Effective date: 13 July 2026
Last updated: 13 July 2026
This Privacy Policy explains how SMART CLIENT IT INNOVATIONS (“xreach51”, “we”, “us”) collects, uses, discloses and protects personal data in connection with the xreach51 platform (the “Service”), our website, and related services.
xreach51 is a business-to-business omnichannel messaging platform. Our customers are businesses that use the Service to communicate with their own contacts over WhatsApp, Telegram, SMS and voice.
1. Controller and processor roles
Our role depends on whose data is involved:
- Customer data (we are the controller). Information about the businesses and individuals who sign up for, administer, or pay for xreach51 accounts — for example account holders, agents and billing contacts.
- End-user data (we are the processor). Contact records, message content, call recordings, transcripts and campaign results that our customers upload to, or generate through, the Service about their customers. Our customer is the controller of that data; we process it on their documented instructions.
If you are an individual who received a message or call from a business using xreach51 and you want your data corrected or deleted, please contact that business directly. If you cannot identify them, write to us at support@xreach51.com and we will route your request to the relevant customer.
2. Personal data we collect
2.1 Data you give us
- Account and identity data: name, business email, phone number, company name, job role, password credentials.
- Billing data: billing address, GSTIN or tax identifiers, and transaction records. Card and bank details are collected and stored by our payment processor, not by us.
- Support and communications data: messages you send to our support, sales or success teams.
2.2 Data we process on our customers’ behalf
- Contact records: phone numbers, names, channel identifiers, tags, segments and custom attributes uploaded by our customers.
- Message content and metadata: WhatsApp, Telegram and SMS message bodies, templates, delivery and read receipts, timestamps.
- Voice data: call metadata (numbers, duration, disposition, DTMF input) and, where the customer enables it, call audio recordings and machine-generated transcripts.
- Campaign and analytics data: send, delivery, pickup, response and funnel metrics.
2.3 Data we collect automatically
- Usage and device data: IP address, browser and device type, pages viewed, actions taken, timestamps.
- Cookies and similar technologies: see section 8.
3. How we use personal data
- To provide, operate, secure and maintain the Service.
- To authenticate users and administer accounts.
- To process payments and manage credit balances.
- To provide support and respond to enquiries.
- To monitor for abuse, spam, fraud and violations of our acceptable use rules and of the WhatsApp Business Messaging Policy.
- To improve the Service, including reliability, latency and speech-recognition quality for Indian languages.
- To send service and administrative notices. Marketing email is sent only on a lawful basis and can be opted out of at any time.
- To comply with legal obligations and enforce our agreements.
We do not sell personal data. We do not share end-user data with third parties for their own marketing purposes.
4. Legal bases (EEA/UK — GDPR)
- Performance of a contract — to deliver the Service you have signed up for.
- Legitimate interests — to secure the platform, prevent abuse, and improve our products, balanced against your rights.
- Legal obligation — to meet tax, accounting and law-enforcement requirements.
- Consent — for optional cookies and for marketing communications where consent is required. You may withdraw consent at any time.
5. Sharing and sub-processors
We share personal data only as needed to run the Service:
- Cloud infrastructure — Amazon Web Services, for hosting, compute and storage.
- Channel providers — Meta Platforms (WhatsApp Business Platform), Telegram, and our telecom/SMS and voice carriers, to actually deliver messages and calls you or our customers initiate.
- Speech and AI providers — where a customer enables conversational voice, for speech-to-text, language modelling and text-to-speech.
- Payment processors — to take payment and issue invoices.
- Professional advisers and authorities — where required by law, or to establish, exercise or defend legal claims.
Sub-processors are bound by written agreements requiring confidentiality and appropriate security. A current list of sub-processors is available on request from support@xreach51.com.
Note that messages sent over WhatsApp and Telegram are also subject to those platforms’ own privacy policies, which we do not control.
6. Google user data
xreach51 offers “Sign in with Google” as an optional way to create and access an xreach51 account. This section describes how we access, use, store and share Google user data, in line with the Google API Services User Data Policy.
6.1 What Google data we access
If you choose to sign in with Google, we request only basic, non-sensitive scopes:
- openid — a unique Google account identifier used to link your Google account to your xreach51 account.
- email — your Google account email address.
- profile — your basic profile information: name and profile picture.
We do not request access to Gmail, Google Drive, Google Contacts, Google Calendar, or any other sensitive or restricted Google API scope.
6.2 How we use it
Google user data is used for one purpose only: to authenticate you and create or access your xreach51 account. Specifically, we use it to verify your identity at sign-in, to create your account record, and to display your name and profile picture inside the application.
We do not use Google user data for advertising. We do not use it to train machine-learning or AI models. We do not use it to send you marketing communications unless you separately opt in.
6.3 How we store it
We store your Google account identifier, email address, name and profile picture URL in our account records, encrypted in transit and at rest, on our infrastructure. We retain this data for as long as your xreach51 account is active. If you delete your account, or disconnect Google sign-in and ask us to remove the data, we delete it, subject to any legal retention obligations.
6.4 How we share it
We do not sell, rent, or transfer Google user data to third parties. We do not share it with data brokers, advertising networks, or for any purpose unrelated to providing the Service. Google user data is disclosed only to our cloud infrastructure provider (Amazon Web Services) purely for the purpose of hosting our application, or where we are legally compelled to disclose it.
6.5 Limited use
xreach51’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6.6 Revoking access
You can revoke xreach51’s access to your Google account at any time from your Google Account permissions page. You can also email support@xreach51.com to request deletion of any Google user data we hold.
7. International transfers
We are based in India and our infrastructure may process data in India and other regions. Where personal data is transferred out of the EEA or UK, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary technical measures such as encryption.
8. Retention
We keep account and billing records for as long as your account is active and thereafter for as long as required to meet legal, tax and accounting obligations.
End-user data — contacts, conversations, messages, recordings and transcripts — is retained for as long as our customer’s account remains active, or until the customer deletes it or instructs us to. On termination of a customer account we delete or return end-user data in accordance with the customer’s agreement with us. Backups are purged on a rolling cycle.
9. Cookies
Our website and application use cookies and similar technologies that are strictly necessary for the site to work (session, authentication, security), and — with consent where required — analytics cookies that help us understand how the site is used. You can control cookies through your browser settings; blocking strictly necessary cookies may break parts of the Service.
10. Security
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, role-based access control, least-privilege access for staff, network isolation, and logging and monitoring. No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a personal data breach affecting your data, we will notify you and the relevant authorities as required by law.
11. Your rights
11.1 GDPR (EEA/UK)
Subject to conditions, you have the right to access, rectify, erase, restrict processing of, and port your personal data, to object to processing based on legitimate interests, and to lodge a complaint with your supervisory authority.
11.2 CCPA/CPRA (California)
California residents have the right to know what personal information we collect and how it is used and disclosed, to request deletion or correction, and to be free from discrimination for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
11.3 India — Digital Personal Data Protection Act, 2023
Data Principals in India have the right to access a summary of their personal data and our processing, to request correction, completion, updating and erasure, to nominate another individual to exercise their rights, and to a grievance redressal mechanism. Grievances may be raised with our Grievance Officer using the contact details in section 12; we will respond within the period prescribed by law.
To exercise any of these rights, email support@xreach51.com. We may need to verify your identity before acting. Where we act as a processor for one of our customers, we will refer your request to them.
12. Children
The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child’s data has been provided to us, contact us and we will delete it.
13. Contact us
SMART CLIENT IT INNOVATIONS
Altf, Meenakshi Tech Park, Phase 2, Gachibowli, Hyderabad, Telangana, India
Email: support@xreach51.com
14. Changes to this policy
We may update this Privacy Policy from time to time. We will change the “Last updated” date above and, where the change is material, notify account holders by email or in-product notice before it takes effect.