Privacy Policy
This policy explains exactly what personal data 2Brother collects, why we collect it, who we share it with, how long we keep it, and how you get it deleted. It covers this website, the 2Brother CRM mobile application, and every Meta, WhatsApp and telephony integration we operate.
- Effective
- 13 July 2026
- Last updated
- 13 July 2026
- Applies to
- 2brother.in and all 2Brother apps & services
1. Who we are
2Brother AI LLP (“2Brother”, “we”, “us”) is the data controller (in India, the Data Fiduciary) for the personal data described in this policy.
- Registered office: Yeshwanthpur, Bengaluru, Karnataka 560022, India
- Privacy contact: mayank@2brother.in
- General contact: mayank@2brother.in · +91 93640 94797
Where we build and operate a system on behalf of a client — for example, a bank or lender running an outbound calling desk — that client is the controller of the leads and customers in their system, and we act as their processor under a written agreement. This policy then describes our own handling; the client's own privacy notice governs their use.
2. What this policy covers
- This website (2brother.in) — public marketing pages.
- The 2Brother CRM mobile app — the Android application used by calling agents.
- The 2Brother web console — the manager and administrator interface.
- Our Meta integrations — WhatsApp Business API, Facebook Login, Graph API, Messenger, Instagram and Conversions API, where we operate them for a client or for ourselves.
3. What data we collect, and why
3.1 Website visitors
We collect the minimum possible. There are no cookies, no advertising pixels, no third-party analytics and no fonts loaded from a third-party CDN on this website. The only data processed is what our web server unavoidably records to serve a page and to defend against abuse.
| Data | Why | Kept for |
|---|---|---|
| IP address, user-agent, URL requested, timestamp (server access log) | Serving the page; detecting and blocking abuse and attacks | Up to 30 days, then deleted |
| Anything you voluntarily send us by email, phone or WhatsApp | Replying to you and, if you become a client, delivering the project | Until you ask us to delete it; business correspondence up to 8 years where tax law requires |
3.2 The 2Brother CRM mobile app (calling agents)
This app is issued by an employer to its own calling agents, typically on company-owned, MDM-managed devices. It processes the following. Each item is used only for the purpose stated and is never sold, never used for advertising, and never used to build a profile of the agent outside their work.
| Data / permission | Why it is needed | Kept for |
|---|---|---|
| Phone number & name (agent account) | To sign the agent in by OTP and attribute their work to them | For as long as the employer's account is active |
Call log (READ_CALL_LOG) | To read back the real connected duration and outcome of a call the agent placed from the app, so the work log is accurate rather than self-reported. Only calls placed through the app are read. | Per the employer's retention setting; default 12 months |
Phone / place calls (CALL_PHONE, READ_PHONE_STATE) | To dial the assigned lead and to detect when the call starts and ends | Not stored beyond the call record |
Microphone / call recording (RECORD_AUDIO) | Quality assurance, dispute resolution and regulatory compliance on outbound calls. Recording is a feature the employer enables. Where the law of the jurisdiction requires the called party's consent, the employer is responsible for obtaining it, and we provide an announcement facility for that purpose. | Per the employer's retention setting; default 6 months, then permanently deleted |
Location (ACCESS_FINE_LOCATION, ACCESS_BACKGROUND_LOCATION where enabled) | Field-agent attendance and safety, while the agent is on an active shift only. Collection stops when the shift ends or the agent goes on break. The agent sees an ongoing notification whenever location is being shared. | Per the employer's retention setting; default 90 days |
| Device & app info (model, OS version, app version, crash logs) | Support, security and diagnosing faults | 12 months |
| Push token (Firebase Cloud Messaging) | Delivering assignment, callback and escalation notifications to the agent | Until the app is uninstalled or the token is refreshed |
| Lead / customer records (name, phone, and the business data the employer imports) | So the agent can do their job. These belong to the employer; we process them on the employer's instructions. | Per the employer's instructions |
3.3 Meta and WhatsApp integrations
When we operate a WhatsApp Business API number, a Facebook/Instagram integration or a Meta app for a client, we process the data Meta passes to us for that purpose:
- WhatsApp: the sender's phone number, their WhatsApp profile name, and the content of messages exchanged with the business — used only to deliver, answer and report on that conversation.
- Facebook Login / Graph API: only the fields the user explicitly grants at the consent screen (typically name, email, public profile) — used only to create and authenticate their account in the client's system.
- Lead Ads: the form fields the person filled in on Meta, passed into the client's CRM so that the business can follow up as the person requested.
- Conversions API: hashed, pseudonymised event data sent to Meta for the client's own campaign measurement, only where the client has a lawful basis and has told their users.
We handle all Meta-sourced data in line with the Meta Platform Terms and the Meta Developer Policies. Specifically: we use the data only to provide the service the user asked for, we do not sell it, we do not transfer it to a data broker or advertising network, we do not use it to build profiles or make eligibility decisions, we keep it only as long as needed, and we delete it on request. Access to Meta data is restricted to the engineers who need it and is logged.
