appointment and site-visit bookings
4.3 Voice calls
Where a business uses the AI voice agent or the dialler, we process call audio, recordings, transcripts and call outcomes. Recording and notice obligations are the calling business's responsibility.
4.4 Website and technical data
- IP address, browser and device type, pages visited and referring URL
- Visitor analytics on customer landing pages, where that customer enables it
- Application logs needed to keep the service running and secure
5. Why we process it
- To deliver, send and display messages across the connected channels
- To run the automations, sequences and AI replies a business has configured
- To maintain each business's contact records, pipeline and calendar
- To authenticate users, enforce permissions and keep tenants separated
- To bill for the service and prevent abuse or fraud
- To provide support, diagnose faults and keep the platform secure
- To meet legal, tax and regulatory obligations
6. Who we share it with
We do not sell personal data. We share it only with the providers below, each of which receives it solely to perform the function listed, and only when the relevant feature is enabled:
| Provider | Purpose |
|---|---|
| Meta Platforms, Inc. | WhatsApp, Instagram and Messenger messaging; Facebook lead forms and ads reporting |
| Twilio Inc. | SMS sending and receiving |
| Vapi Labs, Inc. | AI voice calling and call transcription |
| Google LLC | Calendar scheduling, and Gemini for AI assistant replies and ad copy |
| Cloudinary Ltd. | Image and media hosting |
| Stripe, Inc. | Subscription billing and payments |
| Razorpay Software Private Limited | Subscription billing and payments in India |
The application database is hosted on infrastructure we control. A business may also choose to have its records stored in a database it owns, in which case they are never written to our shared database.
We may also disclose data where required by law or valid legal process, and in a merger or acquisition — in which case this policy continues to apply until you are told otherwise.
7. How long we keep it
- Message and Platform Data: retained for as long as the business keeps it. Disconnecting a channel stops us receiving anything new and removes the stored access credentials, but it does not by itself erase conversations already received — that history stays until the business deletes the underlying records or asks us to erase it, which we complete within 30 days.
- Contact and lead records: kept until the business deletes them or closes its account.
- Account and billing records: kept for as long as the account is open, and afterwards only as long as tax and company law require.
- Logs: kept for a short operational period, then discarded.
8. Deleting your data
Businesses can delete conversations, contacts, connected channels and entire organisations from within the product. Individuals can ask the business that holds their data, or contact us and we will route the request. Full instructions, including how to remove our app from your Facebook or Instagram account, are on the Data Deletion Instructions page. We respond within 30 days.
9. Security
Data is encrypted in transit using TLS. Access tokens for connected channels are encrypted at rest. Access is restricted by role, and every organisation's data is scoped so that one customer cannot read another's. No system is perfectly secure, and we do not claim otherwise; if a breach affects you we will notify you and the relevant authority as the law requires.
10. Your rights
Subject to the law that applies to you — including India's Digital Personal Data Protection Act and, where relevant, the GDPR — you may:
- Ask what personal data we hold and get a copy
- Have inaccurate data corrected or incomplete data completed
- Have your data erased
- Object to or restrict processing, and withdraw consent at any time
- Ask for your data in a portable format
- Nominate another person to exercise these rights on your behalf
- Complain to your data protection authority
Where we act as processor for a business, we will forward your request to that business rather than act on it ourselves.
11. International transfers
Some providers listed in section 6 operate outside India. Where data is transferred abroad, we rely on the safeguards offered by those providers, including standard contractual clauses where applicable.
12. Cookies
We use cookies that are strictly necessary to keep you signed in and to keep the application secure. Customer landing pages may set analytics or advertising cookies where that customer has configured them; those choices are the customer's, and their own notice governs them. You can block cookies in your browser, but the application will not work without the necessary ones.
13. Children
CyberFunnels is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child's data has reached us, contact us and we will delete it.
14. Changes to this policy
If we change this policy we will update the date at the top of this page, and tell account holders directly when the change is material.
15. Contact us
For any privacy question, or to exercise a right above, contact our grievance officer:
Cybersync Technologies Private Limited
Email: support@cybersync-technologies.com
Phone: +918472837846
Block Road, Ramkrishna Nagar, Karimganj, Assam 788166, India