Privacy Policy – SIYOQ
Last updated on: 20th August 2026
This policy explains how Sioniq Tech Private Limited handles personal data in connection with SIYOQ, our business messaging service.
Relationship to our main policy. This policy is specific to SIYOQ and supplements the Sioniq Privacy Policy. Where the two differ in relation to messaging data, this policy governs. For all other Sioniq products, including the JOS platform, the main policy applies.
About this Policy
SIYOQ enables a business to communicate with its own customers over messaging channels, including the WhatsApp Business Platform operated by Meta Platforms, Inc. This policy covers the personal data involved in providing that service.
SIYOQ is available to businesses generally and is not limited to any particular trade. The service is under development and not yet generally available; this policy applies from the date the service is made available to a customer.
Who We are
Sioniq Tech Private Limited
Registered office: 8-2-293/82/A/1107, Plot No. 1107, Road No. 55, Jubilee Hills, Hyderabad, Telangana 500 033, India
Email: info@sioniq.com · Phone: 040 69 888 999, +91 86868 33 999
Our Role in Your Data
Where we are the Data Processor
Our customers are businesses. When a business uses SIYOQ to message its customers, that business decides who is contacted and what is sent. Sioniq processes that data only on the business’s instructions. In this relationship the business is the Data Fiduciary and Sioniq is the Data Processor.
The business is responsible for obtaining and evidencing consent, for the content of its messages, for the notices it gives its own customers, and for handling their rights requests. We assist, but we do not make those decisions.
Where we are the Data Fiduciary
For our own business contacts — the staff of businesses who enquire about SIYOQ, register an account, administer it or contact support — Sioniq decides how that data is used and is responsible for it.
Data We Process
| Category | Examples | Source |
|---|---|---|
| Business and verification data | Legal entity name, registered address, business documents, administrator names, emails and phone numbers | From the business |
| Messaging assets | Business account identifiers, WhatsApp Business Account identifiers, phone number identifiers, sender numbers, display names, access tokens | From the business and from Meta |
| Template data | Template content, variables, language, category and approval status | From the business and from Meta |
| End customer data | Name, phone number, consent status and its source and date, and the record references used to fill a message — order number, invoice number, appointment time, amount | Entered or uploaded by the business |
| Message data | Content of messages sent and received, attachments, timestamps, delivery, read and failure status, failure reasons | Generated by use of the service |
| Platform events | Webhook events received from the messaging platform, including delivery receipts and inbound messages | From Meta |
| Usage and technical data | Log records, IP address, device and browser type, actions taken in the application, audit trail of who sent what | Generated automatically |
We do not knowingly process government identity numbers, payment card numbers, biometric data or health data through SIYOQ. Businesses must not place such data into message content or customer notes.
Why We Process it
- To deliver the service — sending the messages a business instructs us to send, receiving replies, showing delivery status, operating the inbox and producing reports.
- To manage templates — creating, submitting and tracking the approval status of message templates.
- To administer accounts — onboarding, verification support, number registration, billing and usage accounting.
- To support customers — answering queries and diagnosing faults.
- To secure the service — monitoring for abuse, fraud and misuse, and maintaining audit trails.
- To comply with law — meeting statutory, tax and regulatory obligations and responding to lawful requests.
Our lawful bases, where the concept applies, are performance of a contract, our legitimate interests in operating and securing the service, compliance with legal obligations, and consent where consent is required.
WhatsApp Business Platform
To deliver a message, data necessary for delivery — including the recipient’s phone number, message content and attachments — is transmitted to and processed by Meta Platforms, Inc. Meta’s handling of that data is governed by Meta’s own terms and privacy policies and not by this policy.
Each business connects and authorises its own WhatsApp Business Account and registers its own sender number. Sioniq does not send from a shared sender number.
Platform status. Sioniq’s access to the WhatsApp Business Platform is subject to Meta’s review and approval. Sioniq is an independent software company and is not affiliated with, endorsed by, sponsored by or certified by Meta.
