1. scope and our roles
This Policy covers Lemura websites, web applications, customer engagement tools, WhatsApp integrations, AI-assisted features, voice workflows, support, and related services (together, the Services). It applies to website visitors, prospective and current customers, authorised workspace users, and individuals whose information is processed through a customer's use of the Services.
Our role depends on why the information is processed:
- Lemura as controller or data fiduciary. We decide why and how to process website, demo-request, account, billing, support, security, and our own business-operation data.
- Lemura as processor or service provider.A Lemura customer decides why and how its contacts, messages, files, calls, and other Customer Data are used. We process that data on the customer's documented instructions to provide the Services.
A customer agreement or data processing agreement may provide additional terms. If you received a message or call from a business using Lemura, that business is normally the first point of contact for questions about why it has your information.
2. information we handle
The information we handle depends on the features and integrations being used.
- Account and workspace data: name, business email, phone number, company and workspace name, user identifier, role, membership, sign-in and account status, preferences, and communications with us.
- Meta and WhatsApp connection data: WhatsApp Business Account and business portfolio identifiers, phone-number identifiers, display numbers, business profile details, templates, quality and messaging information, analytics, webhook events, OAuth codes, access tokens, and connection credentials. Secrets and tokens stored by Lemura are encrypted at rest and are not displayed back in full.
- Contacts and consent records: names, phone numbers, customer-defined attributes, lists, time zones, opt-in status, consent source and time, opt-outs, blocks, and suppression records supplied or recorded by the customer.
- Campaign and conversation data: campaign settings, approved templates, message text and media, sender and recipient details, timestamps, delivery and read status, replies, conversation history, human handoff state, message analytics, and customer-created labels or notes.
- Knowledge and AI data: documents, images, links, source text, extracted text, embeddings, instructions, prompts, relevant conversation context, generated replies, summaries, classifications, recommendations, and model-usage information.
- Voice data: calling numbers, call direction and timing, duration, call status and outcome, live audio handled by enabled providers, and, where the customer enables them, recordings, transcripts, summaries, collected fields, and escalation information.
- Commercial and administrative data: plan, usage, order, invoice, transaction, tax, and payment-related information where applicable. A payment provider may collect payment-card details directly; Lemura does not need customers to place full card numbers in messages or support requests.
- Website, sales, and support data: the name, email, company, and message submitted through our contact form, demo-booking details submitted to the scheduling provider, support requests, feedback, and related correspondence.
- Device, usage, and security data: IP address, browser and device type, operating system, referring page, session and cookie identifiers, pages and features used, event timestamps, audit events, diagnostic logs, performance data, error details, and sampled session-replay information used for troubleshooting.
Do not submit payment-card numbers, government identifiers, health information, biometric data, or other highly sensitive information through Lemura unless the customer has confirmed that the feature is suitable and Lemura has expressly agreed to that processing in writing.
3. how we collect information
We collect information:
- directly from you when you contact us, create an account, configure a workspace, or use a feature;
- from a customer when it imports contacts, uploads content, configures a campaign, or invites a user;
- from Meta and WhatsApp when an authorised customer connects its account and uses messaging features;
- from recipients when they send messages, interact with campaigns, opt out, or participate in enabled calls;
- automatically from browsers, devices, servers, cookies, logs, analytics, and security tools; and
- from integrations and service providers at a customer's direction or as needed to run our business.
Customers must not provide personal data to Lemura unless they have the rights, notices, permissions, consents, or other lawful basis required for that data and its intended use.
4. how and why we use information
We use information to:
- create and administer accounts, workspaces, roles, authentication, and customer support;
- connect authorised WhatsApp Business assets and send, receive, route, and report on communications;
- manage contacts, consent status, templates, campaigns, inboxes, analytics, and human handoff;
- provide knowledge-grounded AI replies, insights, recommendations, and enabled voice workflows;
- process subscriptions, usage, invoices, payments, and taxes;
- monitor reliability, debug errors, prevent fraud and abuse, enforce terms, and protect the Services;
- respond to requests, provide service notices, and send marketing about Lemura where permitted;
- comply with law, lawful requests, and the requirements of connected providers; and
- analyse and improve the Services using usage information and aggregated or de-identified data.
