QEMRA legal
Privacy Policy
This document explains the rules, responsibilities, and protections that apply when you use QEMRA.
1. Scope
This Privacy Policy explains how KRAVIA PRIVATE LIMITED (“KRAVIA”, “QEMRA”, “we”, “us”) handles personal data when people visit QEMRA, create or manage an account, use QEMRA to operate business messaging and automation, contact us, or interact with a business that uses QEMRA.
QEMRA is intended for businesses and individual professionals or freelancers. Account holders must be at least 18 years old.
For data that a business customer uploads to QEMRA or receives from its own customers, the business generally determines why the data is used and QEMRA processes it to provide the service. Depending on the applicable law, this relationship may be described as customer–processor, controller–processor, or Data Fiduciary–Data Processor. For data that KRAVIA collects for its own account, billing, security, support, compliance and product operations, KRAVIA determines the relevant purposes.
2. Data we collect
We may process:
Account and identity data
Name, business name, email address, login and session information, role, workspace membership, authentication settings and account preferences.
Business profile data
Industry, locations, working hours, services, prices, staff details, FAQs, policies, website and social links, booking rules and other information a user chooses to configure.
Messaging and customer data
WhatsApp identifiers and phone numbers, consent records, contact details, message content, message metadata, delivery/read state, conversation history, tags, notes, bookings, workflow state and human-handoff records.
Files and media
Images, documents, audio and other files received through supported messaging or uploaded to QEMRA.
Billing data
Subscription plan, billing address, GSTIN or tax identifier where provided, invoices, payment references, renewal status and payment state. QEMRA does not store full card or payment credentials; those are handled by Cashfree or another approved payment processor.
Usage, device and security data
IP address, browser/device information, timestamps, login activity, security events, feature usage, diagnostic information and audit records.
Support and grievance data
Information provided in support requests, legal notices, accessibility feedback, security reports, privacy requests, complaints and grievance correspondence.
3. How data is collected
We collect data directly from users; from business customers and authorized team members; through the WhatsApp Business Platform and other integrations a customer enables; from payment, hosting, analytics, email and security providers; from the public website when a user chooses to import publicly available business information; and automatically through essential product logs and, where permitted, analytics technologies.
Where QEMRA offers website import, extracted information is presented for review and is not silently published as business information.
4. Why we use data
We process data to:
- create and secure accounts;
- provide QEMRA, including automation, inbox, contacts, bookings, workflow testing and analytics;
- connect and operate authorized WhatsApp Business accounts;
- deliver, receive and track messages;
- generate and improve a customer’s configured automation;
- provide AI-assisted replies, classification, summaries and workflow suggestions;
- process subscriptions, invoices and taxes;
- provide support and resolve grievances;
- detect abuse, fraud and security threats;
- maintain audit trails, reliability and service continuity;
- comply with law, valid legal requests and contractual obligations; and
- send product updates or marketing communications where appropriate consent or another lawful basis exists.
We do not use customer WhatsApp conversations or customer message content to train QEMRA’s own AI models by default.
5. AI processing
QEMRA may send limited business or conversation content to approved third-party AI providers when necessary to provide enabled features such as reply generation, intent classification, chat summarization and workflow generation.
AI outputs can be inaccurate. QEMRA applies configurable safeguards, confidence checks and human-handoff rules. New business accounts default to Review first for AI replies. Businesses may choose Auto-send, Review first or Human only, subject to product safeguards.
Low-confidence or sensitive scenarios use stricter controls. Important actions with real-world consequences—such as payment links, booking cancellation or changes, refund-related actions, complaints, medical, legal, credit, insurance or employment decisions—require explicit rules and/or appropriate human oversight.
6. Cookies and analytics
QEMRA uses essential cookies or similar technologies for login, security, preferences and core service operation.
QEMRA uses PostHog for product analytics, onboarding funnels and feature-usage measurement. Analytics/performance tracking is enabled only with consent where required by applicable law. See the Cookie Policy for details.
7. WhatsApp data and consent
Businesses using QEMRA are responsible for obtaining and maintaining the permissions and notices required for their own customer messaging.
QEMRA can store consent source, timestamp, acquisition source and opt-out history. Clear opt-outs such as “STOP”, “unsubscribe” or “don’t message me” are used to suppress future promotional messages unless the person later opts in again. Necessary service or transactional messages may continue where permitted by law and platform rules.
QEMRA does not permit purchased, scraped, harvested or otherwise non-consensual contact lists.
