1. Who we are
VEPRIO is an India-based business that provides an AI-powered customer operations platform for businesses. Veprio helps businesses manage customer interactions and operational workflows using software, artificial intelligence and communication technologies.
Veprio may integrate with third-party services such as Meta's WhatsApp Business Platform, telephony and voice providers, AI model providers, hosting providers, databases, monitoring providers and other infrastructure required to provide the service.
Privacy & Grievance Contact:
Chetan Kumor
VEPRIO
India
Email: chetan@veprio.com
Website: https://veprio.com
2. Scope of this policy
This Privacy Policy applies to personal data processed through the Veprio website, applications, customer portals, APIs, communication integrations and other Veprio services.
It applies both to information relating to Veprio's business customers and to information relating to individuals who interact with a business that uses Veprio, including through WhatsApp or voice calls.
This policy does not replace the privacy notice of a business that uses Veprio. A Veprio business customer may have its own privacy obligations and privacy policy governing its relationship with its customers.
3. Our role when processing personal data
Business customer information
When a person creates, manages or communicates with us regarding a Veprio business account, Veprio determines how information required for account administration, billing, support, security, service operation and business communications is processed.
Where applicable, Veprio acts as the relevant controller or Data Fiduciary for that information.
Information processed for Veprio business customers
Businesses may use Veprio to communicate with their customers or prospective customers through supported channels such as WhatsApp or voice calls.
For information Veprio processes on behalf of a business, the business generally determines the purpose of the interaction and how its customer information is used. Veprio processes that information to provide, secure and support the service configured by that business.
Each business is responsible for providing any privacy notice and obtaining any consent, opt-in, permission or other lawful basis required for its collection and use of customer information and communication channels.
4. Personal data we may process
The information we process depends on how Veprio is used and which features a business enables.
Information from business customers and authorised users
- name;
- business or organisation name;
- email address;
- telephone number;
- account credentials and authentication information;
- account preferences and settings;
- AI instructions, prompts and configuration;
- business hours, services and scheduling rules;
- staff or authorised-user information;
- integration configuration;
- identifiers associated with connected communication services;
- billing, subscription and transaction information;
- support requests and communications;
- security and audit information; and
- other information a business voluntarily provides while using or configuring Veprio.
We may process credentials, API keys, tokens or similar integration information where necessary to connect authorised third-party services. We use such information only as necessary to provide and secure the requested integration.
Information relating to a business's customers
Depending on the business's configuration and the communication channel used, Veprio may process:
- name;
- telephone number;
- WhatsApp profile information or identifiers made available through the relevant service;
- messages and conversation content;
- conversation history;
- timestamps;
- incoming and outgoing call information;
- call metadata such as time, duration and status;
- audio streams required to process a call;
- call transcripts;
- call recordings where recording is enabled, disclosed and lawful;
- appointment or booking information;
- enquiry and lead information;
- customer preferences or requests;
- CRM or contact records;
- follow-up status;
- workflow events;
- information derived from interactions, such as conversation summaries, intent classifications or appointment status; and
- other information an individual voluntarily provides during an interaction with a business.
Website and technical information
When someone visits our website or uses Veprio, we or our service providers may process technical information such as:
- IP address;
- browser and device information;
- timestamps;
- security, audit and diagnostic logs;
- pages or features used;
- cookie or analytics information where such technologies are enabled; and
- information necessary to prevent abuse, maintain security and troubleshoot the service.
5. Where personal data comes from
We may receive personal data:
- directly from Veprio business customers and authorised users;
- from individuals who message, call or otherwise interact with a business using Veprio;
- from communication platforms and integrations authorised by the relevant business;
- from service providers that help us operate, secure or support Veprio; and
- automatically through normal use of our website, applications and infrastructure.
6. How we use personal data
We may process personal data to:
- provide, operate and maintain Veprio;
- create and administer business accounts;
- authenticate users and control access;
- receive and manage customer enquiries;
- enable AI-assisted conversations;
- process supported voice calls;
- send and receive supported business messages;
- schedule, modify and manage appointments;
- maintain customer and CRM records;
- maintain conversation history;
- generate conversation or call summaries;
- run workflows and follow-up actions configured by a business;
- retrieve relevant business information from a configured knowledge base;
- enable human handoff;
- administer subscriptions, invoices and payments;
- provide customer support;
- monitor service reliability and performance;
- diagnose technical problems;
- prevent fraud, abuse and security incidents;
- enforce our Terms and policies;
- comply with applicable legal obligations; and
- protect Veprio, our business customers, end-users and third parties.
