Effective Date: June 14, 2026 | Last Updated: June 14, 2026

Privacy Policy

Welcome to Hype Nest Global (“Company,” “we,” “our,” or “us”).

This Privacy Policy (“Policy”) describes how Hype Nest Global, a company with its head office in Bengaluru, Karnataka, India (“Hype Nest Global,” “Company,” “we,” “us,” or “our”), collects, uses, discloses, stores, transfers, and otherwise processes personal information in connection with our websites, software platforms, applications, application programming interfaces (“APIs”), customer portals, mobile applications, artificial intelligence systems, chatbots, voice agents, automation tools, consulting engagements, and related products and services (collectively, the “Services”).

By accessing or using the Services, submitting information to us, creating an account, executing an order form, statement of work, or subscription agreement, or otherwise interacting with Hype Nest Global, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, you must not use the Services or provide personal information to us.

Hype Nest Global strives to process personal information in a manner consistent with applicable privacy and data protection laws, including the Digital Personal Data Protection Act, 2023 of India (“DPDP Act”), the EU General Data Protection Regulation (“GDPR”), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), Meta Platform requirements, and, where applicable, the Google API User Data Policy. This Policy does not constitute a certification of compliance with any particular statute or a warranty that every processing activity satisfies every jurisdictional requirement. Customers remain responsible for determining whether their specific use of the Services is lawful in their industry and jurisdictions.

1. INTRODUCTION

1.1 Hype Nest Global is an enterprise technology company that develops and delivers AI-powered software, SaaS platforms, custom applications, websites, mobile applications, workflow automation, CRM and ERP integrations, AI agents, voice AI, chatbots, analytics tools, market research tooling, cloud applications, and digital transformation consulting.

1.2 Our customers include startups, small and medium-sized businesses, large enterprises, healthcare organizations, educational institutions, manufacturing companies, agencies, financial services firms, and other organizations worldwide.

1.3 This Policy explains:

(a) what information we collect;
(b) how and why we use that information;
(c) with whom we share information;
(d) how we protect information;
(e) how long we retain information;
(f) the rights individuals may have regarding their information; and
(g) how to contact us regarding privacy matters.

1.4 This Policy should be read together with our Terms and Conditions, Cookie Policy, Acceptable Use Policy, AI Usage Policy, and any Data Processing Addendum (“DPA”), Business Associate Agreement, or similar contractual instrument executed with a particular Customer.

1.5 Where Hype Nest Global processes personal data on behalf of a Customer as a data processor, service provider, or equivalent role, the Customer’s instructions, the applicable DPA, and the Customer’s own privacy notices to data subjects generally govern that processing in addition to this Policy.


2. SCOPE

2.1 This Policy applies to personal information processed in connection with:

(a) https://www.hypenestglobal.com and related websites and landing pages;
(b) SaaS platforms, dashboards, and customer portals operated by Hype Nest Global;
(c) APIs, webhooks, and developer tools;
(d) mobile applications published or provided by Hype Nest Global;
(e) AI agents, chatbots, voice AI, and automation workflows configured or hosted by Hype Nest Global;
(f) WhatsApp Business, Facebook, Instagram, and other messaging or social integrations used in connection with the Services;
(g) sales, marketing, support, consulting, onboarding, and billing communications; and
(h) events, demos, proposals, and contractual engagements.

2.2 This Policy applies to individuals worldwide who interact with the Services, including website visitors, account holders, authorized users, end users who interact with Customer-deployed AI agents powered by our technology, and business contacts.

2.3 This Policy does not apply to:

(a) third-party websites, products, or services that we do not control, even if linked from or integrated with the Services;
(b) employment candidate or employee personal data processed solely in Hype Nest Global’s capacity as an employer, which may be covered by separate internal notices; or
(c) processing that a Customer performs independently outside the Services.

2.4 Depending on the context, Hype Nest Global may act as a data controller / data fiduciary (for example, when processing website visitor or billing contact data for our own business) or as a data processor / service provider (for example, when processing Customer end-user data solely to provide contracted Services). The applicable role is determined by the facts of each processing activity and any governing contract.


3. DEFINITIONS

For purposes of this Policy, unless the context otherwise requires:

3.1 “AI Output” means content, text, code, recommendations, predictions, transcriptions, summaries, voice responses, images, actions, or other material generated wholly or partly by artificial intelligence systems within the Services.

3.2 “AI Interaction Data” means Prompts, messages, voice inputs, uploads, tool calls, retrieval queries, model responses, feedback, ratings, and related metadata arising from use of AI features.

3.3 “Customer” means the business or individual that contracts with Hype Nest Global for the Services.

3.4 “Customer Data” means data submitted to, uploaded to, transmitted through, or generated within the Services by or on behalf of a Customer or its Users, including end-user content processed on Customer’s behalf.

3.5 “Meta Platform Data” means information obtained from or about Facebook, Instagram, WhatsApp, or other Meta products through Meta Platform APIs, SDKs, pixels, login, or messaging integrations.

3.6 “Personal Information” or “Personal Data” means information that identifies, relates to, describes, or could reasonably be linked with an identifiable individual, as defined under applicable law. The precise definition may vary by jurisdiction.

3.7 “Processing” means any operation performed on Personal Information, including collection, storage, use, disclosure, transfer, deletion, and anonymization.

3.8 “Prompt” means instructions, queries, context, documents, or data provided to an AI system.

3.9 “Services” means all products and offerings of Hype Nest Global as described in Section 1 and the introductory paragraphs.

3.10 “Special Category Data” or “Sensitive Personal Data” means categories of Personal Information that receive heightened protection under applicable law, which may include health data, biometric data, financial account credentials, government identifiers, and similar categories, depending on jurisdiction.

3.11 “Third-Party Providers” means vendors, subprocessors, and partners that help us operate the Services, including cloud, AI, payments, communications, analytics, and CRM providers.

3.12 “User” means an individual authorized by a Customer to access the Services, and, where context requires, an end user interacting with Customer systems that use the Services.

3.13 “You” means the individual to whom Personal Information relates, or the Customer acting on behalf of such individuals where appropriate.


