This Privacy Policy explains how NeuraFlow collects, uses, stores, shares, and protects information when you visit our website, contact us, use our automation services, or use NeuraFlow products such as NeuraFlow Zap and NeuraFlow Central.
For the purpose of this Privacy Policy:
“NeuraFlow”, “we”, “us”, or “our” means NeuraFlow, a brand of NeuraMax Corporation LLP, operating through the website https://neuraflow.co.in and related products and services.
“NeuraFlow Zap” means one NeuraFlow product or service used for WhatsApp Business Platform workflows, WhatsApp automation, campaigns, chatbot workflows, and customer communication workflows.
“NeuraFlow Central” means one NeuraFlow product used by businesses for team management, task assignment, responsibility tracking, operational collaboration, task notifications, task history, document attachments, and workspace administration.
“You” or “user” means a website visitor, client, business user, team member, or any person who interacts with our services.
“Client” means a business that uses NeuraFlow products or services, including NeuraFlow Zap or NeuraFlow Central where applicable, to manage automation, customer communication, campaigns, chatbot workflows, team and task management, dashboards, analytics, consulting, or related services.
“End customer” means a person who communicates with one of our clients through WhatsApp or another communication channel.
Scope of this Privacy Policy
This Privacy Policy applies to:
- Our website at https://neuraflow.co.in
- Contact forms, booking forms, and inquiry forms
- NeuraFlow product apps and dashboards, including NeuraFlow Zap where applicable
- NeuraFlow Central, including central.neuraflow.co.in and related dashboards, workspaces, notification systems, and task-management workflows where applicable
- WhatsApp Business Platform integrations
- WhatsApp marketing and automation services provided through NeuraFlow Zap or related NeuraFlow services
- Chatbot and customer communication workflows
- Support, onboarding, and consulting services provided by us
This Privacy Policy does not replace the privacy policies of Meta, WhatsApp, or any third-party service that you use separately.
Information We Collect
We collect only the information reasonably required to provide, operate, secure, improve, and support our services.
A. Information you provide directly
We may collect:
- Name
- Business name
- Email address
- Phone number
- Website URL
- Business address
- Job title or role
- Details submitted through contact forms, booking forms, or inquiry forms
- Support requests and communication history
- Billing or invoicing information, where applicable
B. Website and analytics information
When you visit our website, we may collect basic technical information such as:
- Browser type
- Device type
- Approximate location based on IP address
- Pages visited
- Time spent on pages
- Referring website
- Cookie preferences
We use essential cookies to keep the website working. We use analytics cookies only when you consent to them through our cookie banner.
We may use Google Analytics 4 only when analytics cookies are allowed by you.
C. WhatsApp Business Platform information
When a client connects or uses WhatsApp Business Platform through NeuraFlow Zap or related NeuraFlow services, we may process:
- WhatsApp Business Account details
- Business portfolio details
- WhatsApp phone number ID
- Display name and phone number information
- Message template names, categories, language, content, and status
- Webhook events
- Message delivery, read, and failure status
- Inbound and outbound message content
- Customer phone numbers
- Customer names, if provided
- Campaign records
- Opt-in and opt-out records
- Conversation history
- Chatbot workflow logs
- Human handoff records
- Automation configuration data
- Consent source and consent timestamp, where available
D. Client customer data
Our clients may upload, connect, or process information relating to their own customers. This may include:
- Customer name
- WhatsApp number or phone number
- Email address, if provided
- Tags, segments, or preferences
- Order, appointment, inquiry, or lead details
- Communication preferences
- Consent and opt-out status
- Conversation history
Clients are responsible for ensuring that they have collected this information lawfully and have obtained all required permissions, consents, and notices before using it with NeuraFlow products or services, including NeuraFlow Zap where applicable.
E. Chatbot and automation data
When chatbot or automation services are used, we may process:
- Customer questions and replies
- Client-provided FAQs
- Business knowledge base content
- Product or service information
- Lead qualification answers
- Appointment or inquiry details
- Conversation summaries
- Internal notes and routing information
We do not use WhatsApp Business Solution data to create, train, or improve a general-purpose artificial intelligence model.
F. NeuraFlow Central workspace and task data
When a client or user uses NeuraFlow Central, we may process:
- Workspace or company profile information
- Team member names, email addresses, phone numbers, departments, designations, reporting relationships, and account status
- Task titles, descriptions, priorities, due dates, statuses, assigned members, managers, assigners, reviewers, and related responsibility information
- Task comments, updates, reminders, requests, approvals, cancellation reasons, extension reasons, reassignment history, and chronological activity history
- Uploaded documents, attachments, file metadata, file size, file type, upload history, download availability, and retention-related metadata
- Notification preferences, notification contacts, in-app notification records, email, SMS, or push delivery status, delivery logs, and provider response metadata
- Admin actions, setup activity, invite requests, access requests, audit logs, and security-related records
- Basic device, browser, IP, and session information needed for security, authentication, troubleshooting, and service reliability
How We Use Information
We use collected information for the following purposes:
- To operate our website
- To respond to inquiries
- To schedule calls and consultations
- To provide WhatsApp setup and automation services
- To connect client WhatsApp Business Accounts
- To manage WhatsApp message templates
- To send approved WhatsApp messages on behalf of clients
- To receive and display inbound WhatsApp messages
- To run chatbot and automation workflows
- To manage opt-ins, opt-outs, and customer preferences
- To provide human handoff and customer support workflows
- To troubleshoot technical issues
- To detect misuse, fraud, spam, or security issues
- To maintain logs for service reliability and compliance
- To improve our services
- To comply with legal, regulatory, contractual, and platform obligations
- To enforce our Terms of Service
For NeuraFlow Central, we also use information to:
- Create and manage business workspaces
- Manage team members, departments, roles, and reporting hierarchy
- Create, assign, update, review, complete, cancel, reopen, and track tasks
- Maintain task history, activity logs, responsibility records, and audit trails
- Store and retrieve task-related documents and attachments
- Send operational notifications through in-app notifications, email, SMS, and web push where configured
- Enforce access control, visibility rules, account security, and administrative permissions
- Provide support, troubleshooting, reliability monitoring, and service improvement
WhatsApp and Meta Platform Data
Where our services use WhatsApp Business Platform, we process data only for the purpose of providing business messaging, automation, campaign, support, reporting, and related services requested by the client.
We require clients to follow applicable WhatsApp, Meta, and legal requirements, including requirements relating to opt-in, opt-out, approved templates, prohibited content, and customer privacy.
We do not sell WhatsApp message data, WhatsApp contact data, or WhatsApp Business Account data.
Google API and Gmail Data
NeuraFlow Central may use the Gmail API to send operational email notifications from an authorized NeuraFlow sender account. These emails may relate to task assignments, task updates, reminders, reviews, approvals, cancellations, escalations, workspace access, or other operational app activity.
A. Google data we access and process
NeuraFlow Central requests only the https://www.googleapis.com/auth/gmail.send permission. This permission allows Central to send email; it does not allow Central to read a Gmail inbox.
For a Gmail connection, Central may process the Google authorization code, encrypted Gmail refresh token, temporary access token, authorized sender address, granted permission, connection and revocation status, and related timestamps. For each operational email, Central sends the intended recipient email address, subject, and message content to Gmail for delivery.
Central does not use Gmail API access to read inbox messages, read email history, search mailboxes, access labels, download Gmail attachments, monitor personal email content, or manage unrelated Gmail settings.
B. How we use Google data
We use Google data only to connect the approved sender account, obtain a short-lived access token, send operational email requested by Central workflows, test the connection, display limited connection health information, troubleshoot delivery, and disconnect or revoke the integration.
Central does not sell Google user data, use Google user data for advertising, use Google user data to train or improve general-purpose artificial intelligence models, or use it for unrelated profiling or marketing.
C. Who receives or may access Google data
Google LLC processes authorization, token exchange, email sending, and token revocation as the Gmail API provider.
Vercel Inc. processes secure server requests that operate NeuraFlow Central. Supabase Inc. stores the encrypted Gmail refresh token and limited connection, security, and audit metadata on our behalf.
The intended email recipients receive the operational messages addressed to them. Authorized client workspace users may see operational message content when their Central permissions allow it. Authorized NeuraFlow platform operators may view the sender address, granted permission, connection status, timestamps, and limited error or delivery evidence when required for setup, security, or support. They are not shown the stored Gmail refresh token.
We may disclose limited Google-related records to government, regulatory, or law-enforcement authorities only where legally required. We do not disclose Google user data to other clients or unrelated third parties.
D. How we protect Google data
Google data is transmitted over HTTPS. Central encrypts the Gmail refresh token with AES-256-GCM before storing it in Supabase. The encryption key is kept separately in protected server settings and is not stored beside the encrypted token.
Direct browser access to the Gmail credential record is blocked. Gmail connection controls are restricted to authorized NeuraFlow platform operators using stronger account verification. Temporary Gmail access tokens are used in protected server memory for the relevant Google request and are not stored as reusable database credentials. One-time connection state expires after ten minutes, and operational logs must not contain plaintext Google tokens.
E. Google data retention and deletion
A temporary Gmail access token is kept only in server memory for the relevant connection or sending request and is not retained as a reusable stored credential.
The encrypted Gmail refresh token is retained only while the Gmail connection remains active or while a failed revocation still requires resolution. Disconnecting Gmail immediately disables sending and asks Google to revoke access. After revocation is confirmed, Central deletes the stored encrypted Gmail refresh token. If Google cannot confirm revocation, sending remains disabled and the encrypted token is retained only until an authorized operator resolves and confirms removal.
Limited sender, granted-permission, connection, test, delivery, security, and audit metadata may be retained while needed for account operation, troubleshooting, security, accountability, disputes, or legal obligations. We delete or anonymize that metadata when it is no longer required for those purposes.
A user may also remove NeuraFlow Central from their Google Account permissions. To request review or deletion of Google connection data and related metadata, follow https://neuraflow.co.in/data-deletion or email admin@neuraflow.co.in.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Legal Basis for Processing
Depending on the situation, we may process personal data based on:
- Your consent
- Performance of a contract
- Compliance with legal obligations
- Legitimate business interests, such as security, support, service improvement, and fraud prevention
- Client instructions, where we act as a service provider or processor for client customer data
AI and Automation
NeuraFlow services, including NeuraFlow Zap where applicable, may use automation or artificial intelligence features to support business-specific workflows, such as:
- Answering FAQs from a client-approved knowledge base
- Qualifying leads
- Routing inquiries
- Booking appointments
- Generating internal conversation summaries
- Drafting responses for review
- Supporting human handoff
We do not use client WhatsApp Business data or end-customer message data to train, develop, or improve a general-purpose AI model.
Cookies
Our website uses:
- Essential cookies required for website security and functionality
- Analytics cookies only when you consent to them
You can change your cookie choice by clearing your browser storage or adjusting your browser settings.
Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Retention periods may depend on:
- The type of data
- The client’s service plan
- Legal or accounting requirements
- Security and fraud-prevention needs
- WhatsApp or Meta platform requirements
- Dispute resolution requirements
- Backup and disaster recovery cycles
For NeuraFlow Central, workspace records, task records, task history, audit logs, notification records, and document metadata may be retained for operational accountability, security, dispute resolution, compliance, backup, and client service continuity. Uploaded files and attachments may be retained or deleted according to the client’s plan, workspace settings, retention policy, service agreement, or lawful deletion request.
When data is no longer required, we delete, anonymize, or securely archive it.
Data Security
We use reasonable administrative, technical, and organizational safeguards to protect information from unauthorized access, loss, misuse, alteration, or disclosure.
However, no internet-based service can be guaranteed to be completely secure. Users and clients are responsible for maintaining the confidentiality of their account credentials and for using strong access controls.
Your Rights and Choices
Depending on applicable law, you may have the right to:
- Access your personal data
- Correct inaccurate information
- Request deletion of your data
- Withdraw consent
- Object to certain processing
- Request restriction of processing
- Ask how your information is used
- Opt out of marketing communications
To exercise these rights, contact us at:
WhatsApp Opt-Outs
If you receive WhatsApp messages from a business using NeuraFlow services, including NeuraFlow Zap where applicable, and you no longer wish to receive those messages, you may:
- Reply with “STOP” or any opt-out instruction provided in the message
- Contact the business directly
- Block the business on WhatsApp
- Contact us at admin@neuraflow.co.in if you need help identifying the relevant business
We require our clients to respect opt-out requests.
Children’s Privacy
Our services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children without appropriate legal basis or required consent.
Clients must not use NeuraFlow products or services to unlawfully collect or process children’s data.
International Transfers
Some service providers used by us may process data outside your country. Where this occurs, we take reasonable steps to ensure that such processing is protected according to applicable legal and contractual requirements.
Data Deletion
You may request deletion of your data by following our Data Deletion Policy available at:
https://neuraflow.co.in/data-deletion
You may also email us at:
Links to Third-Party Sites
Our website or services may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised “Last updated” date.
Contact Us
For privacy questions, data requests, or complaints, contact:
NeuraFlow, a brand of NeuraMax Corporation LLP Email: admin@neuraflow.co.in Website: https://neuraflow.co.in Address: DLF Phase 1, Gurugram - 122002, Haryana, India