Legal Document

Privacy Policy

Last Updated May 25, 2026
Effective Date May 25, 2026

This Privacy Policy describes how LIT AI Labs Private Limited ("LIT AI Labs," "Company," "we," "us," or "our"), a company incorporated under the laws of India with its registered office at 610, Venus Atlantis Corporate Park, 100 Feet Road, near Shell Petrol Pump, Prahlad Nagar, Ahmedabad, Gujarat 380015, India, collects, uses, stores, shares, and protects your personal information when you access or use our Website and Services.

01 / 18

Introduction

By accessing or using any of our Services, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree with any part of this Policy, you must immediately cease using our Services.

Our Services include, but are not limited to:

  • Bot Made Easy — Unified account management, authentication, subscription billing, and payment processing ecosystem
  • Build E-Commerce — No-code e-commerce platform supporting D2C, Multi-Vendor Marketplace, and B2B models
  • Nutrify Me AI — AI-powered health and nutrition advisory application
  • RapidSales — Sales automation platform with telephony and email integration
  • EzeeChatbot — AI chatbot and conversational automation platform
  • Social Butterfly — Social media management and scheduling tool
Important
We reserve the right to add, modify, rebrand, discontinue, merge, or launch new products and services under the LIT AI Labs ecosystem at any time. This Policy shall automatically apply to all such products unless a separate policy is published for that specific product.
02 / 18

Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to name, email address, phone number, IP address, device identifiers, and any data defined as "personal data" under applicable law.
  • "Data Principal" means the individual to whom the Personal Data relates, as defined under the Digital Personal Data Protection Act, 2023.
  • "Data Fiduciary" means the entity that determines the purpose and means of processing Personal Data. LIT AI Labs acts as a Data Fiduciary.
  • "Processing" includes any operation performed on Personal Data, including collection, storage, use, disclosure, transfer, modification, or deletion.
  • "Third-Party Platform Data" means any data received from third-party platforms, including but not limited to Meta Platforms, Inc. ("Meta"), through APIs, integrations, or user-authorized connections.
  • "Meta Platform Data" means any data obtained from or through Meta's APIs, SDKs, or platform integrations, including data from Facebook, Instagram, WhatsApp Business, and Messenger.
  • "User" or "you" means any individual or entity that accesses or uses our Website or Services.
03 / 18

Information We Collect

3.1 Account and Identity Information

When you create an account through Bot Made Easy or interact with any of our Services, we may collect:

  • Full name
  • Email address
  • Phone number
  • Company or business name
  • Business type and category
  • GSTIN (Goods and Services Tax Identification Number), if voluntarily provided
  • Profile photograph (if uploaded)
  • Password (stored in encrypted/hashed form)
  • Any additional information you voluntarily provide during onboarding, demo requests, or contact form submissions

3.2 Payment and Billing Information

When you subscribe to paid plans or make purchases, we collect:

  • Billing name and address
  • Subscription plan details
  • Transaction history and invoice records
  • Payment method type (e.g., credit card, debit card, UPI, net banking)
Security Note
We do not directly store your full credit card numbers, CVV, or bank account details. All payment processing is handled by Razorpay, which is PCI-DSS compliant. We receive only tokenized references, transaction confirmations, and partial payment identifiers.

3.3 Usage and Analytics Data

We automatically collect information about how you interact with our Services, including pages visited, features used, actions taken, session duration, referral source, search queries, error logs, and feature adoption metrics.

3.4 Device and Technical Information

We collect technical information from devices used to access our Services:

  • IP address, browser type and version
  • Operating system and version, device type
  • Screen resolution, unique device identifiers
  • Language preferences, time zone

3.5 Communication Data

When you contact us or use communication features, we may collect email correspondence, support ticket contents, chat messages and transcripts, phone call metadata (if applicable), and feedback or survey responses.

3.6 Third-Party Platform Data

When you connect third-party accounts to our Services (e.g., social media accounts, messaging platforms), we may receive data authorized by you and permitted by the third-party platform, including social media page and account information, messaging conversation metadata, audience and engagement analytics, content scheduling and posting data, and authentication tokens (stored encrypted).

