WAPGROWAI
LEGAL · HOW WE HANDLE DATA

Privacy Policy

What personal data WAPGROWAI collects, why we hold it, who we share it with, and the rights you have over it - including the conversation data that passes through the WhatsApp Business Platform.

Who we are

WAPGROWAI is operated by WAPGROWAI. We are an official Meta Business Solution Provider, which means we provide access to the WhatsApp Business Platform and the software you use to run conversations on it.

For questions about this policy, or to exercise any of the rights described below, contact us at info@wapgrowai.com. If we have appointed a Data Protection Officer, their details are published at +91 9904566590.

The two roles we play

This distinction matters, and most privacy policies for messaging platforms blur it.

We are the controller of your account data

When you sign up, use the dashboard, contact support, or pay us, we decide why and how that data is processed. We are the controller, and this policy explains what we do.

We are a processor of your customers' conversation data

When your customers message your WhatsApp number, we store and process those messages so that you can read and reply to them. We do it on your instructions and for your purposes. You are the controller; we are the processor. That relationship is governed by our Data Processing Addendum, not by this policy.

What we collect about you

CATEGORYEXAMPLESWHY WE HOLD IT
Account dataName, work email, phone number, company name, roleTo create and secure your account, and to contact you about the service
Billing dataBilling address, tax identifiers, plan, invoicesTo charge you and to meet our tax and accounting obligations
Platform identifiersMeta Business Manager ID, WhatsApp Business Account ID, phone number IDTo connect your account to the WhatsApp Business Platform
Usage dataFeatures used, conversations sent, quality rating, error logsTo operate the service, prevent abuse, and improve the product
Device and log dataIP address, browser, timestamps, pages viewedSecurity, fraud prevention, and diagnosing faults
Support dataMessages you send us, call notes, screenshots you shareTo answer your questions and keep a record of what we agreed

What we process on your behalf

Running conversations means we necessarily handle data about your customers. We process it only to deliver the service you have asked for.

  • Message content - the text, images, documents, and audio your customers send and receive.
  • Contact details - the phone number, WhatsApp profile name, and any attributes you add, such as tags or order references.
  • Conversation metadata - timestamps, delivery and read receipts, which agent replied, and how long it took.
  • Opt-in records - when and how a contact consented to receive messages from you, because you will need to evidence this.

You decide what to collect and how long to keep it. We give you the tools to delete it, and we delete it when you tell us to.

Where the UK GDPR, EU GDPR, or a comparable law applies, we rely on the following bases for processing your account data.

  • Performance of a contract - to provide the service you signed up for, and to bill you for it.
  • Legitimate interests - to secure the platform, prevent abuse, understand how the product is used, and market to existing customers. You can object to this at any time.
  • Legal obligation - to keep tax records, and to respond to lawful requests from authorities.
  • Consent - for optional cookies and for marketing to people who are not yet customers. You can withdraw it at any time.

Who we share it with

We do not sell your data. We share it with a small number of processors who help us run the service, and with Meta, because the service runs on their platform.

RECIPIENTPURPOSEWHERE
Meta PlatformsDelivering messages via the WhatsApp Business PlatformGlobal
Cloud infrastructure providerHosting the application and your dataIndia
Payment providerProcessing subscription paymentsIndia
Analytics and error monitoringDiagnosing faults and improving the productIndia
Support toolingAnswering your questionsIndia

A current list of sub-processors is maintained at [SUB-PROCESSOR LIST URL]. We will give you notice before adding a new one, so that you have the opportunity to object.

International transfers

WhatsApp is a global platform, and delivering a message may involve a transfer outside your country. Where we transfer personal data out of the UK or the EEA, we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses together with a transfer risk assessment.

How long we keep it

  • Account data: for as long as your account is active, and then for 1 Year after closure.
  • Billing records: for the period our tax obligations require, typically 2 years.
  • Conversation data: for the retention period you configure. If you configure none, we apply a default of [DEFAULT RETENTION].
  • Logs and diagnostics: [LOG RETENTION], after which they are deleted or aggregated beyond re-identification.

Your rights

Depending on where you live, you may have some or all of the following rights over your personal data.

  1. Access - a copy of the data we hold about you.
  2. Rectification - correction of anything inaccurate.
  3. Erasure - deletion, where we have no overriding reason to keep it.
  4. Restriction and objection - including the right to object to processing based on legitimate interests.
  5. Portability - a machine-readable export of data you provided to us.
  6. Withdrawal of consent - at any time, without affecting what we did before you withdrew it.
  7. Complaint - to your supervisory authority. In the UK, that is the Information Commissioner's Office.

To exercise any of these, contact info@wapgrowai.com. We will respond within the period the law requires, and normally faster.

Security

We encrypt data in transit and at rest, restrict access to those who need it, log administrative actions, and review our controls regularly. Detail is set out in the Data Processing Addendum.

No system is perfectly secure, and any provider who tells you otherwise is selling something. If a breach occurs that is likely to result in a risk to individuals, we will notify the relevant authority and, where required, the people affected - without undue delay.

Children

The service is intended for businesses. It is not directed at children, and we do not knowingly collect data from anybody under the age of 18+. If you believe we have, contact us and we will delete it.

Changes

We update this policy when the product or the law changes. Material changes will be notified by email or in the dashboard before they take effect. The date at the top always reflects the current version.