4. INFORMATION WE COLLECT

4.1 We collect information in the following primary ways:

(a) information you provide directly to us;
(b) information collected automatically through your use of the Services;
(c) information generated through AI interactions and automations;
(d) information from Customers about their Users and end users when we act as a processor;
(e) information from Third-Party Providers and integrated platforms; and
(f) information from publicly available sources where lawful and relevant to business development.

4.2 The categories of information we collect depend on how you interact with us. Not every category is collected about every individual.

4.3 Sections 5 through 19 describe these categories in greater detail.


5. PERSONAL INFORMATION

5.1 Personal Information we may collect includes:

(a) identifiers such as name, username, alias, and account ID;
(b) contact details such as email address, telephone number, messaging handle, and postal or billing address;
(c) professional details such as job title, employer, department, and business role;
(d) authentication credentials, such as passwords (stored in hashed or otherwise protected form), multi-factor authentication data, and session tokens;
(e) support communications, including tickets, emails, call notes, and chat transcripts;
(f) signature and contracting details associated with proposals, order forms, and SOWs; and
(g) identity verification information where required for security, fraud prevention, or legal compliance.

5.2 We collect Personal Information when you create an account, request a demo, subscribe to communications, contact support, complete forms, participate in onboarding, or otherwise communicate with us.

5.3 Providing certain Personal Information is necessary to create accounts, receive support, or enter into contracts. If you do not provide required information, we may be unable to provide the requested Service.


6. BUSINESS INFORMATION

6.1 Because we primarily serve organizations, we also collect business-related information, which may include:

(a) company name, trade name, and corporate identifiers;
(b) industry, company size, and geographic markets;
(c) billing entity details, tax identifiers (such as GSTIN where applicable), and invoicing contacts;
(d) project requirements, technical specifications, and commercial preferences;
(e) workspace, tenant, and organization configuration data; and
(f) contractual commercial terms and usage entitlements.

6.2 Business information may contain Personal Information about individual contacts (for example, a finance manager’s email address). Such information is treated as Personal Information under this Policy to the extent required by applicable law.

6.3 Customer Content stored in business systems connected to the Services (CRM records, tickets, knowledge base articles, and similar) is processed according to the Customer’s instructions and applicable agreements when we act as a processor.


7. TECHNICAL INFORMATION

7.1 We automatically collect technical information when you access the Services, including:

(a) Internet Protocol (IP) address;
(b) browser type and version;
(c) operating system and platform;
(d) referring and exit URLs;
(e) requested pages, timestamps, and response codes;
(f) network type and connection information; and
(g) approximate location derived from IP address.

7.2 Technical information is used for security, diagnostics, performance optimization, fraud prevention, analytics, and Service delivery.

7.3 Technical information may constitute Personal Information where it can be linked to an identifiable individual.


8. DEVICE INFORMATION

8.1 We may collect device-related information such as:

(a) device identifiers;
(b) device model and manufacturer;
(c) mobile operating system version;
(d) application version;
(e) screen resolution and language settings;
(f) push notification tokens, where enabled; and
(g) advertising or analytics identifiers on mobile devices, subject to platform controls and consent requirements.

8.2 Device information helps us ensure compatibility, deliver notifications, troubleshoot issues, and improve mobile and web experiences.


9. USAGE INFORMATION

9.1 We collect information about how you use the Services, including:

(a) features accessed and actions taken within dashboards and applications;
(b) frequency, duration, and patterns of use;
(c) API call volumes, endpoints invoked, and error rates;
(d) message, voice-minute, token, or other metered usage;
(e) workflow runs, automation triggers, and integration events; and
(f) support and onboarding interactions related to product usage.

9.2 Usage Information enables billing accuracy, capacity planning, product improvement, abuse detection, and customer success support.

9.3 We may generate aggregated or de-identified statistics from Usage Information that do not reasonably identify individuals or Customers, and we may use such statistics for analytics, benchmarking (in anonymized form), and Service improvement.


10. AI INTERACTION DATA

10.1 When you or your end users use AI features, we may process AI Interaction Data, including:

(a) text Prompts, chat messages, and conversation history;
(b) voice audio, transcripts, and call metadata for voice AI features;
(c) documents, knowledge base excerpts, and retrieval context used for grounding;
(d) tool invocation logs and action outcomes;
(e) model identifiers, temperature or configuration parameters, and latency metrics;
(f) AI Output returned to users; and
(g) user feedback such as thumbs-up/down, corrections, or annotations.

10.2 AI Interaction Data may include Personal Information if individuals are named or identifiable in Prompts, uploads, or transcripts.

10.3 Customers should avoid submitting unnecessary sensitive Personal Information to AI features and should configure retention, redaction, and access controls appropriate to their risk profile.

10.4 Hype Nest Global does not use Customer Data to train general-purpose, cross-customer AI models without Customer’s prior written consent. We may process AI Interaction Data to provide, secure, debug, and improve the Services for that Customer, and for abuse prevention, subject to contract and this Policy.


11. UPLOADED FILES

11.1 Customers and Users may upload files to the Services, including documents, spreadsheets, PDFs, images, audio, video, knowledge articles, datasets, and configuration files.

11.2 Uploaded files may contain Personal Information, confidential business information, or regulated data. Customer is responsible for ensuring it has all rights, notices, and consents required to upload and process such files through the Services.

11.3 We process uploaded files to provide the requested functionality (for example, document processing, OCR, RAG indexing, storage, sharing within a workspace, or AI summarization).

11.4 Customers should apply data minimization and avoid uploading Special Category Data unless a lawful basis exists and appropriate contractual and technical safeguards are in place (including a DPA or Business Associate Agreement where required).


12. COOKIES

12.1 We use cookies and similar technologies on our websites and, where applicable, within product interfaces. Cookies are small text files stored on your device that help the Sites function, remember preferences, and understand usage.

12.2 Categories of cookies we use include:

(a) Essential cookies, required for security, authentication, load balancing, fraud prevention, and storing consent preferences;
(b) Functional cookies, which remember language, interface preferences, and similar settings;
(c) Analytics cookies, which help us understand traffic and feature usage; and
(d) Marketing cookies, which support advertising measurement and remarketing where permitted.