3.7 Meta Platform Data

Certain Services (including EzeeChatbot, RapidSales, and Social Butterfly) integrate with Meta Platform APIs. When you authorize a connection to your Meta account(s), we may receive:

  • Facebook Page information (name, ID, category, permissions)
  • Instagram Business/Creator account information
  • WhatsApp Business account information and messaging data
  • Messenger conversation data
  • User profile information authorized through Facebook Login or Instagram Login
  • Page and account insights and analytics
WhatsApp Business API Consent
Where our Services facilitate WhatsApp messaging on your behalf, end-user recipients must have explicitly opted in to receive messages from you. You are responsible for obtaining and maintaining valid opt-in consent from recipients. Recipients may opt out at any time, and you must honor such opt-out requests immediately.

3.8 Health and Nutrition Data (Nutrify Me AI)

If you use Nutrify Me AI, you may voluntarily provide health and nutrition-related information (such as dietary preferences, health goals, allergies, or lab report images). This data is processed transiently by AI models to generate nutritional recommendations and is not permanently stored on our servers after processing.

Disclaimer
Nutrify Me AI is not a medical device, medical service, or substitute for professional medical advice. Health data provided to Nutrify Me AI is excluded from analytics processing and is never shared with advertisers or third parties for marketing purposes.

3.9 Information from Other Sources

We may receive information about you from publicly available sources (business registries, company websites), our business partners and affiliates, third-party identity verification services (when required for compliance), and other users who refer you or share your information with us.

04 / 18

How We Use Your Information

4.1 Service Delivery and Operations

  • Creating and managing your unified account via Bot Made Easy
  • Processing subscriptions, payments, invoices, and refunds through Razorpay
  • Providing, maintaining, and improving our products and features
  • Enabling integrations with third-party services you authorize
  • Providing customer support and responding to inquiries

4.2 Communication

  • Sending transactional notifications (account verification, payment confirmations, security alerts)
  • Sending service updates, feature announcements, and product news
  • Sending marketing communications (only with your consent, with opt-out available)
  • Responding to your inquiries, feedback, and support requests

4.3 Analytics, Improvement, and AI Training

  • Analyzing usage patterns to improve product features and user experience
  • Conducting internal research and development
  • Generating aggregated, anonymized, or de-identified analytics and reports
  • Training and improving AI models and algorithms (using anonymized and aggregated data only; your identifiable Personal Data is never used for AI training without explicit separate consent)

4.4 Safety, Security, and Compliance

  • Detecting, preventing, and addressing fraud, abuse, security incidents, and technical issues
  • Verifying your identity where required
  • Complying with applicable laws, regulations, legal processes, and governmental requests
  • Enforcing our Terms and Conditions, acceptable use policies, and other agreements
  • Protecting the rights, property, and safety of LIT AI Labs, our users, and the public

4.5 Legal and Business Purposes

  • Exercising or defending legal claims
  • Facilitating corporate transactions (mergers, acquisitions, asset sales, reorganizations)
  • Maintaining internal records for audit and compliance purposes
  • Fulfilling contractual obligations to you and our partners
05 / 18

Legal Basis for Processing

We process your Personal Data based on one or more of the following legal bases, depending on the context and applicable jurisdiction:

Legal Basis Description
Consent Where you have provided explicit, informed consent for specific processing activities (e.g., marketing communications, Meta account connections). You may withdraw consent at any time.
Contractual Necessity Where processing is necessary to perform our contract with you or to take pre-contractual steps at your request (e.g., account creation, service delivery).
Legitimate Interest Where processing is necessary for our legitimate business interests (e.g., analytics, security, fraud prevention, product improvement), balanced against your rights and interests.
Legal Obligation Where processing is required to comply with applicable laws, regulations, or court orders (e.g., tax record retention, law enforcement requests).
Vital Interest Where processing is necessary to protect your vital interests or those of another person (rare, emergency situations only). Note: This legal basis applies under GDPR only; it is not a recognized ground under the DPDP Act, 2023.

For users in India, processing is governed by the Digital Personal Data Protection Act, 2023, and the Digital Personal Data Protection Rules, 2025. For users in the EU/EEA, GDPR applies. For California residents, CCPA/CPRA applies. See Section 10 for jurisdiction-specific rights.

06 / 18

Data Sharing & Disclosure

Our Commitment
We do not sell your Personal Data.

6.1 Service Providers and Sub-Processors

Provider Purpose Data Processed
Amazon Web Services (AWS) Cloud infrastructure and hosting (ap-south-1, Mumbai, India) All data stored and processed on our platform
Razorpay Payment processing, subscription billing Payment details, billing information, transaction data
Google Analytics / Firebase Analytics Product analytics and crash reporting Anonymized usage data, device information
MSG91 SMS and OTP delivery Phone number, message content
Twilio / Plivo Telephony and voice services (RapidSales) Phone numbers, call metadata
Meta Platforms WhatsApp Business API, Messenger API messaging integrations Message content, user identifiers as authorized
OpenAI / Google (Gemini) / Anthropic (Claude) AI processing (Nutrify Me AI and other AI features) Anonymized or transient query data only; no persistent storage of identifiable data by AI providers
Email Delivery Providers Transactional and marketing email delivery Email addresses, email content

6.2 Legal and Compliance Disclosures

We may disclose your information when we believe in good faith that disclosure is necessary to comply with applicable law, enforce our Terms and Conditions, detect or prevent fraud and security issues, or protect the rights, property, or safety of LIT AI Labs, our users, or the public.

6.3 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, asset sale, or similar corporate transaction, your Personal Data may be transferred to the successor entity. We will provide notice before your Personal Data becomes subject to a different privacy policy.

6.4 With Your Consent

We may share your information with third parties when you have explicitly consented to or directed such sharing.

6.5 Aggregated and Anonymized Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you, without restriction. Once data has been irreversibly anonymized, it is no longer considered Personal Data under this Policy or applicable law.

07 / 18

Meta Platform Data — Special Provisions

This section applies specifically to data obtained through Meta's APIs and platform integrations and is designed to comply with Meta's Platform Terms, Developer Policies, and Data Use Requirements.

7.1 How We Use Meta Platform Data

We use Meta Platform Data only to:

  • Provide the specific Services you have requested and authorized (e.g., managing your Facebook Pages, scheduling Instagram posts, sending WhatsApp messages, enabling Facebook/Instagram Login)
  • Display your authorized social media content and analytics within our platform
  • Facilitate messaging through WhatsApp Business API and Messenger API as directed by you

7.2 Restrictions on Meta Platform Data

We do not:

  • Sell Meta Platform Data to any third party
  • Use Meta Platform Data for purposes unrelated to the Services you have authorized
  • Transfer Meta Platform Data to any data broker, advertising network, or data reseller
  • Use Meta Platform Data to build or augment user profiles for advertising purposes not authorized by you
  • Use Meta Platform Data to discriminate against or target individuals based on protected characteristics
  • Store Meta Platform Data longer than necessary to provide the requested Services

7.3 Meta Platform Data Retention and Deletion

  • We retain Meta Platform Data only for as long as necessary to provide the Services you have authorized, plus any legally required retention period.
  • When you disconnect your Meta account from our Services, we will delete all Meta Platform Data associated with that connection within 30 days, except where retention is required by law.
  • You may request deletion of your Meta Platform Data at any time by contacting us (see Section 12).
  • If Meta revokes our access to Meta Platform Data or requests deletion, we will comply promptly.

7.4 Meta Platform Data Security

Meta Platform Data is protected by the same security measures described in Section 8 of this Policy, including encryption in transit, access controls, and regular security reviews.

7.5 Changes to Meta Data Use

If we materially change how we use Meta Platform Data, we will notify you and obtain your renewed consent before implementing such changes.

08 / 18

Data Security

We implement industry-standard technical and organizational measures to protect your Personal Data against unauthorized access, alteration, disclosure, or destruction.

8.1 Technical Measures

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher (HTTPS)
  • Access Controls: Role-based access control (RBAC) with least-privilege principles; multi-factor authentication for administrative access
  • Infrastructure Security: Hosted on AWS (ap-south-1, Mumbai, India) with enterprise-grade security controls, including network firewalls, intrusion detection, and DDoS protection
  • Password Security: User passwords are hashed using industry-standard algorithms; plain-text passwords are never stored
  • Token Security: Third-party API tokens and credentials are stored encrypted
  • Monitoring: Continuous security monitoring, logging, and alerting for suspicious activities

8.2 Organizational Measures

  • Confidentiality agreements with all employees and contractors who access Personal Data
  • Regular security awareness training for staff
  • Incident response and breach notification procedures
  • Periodic access reviews and privilege audits
  • Vendor security assessments for sub-processors