We do not sell personal data.
We do not use private customer conversations for third-party advertising.
We do not intentionally use a business's private customer conversation content to train Veprio-owned general-purpose AI models unless a separate written agreement or clear permission expressly provides otherwise.
7. WhatsApp Business Platform data
Certain Veprio features may use Meta's WhatsApp Business Platform. When a business enables WhatsApp functionality, relevant information may be processed through Meta, WhatsApp and Veprio in order to provide and support the applicable messaging experience.
Information obtained through the WhatsApp Business Platform is used only as reasonably necessary to provide and support the applicable messaging interaction and related Veprio services described in this Privacy Policy. We do not sell WhatsApp-derived personal data or use it for unrelated advertising.
Message-thread content may be processed to perform the customer-service or operational workflow configured by the business, such as answering an enquiry, scheduling or modifying an appointment, generating a summary, updating a customer record, carrying out a permitted follow-up or enabling human handoff.
A business using Veprio is responsible for obtaining and maintaining any notice, permission, consent or opt-in required before initiating WhatsApp messages or calls, and for promptly honouring valid requests to stop, opt out or withdraw permission.
Where separate permission is required for a WhatsApp call or a category of communication, the business is responsible for obtaining that permission before initiating the communication.
Veprio and its customers must also comply with applicable Meta and WhatsApp terms, policies, messaging restrictions and commerce rules.
8. Voice calls, recordings and transcripts
If voice functionality is enabled, telephone numbers, call metadata, audio streams, transcripts or other information necessary to establish and process a call may be handled by Veprio and relevant telephony, voice or speech-processing providers.
Some configurations may include transcription, summarisation or recording. Businesses are responsible for providing any legally required notice and obtaining any legally required consent before a call is recorded, transcribed or otherwise processed.
Veprio does not guarantee that recording or transcription is lawful in every location or use case. The business using the feature is responsible for determining the requirements that apply to its calls.
9. AI processing and automated features
Veprio uses artificial intelligence to help businesses handle customer interactions and operational tasks.
To provide an AI-enabled feature, relevant portions of a message, call transcript, business knowledge, conversation history, customer request or other necessary context may be processed by an AI model or AI infrastructure provider.
We seek to limit information sent to such providers to what is reasonably necessary to provide, secure or support the configured feature.
Third-party AI providers process information according to the applicable service configuration, contractual terms and their own obligations.
AI-generated responses, summaries, classifications or actions may occasionally be inaccurate, incomplete or inappropriate. Businesses remain responsible for configuring Veprio appropriately and deciding when human review or handoff is required.
Veprio is not intended to make medical diagnoses, prescribe treatment, provide emergency guidance or replace qualified medical, legal, financial or other regulated professionals.
10. Service providers and sub-processors
We use third-party providers to operate and support Veprio. These may include:
- Meta and the WhatsApp Business Platform;
- AI model and AI infrastructure providers;
- telephony and voice infrastructure providers;
- speech-to-text and text-to-speech providers;
- hosting and application infrastructure providers;
- database and storage providers;
- monitoring, security and logging providers;
- email and support providers; and
- payment or billing providers where applicable.
A service provider receives or processes information only as necessary for the function it performs for Veprio, as otherwise permitted by applicable law, or according to an authorised integration selected by the relevant business.
Our provider list may change as the platform evolves. Questions about current provider categories may be sent to chetan@veprio.com.
11. How we share personal data
We may disclose personal data:
- to the business on whose behalf the relevant customer interaction is being processed;
- to service providers and sub-processors that help us provide, secure, maintain or support Veprio;
- to third-party integrations expressly enabled or authorised by the relevant business;
- when required by applicable law, legal process or a valid governmental request;
- where reasonably necessary to investigate fraud, abuse, security incidents or violations of our Terms; or
- as part of a corporate transaction, reorganisation or transfer of the business, subject to applicable law and appropriate protections.
We do not disclose personal data to third parties for their own unrelated advertising purposes.
12. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the relevant service, maintain the business account, satisfy legitimate operational requirements, resolve disputes, maintain security and comply with applicable legal obligations.
Retention periods vary depending on the type of information, the feature involved, the relevant business's configuration, contractual requirements and applicable law.
When a Veprio account is closed or a valid deletion request is completed, associated information will be deleted, de-identified or anonymised as appropriate, except for information that must be retained for legal, security, fraud-prevention, billing, accounting, dispute-resolution or similar lawful purposes.
Residual copies may remain temporarily in backups or security logs until overwritten or deleted through normal retention processes. Where required and technically applicable, we also instruct relevant service providers to delete personal data associated with a valid deletion request.
13. Security
We use reasonable administrative, technical and organisational safeguards designed to protect personal data against unauthorised access, use, alteration, disclosure, loss or destruction.
Depending on the relevant system, safeguards may include:
- encryption in transit;
- authentication and access controls;
- separation of customer data;
- tenant-level access restrictions;
- credential and secret protection;
- logging and monitoring;
- security testing; and
- procedures for investigating security incidents.
No internet-based service can guarantee absolute security. Businesses are also responsible for protecting their credentials, authorised users and connected third-party accounts.
Suspected privacy or security issues may be reported to chetan@veprio.com.
14. International processing and transfers
Veprio is based in India, but some service providers used to operate the platform may process information in other countries.
Where personal data is processed internationally, we take reasonable steps appropriate to our role to use providers and arrangements intended to protect the information and comply with applicable law.
15. Privacy rights
Depending on your location and applicable law, you may have rights relating to your personal data, including rights to request access, correction, updating or deletion, withdraw consent where processing is based on consent, and raise a grievance.
India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 are being brought into force in phases. Veprio intends to comply with provisions applicable to it as and when those provisions are legally effective.
If you are the customer of a business that uses Veprio, that business is generally the appropriate first point of contact for a request relating to information it controls.
You may also contact Veprio directly at chetan@veprio.com, and where appropriate we will assist the relevant business with the request.
16. Access, correction and deletion
Any individual, regardless of location, may request access, correction or deletion of personal data associated with them. We do not charge a fee merely for submitting a deletion request.
Requests may be submitted by email to chetan@veprio.com or by following the instructions at https://veprio.com/data-deletion.
Business customers should contact us using the email address associated with their Veprio account where possible.
If you are an end-customer of a business using Veprio, please identify the relevant business and the telephone number or other identifier used in your interaction so that we can locate or route the request appropriately.
We may need to verify your identity or authority before disclosing, correcting or deleting information. Verification is used to protect personal data from unauthorised requests.
A deletion request may not result in deletion of information that we are legally required or otherwise lawfully permitted to retain, including limited records required for security, fraud prevention, accounting, billing, legal claims or compliance obligations. Where we retain such information, we limit its use to the applicable purpose.
We will process verified requests within the period required by applicable law and, where no specific period applies, within a reasonable time.
17. Children and minors
Veprio is a business service and is not intended to be purchased, administered or directly operated by children.
A business using Veprio may itself provide services to children or minors. In those circumstances, the business is responsible for determining whether processing a minor's information is lawful and for obtaining parental or guardian consent where required.
18. Healthcare and sensitive information
Veprio may be used by clinics and other service businesses for administrative workflows such as general enquiries, appointment scheduling, reminders, customer support and operational coordination.
Veprio is not a telemedicine service and is not intended to diagnose conditions, prescribe treatment or provide emergency medical guidance.
Businesses must not use Veprio's WhatsApp integration to request, transmit or process health-related information where applicable law, regulation or WhatsApp policy prohibits that processing or requires systems or safeguards that are not in place for the relevant use case.
Businesses are responsible for assessing any heightened legal, contractual or security requirements that apply before using Veprio to process sensitive or regulated information.
19. Website data, cookies and analytics
Our website and infrastructure may process technical information necessary to deliver pages, protect the service, prevent abuse and diagnose performance or security issues.
If Veprio enables non-essential cookies, analytics or similar technologies that require notice or consent under applicable law, we will provide appropriate information or controls.
Website analytics and technical data are separate from private customer conversation content processed through a Veprio business account.
20. Changes to this Privacy Policy
We may update this Privacy Policy as Veprio evolves or as legal, regulatory, platform or operational requirements change.
When we make changes, we will update the “Last updated” date above.
Where required by applicable law or appropriate because of a material change, we may provide additional notice.
We may retain archived copies of prior versions of this Privacy Policy for legal, compliance and audit purposes.
21. Contact and grievance requests
For questions, privacy requests, deletion requests, grievances or complaints relating to Veprio, contact:
Chetan Kumor
VEPRIO
India
Email: chetan@veprio.com
Website: https://veprio.com
We will review privacy and grievance requests and respond in accordance with applicable law.