Last updated: July 2026
Roles
For people, leads, clients, pipeline notes, events, reminders, and messaging configuration inside a company workspace on app.pyppler.com:
- Customer (company) — decides what data to collect, who may access the tenant, and the purposes of follow-up. You are the controller (or equivalent) for that business data.
- Pyppler — processes that data as a service provider / processor to host the product, deliver features you enable, keep backups, and provide support when you ask.
For our own marketing site, accounts, and billing records, see the Privacy Policy — we act as controller for that information.
DPA summary (for customers)
Enterprise or privacy-conscious customers sometimes need a Data Processing Addendum. In substance, our processing of customer content is limited to:
- Purpose — providing Pyppler (hosting, authentication, follow-up automation, messaging delivery you initiate, reporting, and support).
- Instructions — we process workspace content per your configuration and documented product behaviour, not for unrelated advertising.
- Confidentiality — staff access is limited to what is needed for operations and support.
- Sub-processors — infrastructure, email, WhatsApp connectors, and payment gateways you or we enable may process data to deliver those features. We will update this page or notify admins when material provider changes affect typical tenants.
- Deletion / return — admins can delete records in-product. After subscription end, we delete or anonymise customer content within a reasonable period unless law requires retention of billing or dispute records.
- Assistance — we reasonably help customers respond to data-subject requests that must be fulfilled in the product, when you cannot do so alone.
If you need a signed DPA for procurement, contact us with your company details and template preferences.
Security measures
- HTTPS on public endpoints for the marketing site and admin app.
- Hashed password storage for account credentials; session cookies marked appropriately for the admin app.
- Company-scoped (multi-tenant) data separation so one workspace should not see another’s leads.
- Role / permission controls inside the product for team seats where enabled on your plan.
- Backups and operational monitoring appropriate to a production SaaS workload.
- Least-privilege access for our internal tools that touch customer environments.
No online service is perfectly secure. You remain responsible for strong passwords, inviting only trusted users, and securing devices that stay logged into admin.
International & India context
Pyppler is built for Indian SaaS customers (including GST-ready company details). Data may be hosted or processed in regions where our infrastructure and sub-processors operate. We take contractual and technical steps consistent with providing a B2B follow-up product under applicable Indian law, including the Digital Personal Data Protection Act, 2023, as it applies to our role.
Incidents
If we become aware of a security incident that materially affects your customer content, we will notify affected company admins without undue delay and share information reasonably needed for your own obligations.
Contact
Privacy or security questions: info@pyppler.com or the demo / contact form.