Overview & Company Scope
Welcome to ShreeOm Graphic ("we," "us," "our," or the "Company"). We are a premier branding, graphic design, and digital creative agency headquartered in Gandhinagar and Ahmedabad, Gujarat, India.
This Privacy Policy explains how ShreeOm Graphic collects, uses, protects, and discloses personal data obtained through our website (https://www.shreeomgraphic.com), our client communication channels, customer relationship management (CRM) portals, and specifically through our integration with the WhatsApp Cloud API provided by Meta Platforms, Inc.
By accessing our website, initiating a chat conversation, opting into communication through our forms, or sending messages to our official WhatsApp Business phone number (+91 7862982100), you acknowledge and agree to the terms described in this Privacy Policy.
WhatsApp Cloud API Architecture & Meta Disclosure
To offer fast, responsive, and seamless customer service, quotation assistance, and project delivery updates, ShreeOm Graphic integrates with the WhatsApp Business Platform (Cloud API), an enterprise messaging infrastructure owned and operated by Meta Platforms, Inc. (or Meta Platforms Ireland Ltd. for European users).
When you send a WhatsApp message to ShreeOm Graphic, your message is routed through Meta’s secure Cloud API servers to our authorized webhook listener and internal CRM. ShreeOm Graphic acts as the Data Controller determining the purpose of customer communication, while Meta Platforms, Inc. functions as the Data Processor / Technology Service Provider managing the cloud messaging infrastructure.
Your use of WhatsApp as a messaging client is subject to the WhatsApp Privacy Policy and WhatsApp Terms of Service. When communicating with our official business account, our processing of your personal data is governed by this Privacy Policy and Meta's WhatsApp Business Terms.
Information We Collect via WhatsApp Cloud API
We only collect data that is strictly necessary to provide graphic design consultations, project estimates, artwork approvals, and customer support. The categories of information processed include:
| Data Category | Specific Details Collected | Primary Source |
|---|---|---|
| Contact Identifiers | Your WhatsApp phone number (MSISDN), country code, and WhatsApp User ID. | Directly provided when you initiate a conversation or submit a contact request. |
| Profile Information | Your public WhatsApp profile display name and profile picture URL (depending on your individual WhatsApp privacy settings). | Transmitted by Meta's WhatsApp API payload upon incoming message. |
| Communication Content | The text of your inquiries, creative briefs, design specifications, feedback, questions, and revision requests. | Directly authored and sent by you in conversation. |
| Media & Attachments | Images, vector files (AI, EPS, SVG), PDFs, mockups, brand assets, or references shared during design projects. | Uploaded or attached by you in the chat thread. |
| Message Metadata | Message IDs, timestamps (sent, received, read), delivery receipts, and delivery status notifications (e.g. read/failed). | Generated automatically by Meta's Cloud API webhooks. |
We do NOT collect or request: Sensitive personal data such as government identification numbers, financial passwords, banking PINs, or health information over WhatsApp. Please do not transmit sensitive personal credentials over messaging platforms.
Purposes of Data Processing
ShreeOm Graphic processes your personal data and WhatsApp communications strictly for legitimate business and client service objectives:
- Inquiry Resolution & Quotations: Responding to questions regarding our logo design, branding, packaging, UI/UX, and marketing collateral design services.
- Project Collaboration & Proofing: Sending initial design drafts, watermarked previews, revision rounds, and finalized design asset download links.
- Transactional Notifications: Providing invoice acknowledgments, payment receipts, scheduling discovery calls, and project timeline milestones.
- Customer Support: Troubleshooting queries, handling revision requests, and providing prompt after-sales support.
- Service Improvement & Quality Control: Analyzing response latency and delivery success rates to optimize our client communication workflows.
Explicit Opt-In & Consent Mechanism
In strict compliance with Meta's WhatsApp Business Messaging Policy, ShreeOm Graphic ensures that prior affirmative consent is obtained before initiating automated or template-based communications:
- User-Initiated Conversation (Inbound Opt-In): When you click our website’s WhatsApp buttons or scan our QR codes to send us a message, you provide explicit consent for us to respond to your specific request.
- Website Form Submissions: When filling out our website contact form (Get in Touch), you provide your phone number and consent to receiving a follow-up via WhatsApp or phone call regarding your inquiry.
- Contractual Onboarding: Existing clients who sign design service agreements provide written consent to receive project updates and artwork proofs via WhatsApp.
Instant Opt-Out Policy ("STOP" Mechanism)
You maintain total control over your messaging preferences. You may revoke your consent and stop receiving automated or API-driven messages at any time:
Simply reply to any message from our WhatsApp number with the single word:
STOP
or
UNSUBSCRIBE
Upon receiving your "STOP" message:
- Our automated messaging system will immediately flag your phone number as Opted-Out.