12.3 Where required by applicable law, we obtain consent before placing non-essential cookies. Essential cookies may be used as necessary to provide the Sites and Services you request.

12.4 Further detail is provided in Sections 48 and in our Cookie Policy. If there is a conflict regarding cookie mechanics, the Cookie Policy controls for cookie-specific disclosures, while this Policy controls for broader personal data rights.


13. SIMILAR TECHNOLOGIES

13.1 In addition to cookies, we may use:

(a) web beacons and pixels;
(b) local storage and session storage;
(c) software development kits (SDKs);
(d) tagging libraries; and
(e) server-side event tracking.

13.2 These technologies may collect device, usage, and interaction data similar to cookies and are subject to the same category-based consent approach where legally required.

13.3 Clearing cookies or site data in your browser generally removes or resets many of these technologies for that browser profile.


14. ANALYTICS

14.1 We use analytics tools to understand how visitors and Users interact with the Services, diagnose performance issues, and improve usability.

14.2 Analytics data may include page views, session duration, referral sources, approximate geography, device type, feature adoption, and conversion events.

14.3 Analytics may be performed using first-party tooling and Third-Party Providers. Where analytics cookies or identifiers are non-essential, we use them only with appropriate consent where required by law.

14.4 We prefer aggregated and pseudonymized analytics where practicable.


15. MARKETING TECHNOLOGIES

15.1 We may use marketing technologies to measure campaign performance, attribute conversions, suppress duplicate ads, and, where permitted, deliver relevant advertisements about Hype Nest Global.

15.2 Marketing technologies may involve advertising identifiers, campaign parameters, and event tags.

15.3 Non-essential marketing technologies are used only where appropriate consent has been obtained, where required by applicable law.

15.4 You may withdraw marketing cookie consent through our preference tools and may unsubscribe from marketing emails as described in Section 50.


16. META PIXEL

16.1 We may use the Meta Pixel (and related Meta measurement technologies) on our websites to measure advertising effectiveness, understand actions users take after seeing or clicking ads, and support audience building where permitted.

16.2 The Meta Pixel may collect information such as page views, standard and custom events, browser information, and identifiers according to Meta’s tools and your consent and browser settings.

16.3 Where required by law, Meta Pixel tags are activated only after marketing consent.

16.4 Meta processes information under Meta’s own terms and policies. Hype Nest Global does not sell Facebook, Instagram, or WhatsApp user data. Our use of Meta Platform data is limited to providing the services requested by the user and operating legitimate advertising and analytics for our own business where permitted.

16.5 Additional Meta-related processing is described in Sections 31 through 34.


17. GOOGLE ANALYTICS

17.1 We may use Google Analytics or successor Google measurement products to collect aggregated statistics about Site and product usage.

17.2 Google Analytics may use cookies or similar identifiers to distinguish sessions and users and may process IP address, device information, and interaction events.

17.3 Where required, Google Analytics is enabled only after consent. We may implement available controls such as consent mode, IP anonymization, or data retention settings offered by Google.

17.4 Google’s processing is governed by Google’s privacy documentation and contractual terms with us. You may use Google-provided opt-out mechanisms where available, in addition to our cookie preference controls.

17.5 Where Google API services are used in Customer integrations, we strive to handle Google user data in a manner consistent with the Google API User Data Policy and Limited Use requirements applicable to the scopes requested, and we do not use Google user data for prohibited purposes.


18. LOG FILES

18.1 Our servers, applications, and security systems generate log files that may record:

(a) IP addresses and request headers;
(b) authentication events and access attempts;
(c) API requests and error traces;
(d) system events, alerts, and administrative actions; and
(e) security monitoring signals.

18.2 Log files are used for security, troubleshooting, auditing, abuse detection, legal compliance, and Service reliability.

18.3 Log retention periods vary by system criticality and legal requirements. Security logs may be retained longer than routine application logs.

18.4 Access to production logs is restricted to authorized personnel with a need to know.


19. INFORMATION FROM THIRD PARTIES

19.1 We may receive information from:

(a) Customers who authorize Users and provide workspace configuration data;
(b) payment processors regarding payment status (we do not store full payment card numbers when processors handle card data);
(c) cloud, communications, and AI providers regarding delivery, usage, and abuse signals;
(d) CRM and marketing platforms used in our sales operations;
(e) publicly available business directories and professional networking sources for legitimate B2B outreach where lawful; and
(f) Meta, Google, Microsoft, and other identity or platform providers when you choose to connect accounts or use platform login.

19.2 We combine third-party information with information we collect directly where appropriate to operate and improve the Services, personalize communications, and prevent fraud.

19.3 Third parties are responsible for ensuring they have lawful rights to share information with us.


20. HOW WE USE INFORMATION

20.1 We use information for the following purposes:

(a) Providing the Services, including account creation, authentication, hosting, AI features, automations, integrations, support, and customer success;
(b) Performing contracts, including proposals, SOWs, billing, collections, and delivery of Deliverables;
(c) Securing the Services, including monitoring, threat detection, incident response, and fraud prevention;
(d) Improving and developing products, features, documentation, and user experience;
(e) Communicating with you about Service updates, security notices, administrative messages, and support;
(f) Marketing our Services where permitted, including email campaigns and advertising measurement;
(g) Analytics and research, including aggregated insights and Service performance measurement;
(h) Compliance, including responding to legal process, enforcing agreements, and meeting regulatory obligations; and
(i) Corporate transactions, as described in Section 47.

20.2 We do not use Personal Information for purposes that are incompatible with those disclosed in this Policy without providing notice and, where required, obtaining consent or another valid lawful basis.

20.3 When we act as a processor for Customer Data, we process that data to provide the Services according to Customer’s documented instructions and the applicable DPA, and not for our independent marketing purposes.


21. AI PROCESSING

21.1 Certain Services involve AI Processing, including large language models, speech models, embeddings, retrieval-augmented generation, classification, summarization, and agentic tool use.

21.2 AI Processing may occur on infrastructure operated by Hype Nest Global and/or Third-Party AI Providers such as OpenAI, Anthropic, Google, Microsoft Azure, and AWS.

