Privacy Policy
Effective date: 12 August 2026
This Privacy Policy describes how Signity Solutions("Signity," "we," "us," or "our") collects, uses, shares, and protects personal information in connection with SalesForge, our B2B sales outreach and engagement platform available at salesforge.signity.solutions, and any related websites, applications, APIs, and services (collectively, the "Services").
Signity Solutions is a software company headquartered in India.
If you do not agree with this Privacy Policy, please do not use the Services. Questions can be sent to parmod@signitysolutions.com.
1. Who This Policy Covers, and Our Role
The Services are business-to-business (B2B) tools. This Policy applies to:
- Customers and their users — businesses that sign up for the Services and the individual team members (workspace admins, agents) they authorize to use them.
- Prospects and contacts — individuals whose contact details and communications are processed through the Services because a Customer uploads, imports, enriches, or messages them (via email, WhatsApp, LinkedIn, or voice calls).
- Website visitors — people who visit our marketing or product websites.
Controller / processor distinction. For account data of Customers and their users, and for our own website and billing operations, Signity acts as a data controller. For prospect and contact data that Customers upload to or process through the Services — including message content sent and received through connected channels — Signity acts primarily as a data processor / service provideron the Customer's behalf and under the Customer's instructions. Each Customer is responsible for having a lawful basis (and, where required, consent) to contact its prospects and for responding to prospects' privacy requests; we support Customers in doing so as described in this Policy. If you are a prospect who received a message through our platform, the business that contacted you is the controller of your data, and you should direct requests to them in the first instance — though you may also contact us and we will assist or forward your request.
2. Information We Collect
2.1 Information Customers and users provide to us
- Account and profile data: name, work email address, password (stored hashed), company name, job title, workspace settings.
- Billing data: billing contact details and transaction records. Full payment card details are collected and processed by our payment processor and are not stored on our servers.
- Connected account credentials: when a workspace admin connects third-party accounts (Google or Microsoft email accounts, Slack, Twilio, Meta WhatsApp Business, LinkedIn, Apollo, and similar integrations), we receive and store OAuth tokens, API keys, and related identifiers. These credentials are stored encrypted in our databaseand are used only to operate the integration on the Customer's behalf.
- Support communications: messages you send to our support or sales teams.
2.2 Prospect and contact data processed on Customers' behalf
Customers may upload, import, sync, or enrich data about their prospects and leads, including: names, email addresses, phone numbers (including WhatsApp numbers), job titles, company details, LinkedIn profile URLs, notes, tags, custom fields, and engagement history. Customers may also enable data enrichment integrations (such as Apollo) that retrieve additional business-contact information about prospects from third-party providers under the Customer's own agreement with that provider.
2.3 Communications content and metadata
To provide multi-channel outreach, sequences, and the unified inbox ("unibox"), we process the content and metadata of communications sent and received through connected channels, including:
- Email: message bodies, subjects, headers, recipients, open/click/bounce/reply events.
- WhatsApp: message content, template messages, media, phone numbers, delivery/read statuses, and inbound replies (see Section 4 for details on Meta Platform Data).
- LinkedIn: messages and connection activity performed through connected accounts.
- Voice calls: call metadata (numbers, duration, outcome) and, where enabled by the Customer, call recordings and transcripts. Customers are responsible for complying with call-recording consent laws applicable to their calls.
- Opt-out signals:unsubscribe requests and opt-out keywords (e.g., "STOP"), which we record on suppression lists so that opted-out recipients are not contacted again through the Services.
2.4 Information collected automatically
When you use the Services or visit our websites, we automatically collect log and device data: IP address, browser type and version, operating system, device identifiers, referring URLs, pages viewed, feature usage, timestamps, and error/diagnostic data. We collect some of this through cookies and similar technologies (see Section 8).
2.5 Information from third parties
We may receive information from integration providers the Customer connects (e.g., email providers, Meta, Twilio, Apollo, CRMs), from publicly available sources, and from service providers that help us operate the Services.
We do not intentionally collect sensitive personal information (such as health data, biometric data, or government identifiers), and Customers agree not to upload such data to the Services.
3. How We Use Information
We use the information described above to:
- Provide, operate, and maintain the Services, including sending and receiving messages across connected channels on the Customer's behalf and displaying them in the unified inbox;
- Execute campaigns and sequences configured by Customers, including scheduling, throttling, delivery tracking, and reply detection;
- Provide AI-powered features, such as message personalization and drafting assistance. Prospect and message data submitted to AI features is processed by us and, where applicable, by third-party AI/LLM providers acting as our subprocessors under contractual confidentiality and data-use restrictions. We select AI providers whose service terms commit that content submitted through their APIs is not used to train their generalized models;
- Honor opt-outs and maintain suppression lists;
- Authenticate users, secure accounts, prevent fraud and abuse, and enforce our terms and acceptable-use rules (including anti-spam rules);
- Provide customer support and respond to inquiries;
- Process payments and manage subscriptions;
- Analyze usage to improve, debug, and develop the Services (using aggregated or de-identified data where practicable);
- Send administrative and, with any required consent, marketing communications about our own Services (you can opt out at any time);
- Comply with legal obligations and protect our legal rights.