8.3 Limitations

Please Note
While we strive to use commercially reasonable means to protect your Personal Data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security and shall not be liable for any unauthorized access, breach, or data loss to the extent caused by factors beyond our reasonable control.
09 / 18

Data Retention

9.1 General Retention Principles

We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, plus any additional period required by applicable law:

  • Active Account Data: Retained for as long as your account remains active
  • Post-Termination: Upon account deletion or termination, we retain essential data for 3 years (or longer as required by law) for legal defense, dispute resolution, fraud prevention, and regulatory compliance
  • Payment and Financial Records: Retained for a minimum of 8 years from the date of the transaction, as required under Indian tax and financial regulations
  • Communication Records: Support tickets and correspondence retained for 3 years after last interaction
  • Analytics Data: Aggregated analytics data may be retained indefinitely in anonymized form
  • Meta Platform Data: Retained as described in Section 7.3

9.2 Automatic Deletion

After the applicable retention period expires, Personal Data is securely deleted or irreversibly anonymized. Anonymized data is no longer Personal Data and may be retained and used indefinitely for analytics, research, and business purposes.

10 / 18

Your Rights

Depending on your jurisdiction, you may have the following rights regarding your Personal Data:

10.1 Rights Under Indian Law (DPDP Act, 2023 & Rules, 2025)

  • Right to Access: Request confirmation of whether we process your Personal Data and obtain a summary of such data.
  • Right to Correction: Request correction or completion of inaccurate or incomplete Personal Data.
  • Right to Erasure: Request deletion of your Personal Data, subject to our legal retention obligations.
  • Right to Nominate: Nominate another individual to exercise your rights in the event of your death or incapacity.
  • Right to Grievance Redressal: Lodge a complaint with our Grievance Officer or the Data Protection Board of India.

10.2 Rights Under GDPR (EU/EEA Users)

Note
Our Services are primarily directed at users in India. We do not currently maintain an establishment in the EU/EEA and do not appoint an EU Representative under GDPR Article 27. If we begin systematically offering Services to EU/EEA residents or monitoring their behavior, we will appoint an EU Representative and update this section accordingly.

In addition to the rights above, EU/EEA users also have:

  • Right to Portability: Receive your Personal Data in a structured, commonly used, machine-readable format.
  • Right to Restriction: Request restriction of processing in certain circumstances.
  • Right to Object: Object to processing based on legitimate interests, including direct marketing.
  • Right to Withdraw Consent: Withdraw consent at any time without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint: File a complaint with your local data protection supervisory authority.

10.3 Rights Under CCPA/CPRA (California Residents)

  • Know: What Personal Data we collect, use, disclose, and sell (we do not sell Personal Data).
  • Delete: Request deletion of Personal Data, subject to legal exceptions.
  • Opt-Out: Opt out of the sale or sharing of Personal Data (not applicable, as we do not sell or share Personal Data for cross-context behavioral advertising).
  • Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
  • Correct: Request correction of inaccurate Personal Data.

10.4 How to Exercise Your Rights

Subject Privacy Rights Request — [Your Name]
Response Within 30 days (Indian law & GDPR) or 45 days (CCPA)
11 / 18

Account & Data Deletion

11.1 Account Deletion

You may request complete deletion of your account and associated Personal Data by:

  1. Email Request: Sending a written request to prakhar.d@hashtechy.com with the subject line Account Deletion Request

Upon receiving a verified account deletion request:

  • We will confirm receipt within 48 hours
  • Your account will be deactivated immediately upon confirmation
  • All Personal Data will be permanently deleted within 30 days of confirmation, except where retention is required by law
  • All connected third-party integrations (including Meta Platform connections) will be disconnected, and associated third-party data will be deleted within 30 days
  • Any active subscriptions will be terminated. No refunds will be issued for the remaining subscription period unless otherwise required by applicable law

11.2 Data Deletion (Without Account Deletion)

You may request deletion of specific categories of Personal Data without deleting your entire account. Contact us with details of the specific data you wish deleted.

