Skip to main content
Enterprise Trust & Data Governance

Security & Privacy Center

How AgentIQ safeguards customer conversations, WhatsApp data, voice recordings, and business intelligence with bank-grade encryption and DPDP Act 2023 compliance.

100% Direct
Meta Cloud API Integration
DPDP 2023
Indian Data Protection Aligned
TLS 1.3 & AES
End-to-End Transit & Rest
Zero Training
Isolated Tenant Memory

Our Core Security Pillars

Engineered from the ground up for Indian SMBs, clinics, restaurants, and D2C brands.

Meta Cloud API Direct Integration

AgentIQ connects directly to Meta's official WhatsApp Cloud API endpoints using HTTPS and TLS 1.3 encrypted webhooks. We never pass customer chat payloads through unverified third-party middleware proxies or untrusted aggregators.

  • Official Meta WhatsApp Partner standards
  • Instant HMAC-SHA256 signature verification
  • Direct webhook security validation

India DPDP Act 2023 Compliance

Fully aligned with India's Digital Personal Data Protection (DPDP) Act 2023. AgentIQ mandates explicit consent workflows, strict purpose limitation, and provides automated customer data deletion rights upon request.

  • Explicit opt-in consent for messaging
  • Right-to-forget data deletion protocols
  • Purpose-bound lead processing

Zero AI Model Training Policy

Your proprietary business data is sacred. Customer conversation logs, patient appointment notes, restaurant orders, and contact details are NEVER used to train shared base LLM models or accessible to other businesses.

  • Strict tenant isolation & memory barriers
  • Zero data harvesting for public model training
  • Custom private context window isolation

AES-256 Storage & TLS 1.3 Transport

All stored lead data, booking history, and configuration details are encrypted at rest using AES-256 standards. All live data transit—including WebRTC voice streams and website chat widgets—is enforced over TLS 1.3.

  • Bank-grade AES-256 database encryption
  • High-entropy API key management
  • Real-time WebRTC audio buffer purging

Data Protection Matrix

Clear, transparent data handling protocols across every AgentIQ channel.

Data Category Encryption Standard Retention & Storage Third-Party Policy
WhatsApp Messages TLS 1.3 + Meta Cloud API Protocol 30-day active buffer / Configurable purge Never sold or shared
Voice Call Audio WebRTC Encrypted SRTP Audio Stream In-memory session / Instant buffer purge Never stored or analyzed
Customer Leads & CRM Syncs AES-256 Encryption at Rest Account lifecycle / Deleted on request Client CRM & Sheets direct sync only
Payment Intent Data PCI-DSS Tokenized Gateways (Razorpay) Zero credit card or UPI PIN storage Direct gateway processing

Security & Privacy FAQ

Answers to key questions from business owners, IT leads, and compliance teams.

Is AgentIQ compliant with India's Digital Personal Data Protection (DPDP) Act 2023?
Yes. AgentIQ strictly enforces India's DPDP Act 2023 guidelines. We ensure all customer interactions obtain explicit opt-in consent before initiating WhatsApp broadcasts or recording phone conversations, implement strict purpose limitation, and honor full data deletion requests within 48 hours.
Does AgentIQ use my customer messages to train AI models?
No. AgentIQ maintains complete tenant isolation. Your customer conversation logs, appointment details, and patient/client notes are strictly private. They are never fed into public foundation models or accessible by third-party systems.
How are Meta Cloud API WhatsApp webhooks secured?
AgentIQ connects directly to Meta Cloud API servers over TLS 1.3 encrypted HTTPS. Every incoming webhook payload is verified in real-time using HMAC-SHA256 signatures generated with your Meta App Secret, ensuring zero payload tampering or spoofed message injections.
Can our enterprise request a custom NDA or Security Questionnaire?
Absolutely. For clinics, multi-location salon chains, and D2C brands requiring formal vendor risk assessment, custom Non-Disclosure Agreements (NDAs), or enterprise SLA guarantees, our team conducts direct security reviews and compliance sign-offs.

Legal Policies & Compliance

Transparent terms, privacy rights, cookie standards, and vulnerability reporting protocols.

Terms of Service

AgentIQ operates as a 100% managed AI chatbot & voice agent provider in India. All subscriptions include complete done-for-you configuration, system maintenance, and prompt engineering. Services are provided under transparent monthly billing with a 30-day money-back guarantee.

  • Clear setup + recurring retainer billing structure
  • 30-day satisfaction & resolution guarantee
  • Official Meta Cloud API SLA compliance

Privacy Policy & DPDP 2023

We process personal data strictly to fulfill user-requested chats, phone calls, and booking workflows. Under India's Digital Personal Data Protection (DPDP) Act 2023, end users retain complete rights to access, rectify, or purge their data from AgentIQ memory within 48 hours.

  • Zero model training on customer payloads
  • Purpose-bound lead capture & CRM sync
  • Automated data deletion on request

Cookie & Tracking Policy

agentiq.co.in uses minimal session cookies essential for site navigation, security verification, and website chat widget state persistence. We do not sell tracking cookies or share cross-site advertising identifiers.

  • Essential session state cookies only
  • Zero third-party ad retargeting pixels
  • Immediate session storage clearance

Vulnerability Disclosure (VDP)

We welcome security researchers to inspect our public endpoints responsibly. If you discover a potential vulnerability in our Webhooks, Chat Widgets, or Vapi audio streams, report it directly to security@agentiq.co.in.

  • 24-hour security triage response window
  • Safe harbor protection for ethical security researchers
  • Dedicated security lead contact channel
Custom Security Review

Need a Custom NDA or Security Assessment?

Speak directly with our engineering team to review our security architecture, data governance policies, or request a signed enterprise NDA.

WhatsApp