Effective date: 13 July 2026
Last updated: 13 July 2026

This Privacy Policy explains how SMART CLIENT IT INNOVATIONS (“xreach51”, “we”, “us”) collects, uses, discloses and protects personal data in connection with the xreach51 platform (the “Service”), our website, and related services.

xreach51 is a business-to-business omnichannel messaging platform. Our customers are businesses that use the Service to communicate with their own contacts over WhatsApp, Telegram, SMS and voice.

1. Controller and processor roles

Our role depends on whose data is involved:

If you are an individual who received a message or call from a business using xreach51 and you want your data corrected or deleted, please contact that business directly. If you cannot identify them, write to us at support@xreach51.com and we will route your request to the relevant customer.

2. Personal data we collect

2.1 Data you give us

2.2 Data we process on our customers’ behalf

2.3 Data we collect automatically

3. How we use personal data

We do not sell personal data. We do not share end-user data with third parties for their own marketing purposes.

4. Legal bases (EEA/UK — GDPR)

5. Sharing and sub-processors

We share personal data only as needed to run the Service:

Sub-processors are bound by written agreements requiring confidentiality and appropriate security. A current list of sub-processors is available on request from support@xreach51.com.

Note that messages sent over WhatsApp and Telegram are also subject to those platforms’ own privacy policies, which we do not control.

6. Google user data

xreach51 offers “Sign in with Google” as an optional way to create and access an xreach51 account. This section describes how we access, use, store and share Google user data, in line with the Google API Services User Data Policy.

6.1 What Google data we access

If you choose to sign in with Google, we request only basic, non-sensitive scopes:

We do not request access to Gmail, Google Drive, Google Contacts, Google Calendar, or any other sensitive or restricted Google API scope.

6.2 How we use it

Google user data is used for one purpose only: to authenticate you and create or access your xreach51 account. Specifically, we use it to verify your identity at sign-in, to create your account record, and to display your name and profile picture inside the application.

We do not use Google user data for advertising. We do not use it to train machine-learning or AI models. We do not use it to send you marketing communications unless you separately opt in.

6.3 How we store it

We store your Google account identifier, email address, name and profile picture URL in our account records, encrypted in transit and at rest, on our infrastructure. We retain this data for as long as your xreach51 account is active. If you delete your account, or disconnect Google sign-in and ask us to remove the data, we delete it, subject to any legal retention obligations.

6.4 How we share it

We do not sell, rent, or transfer Google user data to third parties. We do not share it with data brokers, advertising networks, or for any purpose unrelated to providing the Service. Google user data is disclosed only to our cloud infrastructure provider (Amazon Web Services) purely for the purpose of hosting our application, or where we are legally compelled to disclose it.

6.5 Limited use

xreach51’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6.6 Revoking access

You can revoke xreach51’s access to your Google account at any time from your Google Account permissions page. You can also email support@xreach51.com to request deletion of any Google user data we hold.

7. International transfers

We are based in India and our infrastructure may process data in India and other regions. Where personal data is transferred out of the EEA or UK, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary technical measures such as encryption.

8. Retention

We keep account and billing records for as long as your account is active and thereafter for as long as required to meet legal, tax and accounting obligations.

End-user data — contacts, conversations, messages, recordings and transcripts — is retained for as long as our customer’s account remains active, or until the customer deletes it or instructs us to. On termination of a customer account we delete or return end-user data in accordance with the customer’s agreement with us. Backups are purged on a rolling cycle.

9. Cookies

Our website and application use cookies and similar technologies that are strictly necessary for the site to work (session, authentication, security), and — with consent where required — analytics cookies that help us understand how the site is used. You can control cookies through your browser settings; blocking strictly necessary cookies may break parts of the Service.

10. Security

We apply technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, role-based access control, least-privilege access for staff, network isolation, and logging and monitoring. No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a personal data breach affecting your data, we will notify you and the relevant authorities as required by law.

11. Your rights

11.1 GDPR (EEA/UK)

Subject to conditions, you have the right to access, rectify, erase, restrict processing of, and port your personal data, to object to processing based on legitimate interests, and to lodge a complaint with your supervisory authority.

11.2 CCPA/CPRA (California)

California residents have the right to know what personal information we collect and how it is used and disclosed, to request deletion or correction, and to be free from discrimination for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.

11.3 India — Digital Personal Data Protection Act, 2023

Data Principals in India have the right to access a summary of their personal data and our processing, to request correction, completion, updating and erasure, to nominate another individual to exercise their rights, and to a grievance redressal mechanism. Grievances may be raised with our Grievance Officer using the contact details in section 12; we will respond within the period prescribed by law.

To exercise any of these rights, email support@xreach51.com. We may need to verify your identity before acting. Where we act as a processor for one of our customers, we will refer your request to them.

12. Children

The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child’s data has been provided to us, contact us and we will delete it.

13. Contact us

SMART CLIENT IT INNOVATIONS
Altf, Meenakshi Tech Park, Phase 2, Gachibowli, Hyderabad, Telangana, India
Email: support@xreach51.com

14. Changes to this policy

We may update this Privacy Policy from time to time. We will change the “Last updated” date above and, where the change is material, notify account holders by email or in-product notice before it takes effect.