Privacy Policy
Last updated: 5 September 2026
Avanya Fabric (“Avanya Fabric”, “we”, “us”) is operated by Kartikey Singh Solanki, a sole proprietorship based in Indore, India. We host and operate customer messaging and business software on behalf of business clients, and we operate the website avanya.tech.
Our role: we process data on our clients' instructions
Most of the personal data on our systems is not ours and is not about our own customers. It belongs to the end customers of the businesses that use Avanya Fabric.
For that data, the client business is the controller — it decides why the data is collected and what happens to it — and Avanya Fabric is the processor, acting only on that client's documented instructions. If you are a customer of a business that uses Avanya Fabric and you want to know how your data is used, that business's own privacy policy governs, and it is the right place to start.
A smaller set of data is ours as controller: the contact and billing details of the client businesses themselves, and basic website analytics. This policy covers both, and says which is which.
Data we process for our clients
- Message content and history — conversations between a client business and its customers over WhatsApp, Instagram, email and web chat, including attachments sent in those conversations.
- Contact records — the phone number, social profile name and profile picture, and any name, email address or notes the client's staff record against a customer.
- Business records — orders, invoices, inventory and similar operational records held in the client’s system for orders, stock, invoices and accounts.
- Agent accounts — names, email addresses and access rights of the client's own staff.
Data received through WhatsApp and Instagram
Where a client connects a WhatsApp Business account or an Instagram professional account, we receive message content and basic sender profile information through the WhatsApp Business Platform and the Instagram Messaging API, so that those conversations appear in the client's agent inbox and the client can reply.
We use that data for one purpose only: to deliver the messaging service to the client whose account it came from. Specifically, we do not:
- use it for advertising, ad targeting, or building advertising profiles;
- sell, rent, or licence it to anyone;
- combine it with data from other clients, or use one client's data to serve another;
- use it to train machine-learning models.
Clients authorise access to their connected WhatsApp or Instagram accounts through those platforms’ own authorisation flows. Clients can revoke our access at any time from their Meta Business settings. Revocation stops our access immediately.
Data we hold as controller
- Client contact and billing details — the name, email address, phone number and business details of the people who engage us, used to provide and invoice the service.
- Website analytics — aggregate, non-identifying information about how avanya.tech is used.
- Operational logs — technical logs needed to keep the platform running, diagnose faults and investigate abuse. These can incidentally contain identifiers such as an IP address or a message ID.
Sub-processors
We use a small number of infrastructure providers to deliver the service:
- Amazon Web Services — hosting, storage and databases, in the Mumbai region (
ap-south-1). - Cloudflare — network routing and protection for the services we expose.
- Meta Platforms — the WhatsApp Business Platform and Instagram Messaging API, for clients who connect those channels.
Client data is stored in India. We will tell affected clients before adding a sub-processor that handles their data.
Retention
We keep data processed for a client for as long as that client's service is active, and delete it when the client's workspace is closed or when the client instructs us to, except where the law requires us to keep a record. Our own invoicing and tax records are kept for the period Indian law requires. Operational logs are kept only as long as they are useful for diagnosis and abuse investigation.
Your rights
If you are a customer of a business that uses Avanya Fabric: contact that business. They decide what happens to your data, and we action deletion, correction and access requests on their instruction. If you contact us directly, we will pass your request to them and tell you we have done so — we cannot act on their data without their instruction. Our User Data Deletion page explains this route.
If you are a client of ours: you may ask us for access to, correction of, or deletion of the data we hold about you as controller, and you may ask us to export or delete the data we hold on your behalf, at any time.
Security
We store credentials securely, separately from the software’s source files. We restrict network access to the services that need to be reachable and deploy the same software versions that were tested. No system is perfectly secure, but we take reasonable technical and organisational measures to protect the data we hold, and we work to keep them current.
Children
Avanya Fabric is a business-to-business service and is not directed to children.
Changes to this policy
We may update this policy. Material changes will be reflected by updating the “Last updated” date above, and we will notify clients of changes that affect how we handle their data.
Contact us
Questions about this policy, or about data we hold? Email avanyafresh@gmail.com.
Avanya Fabric · Proprietor: Kartikey Singh Solanki · Indore, India.