Scope
This policy applies to visitors, authorized business users, connected business accounts, and customer conversations processed through enabled service workflows. A business using the service may separately act as the controller of its customer data and must provide its own notices where required.
Data we process
Depending on the features used, the service may process:
- Account and workspace data such as user identifiers, roles, authentication state, and workspace configuration.
- Business asset data such as connected Page, professional account, WhatsApp Business Account, phone-number, or ad-account identifiers and connection status.
- Customer communication data such as platform-scoped identifiers, profile fields supplied by the platform, message or comment content, timestamps, attachments, and conversation history.
- Operational data such as delivery state, assignments, templates, policy decisions, audit events, error diagnostics, IP address, and device or browser information.
- Support and request data supplied when asking for assistance, exercising a privacy right, or requesting deletion.
Meta Platform Data
When an authorized business user connects a supported Meta product, the service may receive Meta Platform Data for the specific capabilities the user enables. This can include business asset identifiers, Page or professional-account information, customer profile fields made available by Meta, messages, comments, media context, webhook events, messaging-window state, template information, or advertising insights.
Meta Platform Data is used only to provide, secure, troubleshoot, and document the connected workflow. Access depends on the permissions granted by the business user and the access approved by Meta.
How we use data
- Provide and maintain connected communication workflows.
- Route customer requests and preserve relevant conversation context.
- Authenticate users, enforce workspace access, and protect connected assets.
- Apply policy, consent, suppression, and messaging-window controls.
- Monitor reliability, investigate delivery failures, and prevent abuse.
- Respond to support, legal, privacy, and deletion requests.
Sharing and processors
Data may be handled by infrastructure, hosting, security, communication-platform, or support providers only where needed to operate the service. Data may also be disclosed when required by law, to protect users or the service, or as part of a properly authorized business transition. We do not sell customer conversation data or Meta Platform Data.
Retention
Data is retained only for as long as needed for the enabled service, security, dispute resolution, legal obligations, or documented operational requirements. Retention periods may vary by data type and workspace configuration. Data is deleted or de-identified when it is no longer required, subject to lawful preservation obligations and backup rotation.
Security
Administrative, technical, and organizational safeguards are used to reduce the risk of unauthorized access, alteration, disclosure, or loss. These include access controls, encrypted transport, secret separation, logging, and workspace boundaries. No system can guarantee absolute security.
Read more on the Security page.
Your choices and deletion
Authorized users can disconnect supported integrations through the relevant account or platform controls. Data subjects and business users may request access, correction, restriction, or deletion where applicable. Follow the steps on the Data Deletion page so the request can be matched to the correct workspace and connected asset.
Children
The service is intended for business communication and is not directed to children. It should not be used to knowingly collect children’s data without an appropriate legal basis, notice, and safeguards.
Changes
This policy may be updated when the service, connected platforms, or legal requirements change. The date shown above identifies the current version.