Government Requests Policy
Last updated: 16 September 2026
This policy explains how ReMessage, operator of ReMessage, responds when a public authority asks us to disclose personal data about a user. We take these requests seriously and disclose data only where we are legally required to do so.
1. Legality review
Every request from a public authority is reviewed before any data is disclosed. We check that:
- The request is in writing and comes from an identifiable, authorised official.
- It cites the specific legal authority that compels disclosure.
- It is valid under the law of the jurisdiction in which we operate.
- It is specific about the accounts, data types and time period concerned.
Requests that do not meet these conditions are rejected or returned for clarification. Where the request is complex or its legality is unclear, we seek legal advice before responding.
2. Data minimisation
Where we must comply, we disclose only the minimum information necessary to satisfy the specific legal demand. We do not provide bulk data, whole databases, or information outside the scope and time period stated in the request. If a request is broader than necessary, we ask for it to be narrowed before responding.
3. Challenging unlawful requests
Where we consider a request to be unlawful, overbroad, vague or inconsistent with fundamental rights, we may object to it, ask for it to be withdrawn or narrowed, or challenge it through the appropriate legal channel.
4. Documentation
We keep an internal record of requests received, including the requesting authority, the legal basis cited, the scope, the review we carried out, our response, and the people involved in the decision. These records support accountability and any future transparency reporting.
5. Notifying users
Where the law permits and no legal prohibition applies, we notify the affected customer before disclosing their data, so that they have the opportunity to respond. We will not notify where doing so is prohibited by law or where there is a credible risk of harm to a person.
6. Emergency requests
In cases involving an imminent risk of death or serious physical injury, we may disclose limited information to the relevant authority without the usual process, where we have a good faith belief that the emergency is genuine. Such disclosures are documented and reviewed afterwards.
7. What we can and cannot provide
- We can provide only data we actually hold, as described in our Privacy Policy.
- WhatsApp messages between a business and its customers are delivered through Meta's platform. Requests relating to WhatsApp accounts themselves should be directed to Meta Platforms, Inc.
- Where we act only as a data processor on behalf of a business customer, we will normally redirect the request to that customer, who is the data controller.
8. Transparency
We have not received any national security request for user data. Should that change, we will report it here to the extent the law allows.
9. How to submit a request
Public authorities should send requests, on official letterhead and citing the applicable legal authority, to:
ReMessage
TODO: Street, City, State, PIN, India
Email: remessage@gmail.com with the subject “Legal request”.