Privacy Policy
TechTo Networks Effective Date: January 1, 2023 Last Updated: August 10, 2026
Privacy Policy
TechTo Networks ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect personal information in connection with our services, including Bulk SMS, WhatsApp Business API, Google RCS, and DLT (Distributed Ledger Technology) registration assistance under TRAI regulations. This policy is framed in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and applicable TRAI/DLT regulations. Under the DPDP Act, TechTo Networks acts as a "Data Fiduciary" and you, as our customer or website visitor, are a "Data Principal." This Privacy Policy should be read together with our Terms and Conditions, Acceptable Use Policy, Refund & Cancellation Policy, and Cookie Policy, which together form the complete agreement between you and TechTo Networks.
1. Information We Collect
We collect the following categories of information to provide our services:
Personal Information. Name, email address, phone number, business/company name, GST details, billing address, and other information you provide when signing up, purchasing services, or contacting support.
Transactional and Usage Data. Message logs, delivery reports, communication preferences, DLT consent records and templates, API usage data, and account activity.
Regulatory and Compliance Data. Information submitted for DLT entity/header/template registration, including PAN, business registration documents, and authorized signatory details, as required by TRAI.
Cookies and Technical Data. IP address, browser type, device information, and cookies used to operate and improve our website and services. Full details on the categories of cookies we use and how to manage them are set out in our separate Cookie Policy.
2. How We Use Your Information
We use the information we collect to provide, operate, and improve our Bulk SMS, WhatsApp Business API, RCS, and DLT registration services; to complete and maintain DLT entity, header, and template registrations with TRAI-approved platforms; to process orders, manage your account, and provide customer support; to ensure regulatory compliance with TRAI, DLT, and other applicable telecom and data protection regulations; to send service-related communications, technical notices, and, with your consent, marketing updates and offers; and to detect, prevent, and investigate fraud, abuse, or violations of our Terms and Conditions or Acceptable Use Policy. We process personal data only for the purpose for which consent was given or as otherwise permitted under the DPDP Act, and we do not use your data for purposes incompatible with those disclosed at the time of collection.
3. Legal Basis and Consent
Where required under the DPDP Act, we process your personal data on the basis of your consent, given through a clear affirmative action, such as signing up for our services, submitting a form, or providing DLT consent for message categories. You may withdraw consent at any time, as described in Section 7, without affecting the lawfulness of processing carried out before withdrawal. Certain processing, such as retaining DLT consent and scrubbing records for TRAI audit purposes or complying with a legal obligation, may continue even after consent withdrawal, as permitted by law.
4. Data Sharing and Disclosure
We do not sell or rent your personal information. We may share your data only in the following circumstances:
Telecom and Platform Partners. With Telecom Service Providers (TSPs), DLT platform operators, and Meta, for WhatsApp Business API and RCS delivery, strictly to enable service delivery and regulatory compliance.
Regulatory Authorities. With TRAI, DLT platforms, or other government or regulatory bodies where required for compliance, audit, or lawful requests.
Service Providers. With third-party vendors providing technical infrastructure, payment processing, analytics, or customer support, under confidentiality and data-processing agreements that restrict their use of your data to the services they provide us.
Legal Requirements. Where disclosure is required to comply with a legal obligation, court order, or to protect our rights, property, or the safety of our users.
We do not transfer personal data outside India except where necessary for service delivery, for example WhatsApp/Meta infrastructure, and any such transfer is made in accordance with the DPDP Act and applicable government notifications on data transfer restrictions.
5. Cookies
We use cookies and similar tracking technologies to operate our website, remember preferences, personalize content, and analyze site traffic. You can control or disable cookies through your browser settings; note that disabling cookies may affect the functionality of parts of our website. See our Cookie Policy for a full breakdown of the cookies we use and your choices.
6. Data Security
We implement reasonable security practices and procedures as required under the IT Rules, 2011, including encryption in transit, access controls, firewalls, and periodic security reviews, to protect your data against unauthorized access, disclosure, alteration, or destruction. In the event of a personal data breach that is likely to affect you, we will notify you and, where required, the Data Protection Board of India, in accordance with the DPDP Act and its rules.
7. Your Rights
Subject to the DPDP Act and applicable law, you have the right to access a summary of the personal data we hold about you and how it is processed; to correct or update inaccurate or incomplete personal data; to request erasure of your personal data, subject to our legal and regulatory retention obligations set out in Section 8; to withdraw consent at any time for processing based on consent, including opting out of marketing communications; to nominate another individual to exercise your rights on your behalf in the event of death or incapacity; and to raise a grievance with our Grievance Officer under Section 11, escalating to the Data Protection Board of India if unresolved. To exercise any of these rights, contact us using the details in Section 11.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy. Active account and service data is retained for as long as your account remains active, plus a reasonable period thereafter for support and dispute resolution. DLT consent, scrubbing, and template records are retained for the duration required under TRAI/DLT regulations, which may exceed the general retention period applicable to other account data. Data required to comply with tax, accounting, or other statutory obligations is retained for the period mandated by the relevant law. Where no specific regulatory retention period applies, we retain personal data for a maximum of 12 months from the date of last activity, after which it is deleted or anonymized, unless a longer period is required by law or necessary to resolve a dispute.
9. Children's Data
Our services are intended for businesses and individuals who are at least 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will take steps to delete it in accordance with the DPDP Act.
10. Third-Party Links
Our website may contain links to third-party websites, including telecom, payment, or platform partners. We are not responsible for the privacy practices or content of those third-party sites. We encourage you to review their privacy policies independently.
11. Grievance Officer and Contact Us
In accordance with the DPDP Act and the Information Technology Act, 2000 and rules made thereunder, we have designated a Grievance Officer to address your questions, concerns, or complaints regarding this Privacy Policy or our data practices.
TechTo Networks Grievance Officer: [Name to be added] Email: techtonetworks@gmail.comPhone: +91 97460 91023 Address: TechTo Networks, Green Park Villas, Peyad PO, Thiruvananthapuram, Kerala, India
We aim to acknowledge grievances within 48 hours and resolve them within 30 days, or such other period as prescribed under applicable law. If you are not satisfied with our resolution, you may escalate your complaint to the Data Protection Board of India.
12. Governing Law and Severability
This Privacy Policy is governed by the laws of India, and any disputes arising from or relating to this policy shall be subject to the exclusive jurisdiction of the courts of Thiruvananthapuram, Kerala, without prejudice to your right to approach the Data Protection Board of India under the DPDP Act. If any provision of this policy is found to be unenforceable or invalid, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall remain in full force and effect.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. Any changes will be posted on this page with an updated "Last Updated" date. We encourage you to review this policy periodically.