21.3 AI Processing is used to generate AI Output, power agents and automations, index knowledge bases, transcribe and summarize communications, assist support workflows, and provide analytics insights.

21.4 Customers control many configuration choices affecting AI Processing, including knowledge sources, tool permissions, retention settings, and human escalation paths.

21.5 Hype Nest Global shall not use Customer Data to train general-purpose, cross-customer AI models without Customer’s prior written consent. Customer-dedicated fine-tuning or configuration, if any, occurs only where expressly agreed.


22. AUTOMATED DECISION MAKING

22.1 The Services may include automated workflows, scoring, routing, classification, or recommendations.

22.2 Hype Nest Global does not generally make solely automated decisions that produce legal or similarly significant effects about individuals in our capacity as a controller without meaningful human involvement, except where such processing is necessary for a contract, authorized by law, or based on explicit consent, and appropriate safeguards are applied.

22.3 Where Customers configure AI agents or automations that make or inform decisions about their own end users or employees, Customer is responsible for compliance with automated decision-making rules applicable to Customer’s use case, including transparency, human intervention, and contestability requirements under GDPR or similar laws.

22.4 Customers should not use the Services as the sole determinant of high-risk decisions without documented human review.


23. HUMAN REVIEW REQUIREMENT

23.1 AI Output and automated recommendations are decision-support tools. Customers must implement reasonable human review before relying on AI Output for material business, legal, financial, medical, employment, credit, safety, or compliance decisions.

23.2 Hype Nest Global is not responsible for harm arising from a Customer’s failure to implement adequate human oversight.

23.3 Where Hype Nest Global configures an agent on Customer’s behalf, Customer remains responsible for defining escalation paths, override mechanisms, and quality assurance.


24. AI LIMITATIONS

24.1 AI systems are probabilistic. They may produce incomplete, inaccurate, biased, outdated, or contextually inappropriate results, including fabricated citations or other “hallucinations.”

24.2 AI Output should never be relied upon without verification. AI should not replace professional legal, medical, financial, tax, accounting, or regulatory advice.

24.3 Performance varies based on Prompt quality, Customer Data quality, model selection, and configuration. Hype Nest Global does not guarantee specific accuracy levels unless expressly agreed in a written service level commitment.

24.4 Additional AI-specific terms appear in our AI Usage Policy and Terms and Conditions.


25. LAWFUL BASIS FOR PROCESSING

25.1 Where GDPR, UK GDPR, or similar regimes apply and Hype Nest Global acts as a controller, we rely on one or more of the following lawful bases:

(a) Contractual necessity, to provide Services you request or to take steps prior to entering a contract;
(b) Legitimate interests, such as securing Services, improving products, preventing fraud, and conducting B2B marketing that does not override individuals’ rights;
(c) Consent, where required for non-essential cookies, certain marketing, or specific optional processing;
(d) Legal obligation, where processing is required to comply with law; and
(e) Vital interests, in rare cases involving threats to life or safety.

25.2 Under India’s DPDP Act framework, we strive to process personal data for lawful purposes with appropriate notice and, where required, consent, and to honor applicable rights of Data Principals.

25.3 Under CCPA/CPRA, we process Personal Information for business purposes described in this Policy. We do not sell Personal Information for monetary consideration. Whether certain advertising technologies constitute “sharing” or a “sale” under California law depends on configuration; where applicable, we provide opt-out mechanisms consistent with that law.

25.4 Where we act as a processor, the Customer is responsible for establishing its own lawful basis for processing end-user Personal Information.


26. DATA SHARING

26.1 We share Personal Information only as described in this Policy, including with:

(a) Service Providers and subprocessors that assist in operating the Services;
(b) Cloud, AI, payments, communications, and analytics providers;
(c) Professional advisors such as lawyers, accountants, and auditors under confidentiality obligations;
(d) Corporate transaction counterparties as described in Section 47;
(e) Authorities, courts, or regulators when required by law or necessary to protect rights, safety, and security; and
(f) Other parties with your direction or consent.

26.2 We require Service Providers that process Personal Information on our behalf to implement appropriate confidentiality and security obligations and to process data only for specified purposes.

26.3 We do not sell Facebook, Instagram, or WhatsApp user data. We do not sell Personal Information as that term is commonly understood as exchanging data for money. We also do not share Meta Platform Data with third parties for their independent marketing purposes.

26.4 Aggregated or de-identified information that cannot reasonably be used to identify an individual may be shared or used without restriction, subject to applicable law prohibiting re-identification.


27. SERVICE PROVIDERS

27.1 We engage Service Providers to support hosting, infrastructure, email delivery, customer support tooling, analytics, security monitoring, product development, and operations.

27.2 Service Providers may process Personal Information only to perform services for us and must not use it for their own unrelated purposes, except as permitted by law and contract (for example, security event logging on their platforms).

27.3 A list of material subprocessors may be made available to enterprise Customers upon request or through contractual documentation.


28. CLOUD PROVIDERS

28.1 The Services may be hosted on or interconnected with cloud infrastructure providers, including AWS, Microsoft Azure, Google Cloud, DigitalOcean, Vercel, Cloudflare, and similar providers.

28.2 Cloud Providers process data as infrastructure or platform providers under their terms and our contractual arrangements. They may store data in multiple regions depending on Service configuration and redundancy design.

28.3 Customers may have choices regarding region or deployment model in certain enterprise engagements; such choices will be reflected in the applicable Order Form or SOW where offered.


29. PAYMENT PROVIDERS

29.1 We use payment providers such as Stripe and Razorpay to process payments.

29.2 Payment card details are typically collected and processed directly by the payment provider. Hype Nest Global generally receives limited payment metadata such as payment status, last four digits, card brand, billing name, and transaction identifiers.

29.3 Payment Providers process information under their own privacy policies and security standards (including PCI-DSS obligations applicable to them).

29.4 We use payment-related information for billing, accounting, fraud prevention, tax compliance, and customer support.


30. AI PROVIDERS

30.1 AI features may rely on Third-Party AI Providers, including OpenAI, Anthropic, Google, Microsoft Azure, AWS Bedrock, Meta, and similar providers.

