Effective date: 1 August 2026 | Last updated: 1 August 2026
This Policy explains how WhatsBot LTD, operating the “WhatsBot” platform, collects, uses, shares, retains, and protects personal data when you use our websites, applications, dashboard, APIs, integrations, and support services (collectively, the “Service”).
This Policy applies to website visitors, account holders, Authorised Users, prospects, support contacts, and other individuals who interact with us. For account, billing, security, product, and marketing data, we normally act as controller. For contacts, messages, and end-customer data uploaded or processed by a Customer, the Customer normally acts as controller and we act as processor or service provider under its instructions, unless stated otherwise.
Customers may process names, phone numbers, emails, contact lists, messages, orders, store data, conversation content, preferences, and responses through the Service. We generally do not determine the purpose of this data; Customer uses it under its own responsibility and instructions.
We receive data directly from you, your organisation or account administrator, your use of the Service, payment and hosting providers, connected integrations, and lawful public or commercial sources used for business verification or fraud prevention.
| Purpose | Examples | Typical lawful basis |
|---|---|---|
| Provide and perform the Service | Accounts, authentication, messaging, synchronisation, exports, support | Contract or steps at your request |
| Security and abuse prevention | Logging, fraud detection, account and infrastructure protection | Legitimate interests and legal obligation |
| Billing and tax | Payments, invoices, accounting records | Contract and legal obligation |
| Product improvement | Aggregated usage analysis, debugging, feature development | Legitimate interests; consent for cookies where required |
| Operational communications | Security, changes, outages, support | Contract and legitimate interests |
| Marketing | Promotions and product news | Consent or legitimate interests where permitted, with opt-out |
| Compliance and legal claims | Legal requests, investigations, disputes | Legal obligation and legitimate interests |
We access Canva data only after explicit OAuth authorisation and within the scopes approved by the user. We use it to display connection status, manage authorised assets, templates, and designs, upload assets, and create, modify, or export a design at the user’s direction. We protect access and refresh tokens for continued authorised access. We do not sell Canva data, use it for targeted advertising, or expose it to another tenant. When Canva is disconnected, we stop future access and delete or disable active tokens, subject to limited security, legal, and backup retention. Content created in Canva remains governed by the user’s Canva account and Canva policies.
We use Google data only to provide user-requested functionality, such as connecting Google Sheets and reading or writing selected ranges. We do not sell Google user data, use it for advertising, or use it to train general-purpose AI models. Human access is limited to necessary support, security, or legal circumstances with permission or a lawful basis. Access can be revoked in WhatsBot or Google account settings.
Customer is primarily responsible for the purpose and lawful basis for processing contacts and messages. We do not use Customer contact lists to market WhatsBot to Customer’s contacts and do not sell those lists. We may process message content for routing, delivery, automation, support, and abuse detection, based on Customer settings and integrations.
When an AI feature is used, the necessary input may be sent to the provider selected by Customer or identified in the feature. The provider may retain or use data under Customer account settings, agreements, and the provider’s policy. We do not use Customer Content to train a general-purpose model owned by us without separate explicit consent. Avoid submitting sensitive data without legal and security assessment.
We use necessary cookies for login, security, and sessions; preference cookies for language and interface; and may use analytics or marketing cookies after consent where required. You can manage cookies through the browser or consent tool. Disabling necessary cookies may prevent the Service from working. A current cookie list or consent-management tool should be published if non-essential analytics or advertising technologies are enabled.
We do not sell personal data. We may share the minimum necessary data with:
We use subprocessors to operate the Service. We will maintain or provide on request a current list stating provider, purpose, and processing location. Providers are bound by confidentiality and data-protection obligations appropriate to their role, and we manage them as required by applicable law.
Data may be processed outside your country due to hosting or integrations. Where law requires transfer safeguards, we use appropriate mechanisms such as adequacy decisions, standard contractual clauses, approved arrangements, or a lawful exception, together with additional technical and organisational safeguards where appropriate.
| Category | General retention |
|---|---|
| Account and profile data | For the active account and a reasonable period for closure, disputes, and compliance |
| Customer Content and messages | According to Customer settings and plan, until deletion or contract end, followed by a limited deletion and backup cycle |
| OAuth tokens | Until disconnect, account termination, or revocation, then deletion/disablement with temporary backup remnants |
| Security and operational logs | Usually up to 12 months, longer for an incident, dispute, or legal duty |
| Support communications | Usually up to 3 years after ticket or account closure |
| Invoices and tax records | For the statutory period required by applicable law |
| Marketing data | Until opt-out or purpose expiry, with a limited suppression record to respect opt-out |
Retention may vary by plan, contract, law, or investigation. We delete or de-identify data when no longer needed, subject to backup cycles.
We use risk-appropriate safeguards such as encryption in transit, role-based access, protection of secrets and tokens, monitoring and audit logs, backups, patching, reasonable security testing, and logical tenant separation. No system is 100% secure. Users must protect credentials and devices and promptly report suspected compromise.
We investigate confirmed incidents and take containment and remediation measures. We will notify Customers, authorities, or individuals where required by law and within applicable timelines. We may require Customer cooperation where Customer is controller for affected individuals.
Depending on your location and applicable law, you may have rights to:
To exercise rights, contact privacy@whatsbot.at. We may verify identity. If the request concerns an end customer of our Customer, we may refer it to Customer as controller. We charge no fee unless legally permitted for an excessive or repetitive request.
You may opt out through the unsubscribe link, account settings, or by contacting us. Necessary operational and security messages may continue. We do not use Customer end-customer data to market WhatsBot.
The Service may use rules or AI for categorisation, routing, automated responses, or abuse detection, but we do not ordinarily make solely automated final decisions with significant legal effects about direct users. If this changes, we will provide legally required information and rights.
The Service is business-focused and intended for users aged 18 or older. We do not knowingly collect children’s data for direct accounts. If Customer processes a minor’s data, Customer is responsible for a lawful basis, consent, and safeguards. Contact us if you believe a child created an account without permission.
This Policy does not cover independent third-party processing. Review each provider’s privacy policy before connecting it. We do not control their practices merely because a link or integration appears in the Service.
We may update this Policy for product or legal changes. We will post the updated date and provide prominent notice for material changes. Where a new use requires consent, we will obtain it before beginning.
Where Bahrain’s Personal Data Protection Law applies, we process data in accordance with its requirements concerning lawful and transparent processing, security, data-subject rights, and transfers, and provide a channel for rights requests.
Where the Saudi Personal Data Protection Law and Implementing Regulations apply, we define processing purposes, minimise and secure data, support data-subject rights, and apply relevant requirements for transfers outside the Kingdom, retention, destruction, and compliance controls.
Where UK GDPR or GDPR applies, we identify a lawful basis, provide rights of access, rectification, erasure, restriction, objection, portability, and complaint, and use approved international-transfer safeguards where needed. Contact us regarding a representative or data protection officer if appointment is legally required.
Privacy contact:WhatsBot LTD
Email: privacy@whatsbot.at
Support: info@whatsbot.at
Phone: +973 3649 4642
You may also complain to the competent data-protection authority in your jurisdiction.