Security at Relaytiv
Last updated: July 2026
Your customers share conversations with your business through Relaytiv. This page explains where that data lives, who can access it, and how it is protected — in plain language you can share with your own clients.
01 — Where Your Data Lives
In brief: Your customer conversations, contacts, and campaign data are stored on cloud infrastructure in the United States, operated by Relaytiv's hosting provider.
| What | Where it is stored |
|---|---|
| Messages, contacts, campaigns, appointments | Cloud servers, United States |
| Files and media sent through channels | Cloud storage, United States |
| Backups | Cloud storage, United States |
| Payment and billing records | Razorpay (India) — not stored on Relaytiv servers |
| AI processing of message content | AI provider servers (United States) |
02 — Who Can Access It
In brief: Only Relaytiv engineers with a demonstrated operational need can access customer data, and every access is logged.
Access to production systems is controlled through role-based permissions, audit logging, and no standing access. We do not sell or share your data with third parties for advertising purposes.
03 — How the Platform Is Protected
In brief: All data in transit is encrypted with TLS 1.2 or higher. Data at rest is encrypted using AES-256. Admin access requires multi-factor authentication.
- Encryption in transit — TLS 1.2+ on all connections
- Encryption at rest — AES-256 on databases and storage volumes
- MFA on all internal admin accounts
- Secrets management — credentials never committed to source code
04 — Backups and Recovery
In brief: The database is backed up automatically every day. Backups are retained for 30 days and are encrypted.
05 — Sub-Processors and Transfers
In brief: Relaytiv uses a small number of trusted third-party providers. Each one receives only the data required for its specific function.
| Provider | Purpose | Country |
|---|---|---|
| Meta Platforms (Facebook) | WhatsApp Business API — message delivery | United States / Global |
| DM Champ (OneGlimpse B.V.) | WhatsApp Business Platform connectivity | Netherlands (EU) |
| Razorpay Software Pvt Ltd | Payment processing and subscription billing | India |
| AI model providers (OpenAI, Anthropic, or similar) | Processing inbound messages to generate AI replies | United States |
| Google (Workspace / Gmail API) | Sending transactional and notification emails | United States / Global |
| Replit, Inc. | Application hosting and managed infrastructure | United States |
06 — Your Data, Your Rights
In brief: You can request access to, correction of, or deletion of your data at any time by emailing hello@vitiv.ai.
Rights include: access, correction, deletion, portability, and objection under the Digital Personal Data Protection Act 2023 (India) and applicable law. Email hello@vitiv.ai with subject "Data Request". We respond within 14 days.
07 — AI Transparency
In brief: Relaytiv's AI reads inbound messages and generates replies. It does not use your conversations to train AI models. You can disable AI per inbox at any time.
When a message arrives, it is passed to an AI model provider along with your knowledge base and conversation history to generate a reply. Your data is not used to train AI models. AI can be switched off per inbox from your Relaytiv dashboard.
08 — What We Do Not Claim
We are a small, growing team. We have not yet completed SOC 2 or ISO 27001 certification. We do not offer a 100% uptime SLA. AI providers have their own data policies which we cannot independently verify. WhatsApp message delivery is governed by Meta's infrastructure once handed off.
09 — Reporting a Security Issue
If you discover a vulnerability, email hello@vitiv.ai with subject "Security Report". We acknowledge within 2 business days and request 30 days to investigate before public disclosure.