Limited Use of Messaging Data
Data obtained through a messaging platform, including data received from Meta, is used only to provide the messaging service to the business that authorised it. Specifically, Sioniq:
- Does not sell it, and does not use it for advertising or to market Sioniq’s own products;
- Does not use it to develop, train, enrich or improve any other Sioniq product, including the JOS ERP platform, beyond what is necessary to deliver the messaging service the business has requested;
- Does not combine one business’s messaging data with another business’s data; and
- Restricts internal access to the personnel and systems that require it to operate and support the service.
Messaging data is logically segregated per customer tenant, and messaging credentials are held separately from ERP data with their own access controls.
Retention
| Data | Retention |
|---|---|
| Account and business records | Term of the agreement, then as required by tax and company law |
| Message content, attachments and delivery status | Retained for as long as needed to provide the service and its reporting, and deleted on request as set out below |
| Consent and opt-out records | Retained while the business uses the service, and afterwards as evidence of consent, because deleting an opt-out record would risk the person being contacted again |
| Messaging credentials and tokens | Revoked and removed on disconnection or termination |
| System and security logs | 180 days, maintained in India in accordance with the CERT-In Directions of 28 April 2022 |
| Invoices and financial records | As required under Indian tax and company law |
Data Deletion
If you are a business using SIYOQ: you can disconnect your messaging account at any time, which stops all sending immediately and results in revocation of the associated credentials. To have your data deleted, write to info@sioniq.com from your registered administrator address with the subject “Data deletion request” and your organisation name. We will verify the request and delete or irreversibly anonymise your account data, message content, attachments, templates and reports within thirty (30) days, and confirm in writing. You may export your data before requesting deletion.
If you are the customer of a business that messaged you: that business controls your data and decides whether it is deleted. Please ask them directly, or reply to the conversation asking to stop being contacted. You may also write to info@sioniq.com with the phone number concerned and the name of the business, and we will route your request to them and assist with it.
What may be retained: records we are required to keep by law, including invoices and tax records; opt-out and suppression records, retained so that a person who has asked not to be contacted is not contacted again; and security logs for their stated retention period. Backups are purged on their normal retention cycle.
There is no charge for a deletion request.
Your Rights
Subject to applicable law, you may request access to the personal data we hold about you, correction of inaccurate data, erasure, restriction of processing, a copy in a portable form, and withdrawal of consent where processing is based on consent. You may also nominate another individual to exercise your rights in the event of your death or incapacity, as provided under the Digital Personal Data Protection Act, 2023.
Write to info@sioniq.com. We will respond within the period required by law and may ask for information to verify your identity. If you are not satisfied with our response you may complain to the Data Protection Board of India or, where applicable, your local supervisory authority.
If You Received a Message from a Business using SIYOQ
The business that sent the message decided to contact you and is responsible for that decision and for the content of the message. To stop receiving messages, reply to the conversation asking to stop, or contact the business directly. Your opt-out is recorded and suppresses further messages to that number.
If you cannot reach the business, write to info@sioniq.com with the phone number concerned and the name of the business, and we will pass the request on and assist with it.
Security
We apply access controls, encryption of data in transit, encryption at rest where applicable, secrets management for credentials and tokens, role-based permissions, and audit logging of messaging activity. Full detail is set out in the SIYOQ Security Policy.
No system is completely secure. We maintain an incident response process and will notify affected customers and, where required, the Data Protection Board of India and CERT-In, within the periods required by law.
International Transfers
SIYOQ data is hosted with customer data primarily located in India. Message delivery involves transfer to Meta, which processes data outside India. Where we transfer personal data across borders we do so in accordance with applicable law and under contractual protections with recipients.
Children
SIYOQ is a business tool and is not directed at children. We do not knowingly process the personal data of a child as defined under applicable law, and we do not undertake tracking or behavioral monitoring of children. Businesses must not use the service to send commercial or promotional communications to children. If you believe we hold a child’s data, write to info@sioniq.com and we will delete it.
Changes to this Policy
We may update this policy. Where changes are material we will notify customers by email or in the application before they take effect. The effective date is shown at the top of this page.
Contact
Grievance Officer
Sioniq Tech Private Limited
8-2-293/82/A/1107, Plot No. 1107, Road No. 55, Jubilee Hills, Hyderabad, Telangana 500 033, India
Email: info@sioniq.com · Phone: 040 69 888 999
Security matters: security@sioniq.com