TimetoHive (OPC) Private Limited is committed to preserving the confidentiality, integrity, and security of all user data. We never sell, monetize, or rent personal data to third parties.
1 Corporate Entity & Scope
This Privacy Policy applies to the TimetoHive ONE platform, mobile clients, web applications, and related developer APIs operated and provided by TimetoHive (OPC) Private Limited ("TimetoHive", "Company", "we", "our", or "us"), a company incorporated under the provisions of the Companies Act, 2013, India.
This policy is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023 (DPDP Act, 2023).
Under Indian law, for workspace account registrations and billing, TimetoHive acts as a Data Fiduciary. For business workspace data uploaded by enterprise teams, the customer acts as the Data Fiduciary and TimetoHive acts as the Data Processor.
2 Information We Collect
We collect and process only the minimal information required to deliver our productivity and automation services:
A. Information Provided Voluntarily
- Account Credentials: Full name, corporate email address, contact telephone number, organization name, and encrypted login passwords.
- Billing & Payment Data: Tax identification (such as GSTIN for Indian businesses), billing address, and transaction identifiers. Card and UPI transactions are tokenized and processed via RBI-authorized/PCI-DSS compliant payment gateways.
- Workspace Content: Tasks, documents, chat messages, natural language automation triggers, and uploaded workspace attachments.
- Support Inquiries: Communications and support tickets sent to support@timetohiveone.com.
B. Automatically Collected Technical Data
- Network & Device Identifiers: IP address, browser user-agent, operating system, device fingerprint, and access timestamps.
- Operational Logs: System event logs, latency metrics, error diagnostic stacks, and feature utilization telemetry.
C. Third-Party Integrations & Meta APIs
When you connect external productivity tools (e.g., WhatsApp Business Platform, Meta Platforms, Facebook, Instagram, Slack, Google Workspace, GitHub, Figma), we receive authenticated OAuth access tokens strictly limited to the permissions you grant for workflow automation.
WhatsApp Business API Data: When you connect your WhatsApp Business Account via Meta Embedded Signup or access our WhatsApp CRM services, we process customer phone numbers, sender/recipient metadata, message transmission logs, message statuses (sent, delivered, read), and media files sent or received strictly to deliver CRM and messaging functionality. We do not use data obtained from Meta APIs to independently target ads, nor do we sell this data to third-party data brokers, in accordance with Meta's Platform Terms.
3 Purpose & Lawful Processing
We process personal data solely for legitimate, lawful business purposes under Section 4 and Section 7 of the DPDP Act, 2023:
- To provision, authenticate, operate, and maintain your TimetoHive ONE workspace.
- To execute automated natural language routines, triggers, and scheduled task notifications.
- To generate GST-compliant tax invoices, manage subscription renewals, and process refunds.
- To detect and prevent cybersecurity incidents, fraud, identity theft, and unauthorized access.
- To comply with statutory legal obligations under Indian law and orders of competent judicial or law enforcement authorities.
4 Data Processors & Third-Party Sharing
We do not sell, rent, or trade personal data. We engage vetted cloud infrastructure and payment partners bound by stringent data processing contracts:
| Partner / Processor | Processing Purpose | Hosting Location |
|---|---|---|
| Meta Platforms, Inc. / WhatsApp Cloud API | Message routing, webhook delivery, template management, and WhatsApp Business API integration. | Global / United States / Meta Cloud Infrastructure |
| Amazon Web Services (AWS) | Cloud infrastructure, encrypted database storage & compute | India (Mumbai/Hyderabad) & Global Regions |
| Cloudflare | Edge CDN, DDoS protection, Web Application Firewall (WAF) | Global Edge / India POPs |
| Stripe / Razorpay | PCI-DSS & RBI compliant payment gateway, UPI & card billing | India & International |
| Datadog | Application reliability and performance monitoring | Secure Cloud Infrastructure |
5 Security & Encryption Standards
In compliance with Rule 8 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011:
- Data in Transit: TLS 1.3 encryption with strict HSTS and forward secrecy.
- Data at Rest: Industry-standard AES-256 encryption across all primary databases, object storage, and automated backups.
- Access Control: Zero-trust network segmentation, mandatory Multi-Factor Authentication (MFA) for administrative operations, and granular Role-Based Access Control (RBAC).
- Vulnerability Management: Periodic third-party security audits, automated code scanning, and continuous intrusion monitoring.
6 Data Retention & Erasure
Personal and workspace data is retained for the active duration of your subscription. Upon account closure or termination:
- Your workspace is deactivated, and data is preserved for a 30-day recovery window.
- After 30 days, production data is permanently purged from active servers.
- Encrypted backup archives are systematically rotated and erased within 90 days, except where retention is required by Indian statutory tax or financial regulations (e.g., GST audit records).
7 Rights of Data Principals
Under the DPDP Act, 2023, and applicable international data protection frameworks (including GDPR / CCPA), you hold the following rights:
- Right to Access Information: Obtain a summary of personal data processed by us and the identities of data processors.
- Right to Correction & Erasure: Correct misleading or inaccurate information and request erasure of personal data no longer necessary for the original purpose.
- Right of Grievance Redressal: Avail readily accessible grievance redressal mechanisms for any act or omission regarding personal data.
- Right to Nominate: Nominate an individual who may exercise your rights in the event of death or incapacity.
- Right to Withdraw Consent: Withdraw previously given consent for optional data processing at any time.
To exercise these rights, submit a written request to support@timetohiveone.com.
8 Cross-Border Data Transfers
Personal data may be transferred to and processed in countries outside India where our cloud infrastructure providers maintain secure servers, strictly in accordance with notifications and guidelines issued by the Central Government of India under Section 16 of the DPDP Act, 2023.
9 Grievance Officer & Legal Contact (India)
In accordance with the Information Technology Act, 2000, Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act, 2023, the details of the designated Grievance Officer are set out below:
Entity: TimetoHive (OPC) Private Limited
Official Legal & Grievance Email: support@timetohive.com
Jurisdiction: India
Acknowledgment: Within 24–48 hours | Resolution: Within statutory timeline (maximum 15–30 days)
Have privacy questions or need a Data Processing Agreement?
Enterprise and corporate teams requiring customized DPAs, Indian data residency guarantees, or compliance documentation can reach our legal team directly.
Contact Legal Team