Legal

Privacy Policy

Effective October 3, 2026 Last updated

The short version

  • We are a Tech Provider on the WhatsApp Business Platform. We connect clinics and businesses to WhatsApp and send messages on their behalf.
  • We only collect what we need to run that service, and we use it only for that service.
  • We do not sell personal data, and we do not use it for advertising.
  • You can ask us to access, correct or delete your data at any time by emailing hi@magicpixels.org.

1Introduction

This Privacy Policy explains how Magic Pixels (“Magic Pixels”, “we”, “us” or “our”) collects, uses, shares and protects information when you visit magicpixels.org or use our products, FollowUpWell and Sandesh (together, the “Services”).

Magic Pixels is a Tech Provider for the WhatsApp Business Platform, operated by Meta. Our Services let businesses, such as medical clinics, connect their WhatsApp Business Account to our software using Meta’s Embedded Signup, and then send messages such as appointment reminders and follow-ups to their own customers.

  • FollowUpWell automates patient follow-ups and appointment reminders for clinics over WhatsApp.
  • Sandesh helps businesses manage and send WhatsApp messages and message templates to their customers.

Our role

For information about our clients themselves (for example, the clinic’s name and the contact details of the people who sign up), Magic Pixels is the data controller (or “data fiduciary” under India’s Digital Personal Data Protection Act, 2023).

For information our clients send or receive through the Services about their own customers or patients, our client is the controller and Magic Pixels acts as a data processor on their behalf. We process that information only on our client’s instructions and only to provide the Services. If you are a patient or customer of one of our clients, we recommend you also read that business’s privacy policy, and you may direct requests about your data to them or to us.

We comply with the Meta Platform Terms and Developer Policies when handling any data we receive from Meta.

2Data we collect

From Facebook Login and WhatsApp Embedded Signup

When a business connects its WhatsApp account to our Services through Meta’s Embedded Signup flow, Meta shares the following with us, with the business’s permission:

  • Meta Business Manager (Business Portfolio) ID
  • WhatsApp Business Account (WABA) ID
  • Phone number ID and the business phone number and display name
  • Business verification status and any business verification documents submitted through the flow
  • Access tokens granting the permissions whatsapp_business_management, whatsapp_business_messaging and business_management

We use these permissions only to manage the connected WhatsApp Business Account and to send and receive messages on the business’s behalf. We do not use them to access any other part of a Facebook account.

From WhatsApp webhooks

Meta sends us event notifications (webhooks) about the WhatsApp Business Accounts connected to our Services. These include:

  • Incoming messages sent to a client’s business number, including text and any media or attachments
  • Message status updates, such as sent, delivered, read or failed
  • The phone numbers and WhatsApp profile names of people who message, or are messaged by, our clients
  • Message template details and their approval status

From our clients

When a clinic or business signs up for or uses our Services, we collect:

  • Clinic or business name
  • Doctor or contact person’s name
  • Email address and phone number
  • Patient or customer appointment data that the client chooses to send through WhatsApp using our Services, such as a patient’s name, phone number, and appointment date and time

Clients decide what patient information to send through our Services and are responsible for having a lawful basis, including any required consent, to message their patients. We ask clients not to send sensitive medical details, such as diagnoses or test results, through message templates.

Technical data

When you visit our website or use our Services, we automatically collect:

  • IP address, browser type and device information
  • Server and application logs, including request times and error reports
  • Usage information, such as pages visited and features used, collected in aggregate

3How we use data

We use the data described above only to:

  • Onboard clients through Embedded Signup: connect a business’s WhatsApp Business Account and phone number to our Services and verify that the setup works.
  • Send messages on behalf of clinics: deliver appointment reminders, follow-ups and replies to a clinic’s patients, as configured by the clinic.
  • Manage message templates: create, submit for Meta approval, update and track the status of WhatsApp message templates.
  • Provide support: respond to questions, troubleshoot delivery problems and communicate with clients about their account.
  • Keep the Services secure and working: monitor performance, detect abuse and fix errors.
  • Meet legal obligations: comply with applicable law and respond to lawful requests.

Where the EU or UK General Data Protection Regulation (GDPR) applies, we rely on the following legal bases: performance of our contract with clients; our legitimate interests in operating and securing the Services; compliance with legal obligations; and consent, where we ask for it. Under India’s Digital Personal Data Protection Act, 2023 (DPDP Act), we process personal data for the specified purposes above, based on consent or legitimate uses permitted by the Act.

