WhatzAPI WhatzAPI
Features Resellers Pricing FAQ
Login Get started
Legal

Privacy Policy

Last updated: November 1, 2025

Terms of Service Privacy Policy Disclaimer Cookie Policy Acceptable Use Contact Us
Ask a question

This Privacy Policy explains what data we collect, how we use it and the rights you have over it. We do not sell your data — ever.

1. Who we are

We operate this platform as the data controller for the information collected via the website, dashboard and APIs. We treat data protection seriously and aim to comply with the General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act (DPDPA), and equivalent regulations.

2. Data we collect

From you directly

  • Account data: name, email, password (hashed), phone number, company.
  • Billing data: invoicing details and payment method tokens (handled by our PCI-compliant processor; we never store card numbers).
  • Support correspondence: messages you send us through chat, email or WhatsApp.

Generated by usage

  • Message metadata: recipient number, timestamp, delivery/read status, success/failure codes. We do not store the message body beyond the period needed for delivery and reporting unless you enable conversation history.
  • Technical logs: IP address, browser, device, pages visited, errors.
  • Cookies: see our Cookie Policy.

You upload (about your contacts)

When you import contact lists, you act as the data controller for that contact data; we act as your data processor. You confirm you have lawful basis (consent, contract or legitimate interest) to message those contacts.

3. How we use your data

  • To provide, maintain and improve the Service.
  • To bill you and prevent fraud.
  • To notify you about service changes, security incidents and product updates.
  • To respond to support requests.
  • To comply with legal obligations.

4. Legal bases (GDPR)

PurposeLegal basis
Providing the ServiceContract
Billing & taxLegal obligation
Marketing emailsConsent (revocable)
Fraud preventionLegitimate interest

5. Who we share data with

We share data only with vetted subprocessors who help us run the Service:

  • Cloud hosting (data centers in the EU and India).
  • Payment processors (Stripe, Razorpay).
  • Transactional email (SES/SendGrid).
  • Error monitoring (Sentry).

We never sell or rent your data. We may disclose data when required by law (court order, regulatory request) — and where allowed, we will notify you first.

6. International transfers

Where data is transferred outside your region (e.g., EU → India), we rely on Standard Contractual Clauses or equivalent safeguards.

7. Retention

  • Account data: until you delete your account, plus 30 days for backups.
  • Billing records: 7 years (statutory requirement).
  • Message metadata: 90 days, unless you've enabled conversation history.
  • Server logs: 30 days.

8. Your rights

Depending on your jurisdiction you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your data ("right to be forgotten").
  • Restrict or object to processing.
  • Receive a portable copy of your data.
  • Withdraw consent at any time.
  • Lodge a complaint with your data protection authority.

Most of these can be exercised from your dashboard settings. For anything else, contact us — we respond within 30 days.

9. Security

We protect data with TLS 1.3 in transit, AES-256 at rest, hashed passwords (bcrypt), least-privilege access, regular backups and 24×7 monitoring. No system is 100% secure, but we work hard to keep yours safe.

10. Children

The Service is not directed to anyone under 18. We do not knowingly collect data from minors. If you believe a minor has provided data, contact us and we will delete it.

11. Changes

We may update this Policy from time to time. Material changes will be notified by email and/or in-app at least 14 days in advance.

12. Contact

Questions about this Privacy Policy or your data? Reach our Data Protection contact via the Contact page.

WhatzAPI is an independent platform and is not affiliated with, endorsed by, sponsored by or in any way associated with WhatsApp Inc., Meta Platforms Inc. or any of their subsidiaries. "WhatsApp" is a trademark of WhatsApp Inc., used here only to describe interoperability. Service is intended to reduce manual effort for legitimate business communication — bulk spam, fraud or unsolicited contact is strictly prohibited.

WhatzAPI WhatzAPI

The WhatsApp gateway built for businesses that move fast.

Product

Features Resellers Pricing

Legal

Terms Privacy Disclaimer Acceptable Use

Account

Login Register Contact
© 2026 WhatzAPI. All rights reserved. Not affiliated with WhatsApp Inc. or Meta Platforms.