Lemura does not use Customer Content to train a general-purpose AI model. We may use de-identified service and performance information that cannot reasonably be linked to an individual or customer to understand and improve reliability, safety, and product performance.
Where applicable law requires a legal basis, processing may be necessary to perform a contract, take requested pre-contract steps, comply with law, protect legitimate interests such as service security and improvement, support certain permitted or legitimate uses, or act on consent. Consent may be withdrawn for future processing, but withdrawal does not affect processing already lawfully completed.
5. customer data and end users
Customer Data includes contacts, messages, media, files, campaign instructions, knowledge sources, call data, and other content submitted to or generated through a customer workspace. As between Lemura and the customer, the customer controls this data and Lemura processes it to deliver, secure, maintain, and support the requested Services.
- The customer determines recipients, content, purpose, lawful basis, and authorised workspace users.
- The customer must provide required privacy and recording notices and maintain valid messaging and calling permissions.
- The customer must promptly honour blocks, STOP messages, unsubscribe requests, objections, and other opt-outs.
- Authorised customer users may view and act on Customer Data according to their assigned permissions.
- Lemura does not sell Customer Data or independently market to a customer's message or call recipients.
If you are an end user of a Lemura customer, direct your request to the business that contacted you. We will assist that customer with a valid request as required by our agreement and applicable law.
6. Meta and WhatsApp data
A customer may connect WhatsApp through Meta's Embedded Signup or provide authorised WhatsApp Cloud API credentials. This authorises Lemura to access the customer's selected WhatsApp Business Account, business and phone-number details, business profile, templates, messages and status events, and messaging analytics as needed to provide the requested WhatsApp functionality.
For data obtained through the WhatsApp Business Solution, Lemura will:
- process it on the customer's instructions and authorisation to provide and support WhatsApp messaging;
- limit access to the information and permissions reasonably needed for the connected features;
- not sell, license, or distribute it to data brokers, advertisers, or unrelated third parties;
- not use it to track, build, or augment advertising profiles of individual WhatsApp users;
- not retarget people on or off WhatsApp using that data; and
- not combine it with unrelated third-party data for advertising or profiling.
Meta and WhatsApp also process information under their own terms and policies. The customer's use must comply with the WhatsApp Business Terms, WhatsApp Business Messaging Policy, and other applicable Meta terms. Lemura is an independent service provider; it is not Meta or WhatsApp and does not control their separate data practices.
7. AI and voice features
When AI features are enabled, relevant Customer Data may be sent to an AI service provider to create an embedding, extract information, analyse a conversation or document, generate an image, or produce a reply, summary, classification, or recommendation. Lemura uses that information to provide the requested output and does not use Customer Content to train its own general-purpose model.
When voice features are enabled, voice and media providers may process live audio to transport the call, transcribe speech, synthesize speech, and run the configured agent. Depending on customer settings, Lemura may retain a recording, final transcript, summary, outcome, collected fields, and usage record. The customer is responsible for lawful call initiation, caller identification, do-not-call rules, recording and AI disclosures, and all necessary consents.
AI output can be inaccurate or incomplete. Customers should maintain human oversight and must not use Lemura output as the sole basis for medical, legal, financial, emergency, safety-critical, employment, credit, or similarly significant decisions. Lemura is not an emergency calling service.
10. retention
We keep personal data only for as long as reasonably needed for the purpose described in this Policy, the customer's configuration and agreement, security and dispute handling, or a legal, tax, accounting, or provider requirement. Retention therefore varies by data type and customer setup.
- Customer Data is generally kept while the workspace is active or for the period agreed with the customer.
- Customers may configure separate retention periods for voice recordings, transcripts, and structured call data, where available.
- Deleting a workspace removes its active contacts, campaigns, messages, knowledge, voice data, settings, and stored workspace files.
- Account, invoice, security, fraud-prevention, audit, and legal records may be retained for a reasonable period after service use ends.
- Backups may retain residual copies for a limited recovery cycle before overwrite, and providers may retain data under their own documented obligations.
When data is no longer needed, we delete it, anonymise it, or isolate it until secure deletion is possible. We may retain information where law requires it, a valid legal hold applies, or it is necessary to prevent fraud, abuse, or security harm.
