This page describes how to request deletion of personal data processed by GrowBro AI Solutions Private Limited (operating as “GrowBro”). It is also the page registered with Meta as our Data Deletion Instructions URL for the GrowBro WhatsApp Business, Instagram, and Messenger apps; following the steps below satisfies that requirement.
Who can request deletion
- Account holders (our Customers) — businesses that use the GrowBro CRM. You are the data fiduciary / controller for your own end users’ data; GrowBro processes that data on your behalf.
- End users of our Customers — people who chatted with a GrowBro-powered WhatsApp number, Instagram or Messenger account, or a website chat widget. We will route your request to the relevant Customer where GrowBro acts as processor, and confirm action with you.
How to request deletion
What we delete and what we retain
On a verified deletion request, we delete personal data from active production systems. Some data is retained for limited, legally permitted purposes:
- Active records (account, leads, chats, AI configs, OAuth tokens) — deleted from active systems.
- Backups — backups are retained on a rolling 30-day window; deletions propagate to backups as they roll off. Restoring a backup older than your deletion request will re-instate the data, but it will be re-deleted on the next purge cycle.
- Security & audit logs — retained for up to 12 months to investigate fraud, abuse, or security incidents.
- Billing & tax records — retained for 8 years as required under the Indian Companies Act, 2013 and Income Tax Act.
- Aggregated / de-identified data — usage statistics that no longer identify any individual may be retained for analytics and product improvement.
Third-party platforms
Data shared with platforms integrated through GrowBro is subject to those platforms’ own data retention and deletion policies. To remove your data from those platforms directly:
- Google (Calendar, Sheets): revoke GrowBro’s access at myaccount.google.com/permissions, or disconnect from the GrowBro CRM Integrations page. After revocation, we lose all ability to access your Google data; existing copies in your Customer’s CRM are deleted under the rules above.
- Meta (WhatsApp, Instagram, Messenger): conversation history with the GrowBro-connected business number/page lives with both that business and on Meta’s servers. Contact the business directly to delete data they hold about you. To delete your Facebook/Instagram data more broadly, see facebook.com/help and help.instagram.com.
- HubSpot: if your records were synced to HubSpot, contact the HubSpot account owner or HubSpot directly.
- Razorpay: payment records are governed by Razorpay’s terms and Indian financial-record-keeping rules.
Verification
To protect your data from unauthorised deletion, we will verify your identity before acting. For most requests this means responding from the email address on your GrowBro account. For end-user requests where we do not have an existing relationship with you, we may ask you to provide identifying information that matches what the relevant Customer holds (e.g., a phone number that was used to message the bot).
CCPA-authorised agents must provide written permission signed by the consumer; we may also contact the consumer to confirm.
Refusals & appeals
We may decline a deletion request to the extent we have a legal obligation to retain the data (e.g., billing/tax records, fraud-prevention logs) or where we cannot adequately verify your identity. We will explain the reason in writing and tell you what you can do next.
If you are not satisfied with our response, you may escalate to our Grievance Officer (Aakash Roy, Founder) at grievance@growbro.ai, or lodge a complaint with the Data Protection Board of India, your EU/UK supervisory authority, or the California Privacy Protection Agency as applicable.
Confirmation
On completion, we will send a written confirmation to the email address used to submit the request, including a reference number you can quote in any follow-up correspondence.