Home/Help Center/Data processing and storage

Account, billing and security

Data processing and where data is stored

How VGraple CRM processes customer data: hosting, encryption at rest, sub-processors, retention, the DPA, and how to answer a customer's access or deletion request.

By Chirag Darji · Updated 27 Aug 2026 · 5 min read

On this page
  1. Roles under data protection law
  2. Where data is stored
  3. How data is protected
  4. Encryption in practice
  5. Access inside VGraple
  6. Incident response
  7. Sub-processors
  8. Where WhatsApp messages travel
  9. Retention
  10. The data processing agreement
  11. Answering a customer's request
  12. Troubleshooting
Team members in VGraple CRM with owner, admin and agent roles and their permissions

VGraple CRM processes personal data on your behalf: your customers' numbers, names and conversations. This guide explains where that data lives, how it is protected, which third parties touch it, how long it is kept and how the data processing agreement (DPA) binds us, so you can answer your own customers, auditors and procurement teams.

Roles under data protection law

You are the data controller (data fiduciary under India's DPDP Act): you decide why and how customer data is processed. VGraple CRM is the processor, acting on your instructions under the DPA. Meta is a separate processor for WhatsApp delivery under its own terms with you.

Where data is stored

Production runs on Oracle Cloud infrastructure managed by VGraple, with the database, media storage and encrypted backups in the same environment. The security page lists the current region and the sub-processors; if a region option matters for your compliance, ask support before onboarding.

Profile settings in VGraple CRM with two-factor authentication

How data is protected

  • Personal fields are encrypted at rest at field level, with separate blind-index columns so search and deduplication work without decrypting.
  • Volumes and backups are encrypted; backups are tested and rotate on a fixed schedule.
  • All traffic is TLS; Meta webhooks are signature-verified; outbound webhooks are HMAC-signed.
  • Access inside the app is role-based; secrets are Owner-only; every significant action is in the audit log.
  • Support access to your workspace happens only for a request you opened and is logged as a super admin action.

Encryption in practice

Personal fields are encrypted with keys held outside the database, so a database dump on its own is unreadable. To keep search working without decrypting every row, each searchable field also has a blind index: a keyed hash that lets the app find a contact by phone or email without storing the value in the clear. This is why some searches are exact-match only. Media is stored in encrypted object storage and served through signed, expiring links; Meta's own media links expire and are never relied on.

Access inside VGraple

Production access is limited to named engineers, protected by hardware-backed multi-factor authentication, and used for operations and for support requests you open. Every support action inside a customer organisation is written to that organisation's audit log with the super admin flag. No one at VGraple reads customer conversations for any other purpose, and conversations are never used to train models.

Incident response

If a security incident affects your data, you are notified within the timeline set in the DPA with what happened, what data was involved and what to do, and the incident is recorded on the security page once resolved. Report anything you notice (a suspicious session, an email that looks like it came from VGraple CRM but did not) to support; the sender name on genuine emails is always "VGraple CRM".

Sub-processors

PurposeWhat they receive
Hosting and storageAll data, encrypted at rest
Transactional emailRecipient address and email content for alerts and lifecycle emails
Push notificationsDevice tokens and notification text for the Android app
Error monitoringTechnical error data with personal fields scrubbed
AI model providersThe conversation or text needed for a reply, summary or suggestion, per request; not used for training
Payment gatewaysOnly your own gateway credentials and link references; funds never pass through VGraple

The full list with company names is in the DPA and on the security page; changes are announced in advance.

Where WhatsApp messages travel

A customer's message goes from their phone to Meta's servers (end-to-end encrypted between the phone and Meta's Cloud API endpoint), then from Meta to VGraple CRM over TLS by webhook, then into the encrypted database and to the agents entitled to see it. Outbound replies follow the same path in reverse. Meta's own handling is governed by your agreement with Meta as the account owner; VGraple CRM's handling is governed by the DPA. Nothing is stored on VGraple's side in plain text, and nothing leaves the platform except to the sub-processors listed above for the purposes stated.

Retention

Data stays for as long as your organisation is active. After deactivation, data is retained until you request deletion or the retention period in the DPA elapses; backups expire on rotation. Audit logs are kept for the same period. You can delete individual contacts at any time.

The data processing agreement

The DPA applies automatically under the terms of service and contains standard contractual clauses for international transfers, the sub-processor list, security measures, breach notification timelines and assistance with data subject requests. Request a countersigned copy from support for procurement.

Answering a customer's request

RequestWhat to do
AccessSearch the contact, export the record and the conversation history
CorrectionEdit the contact fields; the change is logged
ErasureDelete the contact; block if they should not be messaged again
Objection to marketingSet marketing consent to opted out, or let a STOP reply do it
PortabilityExport the contact and leads records as CSV

Troubleshooting

SymptomLikely causeFix
Procurement asks for a signed DPAStandard requestAsk support for the countersigned copy
A customer asks where their data isRegion questionPoint them to the security page or your privacy notice
Need to exclude a sub-processorFor example, AI providersDisable AI features or bring your own key; email and push are needed for the service

Support hours are Monday to Friday, 10 AM to 7 PM IST.

Frequently asked questions

Where is my data stored?
On VGraple CRM's production infrastructure hosted with Oracle Cloud, with encrypted backups; the security page lists the region and sub-processors and is kept current.
Is customer data encrypted?
Personal fields (names, phone numbers, emails, addresses and similar) are encrypted at field level with searchable blind indexes; storage volumes and backups are encrypted; all traffic uses TLS.
Who are the sub-processors?
Hosting, transactional email, push notifications, error monitoring and AI model providers, listed on the security page and in the DPA.
Do you sign a DPA?
The DPA at /dpa applies to every customer through the terms; a countersigned copy is available on request for procurement.
Is message content used to train AI?
No. Conversations sent to a model provider for a reply, summary or suggestion are processed for that request only; bring your own key to route them to your own provider.
How do I handle a customer's access or deletion request?
Search the contact, export their record for an access request, or delete the contact for erasure; both are logged.

Run your WhatsApp on VGraple CRM

Free forever plan, official Meta WhatsApp Business API, set up in 15 minutes. No card needed.