We do notsell personal information, and we do not use prospect data processed on a Customer's behalf for our own advertising.
4. WhatsApp and Meta Platform Data
This section applies when a Customer connects a WhatsApp Business Account (WABA) to the Services — either through Twilio or directly through the Meta WhatsApp Business Platform (Cloud API) using Meta's Embedded Signup flow (including Coexistence setups where the Customer continues to use the WhatsApp Business app alongside the API).
4.1 What we access via Meta APIs
When a Customer completes Embedded Signup and connects their own Meta business assets, we receive and store:
- Access tokens for the Customer's WhatsApp Business Account (stored encrypted in our database);
- Business asset identifiers: WhatsApp Business Account ID (WABA ID), phone number IDs, business phone numbers, display names, and message template metadata;
- Message data exchanged via the Cloud API:outbound messages we send on the Customer's behalf, inbound replies from prospects, delivery and read statuses, and — in Coexistence setups — message echoes of replies the Customer sends from their own WhatsApp Business app, so the conversation can be shown in the unified inbox;
- Recipient phone numbers and profile names as provided by the WhatsApp Business Platform in webhook payloads.
4.2 How we use it
We use this data solely to provide the Services to the Customer that connected the account: sending approved template and session messages, receiving and displaying replies, tracking delivery status, syncing templates, maintaining conversation history in the inbox, and honoring opt-outs. Recipients who reply with an opt-out keyword (such as "STOP") are added to the Customer's suppression list and excluded from further outreach through the Services.
We do not use WhatsApp message content or Meta Platform Data for advertising, we do not sell it, and we do not share it with third parties except the subprocessors needed to host and operate the Services (Section 6) or as required by law.
4.3 Compliance with Meta terms
Our processing of data obtained through Meta's platform is governed by, and we require our Customers to comply with, the Meta Platform Terms and Developer Policies, the WhatsApp Business Terms of Service, the WhatsApp Business Messaging Policy, and (where applicable) the Meta/WhatsApp Business Data Processing Terms. Customers are responsible for obtaining any opt-ins required by WhatsApp's policies before messaging recipients.
4.4 Retention and deletion of Meta Platform Data
We retain Meta Platform Data only as long as needed to provide the Services to the relevant Customer. When a Customer disconnects their WhatsApp integration or deletes their workspace, we delete the stored access tokens and, within a commercially reasonable period not exceeding 30 days, delete or de-identify the associated WhatsApp message data, subject to residual copies in encrypted backups that are purged on our standard backup rotation and to any retention required by law. If Meta notifies us that a user or business has removed our app's access, we honor the deletion obligations in Meta's Platform Terms. See also Section 11 (Data Deletion) and our Data Deletion Instructions.
5. Legal Bases for Processing
Where the EU/UK General Data Protection Regulation (GDPR) applies and we act as controller, we rely on:
- Contract performance — to provide the Services to Customers and their users;
- Legitimate interests — to secure and improve the Services, prevent abuse, and market our own Services to business contacts (balanced against your rights);
- Consent — where required, e.g., for certain cookies or marketing communications (withdrawable at any time);
- Legal obligation — to comply with applicable law.
Where India's Digital Personal Data Protection Act, 2023 (DPDP Act)applies, we process personal data on the basis of the data principal's consent or for legitimate uses recognized by the Act, and we act as a Data Processor for Customer-provided prospect data with the Customer as the Data Fiduciary.
Where we process prospect data as a processor, the Customer is responsible for establishing the legal basis for the outreach it conducts.
6. How We Share Information; Subprocessors
We share personal information only as follows:
- Subprocessors / service providers, under contracts restricting their use of the data, including: cloud hosting and storage providers that host our infrastructure and databases; Meta Platforms (WhatsApp Business Platform / Cloud API) — to send and receive WhatsApp messages for connected accounts; Twilio— for WhatsApp (via Twilio) and voice calling functionality; email delivery providers and the Customer's own connected email accounts (Google/Microsoft); AI/LLM providers — to power AI personalization and drafting features; data enrichment providers (e.g., Apollo) — only when the Customer enables the integration; and payment processors, analytics, and customer-support tooling.
- Integration providers the Customer connects:when a Customer connects a third-party account (Slack, LinkedIn, CRM, etc.), data flows to and from that provider as directed by the Customer, under the provider's own terms and privacy policy.
- Within the Customer's workspace:information is visible to other authorized users of the same workspace according to the Customer's settings.
- Legal and safety: to comply with law, respond to lawful requests, enforce our terms, or protect the rights, safety, and property of Signity, our Customers, or others.
- Business transfers:in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy's protections.
We maintain a current list of subprocessors, available on request at parmod@signitysolutions.com.