30.2 Prompts, context, and outputs may be transmitted to AI Providers to generate AI Output. The availability, retention, and training practices of AI Providers are governed by their terms and by the integration mode we configure.

30.3 We select and configure AI Providers using commercially reasonable efforts to align with Customer confidentiality expectations and contractual commitments. Enterprise Customers may request specific contractual protections through a DPA or SOW.

30.4 Hype Nest Global is not responsible for independent acts or omissions of AI Providers beyond our commercially reasonable selection, configuration, and contractual oversight, except as required by mandatory law.


31. META PLATFORM DATA

31.1 Hype Nest Global may integrate with Meta technologies, including Facebook, Instagram, WhatsApp Business Platform, Meta Pixel, and related APIs, when Customers enable such integrations or when visitors interact with our marketing properties.

31.2 Our use of Meta Platform Data is limited to providing the services requested by the user and operating the integrations and business functions described in this Policy.

31.3 Hype Nest Global does not sell Facebook, Instagram, or WhatsApp user data.

31.4 We strive to comply with Meta Platform Terms, Meta Developer Policies, and applicable WhatsApp Business terms when accessing Meta Platform Data.

31.5 Meta Platform Data may include profile information, page permissions, messaging content necessary to deliver Customer-requested automations, ad measurement events, and technical metadata, depending on the integration and permissions granted.

31.6 Customers who connect Meta assets are responsible for ensuring they have lawful rights and required notices/consents for messaging and data use involving their end users.


32. FACEBOOK LOGIN DATA

32.1 If you choose to sign in or connect using Facebook Login, we may receive information authorized by you and permitted by Meta, which may include your name, email address, profile identifier, and other fields associated with the granted permissions.

32.2 We use Facebook Login Data to authenticate you, create or link an account, and provide connected features you request.

32.3 You may disconnect Facebook Login through your account settings (where available) or through Facebook’s application settings. Disconnecting may limit related features.

32.4 We do not sell Facebook Login Data. Our use is limited to providing the services requested by the user.


33. INSTAGRAM DATA

33.1 Where Customers connect Instagram business or creator assets, we may process Instagram Data necessary to provide requested features, such as content management support, messaging automations, insights displays, or comment moderation tools, depending on product scope.

33.2 Instagram Data is processed according to granted permissions, Meta Platform Terms, Customer instructions, and this Policy.

33.3 Hype Nest Global does not sell Instagram user data. Use is limited to providing the services requested by the user and the Customer’s configured workflows.

33.4 Customers remain responsible for complying with Instagram and Meta rules, including disclosure and consent obligations for automated interactions.


34. WHATSAPP BUSINESS DATA

34.1 Where Customers use WhatsApp Business Platform integrations through the Services, we may process WhatsApp Business Data such as phone numbers, message content, templates, delivery status, media, and conversation metadata necessary to send, receive, route, log, and automate messages.

34.2 WhatsApp Business Data is processed to provide the messaging and automation services requested by the Customer and end users initiating or consenting to conversations, subject to WhatsApp and Meta terms and applicable anti-spam and electronic communications laws.

34.3 Hype Nest Global does not sell WhatsApp user data. Our use of WhatsApp Business Data is limited to providing the services requested by the user and fulfilling Customer-configured business workflows.

34.4 Customers must maintain lawful opt-in, opt-out, and disclosure practices for WhatsApp communications and must not use the Services for spam or prohibited messaging categories.

34.5 Message content may be sensitive. Customers should configure retention and access controls appropriately and avoid transmitting unnecessary Special Category Data over messaging channels.


35. DATA RETENTION

35.1 We retain Personal Information only for as long as reasonably necessary to fulfill the purposes described in this Policy, including:

(a) providing and improving the Services;
(b) maintaining business and tax records;
(c) resolving disputes and enforcing agreements;
(d) detecting and preventing security incidents and abuse; and
(e) complying with legal obligations.

35.2 Retention periods vary by data category. For example:

(a) account and billing records are typically retained for the account life plus a period required for legal and accounting purposes;
(b) support tickets may be retained for a period useful for service continuity and quality;
(c) security logs may be retained according to security policy;
(d) marketing contact records are retained until unsubscribe or inactivity criteria are met, subject to suppression list retention; and
(e) Customer Data in active workspaces is retained until Customer deletes it, the subscription ends and export/deletion windows expire, or deletion is requested and effectuated under contract.

35.3 When retention is no longer necessary, we delete or de-identify Personal Information, except where retention is required by law or needed for legitimate dispute resolution and security purposes.

35.4 Backup systems may retain residual copies for a limited period after deletion from production systems until overwritten in accordance with backup cycles.


36. SECURITY MEASURES

36.1 Hype Nest Global implements commercially reasonable administrative, technical, and physical safeguards designed to protect Personal Information against unauthorized access, disclosure, alteration, and destruction.

36.2 Security measures may include, depending on the Service:

(a) encryption in transit;
(b) encryption at rest where supported by the relevant systems;
(c) access controls and least-privilege principles;
(d) authentication controls, including multi-factor authentication options where available;
(e) network protections such as firewalls and segmentation;
(f) monitoring, logging, and alerting;
(g) secure cloud infrastructure provided by reputable Cloud Providers;
(h) employee access controls and confidentiality obligations; and
(i) periodic review of security practices and vendor risk.

36.3 Despite these measures, no method of transmission over the Internet or method of electronic storage is completely secure. Absolute security cannot be guaranteed.

36.4 Customers are responsible for securing their own credentials, endpoints, connected systems, and configurations under their control, and for promptly applying security recommendations we communicate.


37. ENCRYPTION

37.1 We use encryption technologies to protect data in transit, typically including Transport Layer Security (TLS) for web and API communications.

37.2 Data at rest may be encrypted using provider-managed or application-managed encryption features depending on the system and plan.

37.3 Encryption keys are protected using access controls and cloud key management practices appropriate to the environment.

37.4 Encryption reduces but does not eliminate risk. Customers should avoid transmitting highly sensitive data through channels not designed for that sensitivity level.


