Security at Relaytiv

Last updated: July 2026

Your customers share conversations with your business through Relaytiv. This page explains where that data lives, who can access it, and how it is protected — in plain language you can share with your own clients.

01 — Where Your Data Lives

In brief: Your customer conversations, contacts, and campaign data are stored on cloud infrastructure in the United States, operated by Relaytiv's hosting provider.

WhatWhere it is stored
Messages, contacts, campaigns, appointmentsCloud servers, United States
Files and media sent through channelsCloud storage, United States
BackupsCloud storage, United States
Payment and billing recordsRazorpay (India) — not stored on Relaytiv servers
AI processing of message contentAI provider servers (United States)

02 — Who Can Access It

In brief: Only Relaytiv engineers with a demonstrated operational need can access customer data, and every access is logged.

Access to production systems is controlled through role-based permissions, audit logging, and no standing access. We do not sell or share your data with third parties for advertising purposes.

03 — How the Platform Is Protected

In brief: All data in transit is encrypted with TLS 1.2 or higher. Data at rest is encrypted using AES-256. Admin access requires multi-factor authentication.

04 — Backups and Recovery

In brief: The database is backed up automatically every day. Backups are retained for 30 days and are encrypted.

05 — Sub-Processors and Transfers

In brief: Relaytiv uses a small number of trusted third-party providers. Each one receives only the data required for its specific function.

ProviderPurposeCountry
Meta Platforms (Facebook)WhatsApp Business API — message deliveryUnited States / Global
DM Champ (OneGlimpse B.V.)WhatsApp Business Platform connectivityNetherlands (EU)
Razorpay Software Pvt LtdPayment processing and subscription billingIndia
AI model providers (OpenAI, Anthropic, or similar)Processing inbound messages to generate AI repliesUnited States
Google (Workspace / Gmail API)Sending transactional and notification emailsUnited States / Global
Replit, Inc.Application hosting and managed infrastructureUnited States

06 — Your Data, Your Rights

In brief: You can request access to, correction of, or deletion of your data at any time by emailing hello@vitiv.ai.

Rights include: access, correction, deletion, portability, and objection under the Digital Personal Data Protection Act 2023 (India) and applicable law. Email hello@vitiv.ai with subject "Data Request". We respond within 14 days.

07 — AI Transparency

In brief: Relaytiv's AI reads inbound messages and generates replies. It does not use your conversations to train AI models. You can disable AI per inbox at any time.

When a message arrives, it is passed to an AI model provider along with your knowledge base and conversation history to generate a reply. Your data is not used to train AI models. AI can be switched off per inbox from your Relaytiv dashboard.

08 — What We Do Not Claim

We are a small, growing team. We have not yet completed SOC 2 or ISO 27001 certification. We do not offer a 100% uptime SLA. AI providers have their own data policies which we cannot independently verify. WhatsApp message delivery is governed by Meta's infrastructure once handed off.

09 — Reporting a Security Issue

If you discover a vulnerability, email hello@vitiv.ai with subject "Security Report". We acknowledge within 2 business days and request 30 days to investigate before public disclosure.