- You will receive an automated confirmation acknowledging your opt-out.
- No further template or automated marketing messages will be transmitted to your number via our Cloud API.
- If you wish to re-subscribe in the future, you may do so at any time by simply messaging START or contacting our team.
Data Retention & User Data Deletion Rights (Right to Erasure)
Data Retention Period: We retain WhatsApp communication logs and client media assets only for as long as necessary to accomplish the design services requested, maintain business and accounting records required by Indian tax legislation, or fulfill legitimate legal obligations (typically up to 12 months following project completion, after which conversation logs are archived or purged).
Your Right to Data Deletion (Right to be Forgotten): Under the Digital Personal Data Protection Act, 2023 (DPDP Act) and international data protection laws (such as GDPR), you possess the absolute right to request the deletion of your personal data, chat history, and uploaded media from our systems.
You can initiate a Data Deletion Request through any of the following methods:
- Click the Request Data Deletion button on this page to launch our automated email request generator.
- Send an email to info@shreeomgraphic.com with the subject line "WhatsApp Cloud API Data Deletion Request", specifying your WhatsApp phone number.
- Send a WhatsApp message to +91 7862982100 stating "Please delete all my stored personal data and chat history."
Third-Party Disclosures & Non-Monetization Guarantee
ShreeOm Graphic enforces a strict Zero-Sale Policy regarding client information:
- We NEVER sell, trade, rent, lease, or monetize your name, phone number, messages, or design files to third-party data brokers, marketers, or advertisers.
- Authorized Service Providers: Personal data is shared solely with trusted service providers essential for operating our business, specifically:
- Meta Platforms, Inc. / WhatsApp: For routing, transmitting, and delivering Cloud API messages under enterprise data protection addenda.
- Cloud Infrastructure Providers (Firebase / Google Cloud): For encrypted database storage of client inquiry tickets and order records.
- Legal Compliance: We may disclose information if required to do so by applicable Indian law, court subpoenas, or law enforcement orders in compliance with the Indian Information Technology Act, 2000.
Data Security, Encryption & Webhook Safeguards
We enforce multi-layered technical and organizational safeguards to ensure your WhatsApp messages and customer details are protected against unauthorized access, loss, or alteration:
- Transport Encryption (TLS 1.3 / HTTPS): All data sent between your browser, our servers, and Meta's WhatsApp Cloud API endpoints is transmitted over secure Transport Layer Security (TLS 1.3) protocols.
- Webhook Signature Verification: All incoming WhatsApp webhook payloads received by our servers are cryptographically validated using HMAC-SHA256 signatures (the
X-Hub-Signature-256header) using our secure Meta App Secret. This ensures incoming messages originate exclusively from Meta and eliminates spoofing risks. - Access Controls: Client conversations and contact details are restricted to authorized design project managers and administrators through role-based access control (RBAC) and multi-factor authentication (MFA).
- Database Protection: Contact forms and lead data stored in our cloud infrastructure are protected with enterprise-grade firewalls and rest encryption.
Legal Grounds & Your Statutory Rights
Depending on your jurisdiction, you are entitled to statutory rights regarding your personal data under the Digital Personal Data Protection Act, 2023 (India), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the General Data Protection Regulation (GDPR):
- Right to Access: The right to request a copy of the personal data and conversation logs we maintain concerning you.
- Right to Rectification: The right to correct any inaccurate or incomplete personal contact details.
- Right to Erasure: The right to request the permanent deletion of your data as detailed in Section 7.
- Right to Restrict or Object to Processing: The right to object to specific modes of processing or withdraw previously granted consent without affecting past lawful processing.
- Right to Grievance Redressal: The right to have any grievances resolved within statutory timelines by our designated Grievance Officer.
Children's Privacy Protection
Our website, graphic design services, and WhatsApp messaging channels are intended for business owners, professionals, and individuals aged 18 and older. We do not knowingly market our services to, or collect personal data from, children under the age of 13 (or under 18 without parental consent). If we discover that a minor has provided us with personal information via WhatsApp without verified parental authorization, we will promptly delete that information from our records.
Updates to this Privacy Policy
We may update this Privacy Policy periodically to reflect enhancements in our WhatsApp Cloud API features, revisions to Meta’s Platform Policies, or adjustments in statutory regulations. When changes are published, we will revise the "Last Updated" date at the top of this page. We encourage you to review this policy intermittently to stay informed of our data security commitments.
Grievance Officer & Official Contact Information
If you have any questions, concerns, comments, or wish to exercise any of your privacy rights regarding our WhatsApp Cloud API integration, please reach out directly to our designated Data Protection & Grievance Redressal Officer: