Trust & Transparency v3.4.1

Privacy Policy

We prioritize complete sovereign control, zero non-consensual sharing, and rigorous compliance standards for all high-volume WhatsApp Cloud API enterprise messaging pipelines.

verified Last Updated: October 15, 2024 · GDPR, CCPA & HIPAA Compliant
download Download DPA (PDF)
SECTION 01

1. Overview & Data Controller

WapiCloud Inc. (“WapiCloud”, “we”, “us”, or “our”) operates an enterprise-grade cloud connectivity layer interfacing directly with the Meta WhatsApp Cloud API. Under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and equivalent global regulations:

badge Data Controller

For customer account details, billing logs, portal usage, and API keys created directly by registered platform administrators.

hub Data Processor

For all recipient phone numbers, conversational messages, webhook triggers, and automated payload templates dispatched via our endpoints.

shield

Zero-Data Selling Pledge

We do not sell, rent, monetize, or train proprietary foundation models on customer conversations or end-user data. Payloads only cross transit pipelines to execute authenticated delivery tasks.

SECTION 02

2. Information We Collect

The data we process is strictly compartmentalized based on architectural layers to safeguard confidentiality.

Category Specific Elements Purpose Retention
End-User Identifiers Recipient WhatsApp MSISDN, Phone country prefix, Verified profile names Message dispatching, routing, inbound webhook triggers Configurable (0–90 days)
Message Payloads Template parameters, text strings, media binary URIs, interactive button replies Format validation, API delivery relay, retry buffer Ephemeral (Max 72 hrs)
Telemetry & API Logs IP addresses, API Token IDs, HTTP status codes, latency timings, error codes Rate limiting, fraud prevention, SLA tracing 180 Days
Billing Records Credit card last-4, billing address, VAT/Tax identification number, tier usage Invoicing, legal taxation compliance 7 Years (Statutory)
lock

Message Transit & Encryption Guarantee

All communications passing through WapiCloud are protected by strict TLS 1.3 encryption in transit and AES-256 at rest. Payload caching is fully transient: once Meta receives the message envelope, message bodies are marked for irreversible deletion.

SECTION 03

3. How We Process WhatsApp Message Data

As a licensed provider interfacing with the official WhatsApp Business Cloud API, our data ingestion adheres strictly to Meta Platform terms and international privacy frameworks:

  • check_circle Explicit Opt-In Enforcement: Customers are legally obligated to ensure all recipient end-users have rendered verifiable affirmative consent before any transactional or promotional messaging is initiated.
  • check_circle Automatic Unsubscribe Hooks: Standard STOP/OPT-OUT reply keywords are automatically processed via edge listeners, allowing real-time suppression of future dispatches without manual intervention.
  • check_circle Strict Payload Redaction: When developer logging is enabled, sensitive variables within approved WhatsApp message templates can be masked on demand using our deterministic Regex Redaction feature.
SECTION 05

5. Storage, Encryption & SOC2 Controls

Our cloud infrastructure is engineered according to Zero-Trust architecture paradigms:

verified_user

SOC 2 Type II Certified

Annual independent third-party audit of Security, Availability & Confidentiality Trust Principles

ENCRYPTION AT REST AES-256 GCM Customer-managed KMS keys available
IN TRANSIT TLS 1.3 / mTLS Strict HSTS, Perfect Forward Secrecy
DATA RESIDENCY EU, US, APAC Isolated sovereign tenant zones
SECTION 06

6. Subprocessors & Meta Platforms

WapiCloud engages select infrastructure subprocessors to provide core cloud platform capabilities. Prior to onboarding, each subprocessor undergoes rigorous security vetting:

Entity Processing Purpose Location Safeguard Mechanism
Meta Platforms, Inc. / Meta Ireland Ltd. Direct WhatsApp network transit & final message delivery USA / Ireland EU-US DPF & Meta DPA
Amazon Web Services (AWS) Cloud compute instances, auto-scaling queues & vault keys Frankfurt (EU) / N. Virginia (US) Standard Contractual Clauses
Stripe, Inc. Subscription billing execution & PCI-DSS compliant checkout USA PCI-DSS Level 1 / SCCs
SECTION 07

7. Data Retention & Auto-Purge Cycles

We adhere to data minimization principles. Once a transactional event is completed, our auto-purge daemon performs cryptographic unlinking and bit-level overwriting:

IMMEDIATE DELETE

Zero-Log Mode

Customers can activate Zero-Log Mode via API flags to destroy payload payloads instantly post-dispatch.

72-HOUR BUFFER

Delivery Retries

Undelivered network messages are queued for up to 72 hours, after which unacknowledged items are purged.

30-DAY HARD WIPE

Account Closure

Upon customer account cancellation, all backups and related tenant records are expunged within 30 days.

SECTION 08

8. International Data Transfers

Where cross-border data transfers occur from the EEA, Switzerland, or UK to countries without an Adequacy Decision under Article 45, WapiCloud executes Standard Contractual Clauses (SCCs) approved by the European Commission, fortified by supplementary technical safeguards including end-to-end payload envelope hashing.

SECTION 09

9. Your Rights & Data Subject Requests (DSR)

Depending on your jurisdiction, you possess specific sovereign statutory rights regarding your personal information:

visibility Right to Access & Portability
delete_forever Right to Erasure (“Be Forgotten”)
edit_note Right to Rectification
block Right to Restrict or Object to Processing

Note for End Users: If your mobile number was contacted by an enterprise client using WapiCloud, we act solely as their Data Processor. Please direct your initial erasure or access request directly to the company sending you messages. We provide rapid tooling for them to complete your request within 48 hours.

SECTION 10

10. Contact Privacy Officer

For questions regarding our privacy architecture, SOC2 audit packets, or to exercise regulatory rights:

WapiCloud Global Data Protection Officer Attn: Legal & Compliance Team · WapiCloud Inc. privacy@wapicloud.io
mail Email DPO
assignment_turned_in Enterprise Agreements

Need to submit a Data Subject Request (DSR) or sign a custom DPA?

Our automated DSR portal and legal compliance specialists are available to review custom enterprise Data Processing Addendums with custom residency clauses.