38. USER RIGHTS

38.1 Depending on your location and role (for example, Data Principal under the DPDP Act, data subject under GDPR/UK GDPR, or consumer under CCPA/CPRA), you may have rights regarding your Personal Information, which may include rights to:

(a) access and obtain a copy of Personal Information;
(b) correct inaccurate Personal Information;
(c) delete Personal Information;
(d) portability of Personal Information;
(e) restrict or object to certain processing;
(f) withdraw consent where processing is consent-based;
(g) opt out of sale or sharing of Personal Information where those concepts apply; and
(h) lodge a complaint with a supervisory authority.

38.2 These rights are not absolute and may be limited by law, exemptions, conflicting rights of others, and our reasonable verification requirements.

38.3 If Personal Information is processed by Hype Nest Global solely as a processor on behalf of a Customer, we may direct you to the relevant Customer to exercise your rights, and we will assist the Customer as required by contract and law.


39. ACCESS REQUESTS

39.1 You may request confirmation of whether we process your Personal Information and request access to such information by contacting joydip@hypenestglobal.com with the subject line “Privacy Access Request.”

39.2 We may request information reasonably necessary to verify your identity and locate relevant records.

39.3 We will respond within the timeframe required by applicable law or, where no specific timeframe applies, within a reasonable period.

39.4 Where requests are manifestly unfounded or excessive, we may charge a reasonable fee or refuse the request to the extent permitted by law.


40. CORRECTION REQUESTS

40.1 You may request correction of inaccurate or incomplete Personal Information by contacting joydip@hypenestglobal.com with the subject line “Privacy Correction Request.”

40.2 Account holders may also update certain profile information directly through account settings where available.

40.3 We may verify the accuracy of correction requests and may retain prior records where required for audit, security, or legal purposes.


41. DELETION REQUESTS

41.1 You may request deletion of Personal Information by contacting joydip@hypenestglobal.com with the subject line “Privacy Deletion Request.”

41.2 We will process deletion requests within a reasonable timeframe unless retention is required by law, necessary for security and fraud prevention, required to complete a transaction, needed to resolve disputes, or otherwise permitted or required under applicable law or contractual obligations.

41.3 Deletion of account data may result in loss of access to the Services and associated content.

41.4 Residual copies in backups may persist for a limited period until overwritten.

41.5 Additional deletion procedures for Meta Platform Data and account deletion are described in Sections 51 and 52.


42. DATA PORTABILITY

42.1 Where applicable law provides a right to data portability, you may request a copy of certain Personal Information in a structured, commonly used, and machine-readable format by contacting joydip@hypenestglobal.com.

42.2 Portability rights typically apply to information you provided to us and that is processed by automated means based on consent or contract, subject to legal limits.

42.3 Customers may export Customer Data using product export tools where available, or by requesting assistance through support for enterprise plans.


43. RESTRICT PROCESSING

43.1 Where applicable, you may request that we restrict processing of your Personal Information in circumstances recognized by law, such as when accuracy is contested or processing is unlawful and you oppose deletion.

43.2 During restriction, we will store the information and process it only for limited purposes permitted by law, such as establishment of legal claims or with your consent.

43.3 Submit restriction requests to joydip@hypenestglobal.com with relevant details.


44. WITHDRAW CONSENT

44.1 Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

44.2 Withdrawal methods include:

(a) cookie preference center controls for non-essential cookies;
(b) unsubscribe links in marketing emails;
(c) disconnecting third-party integrations; and
(d) emailing joydip@hypenestglobal.com.

44.3 If you withdraw consent required for a feature, we may be unable to continue providing that feature.


45. INTERNATIONAL DATA TRANSFERS

45.1 Hype Nest Global is based in India and serves Customers worldwide. Personal Information may be transferred to, stored in, or processed in India and other countries where we or our Service Providers operate, including the United States and other jurisdictions.

45.2 These countries may have data protection laws different from those in your jurisdiction.

45.3 Where required by applicable law, we implement appropriate safeguards for cross-border transfers, which may include contractual clauses, provider certifications or transfer mechanisms, and transfer risk assessments, as applicable to the transfer context.

45.4 By using the Services, you understand that your information may be transferred internationally as described in this Policy, subject to your rights under mandatory law.


46. CHILDREN’S PRIVACY

46.1 The Services are directed to business users and are not intended for children.

46.2 We do not knowingly collect Personal Information from children under eighteen (18) years of age, or under the age of digital consent applicable in a given jurisdiction, for our own purposes.

46.3 Customers who use the Services in contexts involving minors (for example, educational institutions) are solely responsible for obtaining required consents and complying with child protection and education privacy laws.

46.4 If you believe we have collected Personal Information from a child inconsistently with applicable law, contact joydip@hypenestglobal.com, and we will take appropriate steps to delete such information where required.


47. BUSINESS TRANSFERS

47.1 If Hype Nest Global is involved in a merger, acquisition, corporate reorganization, financing, insolvency proceeding, or sale of all or substantially all assets, Personal Information may be transferred to counterparties and advisors as part of that transaction, subject to appropriate confidentiality arrangements.

47.2 The successor entity will be bound to protect Personal Information in a manner consistent with this Policy, or will provide notice of material changes and any choices required by law.

47.3 Personal Information may also be disclosed during due diligence to the extent reasonably necessary and protected by contractual controls.


48. COOKIES AND CONSENT

48.1 We use cookies and similar technologies as described in Sections 12 through 17 and in our Cookie Policy.

48.2 Cookie categories include Essential, Functional, Analytics, Marketing, and Third-Party cookies.

48.3 Non-essential cookies are used only where appropriate consent has been obtained, where required by applicable law.

48.4 You may manage cookie preferences through:

(a) our cookie banner or preference center (where available);
(b) browser settings that block or delete cookies; and
(c) industry or platform opt-out tools for interest-based advertising.

48.5 Blocking essential cookies may impair Site and Service functionality.

48.6 Google Analytics and Meta Pixel are treated as analytics/marketing technologies and are consent-gated where required.