4. Why we are allowed to process this data
- Contract — to deliver the service you or your employer engaged us for.
- Consent — for call recording and location, which are surfaced in-app with a clear notice, and for any marketing message you opt in to. Consent can be withdrawn at any time, and withdrawing it stops that processing.
- Legal obligation — tax, accounting and telecom record-keeping.
- Legitimate interests — securing our systems and preventing fraud and abuse, balanced against your rights.
In India this is governed by the Digital Personal Data Protection Act, 2023. For individuals in the EEA/UK, the corresponding GDPR bases apply, and the rights in section 7 are honoured on the same terms.
5. Who we share data with
We do not sell personal data. We share it only with the processors below, only to the extent needed to run the service, and only under contract.
| Who | What they receive | Why |
|---|---|---|
| Our cloud hosting provider (DigitalOcean, India/Bangalore region) | All service data, encrypted at rest | Running the servers and database |
| Meta Platforms (WhatsApp Cloud API, Graph API) | Message content and recipient number for the conversation being delivered | Sending and receiving WhatsApp / Meta messages |
| Google (Firebase Cloud Messaging) | Device push token and notification payload | Delivering push notifications |
| SMS / OTP provider (MSG91) | Phone number and the one-time code | Sending login OTPs |
| Cloud telephony providers (Exotel, Servetel, Airtel IQ), where the client uses them | The numbers involved in a call, and the recording | Connecting masked calls and storing recordings |
| Our clients | The data their own agents generate in their own instance | It is their operation and their data |
| Law enforcement / courts | Only what a valid, binding legal order compels | Legal obligation. We narrow every request to the minimum and tell you unless legally barred. |
6. Where data is stored, and how it is protected
- Primary storage is in India. Meta, Google and other global processors may process data outside India under their own standard contractual safeguards.
- All traffic is encrypted in transit with TLS. Databases and file storage are encrypted at rest.
- Credentials for third-party providers are stored encrypted with AES using a key held outside the database.
- Each client's data is isolated by tenant, and access is role-based. Recordings are served only over authenticated, time-limited links.
- Engineer access to production is limited to named individuals, requires key-based authentication, and is logged.
- If a breach occurs that is likely to affect you, we will notify the affected users and the Data Protection Board of India as the DPDP Act requires.
7. How long we keep data
The retention periods are listed against each data type in section 3. In general: we keep personal data only for as long as it serves the purpose it was collected for, then delete it. When a client ends their contract, we delete or return their entire dataset within 90 days, except where tax or accounting law requires us to keep an invoice record.
8. Your rights
Whoever you are and wherever you are, you can ask us to:
- Access — get a copy of the personal data we hold about you.
- Correct — fix anything inaccurate or incomplete.
- Delete — erase your data. See Data Deletion Instructions.
- Withdraw consent — for anything we relied on consent for, with effect going forward.
- Port — receive your data in a machine-readable format.
- Object / restrict — object to a processing activity or ask us to pause it.
- Nominate — under the DPDP Act, nominate someone to exercise these rights if you die or become incapacitated.
- Complain — to us first, and then to the Data Protection Board of India (or your local supervisory authority).
Write to mayank@2brother.in. We verify your identity, and we answer within 30 days. Exercising any of these rights is free.
If you are an agent whose employer runs our software, we will forward your request to your employer, who controls that data — and we will tell you that we have done so.
9. Grievance Officer
As required by the Information Technology (Intermediary Guidelines) Rules, 2021 and the DPDP Act, 2023:
- Name: Mayank Dwivedi
- Email: mayank@2brother.in
- Address: Yeshwanthpur, Bengaluru, Karnataka 560022, India
The Grievance Officer acknowledges every complaint within 24 hours and resolves it within 15 days.
10. Children
Our services are business tools and are not directed at children. We do not knowingly collect the personal data of anyone under 18. If we learn that we have, we delete it. Under the DPDP Act we do not undertake tracking, behavioural monitoring or targeted advertising directed at children under any circumstances.
11. Cookies
This website uses no cookies at all — none for analytics, none for advertising, none for preferences. There is nothing to consent to and nothing to opt out of.
The CRM web console, which is a private application you must log in to, uses a single strictly-necessary session token to keep you signed in. It carries no tracking value and expires when your session ends.
12. Changes to this policy
If we change this policy we update the “Last updated” date at the top, and for any material change we notify affected users by email or in-app before it takes effect. Previous versions are available on request.
13. Contact
2Brother AI LLP
Yeshwanthpur, Bengaluru, Karnataka 560022, India
Privacy: mayank@2brother.in
General: mayank@2brother.in · +91 93640 94797
Questions about this document?
Write to mayank@2brother.in and a human will answer. We respond to every privacy request within 30 days, and usually far sooner.