Privacy Policy
Last updated: 14 July 2026
whispr Labs (“whispr Labs”, “we”, “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, disclose and safeguard your personal data when you use our platform.
This Policy is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023 (“DPDP Act”). By using the Platform, you consent to the practices described here and in our Terms of Service.
1. Who We Are (Data Fiduciary)
For the purposes of the DPDP Act, whispr Labs is the “Data Fiduciary” that determines the purpose and means of processing your personal data. We are based in Bengaluru, India, and host data primarily in the Mumbai region.
2. Consent
We process your personal data based on the consent you provide when you register or use the Services, and for other lawful purposes permitted under the DPDP Act. You may withdraw your consent at any time by contacting us (see Section 12), though this may limit your ability to use certain features. Withdrawal does not affect processing carried out before withdrawal.
3. Information We Collect
We collect the following categories of personal data:
- Account & identity data: name, company/organisation name, email address, mobile number, user type (creator, agency, brand) and country.
- Sensitive personal data or information (SPDI): passwords and payment information, which are collected and processed with reasonable security safeguards. Payment card details are handled by RBI-compliant payment gateways and are not stored by us.
- Usage & device data: IP address, browser type, device identifiers, pages visited, and interactions with the Platform.
- Third-party / public data: publicly available creator information (including from Instagram / Meta) used to generate analytical reports.
4. How and Why We Use Your Data
We process personal data for the following lawful purposes:
- To create and manage your account and authenticate you;
- To provide, personalise and improve the Services and generate creator reports;
- To process payments, subscriptions and issue invoices (including GST compliance);
- To communicate with you about your account, security, updates and support;
- To detect, prevent and address fraud, abuse and security incidents;
- To comply with legal obligations and enforce our Terms.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, or as required to comply with legal, accounting or regulatory obligations. When data is no longer required, we will delete or anonymise it in accordance with the DPDP Act.
7. Data Security
We implement reasonable security practices and procedures as required under the SPDI Rules and the DPDP Act, including encryption in transit, access controls, and the use of in-memory or short-lived tokens for authentication. While we strive to protect your data, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a personal data breach, we will notify the Data Protection Board of India and affected users as required by law.
8. Your Rights as a Data Principal
Under the DPDP Act, you have the right to:
- Access a summary of your personal data and how it is processed;
- Request correction, completion, updating or erasure of your personal data;
- Withdraw consent previously given;
- Nominate another individual to exercise your rights in the event of death or incapacity;
- Grievance redressal (see Section 12) and the ability to escalate to the Data Protection Board of India.
To exercise these rights, email us at privacy@whisprlabs.io. We may need to verify your identity before acting on a request.
10. Children’s Data
The Services are not directed at children as defined under the DPDP Act. We do not knowingly collect personal data of children without verifiable parental consent. If you believe we have inadvertently collected such data, please contact us and we will delete it.
11. Data Storage and Transfers
Your data is stored on servers located in India (Mumbai region). Where data is transferred to or processed by service providers outside India, we do so only in accordance with the DPDP Act and applicable government notifications, with appropriate safeguards in place.
12. Grievance Officer and Data Protection Contact
In compliance with the Information Technology Act, 2000, the SPDI Rules, the IT (Intermediary Guidelines) Rules, 2021 and the DPDP Act, the details of our Grievance Officer are below. We will acknowledge complaints within 24 hours and endeavour to resolve them within 15 days of receipt.
- Grievance Officer: The Grievance Officer, whispr Labs
- Email: grievance@whisprlabs.io
- Privacy queries: privacy@whisprlabs.io
- Address: whispr Labs, Bengaluru, India
13. Changes to this Policy
We may update this Privacy Policy from time to time. The revised version will be posted on this page with a new “Last updated” date. We encourage you to review it periodically.
14. Contact Us
For questions about this Privacy Policy or our data practices, contact us at support@whisprlabs.io.