49. THIRD-PARTY LINKS

49.1 The Services may contain links to third-party websites, applications, and services that we do not control.

49.2 This Policy does not apply to third-party practices. We encourage you to review the privacy policies of any third party you access.

49.3 Hype Nest Global is not responsible for the content or privacy practices of third parties.


50. MARKETING COMMUNICATIONS

50.1 We may send Service-related administrative messages that are not marketing, such as security alerts, billing notices, and product updates necessary to provide the Service. These communications may not offer an unsubscribe option where they are transactional in nature.

50.2 Where permitted by law, we may send marketing emails, newsletters, event invitations, and promotional messages about Hype Nest Global Services.

50.3 You may opt out of marketing emails by using the unsubscribe link in the message or by contacting joydip@hypenestglobal.com. We will honor opt-outs within a reasonable timeframe and may retain minimal information on a suppression list to ensure we do not re-contact you.

50.4 Opting out of marketing does not opt you out of transactional Service communications.

50.5 WhatsApp, SMS, or voice marketing, if used, will be conducted only with required consents and in accordance with applicable electronic communications laws and channel provider policies.


51. ACCOUNT DELETION

51.1 Customers and Users may request deletion of their accounts by contacting joydip@hypenestglobal.com or, where available, through in-product account settings.

51.2 Account deletion requests will be processed within a reasonable timeframe, subject to:

(a) verification of authority (especially for organization-owned accounts);
(b) settlement of outstanding fees where applicable;
(c) export windows for Customer Data where contractually provided; and
(d) legal retention requirements.

51.3 Organization administrators may control User access independently of individual deletion requests. If you are a User of a Customer organization, your workspace data may be controlled by that Customer.

51.4 After account deletion, residual backup copies may persist for a limited period, and certain records (for example, invoices) may be retained as required by law.


52. DATA DELETION REQUESTS

52.1 Users may request deletion of their personal information by contacting:

Email: joydip@hypenestglobal.com
Subject line: Data Deletion Request

52.2 Requests should include your name, account email or identifiers, description of the data to be deleted, and any Meta/Facebook/Instagram/WhatsApp identifiers relevant to the request.

52.3 Requests will be processed within a reasonable timeframe unless retention is required by law or contractual obligations.

52.4 For Meta Platform Data deletion requests related to Facebook Login or Meta integrations, you may also remove our app’s access through your Meta account settings. Upon receiving a complete deletion request, we will delete Meta Platform Data we hold that is no longer needed to provide the Services, subject to legal retention exceptions, and will confirm completion where required by Meta policies.

52.5 Where we process data solely as a processor for a Customer, end users should generally submit deletion requests to that Customer. We will assist Customers with deletion in accordance with our DPA and product capabilities.

52.6 Hype Nest Global does not sell Facebook, Instagram, or WhatsApp user data, and deletion requests will not be delayed for any purpose of selling or commercially exploiting such data.


53. INCIDENT RESPONSE

53.1 In the event Hype Nest Global becomes aware of a security incident that has resulted in unauthorized access to, or disclosure of, Personal Information under our control, we will take appropriate investigative and remedial steps.

53.2 We will notify affected Customers and/or individuals without undue delay, and in any event within timeframes required by applicable law, and will provide reasonably available information regarding the nature of the incident, likely consequences, and measures taken or proposed.

53.3 Customers must promptly notify us if they become aware of unauthorized access to their accounts or integrations that may affect the security of the Services.

53.4 Notification timing and content may be constrained by law enforcement requests, ongoing investigation needs, and the maturity of available facts.


54. CHANGES TO POLICY

54.1 We may update this Privacy Policy from time to time to reflect changes in our Services, legal requirements, or business practices.

54.2 The Effective Date and version at the top of this Policy will be revised when updates are published.

54.3 Material changes will be communicated by posting the updated Policy on our website and, where appropriate, by email or in-product notice. Where required by law, we will provide advance notice or obtain consent for material changes.

54.4 Continued use of the Services after the effective date of an updated Policy constitutes acceptance of the updated Policy to the extent permitted by law. If you do not agree, you must stop using the Services and may request account closure.


55. CONTACT INFORMATION

55.1 For privacy questions, requests, or concerns, contact:

Hype Nest Global
Head Office: Bengaluru, Karnataka, India
Website: https://www.hypenestglobal.com
Email: joydip@hypenestglobal.com

55.2 Please include sufficient detail for us to understand and respond to your request, including the nature of the request and relevant account identifiers.

55.3 If you are an EU/UK data subject and believe we have not adequately addressed your concern, you may lodge a complaint with your local supervisory authority. If you are in India, you may pursue remedies available under the DPDP Act and related rules once applicable. We encourage you to contact us first so we can attempt to resolve your concern directly.


56. ROLES AND RESPONSIBILITIES OF CUSTOMERS

56.1 Customers that use the Services to process Personal Information of their own employees, clients, patients, students, or end users are responsible for:

(a) providing required privacy notices to data subjects;
(b) obtaining required consents and establishing lawful bases;
(c) configuring the Services securely and appropriately;
(d) ensuring industry-specific compliance (including healthcare, financial services, and education rules); and
(e) handling data subject requests directed to them as controller/fiduciary.

56.2 Hype Nest Global’s provision of technology does not constitute legal advice or a representation that a Customer’s particular deployment is compliant.

56.3 Enterprise Customers may request a DPA to govern processor obligations, security measures, subprocessors, and cross-border transfer terms.


57. SENSITIVE AND SPECIAL CATEGORY DATA

57.1 We do not request Special Category Data or Sensitive Personal Data through general website forms.

57.2 If Customers choose to process health, biometric, financial, government ID, or similarly sensitive data through the Services, Customers must ensure a lawful basis, implement heightened safeguards, and execute any required additional agreements (such as a Business Associate Agreement for HIPAA-covered data).

57.3 AI features should not be used for sensitive data processing unless the Customer has assessed risks and configured appropriate controls.

57.4 Hype Nest Global may refuse or suspend processing that creates unacceptable legal or security risk.


58. HEALTHCARE CONTEXT

58.1 Where Customers are healthcare providers or process health-related information, the Services are administrative and operational tools unless expressly agreed otherwise in writing.

58.2 AI Output is not medical advice, diagnosis, or clinical decision support. Human clinical judgment remains essential.

58.3 Customers are responsible for compliance with applicable patient privacy laws, including the DPDP Act and, where applicable, HIPAA and related frameworks.


59. FINANCIAL AND LEGAL CONTEXT

59.1 AI Output and analytics do not constitute financial, investment, tax, accounting, or legal advice.

59.2 Customers and individuals should consult qualified professionals before making regulated or high-stakes decisions based on outputs from the Services.


60. DO NOT TRACK AND GLOBAL PRIVACY CONTROLS

60.1 Some browsers offer “Do Not Track” signals. Because there is no common industry standard for responding to DNT, our practices are described in this Policy and our Cookie Policy rather than relying solely on DNT.

60.2 Where we deploy technologies that recognize Global Privacy Control or similar opt-out preference signals for CCPA/CPRA “sale”/”sharing” opt-outs, we will process such signals as required by applicable law for the relevant browser/device context.


61. CALIFORNIA PRIVACY DISCLOSURES

61.1 This Section provides additional information for California residents.

61.2 Categories of Personal Information we may collect are described in Sections 4 through 19 and include identifiers, commercial information, internet/electronic activity, professional information, and inferences drawn from such information for Service improvement and limited marketing.

61.3 We collect Personal Information for the business and commercial purposes described in Section 20.

61.4 We disclose Personal Information to Service Providers and other parties described in Sections 26 through 34 for business purposes.

61.5 We do not sell Personal Information for money. Certain advertising technologies may be considered “sharing” under CCPA/CPRA; where applicable, California residents may opt out via cookie preference tools and by emailing joydip@hypenestglobal.com with the subject line “California Opt-Out.”

61.6 California residents may request access, deletion, correction, and information about our practices, subject to verification and legal exceptions.

61.7 We will not discriminate against California residents for exercising CCPA/CPRA rights.


62. EUROPEAN AND UK PRIVACY DISCLOSURES

62.1 For individuals in the EEA, Switzerland, or United Kingdom, Hype Nest Global’s lawful bases are described in Section 25.

62.2 International transfers are described in Section 45.

62.3 Data subject rights are described in Sections 38 through 44.

62.4 Where required, our EU/UK representative details (if appointed) will be published on our website or provided on request.

62.5 Supervisory authority complaints may be lodged in your place of residence or work, or where an alleged infringement occurred.


63. INDIA DPDP DISCLOSURES

63.1 Hype Nest Global strives to process digital personal data in accordance with the principles of the DPDP Act, including lawful purpose, data minimization consistent with purpose, and security safeguards.

63.2 Data Principals may have rights to access, correction, erasure, and grievance redressal as provided under applicable DPDP rules.

63.3 Privacy requests and grievances may be submitted to joydip@hypenestglobal.com. We will address grievances within a reasonable period consistent with applicable requirements.

63.4 Where we process personal data on behalf of a Customer as a Data Processor, Customer’s instructions and the DPA govern such processing.


64. META PLATFORM TERMS AND DEVELOPER OBLIGATIONS

64.1 When we access Meta Platform Data, we strive to comply with Meta Platform Terms, Developer Policies, WhatsApp Business terms, and related requirements.

64.2 Permissions requested from Meta are limited to those needed to provide requested features.

64.3 We do not use Meta Platform Data for unauthorized surveillance, discriminatory practices prohibited by Meta policies, or sale to data brokers.

64.4 Hype Nest Global does not sell Facebook, Instagram, or WhatsApp user data. Our use of Meta Platform data is limited to providing the services requested by the user.

64.5 We provide a mechanism for data deletion requests as described in Section 52 and will respond to Meta-required callbacks or user deletion signals where implemented for specific apps.


65. GOOGLE API USER DATA

65.1 If the Services access Google user data via Google APIs, Hype Nest Global’s use of that data will be limited to providing or improving user-facing features that are prominent in the requesting application’s user interface, consistent with Google API User Data Policy and Limited Use rules applicable to the scopes requested.

65.2 We do not use Google user data for serving advertisements, and we do not transfer Google user data to third parties except as necessary to provide or improve features, as required for security/legal reasons, or as part of a merger/acquisition with notice, subject to Google policy requirements.

65.3 Human reading of Google user data, if any, is limited to policy-permitted circumstances such as security investigations, debugging with user consent, or compliance obligations.


66. RECORDING AND COMMUNICATIONS MONITORING

66.1 We may record calls or retain chat transcripts for training, quality assurance, and record-keeping where permitted by law and, where required, with notice or consent.

66.2 Customers using voice AI or call features must provide legally required notices to call participants regarding recording, AI assistance, and monitoring.


67. AGGREGATED AND DE-IDENTIFIED DATA

67.1 We may create aggregated, anonymized, or de-identified datasets from Service usage for analytics, research, benchmarking in non-identifying form, security, and product improvement.

67.2 We will not attempt to re-identify individuals from de-identified data except as permitted by law for testing de-identification effectiveness or as required to match records for security investigations.


68. ENFORCEMENT AND DISPUTE CONTEXT

68.1 Privacy-related disputes arising from contractual relationships with Customers are subject to the governing law and dispute resolution provisions of the Terms and Conditions, without prejudice to mandatory data protection rights that cannot be waived.

68.2 Nothing in this Policy limits rights that cannot be waived under mandatory applicable law.


69. INTERPRETATION

69.1 Headings are for convenience only and do not affect interpretation.

69.2 Words importing the singular include the plural and vice versa.

69.3 “Including” means “including without limitation.”

69.4 References to laws include amendments, re-enactments, and successor legislation.

69.5 If any provision of this Policy is found unenforceable, the remaining provisions continue in effect.


70. ENTIRE PRIVACY NOTICE

70.1 This Policy, together with the Cookie Policy and any applicable DPA or product-specific privacy notice, constitutes Hype Nest Global’s primary public privacy notice for the Services.

70.2 Product-specific supplemental notices may apply to particular features; those notices control for conflicts specific to those features.

If you have questions, contact joydip@hypenestglobal.com.

BY USING THE SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY.