1. Overview & Data Controller
WapiCloud Inc. (“WapiCloud”, “we”, “us”, or “our”) operates an enterprise-grade cloud connectivity layer interfacing directly with the Meta WhatsApp Cloud API. Under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and equivalent global regulations:
For customer account details, billing logs, portal usage, and API keys created directly by registered platform administrators.
For all recipient phone numbers, conversational messages, webhook triggers, and automated payload templates dispatched via our endpoints.
Zero-Data Selling Pledge
We do not sell, rent, monetize, or train proprietary foundation models on customer conversations or end-user data. Payloads only cross transit pipelines to execute authenticated delivery tasks.
2. Information We Collect
The data we process is strictly compartmentalized based on architectural layers to safeguard confidentiality.
| Category | Specific Elements | Purpose | Retention |
|---|---|---|---|
| End-User Identifiers | Recipient WhatsApp MSISDN, Phone country prefix, Verified profile names | Message dispatching, routing, inbound webhook triggers | Configurable (0–90 days) |
| Message Payloads | Template parameters, text strings, media binary URIs, interactive button replies | Format validation, API delivery relay, retry buffer | Ephemeral (Max 72 hrs) |
| Telemetry & API Logs | IP addresses, API Token IDs, HTTP status codes, latency timings, error codes | Rate limiting, fraud prevention, SLA tracing | 180 Days |
| Billing Records | Credit card last-4, billing address, VAT/Tax identification number, tier usage | Invoicing, legal taxation compliance | 7 Years (Statutory) |
Message Transit & Encryption Guarantee
All communications passing through WapiCloud are protected by strict TLS 1.3 encryption in transit and AES-256 at rest. Payload caching is fully transient: once Meta receives the message envelope, message bodies are marked for irreversible deletion.
3. How We Process WhatsApp Message Data
As a licensed provider interfacing with the official WhatsApp Business Cloud API, our data ingestion adheres strictly to Meta Platform terms and international privacy frameworks:
- check_circle Explicit Opt-In Enforcement: Customers are legally obligated to ensure all recipient end-users have rendered verifiable affirmative consent before any transactional or promotional messaging is initiated.
- check_circle Automatic Unsubscribe Hooks: Standard STOP/OPT-OUT reply keywords are automatically processed via edge listeners, allowing real-time suppression of future dispatches without manual intervention.
- check_circle Strict Payload Redaction: When developer logging is enabled, sensitive variables within approved WhatsApp message templates can be masked on demand using our deterministic Regex Redaction feature.
4. Legal Basis for Processing (GDPR Art. 6)
For individuals residing in the European Economic Area (EEA), the United Kingdom, or Switzerland, processing operations rely on the following codified legal grounds:
Executing messaging API commands, maintaining webhook relays, and generating usage analytics as requested through your active subscription tier.
Detecting abusive spam floods, mitigating malicious API injections, and optimizing server uptime across our distributed gateway clusters.
Satisfying statutory financial accounting mandates, international sanctions checks, and responding to legally enforceable judicial subpoenas.
Delivery of non-essential product update announcements, developer surveys, and participation in beta features.
5. Storage, Encryption & SOC2 Controls
Our cloud infrastructure is engineered according to Zero-Trust architecture paradigms:
SOC 2 Type II Certified
Annual independent third-party audit of Security, Availability & Confidentiality Trust Principles
6. Subprocessors & Meta Platforms
WapiCloud engages select infrastructure subprocessors to provide core cloud platform capabilities. Prior to onboarding, each subprocessor undergoes rigorous security vetting:
| Entity | Processing Purpose | Location | Safeguard Mechanism |
|---|---|---|---|
| Meta Platforms, Inc. / Meta Ireland Ltd. | Direct WhatsApp network transit & final message delivery | USA / Ireland | EU-US DPF & Meta DPA |
| Amazon Web Services (AWS) | Cloud compute instances, auto-scaling queues & vault keys | Frankfurt (EU) / N. Virginia (US) | Standard Contractual Clauses |
| Stripe, Inc. | Subscription billing execution & PCI-DSS compliant checkout | USA | PCI-DSS Level 1 / SCCs |
7. Data Retention & Auto-Purge Cycles
We adhere to data minimization principles. Once a transactional event is completed, our auto-purge daemon performs cryptographic unlinking and bit-level overwriting:
Zero-Log Mode
Customers can activate Zero-Log Mode via API flags to destroy payload payloads instantly post-dispatch.
Delivery Retries
Undelivered network messages are queued for up to 72 hours, after which unacknowledged items are purged.
Account Closure
Upon customer account cancellation, all backups and related tenant records are expunged within 30 days.
8. International Data Transfers
Where cross-border data transfers occur from the EEA, Switzerland, or UK to countries without an Adequacy Decision under Article 45, WapiCloud executes Standard Contractual Clauses (SCCs) approved by the European Commission, fortified by supplementary technical safeguards including end-to-end payload envelope hashing.
9. Your Rights & Data Subject Requests (DSR)
Depending on your jurisdiction, you possess specific sovereign statutory rights regarding your personal information:
Note for End Users: If your mobile number was contacted by an enterprise client using WapiCloud, we act solely as their Data Processor. Please direct your initial erasure or access request directly to the company sending you messages. We provide rapid tooling for them to complete your request within 48 hours.
10. Contact Privacy Officer
For questions regarding our privacy architecture, SOC2 audit packets, or to exercise regulatory rights: