Privacy Policy
How Drista Cloud Solutions collects, protects, processes, and respects your personal and business data.
Last Updated: September 22, 2026
Public Document Guarantee • Publicly Accessible Without Login
This Privacy Policy is hosted at https://drista.in/privacy and is completely publicly accessible. Any visitor, prospective client, registered business, end-customer, or platform reviewer (including Meta / WhatsApp App Review teams) can view this policy in its entirety at any time without creating an account, entering credentials, or logging into any portal.
Key Policy Sections
1. Introduction & Scope
Drista Cloud Solutions ("Drista", "we", "us", or "our") provides specialized software applications, cloud management platforms (including Drista ERP, Sports Management, Housing Society Management, Field Sales, and Lead Management), and cloud integration tools accessible via https://drista.in.
This Privacy Policy describes our practices regarding the collection, processing, storage, transmission, and deletion of personal and business data. It applies to all users of our public website, subscribers of our cloud software modules, their authorized team members, and individuals whose communications or contact information are processed through our integrations, including the Meta Platforms / WhatsApp Business API.
2. Customer & Business Information Handling
We process two primary categories of information when businesses utilize the Drista platform:
- Business Entity Information: When an enterprise or business registers on Drista, we collect corporate identifying information such as business legal name, trade name, Goods and Services Tax Identification Number (GSTIN) or equivalent tax ID, registered office address, primary business phone number, official email addresses, billing coordinates, and administrator contact credentials.
- Customer & End-User Records Managed by Businesses: Businesses utilize Drista software to manage operational records. Depending on the product module, this may include client directories, lead profiles, player/student enrollments in sports academies, apartment resident rosters in housing society management, employee lists, and customer invoicing ledgers.
Multi-Tenant Data Segregation: All business client data and customer records are logically partitioned using multi-tenant architecture with strict database-level security policies. An organization’s data is solely accessible to that organization's authorized users and cannot be viewed, accessed, or shared with other businesses on the platform.
3. WhatsApp Business API & Meta Platform Data Disclosures
Specific disclosure regarding Meta Graph API and WhatsApp Business Solution integrations
Drista integrates with the official Meta Cloud API / WhatsApp Business API to enable verified businesses to send transactional alerts, invoices, attendance notifications, booking confirmations, and customer support communications. The following sub-sections explicitly detail how WhatsApp data assets are handled.
3.1 WhatsApp Business Account (WABA) Information
When a business connects its WhatsApp Business Account with Drista Cloud Solutions, we collect and process the following account-level identifiers:
- WhatsApp Business Account ID (WABA ID): Unique numerical identifier assigned by Meta to the business account.
- Phone Number ID: Meta-assigned unique ID for the specific registered phone number connected to the API.
- Business Profile Metadata: Business display name, verified category, official email address, website URL, description/about text, and profile picture avatar URL as configured in Meta Business Manager.
- Account Status & Quality Rating: Account verification status, messaging tier limits, and phone number quality scores supplied by Meta via webhooks.
Purpose of Use: This information is strictly utilized to authenticate the business with Meta's servers, manage message templates, display status within the customer's Drista dashboard, and ensure compliance with WhatsApp Business messaging policies.
4. Phone Numbers & Protection
Phone numbers are critical identifiers in WhatsApp communications. We handle two types of telephone numbers:
- Registered Business Phone Numbers: The telephone number registered with Meta by the business to send outgoing communications.
- Recipient / Customer Phone Numbers: Phone numbers of individuals (end-customers, leads, students, society residents, or invoice recipients) who have provided their contact number to the business to receive service updates, transactional documents, and customer service.
Phone numbers are stored in encrypted databases, transmitted solely over TLS-encrypted connections, and processed exclusively to deliver messages explicitly directed by the authorized business or initiated by the end-user.
5. Messages & Message Metadata
When processing communications through the WhatsApp Business API, Drista handles the following message components:
- Message Contents: Inbound text queries submitted by end-users, outbound transactional template messages (e.g., fee reminders, receipts, automated notifications), interactive button clicks, and media attachments (such as PDF invoices or images sent by either party).
- Message Metadata: Technical parameters associated with transmission, including unique WhatsApp Message IDs (WAMID), sender and recipient phone numbers, transmission timestamps, delivery status receipts ("sent", "delivered", "read", "failed"), error codes (if delivery fails), and conversation category classifications (utility, authentication, service, or marketing).
Processing Purpose: Message content and metadata are processed solely to facilitate the delivery of requested communications, display conversation threads within the client's CRM inbox, trigger business automation workflows, and provide delivery audit reports.
No Advertising or AI Training: Message contents are never analyzed, indexed, or processed for behavioral advertising, profiling, interest-based tracking, or training public artificial intelligence models.
6. API & Access Tokens
Connecting to Meta's Graph API requires authentication credentials, including Meta System User access tokens, permanent or temporary Graph API tokens, App Secrets, and Webhook Verification Tokens.
- Encrypted Storage: All access tokens and secret keys are stored securely using industry-standard AES-256 encryption at rest and isolated within secure key vaults and encrypted server environments.
- Principle of Least Privilege: Drista requests only the exact API permissions required to perform authorized messaging and account synchronization (e.g.,
whatsapp_business_messagingandwhatsapp_business_management). - Zero Public Exposure: API credentials and access tokens are strictly server-side; they are never exposed in client-side code, web bundles, browser local storage, or public source repositories.
- Token Revocation: When a business client disconnects WhatsApp from their Drista workspace or deletes their account, all corresponding access tokens are immediately invalidated and permanently purged from our servers.
7. Data Sharing with Meta Platforms, Inc.
Because the WhatsApp messaging infrastructure is operated by Meta Platforms, Inc. ("Meta"), utilizing our WhatsApp integration involves direct data transmission between Drista servers and Meta's official Graph API endpoints:
- Transmitted Information: When a message is sent or received, the message payload, recipient phone number, template parameters, and media URLs are transmitted to Meta's servers for delivery to the end-user's WhatsApp client.
- Sub-Processor Role: Meta operates as a cloud communications provider and sub-processor for message delivery. All data exchange is governed by Meta's Commercial Terms, the WhatsApp Business Terms of Service, and the WhatsApp Business Data Processing Terms.
- No Unauthorized Disclosures: Outside of necessary API transmission to deliver messages via Meta's infrastructure, Drista does not transfer customer databases, contact lists, or private CRM records to Meta for Meta's independent marketing or third-party advertising.
8. Data Retention & Pruning Policies
We adhere to the principle of data minimization and retain personal and communication data only as long as necessary to fulfill operational, contractual, and legal obligations:
| Data Category | Retention Period | Disposal Action |
|---|---|---|
| WhatsApp Message Delivery Logs & Status Receipts | Up to 90 days for delivery verification and billing reconciliation | Automatically pruned from operational databases |
| Ephemeral Media Attachments & Temporary Caches | Maximum 30 days following transmission | Permanently deleted from temporary cloud storage |
| WhatsApp API Access Tokens & Credentials | Duration of active integration | Purged immediately upon integration disconnection |
| Business Account Records & CRM Contacts | Duration of active subscription + legal statutory periods (taxes/invoices) | Purged upon account closure or verified deletion request |
9. How a Business or Customer Can Request Data Deletion
Step-by-step instructions for businesses and individual end-users to request complete deletion of their data
For Businesses (Account Administrators & Merchants)
Businesses can disconnect their WhatsApp integration or request complete removal of all associated business data through the following options:
- Immediate Self-Service Disconnection: Log into your Drista admin portal, navigate to Settings > Integrations > WhatsApp Business API, and click "Disconnect Integration". This instantly revokes all stored API tokens and halts incoming webhooks.
- Revocation via Meta Business Manager: Open Meta Business Manager > Business Settings > Connected Apps, select Drista Cloud Solutions, and click "Remove Access".
- Formal Data Purge Request: Send an email from your registered business email address to contact@drista.in with the subject line
WhatsApp Business Data Deletion Request. Specify your Business Name, WABA ID, and registered Phone Number ID.
For Individual End-Customers & Message Recipients
If you are an individual recipient (e.g., student, parent, apartment resident, or customer) who received WhatsApp messages sent through Drista by a business:
- Direct Request to the Business: You may contact the business or organization that communicates with you directly and request that they delete your contact card and messaging history from their Drista workspace.
- Direct Deletion Request to Drista: You can contact Drista directly by emailing contact@drista.in with the subject line
Customer Data Deletion Request. Please provide your phone number (including country code) and the name of the business. Upon verification, Drista will purge your contact record and associated message logs from our active databases.
Processing Timeline & Written Confirmation:
- All data deletion requests are acknowledged within 48 hours.
- Data is permanently eradicated from active databases and services within 30 days.
- Residual backup copies are overwritten and purged in accordance with our regular automated backup lifecycle (maximum 90 days).
- A formal written confirmation of completion is issued to the requester via email once the process is complete.
10. Data Security Standards
We implement comprehensive technical, administrative, and physical security safeguards designed to protect personal and business information against unauthorized access, loss, misuse, or alteration:
- Encryption in Transit: All HTTP traffic is protected by Transport Layer Security (TLS 1.2/1.3) with modern cipher suites.
- Encryption at Rest: Database volumes, file attachments, and secret credentials are encrypted at rest using industry-standard AES-256 encryption.
- Access Control: Access to production databases and cloud environments is restricted to authorized personnel under least-privilege principles with mandatory Multi-Factor Authentication (MFA).
- Audit Logging: System access and administrative actions are logged for security auditing and real-time anomaly detection.
11. Your Privacy Rights
Depending on applicable data protection laws, you possess the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal information.
- Right to Erasure ("Right to be Forgotten"): Request the permanent deletion of your data as detailed in Section 9.
- Right to Restriction or Objection: Object to or request the limitation of our processing of your personal data.
- Right to Data Portability: Request an export of your information in a structured, commonly used, machine-readable format.
To exercise any of these statutory rights, please submit your request to contact@drista.in.
12. Changes to this Privacy Policy
We may periodically revise this Privacy Policy to reflect modifications to our platform, evolving regulatory requirements, or changes to third-party integration policies (including Meta Platform policies). When updates are made, we will revise the "Last Updated" date at the top of this page. We encourage you to review this page periodically to stay informed about our data handling practices.
13. Contact Us & Grievance Redressal
For inquiries, feedback, privacy concerns, or data deletion requests, you may contact our Privacy & Data Protection team:
Drista Cloud Solutions
Privacy & Data Protection Officer: contact@drista.in
General Support: contact@drista.in
Official Website: https://drista.in
Public Policy URL: https://drista.in/privacy