Legal

Data Policy

A plain-language look at exactly what data Genluno processes, where it goes, and how the broker–lead relationship works.

Last updated: 19 September 2026

1. Purpose of this policy

This Data Policy supplements our Privacy Policy with the operational detail of how lead and broker data moves through Genluno. Read it alongside the Privacy Policy and Terms & Conditions.

2. Controller and processor roles

When a broker routes their leads through Genluno, the broker is the controller of that lead data and Genluno is the processor acting on the broker's documented instructions. Genluno is the controller of broker account, settings, and billing data.

3. Data we process

The Service processes the following categories of personal data:

  • Lead identity and contact: name and phone/WhatsApp number.
  • Enquiry content: WhatsApp messages, budget, locality, timeline, and buy/rent intent.
  • Source metadata: originating portal or channel and enquiry timestamps.
  • Broker profile: name, email, brokerage, city, language, and notification numbers.
  • Billing: subscription status and payment references (no raw card data is stored by Genluno; Cashfree processes the payment).
  • Operational logs: request timestamps, IP address, and error diagnostics.

4. Where data flows

Lead messages travel between the lead, Meta's WhatsApp Business Cloud API, and Genluno's servers. Conversation text is sent to our AI provider to generate qualification replies. Application data is stored in a managed PostgreSQL database, with a queue service coordinating scheduled tasks. Emails are sent by Resend; payments are processed by Cashfree.

5. Sub-processors

We rely on the following sub-processors, each limited to its stated purpose:

  • Meta Platforms (WhatsApp Business Cloud API) — sending and receiving WhatsApp messages.
  • OpenAI — generating qualification replies from conversation text.
  • Neon (managed PostgreSQL) — primary application database.
  • Redis Cloud — job queues for first-touch and scheduling.
  • Resend — transactional and summary emails.
  • Cashfree — subscription billing and payment processing.
  • Cloud hosting provider — running the application servers.

6. Legal basis

We process broker data to perform our contract with the broker and for our legitimate interest in running and securing the Service. Lead data is processed on behalf of the broker, who is responsible for the lawful basis and any consent required to contact the lead.

7. Retention and deletion

Lead data is retained while the broker's account is active and for a reasonable window afterward, then deleted or anonymised. A broker may request export or deletion of their tenant's data at any time by writing to email us. Billing records are kept as long as tax law requires.

8. Security measures

We protect data with TLS encryption in transit, access controls scoped per brokerage (tenant isolation), signed and verified inbound webhooks, and secrets held in a managed secret store rather than in code.

9. Opt-out and rights

Leads can stop messages at any time by replying with a stop request; that number is then suppressed. Requests to access, correct, or delete data can be sent to email us or, for leads, to the broker handling their enquiry.

10. Contact

For any data question or request, contact email us or WhatsApp +91 92268 22958.