8. Sharing and subprocessors
We disclose data only as reasonably necessary to operate QEMRA, including to approved providers for WhatsApp messaging, payments, hosting and infrastructure, database services, email delivery, AI features, analytics, professional support, legal/compliance and security.
Our current provider categories and material subprocessors are listed in the QEMRA Subprocessor List.
We may also disclose data when required by a legally valid court, regulator or government request; to investigate fraud, abuse or security incidents; to protect users, KRAVIA or third parties; or during a merger, acquisition, restructuring or sale of relevant assets, subject to appropriate safeguards.
For government or legal demands, we seek to verify the request, disclose only what is legally required and notify the affected customer where legally permitted.
9. International and regional processing
QEMRA aims to use India-based hosting for Indian customers where practical and region-appropriate hosting for international customers as the service expands.
Some approved providers may process data outside a customer’s home country. Where required, QEMRA uses appropriate contractual, technical and organizational safeguards for cross-border processing.
10. Data retention
Default retention includes:
- WhatsApp conversation/message history: 180 days;
- WhatsApp media and attachments: 90 days;
- security and audit logs: 1 year;
- automation decision/action audit records: 1 year;
- internal error/diagnostic logs: 30 days;
- deleted-account data: scheduled for deletion within 30 days;
- encrypted backups containing deleted data: normally removed through backup rotation within 30 days;
- inactive free accounts: may be deleted after 12 months of inactivity following 30 days’ notice.
Billing, tax, fraud-prevention, security, dispute and legally required records may be kept longer when necessary. More detail appears in the Data Retention & Deletion Policy.
11. Security
QEMRA uses measures designed to protect data, including encryption in transit and at rest where applicable, role-based access, tenant isolation, secure sessions, audit logging, access controls, optional multi-factor authentication, backups and operational monitoring.
Authorized KRAVIA/QEMRA personnel may access customer conversations only when reasonably necessary for support, security, abuse investigation or troubleshooting, with restricted access and audit logging.
No online service can guarantee absolute security.
12. Security incidents
If a data or security incident materially affects a customer, QEMRA will notify affected customers without undue delay and provide available information about the impact and recommended actions, subject to applicable legal requirements.
13. Your rights and choices
Depending on your location and the law that applies, you may have rights to request access, correction, completion, deletion, withdrawal of consent, restriction/objection, export, complaint to an authority, or nomination/authorization of another person where the law provides such a right.
QEMRA also voluntarily provides reasonable account export and deletion tools even where a specific statutory right is not yet in force.
For end-customer data controlled by a business using QEMRA, the end customer should normally contact that business first. QEMRA will assist the business with appropriate rights requests.
14. Children and minors
QEMRA accounts are limited to people aged 18 or older.
A business customer may use QEMRA to communicate with or process data relating to minors only where it has obtained any required parent/guardian consent or has another valid lawful basis and complies with applicable law. QEMRA is not designed for children to create their own accounts.
15. Automated processing
QEMRA may automate routine messaging, workflow routing and business operations. QEMRA does not permit customers to rely on QEMRA alone for fully automated high-impact decisions such as medical diagnosis, emergency response, legal advice, lending/credit, insurance eligibility or employment decisions without appropriate human oversight.
Where human support is offered by the business, QEMRA is designed to provide a clear path to human handoff.
16. Account deletion and export
Before deleting an account, customers may request or generate a reasonable export of their business data using CSV/JSON for structured data and ZIP archives for attachments where applicable.
Deletion is scheduled within 30 days, subject to legal, tax, fraud-prevention, security and dispute-retention obligations. Some deleted data may remain temporarily in encrypted backups until normal backup rotation completes.
17. Communications
Essential account, billing, security and service notices may be sent as needed.
Product updates, offers, tips and promotional emails are sent only where appropriate consent or another permitted basis exists, and include clear opt-out controls.
18. Changes to this policy
We normally provide at least 30 days’ notice of material changes through email and an in-app notice. Shorter notice may be used when required by law or for urgent legal or security changes.
If translated versions are provided, the English version controls if there is a conflict.
19. Contact and grievances
Grievance Officer: Grievance Officer Email: noreply@qemra.vmnexa.co.in Customer care / grievance phone: {{CUSTOMER_CARE_PHONE}} Address: 4-340, Salipeta, Opp. HDFC Bank, Malikipuram, Dr. B.R. Ambedkar Konaseema District, Andhra Pradesh, India – 533253
Formal grievances are targeted for acknowledgment within 48 hours and resolution or a substantive response within 30 days, unless a shorter period is required by law.
