Legal

Privacy Policy

How Settl collects, uses and protects personal data

Effective date: 22 July 2026Version 1.0Prepared under the Digital Personal Data Protection Act, 2023 (India)
Important — draft for legal review. This Privacy Policy is a comprehensive draft prepared for the Settl platform and reflects Indian data protection requirements as commonly applied. It is not legal advice and has not been settled by an advocate. It must be reviewed by a qualified Indian legal practitioner before publication, and must be kept consistent with your actual data practices — a policy that describes practices you do not follow creates more risk than no policy at all.

1. Introduction & Scope

This Privacy Policy explains how AIVONT AI LABS, having its registered office at 559-569, Tower-B1, Gurgaon, Haryana 122018, India (“Settl”, “we”, “us”), collects, uses, stores, shares and protects personal data in connection with the Settl platform at settl.chat (the “Services”).

This Policy is published in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. It forms an integral part of our Terms & Conditions.

Who this Policy is for

  • Customers — Indian businesses that subscribe to Settl to follow up on their own receivables.
  • Users— individuals who access a Customer's Settl account, including owners, staff and partner firms.
  • Debtors — customers or buyers of our Customers who receive payment reminder messages sent through Settl. If you received a WhatsApp message from a business using Settl, Section 9 is written for you.
  • Visitors — anyone browsing settl.chat.

2. Our Role: Who Decides What Happens to Your Data

Indian data protection law distinguishes between the party that decides why and how personal data is processed (the Data Fiduciary) and the party that processes it on their behalf (the Data Processor). Settl occupies both roles depending on the data in question.

Category of dataSettl's roleWho decides
Debtor Data — names, mobile numbers, invoice particulars and message history uploaded or synced by a CustomerData ProcessorThe Customer is the Data Fiduciary and instructs us
Customer account data — business details, user names, emails, login and billing recordsData FiduciarySettl
Website and product usage data — device, log and analytics dataData FiduciarySettl

What this means in practice.When a business uses Settl to remind its buyers about unpaid invoices, that business — not Settl — decides who is contacted and why. Settl processes that data only on the business's instructions. Requests to access, correct or erase debtor information should therefore be made to the business that sent the message; we will assist them in responding.

3. Personal Data We Collect

3.1 Data you provide to us

  • Account and business data:business name, contact person's name, mobile number, email address, business address, GSTIN, and your Virtual Payment Address (VPA) for generating UPI links.
  • Authentication data: login credentials in hashed form, session tokens, and multi-factor authentication settings.
  • Billing data:subscription plan, invoices issued, payment status and transaction references. Card and bank details are handled by our payment processor and are not stored on Settl's servers.
  • Debtor Data you upload: debtor names, mobile numbers, invoice numbers, amounts, due dates, and payment status — imported by file, entered manually, or synced from your accounting software.
  • Support communications: messages, screenshots and information you send us at support@settl.chat.

3.2 Data generated through use of the Services

  • Message data: the content, timestamps and delivery/read status of reminders sent, and the content of replies received from Debtors through WhatsApp.
  • Activity data: actions taken in the dashboard, sequences configured, invoices marked paid, extensions approved.
  • Technical data: IP address, browser and device type, operating system, access timestamps, and error logs.
  • Product analytics: feature usage and funnel events used to improve the Services.

3.3 Data from third parties

  • Meta / WhatsApp Business Platform: your WhatsApp Business Account identifiers, number quality rating, template approval status, message delivery webhooks, and inbound message content.
  • Accounting software: where you install our Tally TDL integration, outstanding voucher and receipt data synced from your Tally installation.
  • Referral partners: where a chartered accountancy firm or partner refers you, we receive your business name and contact details for onboarding.

3.4 What we do not collect

We do not knowingly collect sensitive personal data such as biometric data, health data, caste or religious identifiers, or financial account credentials. We do not collect data relating to children, and the Services are not directed at persons under 18. We do not store your customers' card, bank account or UPI PIN details at any time — see Section 5.