We do not use data received from Meta or from our clients’ conversations for advertising, to build profiles for marketing, or to train artificial intelligence models.

4How we share data

We do not sell, rent or trade personal data. We share it only with the service providers we need to run the Services:

RecipientWhyWhat
Meta Platforms, Inc. and Meta Platforms Ireland Ltd.Operating the WhatsApp Business Platform: sending and receiving messages, template approval, account and phone number management.Business account identifiers, phone numbers, message content and templates.
Vercel Inc. (running on Amazon Web Services)Hosting our website, APIs and webhook endpoints.All data that passes through our services, including webhook payloads and technical logs.
Google LLC (Google Sheets API)Temporary operational data store while we move to a dedicated database.Client account details, webhook events, message status and appointment data sent by clinics.

Each of these providers processes data under its own terms and security commitments. We may also disclose data if required by law, to protect the rights and safety of our users or the public, or as part of a merger, acquisition or sale of assets, in which case we will notify affected clients before their data becomes subject to a different privacy policy.

5Data retention

We keep personal data only for as long as we need it for the purposes described in this policy:

  • Access tokens and WhatsApp account identifiers are kept while a business remains connected to our Services, and deleted within 30 days after the business disconnects or closes its account.
  • Message content, status updates and appointment data are kept for as long as the client’s account is active, and deleted within 90 days after the account is closed, unless the client asks us to delete them sooner.
  • Technical logs are kept for up to 90 days.
  • Client contact and billing records may be kept longer where required by tax, accounting or other legal obligations.

6Security

We use reasonable technical and organisational measures to protect personal data, including:

  • Encryption in transit (HTTPS/TLS) for all traffic to and from our Services and Meta’s APIs
  • Keeping API keys and credentials out of source code, in encrypted environment configuration
  • Restricting access to the systems that store access tokens and client data
  • Limiting access to personal data to the people who need it to operate and support the Services

No system is perfectly secure. If we become aware of a breach that affects your personal data, we will notify affected clients, and the relevant authorities where required, without undue delay.

7International transfers

Magic Pixels is based in India. Our service providers, including Meta, Vercel, Amazon Web Services and Google, may store and process data in the United States, the European Union, India and other countries.

Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, as incorporated into our providers’ data processing terms. Transfers out of India are made in line with the DPDP Act and any restrictions notified by the Government of India.

8Your rights

Depending on where you live, including under the GDPR and India’s DPDP Act, you have the right to:

  • Access the personal data we hold about you and get a copy of it
  • Correct personal data that is inaccurate or incomplete
  • Delete your personal data
  • Withdraw consent at any time, where we rely on consent
  • Object to or restrict certain processing, and request data portability (GDPR)
  • Nominate another person to exercise your rights in the event of death or incapacity (DPDP Act)
  • Raise a grievance with us, and complain to your local data protection authority or the Data Protection Board of India

How to request access, correction or deletion

  1. Email hi@magicpixels.org with the subject “Data request”.
  2. Tell us what you would like us to do (access, correct or delete) and include the phone number or email address linked to your data, plus the clinic or business name if you are a patient or customer.
  3. We may ask you to confirm your identity. We will respond within 30 days.

Businesses can also remove our access at any time from Meta Business Settings, under Integrations → Connected apps. Once disconnected, we delete the related access tokens as described in Data retention.

If you are a patient or customer of one of our clients, we may pass your request to that business, since they control your data, and will help them respond to it.

9Children’s privacy

Our Services are intended for businesses and are not directed at children. We do not knowingly collect personal data directly from anyone under 18. Clinics may send appointment information about patients who are minors; in that case, the clinic is responsible for obtaining verifiable consent from a parent or lawful guardian as required by law. If you believe a child has given us personal data directly, contact us and we will delete it.

10Cookies

Our website does not use advertising or tracking cookies. We measure website traffic with Vercel Web Analytics, which counts visits in aggregate without setting cookies.

If you sign in to one of our products, we use strictly necessary cookies to keep you signed in and to protect your session. These cannot be turned off without breaking sign-in. Meta may set its own cookies during the Embedded Signup flow, which are governed by Meta’s cookie policy.

11Changes to this policy

We may update this policy as our Services or the law change. When we do, we will update the “Last updated” date at the top of this page. If a change materially affects how we handle personal data, we will notify active clients by email before it takes effect.

12Contact us

For any questions about this policy, to exercise your rights, or to raise a grievance, contact us:

Company
Magic Pixels
Email us