comments in the source. Get it reviewed before onboarding real customers. --}} Privacy Policy — Oriel Chat Engine
Oriel Chat Engine

Privacy Policy

Last updated 12 September 2026 · Oriel Inc., 599, 17B, Phase 1, Surat Nagar, Gurugram, Haryana, India

The short version.

1. Who we are, and which role we play

Oriel Chat Engine is operated by Oriel Inc. (599, 17B, Phase 1, Surat Nagar, Gurugram, Haryana, India).

This matters for understanding your rights, so we will be precise about it:

If you are… Then…
a business using Oriel Chat Engine You are the data custodian (data fiduciary) for your own customers' data. You decide what to collect and why. We are your processor: we hold and process it on your instructions, and we do not use it for our own purposes.
a customer of one of those businesses Your relationship is with that business. We process your data on their behalf. You may still contact us directly — see Data Deletion — and we will act on it, and tell the business.

2. What we collect

Data Why we hold it
WhatsApp phone number It is the address a message is sent to. Without it there is no service.
Message content
(inbound and outbound)
The conversation itself — what the customer wrote and what the business replied. Held so an agent can see the history of the conversation they are in.
Contact details and attributes
(name, email, and any custom fields a business uploads — e.g. city, order number)
Provided by the business, from its own records. Used to address the customer by name and to personalise the content of a message.
Media
(images, documents, audio, video sent in a chat)
Stored so the conversation is complete. Held in a private bucket; every view by a member of staff mints a short-lived link and is recorded in an audit log.
Booking details
(if the business uses bookings)
The appointment: who, with whom, when. A business record of a commitment that was made.
Consent state
(opted in / opted out)
So we can refuse to message somebody who told us to stop. This one is never deleted by our retention sweep — see §6.
Staff account data
(name, email, password hash, 2FA secret)
For the people who log in to the business's panel. Not customer data.

We do not sell personal data, we do not use it to train models, and we do not use one business's customer data for any other business or for our own marketing.

3. Why we process it, and on what lawful basis

Transactional and service messages — performance of a contract

Replying to a customer who wrote to you, confirming a booking they made, reminding them of an appointment they asked for. The customer initiated the interaction; the message is the service.

Marketing messages — CONSENT, and nothing else

Marketing on WhatsApp requires an explicit, WhatsApp-specific opt-in.

It cannot be a pre-ticked box. It cannot be inherited from an email list or an SMS consent. It cannot be assumed because somebody bought something. The person must have knowingly agreed to receive WhatsApp messages from that specific business. Businesses using Oriel Chat Engine agree to this in our Terms, and it is a condition of using the platform at all.

A booking is not consent to be marketed to. Somebody who books an appointment has agreed to hear about that appointment. They have not agreed to receive an offer.

4. How someone stops receiving messages

Reply STOP to any message.

That marks the contact as opted out. From that moment, the opt-out is enforced in two separate places: when a broadcast audience is built (an opted-out person is never added to it) and again at the instant of sending each individual message (so somebody who opts out during a broadcast still does not receive it). Appointment reminders and agent replies go through the same check.

You can also email support@orielpress.com and we will opt you out, and tell the business.

5. Who we share it with

These are our sub-processors. This is the whole list.

Who What they get Why
Meta Platforms
(WhatsApp Cloud API)
Phone numbers, message content, media. They are WhatsApp. A message cannot be delivered without passing through them. Governed by Meta's own terms and privacy policy.
Cloudflare
(R2 object storage)
Media files. Where images, documents and voice notes are stored. The bucket is private; access is by short-lived signed link only, minted per view and audited.
Google
(Calendar API)
Booking times, and the customer's name and phone number in the calendar event. Only if the business chooses to connect a Google Calendar. So the appointment appears in the calendar the business actually uses. If no calendar is connected, nothing is sent to Google at all.
Hetzner The database (everything above). The servers this runs on.
Resend A business administrator's email address. To email operational alerts to the business (e.g. "your WhatsApp number's quality rating has dropped"). No customer data is sent.

We do not share personal data with anybody else — no data brokers, no advertisers, no analytics vendor with access to message content.

Some of these providers process data outside India. We use them because the service cannot be delivered otherwise — WhatsApp messages necessarily pass through Meta's infrastructure.

6. How long we keep it

Message history: 90 days.

Message content and the media attached to it are permanently deleted 90 days after the message was sent or received — from our database and from the storage bucket. This runs automatically. It is not a promise to delete on request; it happens on its own.

A business can ask us to set a different period for their account — longer, if they are under a legal hold or a statutory retention obligation in their industry. That is a per-business setting, and where one is in effect, this is the paragraph that stops being accurate for that business's data.

What is not deleted by that sweep, and why

Kept Why
Your opt-out This is the important one. If we deleted the record that you asked us to stop, the next time the business uploaded its contact list you would be re-added as a fresh contact — with no opt-out — and we would message you again. Keeping the fact that you said no is how we keep saying no. It is the minimum we can hold to honour your own instruction.
Bookings A business record: an appointment that was made, and kept or not kept. Deleting it does not protect your privacy; it loses the business its own diary. Ask us and we will delete it — see below.
Audit logs The record of who accessed what, and of what we deleted and when. An audit trail that deletes itself cannot evidence anything — including the fact that we honoured your deletion request. It holds identifiers and actions, not message content.

If you want all of it gone, including the above, ask — that is what Data Deletion is for.

7. Deleting your data

Email support@orielpress.com with the phone number the messages were sent to.

We will confirm within 7 days and complete the deletion within 30 days. This includes message content, media (including the files in storage), contact details and bookings.

The full procedure — what we ask for, what happens, and what we keep and why — is on the Data Deletion page.

8. Your rights

You can ask us to:

Because we are usually the processor and the business is the custodian, we may need to involve them to action a request. We will do that, and we will tell you we have.

If you are unhappy with how we have handled a request, write to support@orielpress.com and we will treat it as a grievance and respond.

9. Security

No system is perfectly secure, and we will not pretend otherwise. If we discover a breach affecting your data, we will tell the affected businesses and, where required, the authority.

10. Children

Oriel Chat Engine is a tool for businesses. It is not intended for children, and we do not knowingly process the data of anybody under 18. If you believe we hold a child's data, email us and we will delete it.

11. Changes

If we change this policy in a way that materially affects how we handle personal data, we will update the date at the top and notify the businesses using the platform.

12. Contact

Oriel Inc.

599, 17B, Phase 1
Surat Nagar
Gurugram, Haryana
India

support@orielpress.com