We never sell personal data
No advertising, no data brokers, and no tracking or analytics cookies.
Message content is deleted
Message bodies are purged and phone numbers masked after 30 days by default.
Your rights, one form away
Access, correct or erase your data, withdraw consent or nominate someone.
Answered within 48 hours
Requests and grievances are acknowledged within 48 hours and resolved within 30 days.
1.About this policy
This policy explains how SMS21, “we” or “us”, collects and processes personal data when you visit our website, create an account, use our dashboard or APIs, pay us, or contact us. It is our notice under section 5 of the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the Digital Personal Data Protection Rules, 2025.
Words used here have the meaning the DPDP Act gives them. In short: you are the Data Principal (the person the data is about); a Data Fiduciary decides why and how personal data is processed; a Data Processor processes it on a Data Fiduciary’s behalf.
You can ask for this notice in English or in any language listed in the Eighth Schedule to the Constitution of India through the contact form.
2.Our two roles
- Data Fiduciary. For the people who use SMS21 (account holders, team members, visitors to this website and anyone who writes to us), we decide how their data is used. This policy covers that data in full.
- Data Processor. When our customers send OTPs, SMS or WhatsApp messages through us, the phone numbers, message text and replies belong to the customer’s own relationship with their users. The customer is the Data Fiduciary for that data and we process it only on their instructions, under our Terms. See If you received a message.
3.Personal data we collect
We collect only what we need for the purposes in the next section.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Name, email address, mobile number, password (stored only as a one-way hash), company name, role, two-step verification settings | You, when you sign up or are invited by a team |
| Business and KYC | Legal business name, address, GSTIN, DLT entity and sender ID registrations, WhatsApp Business account details | You or your organisation |
| Billing | Wallet top-ups, invoices, UPI transaction references (UTR), payment status. Card and bank details are handled by the payment gateway, never stored by us | You and our payment gateway |
| Usage and security | IP address, browser, sign-in times, API request logs, audit logs of changes made in your account | Generated automatically when you use the service |
| Messages (as processor) | Recipient phone numbers, message text, delivery status, replies, WhatsApp media | Our customers, through the API or dashboard |
| Correspondence | What you tell us through the contact form, email or phone, including data-protection requests | You |
4.Why we use it
| Purpose | Ground under the DPDP Act |
|---|---|
| Create and secure your account, sign you in, verify your mobile number | Your consent, given when you sign up |
| Deliver messages you ask us to send and report their delivery | Your consent, and our customer’s instructions for their recipients’ data |
| Charge your wallet, process top-ups and issue GST invoices | Your consent; and compliance with tax and accounting law (section 7) |
| Prevent fraud, spam and abuse; enforce DLT and messaging rules; keep audit logs | Legitimate uses for compliance with law and to protect the service (section 7) |
| Answer your questions, requests and grievances | Data you provide voluntarily for that purpose (section 7(a)) |
| Service emails: password resets, low-balance alerts, receipts, security notices | Your consent, as part of using the service |
| Respond to lawful requests from courts, regulators, TRAI, telecom operators and law enforcement | Compliance with law and judicial orders (section 7) |
We do not use personal data for advertising, we do not build profiles for marketing, and we do not make decisions about you by automated means alone.
5.Consent and withdrawal
Where we rely on consent, it is asked for clearly, for the purposes described here, and you can withdraw it at any time — as easily as you gave it — by writing to us through the contact form or by closing your account. Withdrawing consent does not affect processing that took place before it, and we stop processing within a reasonable time, unless the law requires us to keep certain records (for example invoices).
Some data is essential to provide the service, so withdrawing consent for it means we can no longer operate your account. We will tell you when that is the case. You may also give, manage or withdraw consent through a Consent Manager registered with the Data Protection Board of India, once such managers are available.
6.If you received a message
If you received an OTP, SMS or WhatsApp message sent through SMS21, the business named in the message sent it and is responsible for why it holds your number. Please contact that business first to access or erase your data or to withdraw consent.
- Stop promotional messages. Reply STOP to a message where the sender offers it; opted-out numbers are blocked for that sender automatically. For SMS in India you can also register a preference on the National Customer Preference Register by calling or texting 1909.
- Tell us too. If the business does not respond or you believe a message was spam, write to us under “Grievance” and include the sender name, the time and your number. We investigate and can suspend senders who break our rules.
8.Processing outside India
Some providers, such as international SMS carriers and the WhatsApp Business Platform, process data in other countries. We transfer personal data outside India only as section 16 of the DPDP Act allows, never to a country the Central Government has restricted, and with contractual safeguards equivalent to this policy.
9.How long we keep it
We keep personal data only as long as the purpose requires, then erase it, unless a law requires us to keep it longer. Current defaults:
| Data | Kept for |
|---|---|
| Message text | 30 days, then purged; the phone number is masked (e.g. 91******3210) |
| OTP codes | Never stored readable: only a one-way hash, kept 30 days |
| Replies received (inbound messages) | 90 days, then text removed and numbers masked |
| API request logs and webhook events | 30 days |
| Test (sandbox) data | 7 days |
| Signed-out and expired sessions | 30 days |
| Security and traffic logs | At least one year, as the DPDP Rules, 2025 require, to detect and investigate misuse |
| Invoices, payments and wallet ledger | As long as tax and company law requires, usually 8 years |
| Account data | While the account is open; erased within 30 days after you ask us to close it, except records the law requires us to keep |
| Contact-form messages | Until resolved, then up to 3 years, or erased on request |
10.How we protect it
We use reasonable security safeguards, including:
- Encryption in transit (HTTPS/TLS) and encryption of provider credentials and email content at rest.
- Passwords, OTP codes and API keys stored only as one-way hashes; API keys shown once.
- Two-step verification, IP allow-lists for API keys, and role-based access for teams.
- Tamper-evident audit logs of administrative actions, and least-privilege staff access.
- Rate limits, fraud monitoring, backups and regular security reviews.
No system is perfectly secure. Please keep your password and API keys secret and tell us immediately if you suspect misuse. Read more on our Security page.
11.Personal data breaches
If a personal data breach affects you, we will tell you without delay, in plain language: what happened, when, the likely consequences, what we are doing about it, what you can do to protect yourself, and whom to contact. We also report breaches to the Data Protection Board of India as the DPDP Act and Rules require, with a detailed report within 72 hours of becoming aware of it.
12.Your rights
Under the DPDP Act you have the right to:
- Access. a summary of the personal data we process about you, the processing we carry out, and the Data Fiduciaries and Processors we have shared it with.
- Correction and completion. of inaccurate or incomplete data, and to update it. Most account details can be changed in the dashboard under your profile.
- Erasure. of data we no longer need, unless the law requires us to keep it.
- Withdraw consent. at any time, as explained above.
- Grievance redressal. through our Grievance Officer, and then the Data Protection Board of India.
- Nominate. another person to exercise your rights if you die or become incapable of doing so.
How to make a request
Use the data protection request form or email the Grievance Officer at the address in section 16. Tell us which right you want to exercise. We may ask you to confirm your identity (for example from the email address on your account) before acting — this protects your data from others. We acknowledge requests within 48 hours and complete them within 30 days. There is no charge.
13.Your duties
Section 15 of the DPDP Act asks Data Principals to comply with the law, not to impersonate anyone, not to suppress material information, not to file false or frivolous grievances or complaints, and to give only verifiably authentic information when exercising the right to correction or erasure.
14.Children’s data
SMS21 is a business service for people aged 18 and over. We do not knowingly process a child’s personal data, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has given us personal data, contact us and we will erase it.
Customers whose own users include children are responsible, as Data Fiduciaries, for obtaining verifiable consent from a parent or lawful guardian before sending them messages.
16.Grievance Officer and the Board
Grievance Officer
Grievance Officer
SMS21
Use the contact form
Data Protection Board of India
If you are not satisfied with our response, or we do not respond within 30 days, you may complain to the Data Protection Board of India under section 13 of the DPDP Act, after using our grievance process.
To raise a grievance, use the grievance form. We acknowledge it within 48 hours and resolve it within 30 days, well inside the 90 days the DPDP Rules, 2025 allow.
17.Changes to this policy
We will update this policy when our processing or the law changes. The effective date at the top shows the current version. For material changes we will notify account holders by email or in the dashboard before they take effect and, where we rely on consent, ask for it again.
Effective date