7. International Data Transfers
We are based in India, and our subprocessors may process data in other countries (including the United States and the European Union). Where we transfer personal data internationally as a controller or processor, we use appropriate safeguards required by applicable law, such as the European Commission's Standard Contractual Clauses for transfers of EU/UK data, contractual data-protection commitments with subprocessors, and technical measures such as encryption.
8. Cookies and Similar Technologies
We use cookies and similar technologies (such as local storage and pixels) to:
- Keep you signed in and remember preferences (strictly necessary);
- Measure usage and performance of the Services (analytics);
- Track email opens and link clicks in messages sent by Customers through the Services (a tracking pixel and redirect links), where the Customer enables tracking.
You can control cookies through your browser settings; disabling strictly necessary cookies may break parts of the Services. Where required by law, we request consent for non-essential cookies. We do not currently respond to "Do Not Track" browser signals.
9. Data Retention
We retain personal information for as long as needed to provide the Services and for legitimate business or legal purposes:
- Account data: for the life of the account and up to 90 days after account deletion, except records we must keep longer (e.g., billing/tax records);
- Prospect data and message content (processed for Customers):for as long as the Customer's workspace retains it; deleted when the Customer deletes it or closes their account, subject to the deletion window in Section 11;
- Suppression/opt-out lists: retained longer where needed to keep honoring opt-outs;
- Connected-account credentials (OAuth tokens, API keys): until the integration is disconnected or the account is deleted, then deleted;
- Logs and diagnostics: for a limited operational period;
- Backups: encrypted backups are purged on a rolling schedule.
When retention ends, we delete or irreversibly de-identify the data.
10. Security
We implement technical and organizational measures designed to protect personal information, including: encryption in transit (TLS); encryption of stored third-party credentials and access tokens; role-based access controls and workspace isolation; least-privilege access for staff; logging and monitoring; and secure software development practices.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a personal data breach, we will notify affected Customers and regulators as required by applicable law (including the GDPR and the DPDP Act).
11. Data Deletion
Step-by-step instructions are published on our Data Deletion Instructions page. In summary, you can request deletion of your personal data at any time:
- Account deletion (Customers and users): a workspace admin can request deletion of the workspace/account by emailing parmod@signitysolutions.com from the email address associated with the account. Upon a verified request, we deactivate the account and delete the associated personal data — including connected-account credentials, WhatsApp/Meta Platform Data, prospect data, and message history — within 30 days, except data we must retain for legal, billing, security, or dispute-resolution purposes and residual copies in encrypted backups that are purged on our standard rotation.
- WhatsApp / Meta users and businesses:if you connected a WhatsApp Business Account through Meta's Embedded Signup and want data obtained via Meta's platform deleted, disconnect the integration in the product and/or email parmod@signitysolutions.comwith the subject "Meta Data Deletion Request," including your workspace name and WABA/phone number ID if known. We also honor deletion requests received from Meta.
- Prospects/message recipients:you may ask the business that contacted you to delete your data, reply with an opt-out keyword (e.g., "STOP") to stop WhatsApp messages, use the unsubscribe link in emails, or email us at parmod@signitysolutions.com; we will forward the request to the relevant Customer and assist with deletion as their processor.
We will confirm completion of verified deletion requests and may ask for information necessary to verify your identity before acting.
12. Your Rights
Depending on where you live, you may have rights to:
- Access the personal data we hold about you and receive a copy;
- Correct inaccurate or incomplete data;
- Delete your data (see Section 11);
- Restrict or object to certain processing, including direct marketing;
- Data portability — receive your data in a structured, machine-readable format;
- Withdraw consent at any time, without affecting prior processing;
- Complain to a supervisory authority — your local EU/UK data protection authority, or the Data Protection Board of India under the DPDP Act;
- Under the DPDP Act, nominate another individual to exercise your rights in case of death or incapacity, and use available grievance redressal — contact our Grievance Officer at parmod@signitysolutions.com.
To exercise these rights, email parmod@signitysolutions.com. We respond within the timelines required by applicable law. If your request concerns data we process on behalf of a Customer (e.g., you are a prospect), we may refer the request to that Customer and assist them in responding.
13. Children
The Services are intended for business users aged 18 or older. We do not knowingly collect personal information from anyone under 18, and Customers must not use the Services to contact minors. If you believe we have collected data from a person under 18, contact us at parmod@signitysolutions.com and we will delete it.
14. Third-Party Services
The Services interoperate with third-party platforms (Meta/WhatsApp, Google, Microsoft, LinkedIn, Slack, Twilio, Apollo, and others) that Customers choose to connect. Those providers process data under their own privacy policies, which we encourage you to review. We are not responsible for the privacy practices of third parties.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a revised effective date and, for material changes, notify Customers by email or in-product notice before the changes take effect. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.
16. Contact Us
Signity Solutions
Email: parmod@signitysolutions.com
Website: signitysolutions.com
Product: salesforge.signity.solutions