11.3 Meta Platform Data Deletion

You may request deletion of Meta Platform Data specifically by:

  • Disconnecting your Meta account(s) from within the applicable Service (EzeeChatbot, RapidSales, Social Butterfly, or any other Meta-integrated Service)
  • Sending a written request to prakhar.d@hashtechy.com with the subject line Meta Data Deletion Request
  • Revoking permissions via your Meta account settings at facebook.com/settings → Business Tools

11.4 Callback URL for Meta Data Deletion

For Meta platform integrations, we provide a data deletion callback endpoint at https://litailabs.com/meta/data-deletion. When a user removes our app from their Meta account, Meta sends a deletion request to our callback URL, and we process the deletion within 30 days. Users can verify deletion status using the confirmation code provided.

11.5 Effects of Deletion

  • You will lose access to all Services, transaction history, and saved configurations
  • Any data that has been irreversibly anonymized prior to the deletion request will not be deleted, as it is no longer Personal Data
  • Certain data may be retained in encrypted backup systems for up to 90 days from the deletion date before being purged from backup cycles
  • We may retain limited data as required by law (see Section 9)
12 / 18

Cookies & Tracking Technologies

12.1 Types of Cookies Used

Category Purpose Duration
Strictly Necessary Essential for website functionality, authentication, and security Session / Persistent
Performance & Analytics Understanding how visitors use our Services (via Google Analytics, Firebase) Up to 26 months
Functionality Remembering your preferences and settings Up to 12 months

12.2 Third-Party Cookies

Our Services may include cookies set by third-party analytics and functionality providers. We do not control these cookies and recommend reviewing the privacy policies of these third parties.

12.3 Managing Cookies

You may manage or disable cookies through your browser settings. Disabling certain cookies may affect the functionality of our Services. By continuing to use our Services after being notified of our cookie use, you consent to the placement of non-essential cookies, except where applicable law requires explicit opt-in consent (e.g., EU/EEA under ePrivacy Directive).

13 / 18

International Data Transfers

13.1 Primary Storage

Your Personal Data is primarily stored on servers located in India (AWS ap-south-1, Mumbai). However, in the course of providing our Services, your data may be transferred to and processed in jurisdictions outside India where our sub-processors operate.

13.2 Safeguards for International Transfers

Where Personal Data is transferred outside your jurisdiction, we ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (for EU/EEA data)
  • Data processing agreements with all sub-processors incorporating appropriate security and confidentiality obligations
  • Compliance with cross-border transfer mechanisms recognized under the DPDP Act, 2023

13.3 Data Processing Agreement

For business customers and partners requiring a formal Data Processing Agreement (DPA) or Standard Contractual Clauses, please contact us at prakhar.d@hashtechy.com.

14 / 18

Children's Privacy

Our Services are not directed to individuals under the age of 18 years. We do not knowingly collect Personal Data from children under 18. If we become aware that we have inadvertently collected Personal Data from a child under 18, we will take immediate steps to delete such data.

If you believe that a child under 18 has provided us with Personal Data, please contact us immediately at prakhar.d@hashtechy.com.

15 / 18

Third-Party Links & Services

Our Services may contain links to or integrations with third-party websites, platforms, and services that are not owned or controlled by LIT AI Labs. We are not responsible for the privacy practices, content, or security of any third-party services.

We encourage you to review the privacy policies of any third-party services before providing them with your information or authorizing integrations. Your use of third-party services is at your own risk.

16 / 18

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations. Changes will be effective upon posting to our Website.

  • Material Changes: For material changes, we will provide at least 15 days' prior notice via email to your registered email address, in-platform notification, or prominent notice on our Website before the changes take effect.
  • Continued Use: Your continued use of our Services after the effective date of any changes constitutes your acceptance of the updated Policy.
  • Non-Acceptance: If you do not agree with the updated Policy, you must discontinue use of our Services and may request account deletion as described in Section 11.
17 / 18

Grievance Officer

In accordance with the Information Technology Act, 2000, and the Digital Personal Data Protection Act, 2023, the Grievance Officer for LIT AI Labs is:

Prakhar Dubey
Address 610, Venus Atlantis Corporate Park, 100 Feet Road, near Shell Petrol Pump, Prahlad Nagar, Ahmedabad, Gujarat 380015, India
Acknowledgment Within 48 hours of receipt
Resolution Within 30 days of receipt, in accordance with applicable law
18 / 18

Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

LIT AI Labs Private Limited
Address 610, Venus Atlantis Corporate Park, 100 Feet Road, near Shell Petrol Pump, Prahlad Nagar, Ahmedabad, Gujarat 380015, India
Website litailabs.com
WhatsApp