11. security
Lemura uses technical and organisational safeguards appropriate to the nature of the information. These include encrypted network transport, encrypted storage of access tokens and connection secrets, role-based access controls, tenant-level separation and database policies, least-privilege service access, signed or verified webhooks, audit logging, monitoring, and protected production credentials.
Customers must keep their account credentials and API secrets secure, limit user permissions, and notify us promptly of suspected unauthorised access. No Internet transmission or storage system is completely secure, so we cannot guarantee absolute security. If we identify a personal-data breach, we will investigate and provide notices required by applicable law and our agreements.
12. international transfers
Lemura is operated from India. We and our providers may process information in India, the United States, and other countries where infrastructure, personnel, or service providers are located. Those countries may have different privacy laws from your own.
Where required, we use contractual, organisational, or other lawful safeguards for cross-border transfers. Meta, WhatsApp, and other independent providers conduct their own global operations under their respective terms and transfer mechanisms.
13. your choices and rights
Depending on where you live and the context in which we process information, you may have the right to request access, a copy, correction, completion, deletion, restriction, portability, or information about processing; to object or withdraw consent; to opt out of marketing; to nominate another person where applicable; and to complain to the relevant regulator.
- Account users can update certain profile, workspace, and communication settings in the Services.
- Marketing emails may be stopped using the unsubscribe method in the message or by contacting us.
- WhatsApp recipients should use the sender's STOP or opt-out method or contact the sender business directly.
- Requests about data controlled by a Lemura customer should first be sent to that customer.
To exercise a right with Lemura, email contact@lemura.in with the subject “Privacy Request.” We may ask for information reasonably necessary to verify identity, authority, account ownership, and request scope. We will respond within the period required by applicable law and will explain if an exception applies.
14. data deletion instructions
You can request deletion in any of the following ways:
- Delete a customer workspace. A workspace owner can sign in at the Lemura application, select the relevant workspace, open the Dashboard, choose “Delete workspace,” and type the workspace name to confirm. This permanently deletes active workspace members and invites, contacts, campaigns, messages, knowledge bases, voice data, settings, and stored files. It does not delete the user's sign-in identity or another workspace.
- Send a deletion request. Email contact@lemura.in with the subject “Data Deletion Request.” Include the registered email address, business and workspace name, the data or account to delete, and, if relevant, the WhatsApp Business Account or phone-number identifier. Do not send passwords, access tokens, full payment details, or unnecessary message content.
- If a business contacted you. Ask that business to delete or correct your information. If you also contact Lemura, identify the sender business and sender number so we can locate the responsible customer without collecting more information than necessary.
- Revoke Meta access.You can remove Lemura from Facebook Settings under Business Integrations. See Meta's business-integration removal instructions. Revocation stops future access through that connection but does not by itself delete information previously stored in Lemura, so also delete the workspace or submit a deletion request.
After verification, we will delete or anonymise the requested information from active Lemura systems, notify relevant processors where required, and confirm completion, unless retention is required for law, security, fraud prevention, dispute resolution, or another permitted purpose. Residual backup copies are removed through normal overwrite cycles and are not restored to active use.
15. children
Lemura accounts and business Services are not directed to people under 18, and we do not knowingly invite children to create accounts. If you believe a child has provided personal data directly to Lemura without valid authorisation, contact us so we can investigate and take appropriate action.
A customer that uses Lemura to communicate with a child is responsible for confirming that the communication and processing are lawful and for obtaining any required parent or guardian authorisation.
16. policy updates
We may update this Policy to reflect changes in the Services, providers, law, or our data practices. We will post the revised version at this URL and update the date above. If a change is material, we will provide additional notice through the Services, email, or another reasonable method where appropriate or required.
17. contact us
For privacy questions, complaints, rights requests, or data deletion, contact the privacy and grievance contact for:
Conccoder Innovations Private Limited
Lemura privacy and grievance contact
India
Email: contact@lemura.in
Please include enough detail to identify the relevant account, workspace, customer, or communication. Do not email passwords, API keys, access tokens, or unnecessary sensitive content.