4. Why We Process Personal Data

PurposeData usedBasis
Providing the Services — sending reminders, receiving replies, tracking invoicesDebtor Data, message data, account dataPerformance of contract with the Customer; Customer's instructions as Data Fiduciary
Account creation, authentication and access controlAccount and authentication dataPerformance of contract
Billing, invoicing and GST complianceBilling data, GSTINLegal obligation; performance of contract
Customer support and troubleshootingSupport communications, technical logsLegitimate use for the purpose for which data was provided
Security, fraud prevention and abuse detectionTechnical data, activity dataLegal obligation; legitimate use
Improving reliability and usability of the ServicesAggregated and de-identified usage analyticsLegitimate use
Service communications — outage notices, plan changes, policy updatesContact detailsPerformance of contract
Marketing communications about SettlContact detailsConsent, withdrawable at any time

We do not sell personal data.We do not rent, trade or sell personal data to any third party, and we do not use Debtor Data for advertising or for training generally-available AI models. AI features within the Services process message content solely to serve that Customer's own reminder workflow.

5. UPI Links: We Never Handle Your Money

5.1Reminders sent through Settl may contain a UPI deep link generated from the Customer's own Virtual Payment Address. When a Debtor taps it, their own UPI application opens with the amount pre-filled.

5.2Funds move directly from the Debtor's bank account to the Customer's bank account through NPCI infrastructure. Settl does not receive, hold, route, escrow or settle any money, and does not process any payment transaction. We therefore never see or store UPI PINs, card numbers, CVVs, bank account numbers or net-banking credentials.

5.3The only payment-related information in our systems is the Customer's own VPA (used to build the link) and the payment status that the Customer or their accounting software records.

6. WhatsApp and Meta

6.1The Services operate on the WhatsApp Business Platform. Messages sent and received through Settl are transmitted through Meta's infrastructure and are subject to Meta's own privacy practices, over which we have no control.

6.2 Messages sent through the WhatsApp Business Platform are not end-to-end encrypted in the same manner as personal WhatsApp chats, because the business (and Settl as its processor) necessarily has access to message content in order to provide the Services.

6.3 We store message content and metadata so that Customers can view conversation history, so that our AI can detect payment-related intent, and so that opt-out requests are honoured reliably.

6.4We encourage you to review Meta's WhatsApp Business Privacy Policy for information on how Meta processes data on its platform.

7. When We Share Personal Data

We share personal data only in the following circumstances, and only to the extent necessary:

  • With the Customer: Debtor Data and message history are visible to the Customer whose account holds them, and to users they authorise, including staff and any partner firm granted dashboard access.
  • With sub-processors: cloud hosting, WhatsApp Business Platform / Business Solution Providers, email delivery, error monitoring, product analytics, and payment processing for our own subscription billing. Each is bound by contractual confidentiality and data protection obligations. A current list is available on request at support@settl.chat.
  • With professional advisers: auditors, lawyers and accountants, under duties of confidentiality.
  • For legal reasons: where disclosure is required by law, by a court or tribunal, or by a competent authority; or where necessary to establish, exercise or defend legal claims, or to prevent fraud, harm or a security incident.
  • On a business transfer: in connection with a merger, acquisition, restructuring or sale of assets, subject to the acquirer honouring this Policy. You will be notified of any such change.

8. Storage, Security & International Transfers

8.1 Location. Personal data is primarily stored on servers located in India. Any transfer outside India will be made only to jurisdictions permitted under the DPDP Act and subject to appropriate contractual safeguards.

8.2 Security measures. We implement reasonable security safeguards appropriate to the risk, including:

  • encryption of data in transit using TLS, and encryption of sensitive fields at rest;
  • role-based access control, with staff access limited to what is necessary for their function;
  • audit logging of administrative actions;
  • hashed credential storage and support for multi-factor authentication;
  • regular backups, patching and vulnerability management;
  • contractual security obligations on all sub-processors.

8.3 No system is perfectly secure. While we take security seriously, we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential and for promptly notifying us at support@settl.chat of any suspected unauthorised access.

8.4 Breach notification. In the event of a personal data breach, we will notify the Data Protection Board of India and affected persons as required under the DPDP Act, and will notify affected Customers without undue delay so that they can meet their own obligations as Data Fiduciaries.

9. How Long We Keep Data

DataRetention period
Debtor Data and message historyFor the life of the account; deleted or irreversibly anonymised within 90 days of account termination (30 days for export, then deletion)
Opt-out / suppression recordsRetained indefinitely, in minimal form, so that a person who has opted out is never contacted again through Settl
Billing and tax recordsAs required under the Income-tax Act, 1961, the GST laws and the Companies Act, 2013 — ordinarily 8 years
Security and access logsUp to 12 months, or longer where required for an ongoing investigation
Support communicationsUp to 24 months
Marketing contact dataUntil consent is withdrawn

10. Your Rights Under the DPDP Act

Subject to the conditions and exemptions in the DPDP Act, you have the following rights in respect of your personal data:

  • Right to access: obtain a summary of the personal data being processed and the processing activities undertaken.
  • Right to correction and erasure: have inaccurate or misleading data corrected, incomplete data completed, and data erased where it is no longer needed for the purpose it was collected.
  • Right to grievance redressal: complain to us through the channels in Section 12 and receive a response within the statutory period.
  • Right to nominate: nominate another individual to exercise your rights in the event of your death or incapacity.
  • Right to withdraw consent: where processing is based on consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

How to exercise these rights: write to support@settl.chat from your registered email address. We may ask for information to verify your identity. We will respond within the timelines prescribed under the DPDP Act.

If you are a Debtor exercising rights over data a business uploaded about you, please contact that business directly — they are the Data Fiduciary and control that data. If you cannot identify or reach them, write to us at support@settl.chat and we will facilitate contact and, where you request it, action your opt-out immediately.

11. If You Received a Reminder Message From Us

This section is written for Debtors — individuals or businesses who received a WhatsApp payment reminder sent through Settl.

11.1 Why you received a message. A business you deal with uses Settl to follow up on its unpaid invoices. That business supplied your mobile number and invoice details. Settl sent the message on their behalf and in their name.

11.2 How to stop receiving messages. Reply STOP on the same WhatsApp thread. Your opt-out is actioned within 60 seconds and applies permanently — it survives any later re-upload of your number by that business.

11.3 If you believe the amount is wrong or already paid, reply on the same thread. Your message goes to the business, which is responsible for resolving the dispute. Settl cannot verify, waive, reduce or enforce any amount.

11.4 If a message was harassing, threatening or sent at an unreasonable hour, please tell us at support@settl.chat. Our Terms prohibit such conduct, and we investigate and act against accounts that misuse the Services, including suspension.

11.5 Payments. Any UPI link in the message pays the business directly from your own UPI app. Settl never receives your money and never asks for your UPI PIN, OTP, card number or bank credentials. Treat any request for such details as fraudulent and report it to us.

12. Cookies & Website Analytics

12.1 settl.chat uses cookies and similar technologies that are strictly necessary for the site and dashboard to function (session management, authentication, security), together with analytics cookies that help us understand how the site is used.

12.2 You can control or delete cookies through your browser settings. Disabling strictly necessary cookies will prevent you from logging in or using the dashboard.

12.3 We do not use third-party advertising cookies or cross-site tracking for behavioural advertising.

13. Grievance Officer & Contact

For any question, request or complaint relating to this Policy or to the processing of personal data, contact:

DesignationGrievance Officer / Data Protection Contact
EntityAIVONT AI LABS
Address559-569, Tower-B1, Gurgaon, Haryana 122018, India
Emailsupport@settl.chat
AcknowledgementWithin 48 hours of receipt
ResolutionOrdinarily within 15 days; within statutory timelines under the DPDP Act

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India in accordance with the DPDP Act.

14. Changes to This Policy

14.1 We may update this Policy from time to time. The current version is always available at settl.chat/privacy with its effective date.

14.2 Where a change materially affects how we handle personal data, we will notify Customers by email or in-product notice at least fifteen (15) days before it takes effect.

14.3 Previous versions are archived and available on request at support@settl.chat.

Pre-publication checklist

  • Have an Indian advocate review Sections 2, 5, 8, 9 and 10.
  • Confirm every statement matches your actual technical practice — particularly storage location, encryption, retention periods and the sub-processor list.
  • Publish at settl.chat/privacy and link it from signup, footer and every reminder template footer.
  • Record affirmative acceptance with a timestamp at signup.
  • Prepare a short debtor-facing summary of Section 11 for the link included in reminder messages.