Privacy Policy

The information below provides details about our privacy policy and we ask that you take the time to read it.

 

Privacy Policy

Effective date: 1 August 2026 | Last updated: 1 August 2026

This Policy explains how WhatsBot LTD, operating the “WhatsBot” platform, collects, uses, shares, retains, and protects personal data when you use our websites, applications, dashboard, APIs, integrations, and support services (collectively, the “Service”).

1. Scope and roles

This Policy applies to website visitors, account holders, Authorised Users, prospects, support contacts, and other individuals who interact with us. For account, billing, security, product, and marketing data, we normally act as controller. For contacts, messages, and end-customer data uploaded or processed by a Customer, the Customer normally acts as controller and we act as processor or service provider under its instructions, unless stated otherwise.

2. Personal data we collect

2.1 Data you provide

  • Name, email, phone number, organisation, country, language, role, and profile details.
  • Account data, hashed passwords, security settings, team members, and permissions.
  • Subscription, billing, transaction, tax, payment-token, card-last-four, and payment-status data provided by payment processors.
  • Support messages, feedback, surveys, complaints, and rights requests.
  • Files, images, templates, messages, prompts, and other content you upload.

2.2 Data collected automatically

  • IP address, device, operating system, browser, language, time zone, session identifiers, and cookies.
  • Login records, pages and features used, request time, errors, diagnostics, performance, plan consumption, and audit logs.
  • Security information such as login attempts, account changes, abuse indicators, and fraud signals.

2.3 End-customer data

Customers may process names, phone numbers, emails, contact lists, messages, orders, store data, conversation content, preferences, and responses through the Service. We generally do not determine the purpose of this data; Customer uses it under its own responsibility and instructions.

2.4 Integration data

  • Meta/WhatsApp: business-account identifiers, phone numbers, template identifiers, message status, inbound and outbound messages, webhook events, access tokens, and permissions.
  • Canva: authorised profile data, assets, brand-template metadata/content, design metadata/content, export results, OAuth access and refresh tokens, and user-action logs.
  • Google: authorised account data, selected spreadsheets/files and ranges, and OAuth tokens.
  • Salla, Shopify, WooCommerce and commerce services: store, customer, order, product, payment, shipping, and event data selected for synchronisation.
  • AI providers: prompts, text, files, or instructions sent to the selected provider and generated output.
  • Payment providers: payment status, amount, currency, transaction reference, anti-fraud information, and limited payment-method data.

3. Sources of data

We receive data directly from you, your organisation or account administrator, your use of the Service, payment and hosting providers, connected integrations, and lawful public or commercial sources used for business verification or fraud prevention.

4. Purposes and lawful bases

Purpose Examples Typical lawful basis
Provide and perform the Service Accounts, authentication, messaging, synchronisation, exports, support Contract or steps at your request
Security and abuse prevention Logging, fraud detection, account and infrastructure protection Legitimate interests and legal obligation
Billing and tax Payments, invoices, accounting records Contract and legal obligation
Product improvement Aggregated usage analysis, debugging, feature development Legitimate interests; consent for cookies where required
Operational communications Security, changes, outages, support Contract and legitimate interests
Marketing Promotions and product news Consent or legitimate interests where permitted, with opt-out
Compliance and legal claims Legal requests, investigations, disputes Legal obligation and legitimate interests

5. Canva data

We access Canva data only after explicit OAuth authorisation and within the scopes approved by the user. We use it to display connection status, manage authorised assets, templates, and designs, upload assets, and create, modify, or export a design at the user’s direction. We protect access and refresh tokens for continued authorised access. We do not sell Canva data, use it for targeted advertising, or expose it to another tenant. When Canva is disconnected, we stop future access and delete or disable active tokens, subject to limited security, legal, and backup retention. Content created in Canva remains governed by the user’s Canva account and Canva policies.

6. Google data

We use Google data only to provide user-requested functionality, such as connecting Google Sheets and reading or writing selected ranges. We do not sell Google user data, use it for advertising, or use it to train general-purpose AI models. Human access is limited to necessary support, security, or legal circumstances with permission or a lawful basis. Access can be revoked in WhatsBot or Google account settings.

7. Messages and contacts

Customer is primarily responsible for the purpose and lawful basis for processing contacts and messages. We do not use Customer contact lists to market WhatsBot to Customer’s contacts and do not sell those lists. We may process message content for routing, delivery, automation, support, and abuse detection, based on Customer settings and integrations.

8. Artificial intelligence

When an AI feature is used, the necessary input may be sent to the provider selected by Customer or identified in the feature. The provider may retain or use data under Customer account settings, agreements, and the provider’s policy. We do not use Customer Content to train a general-purpose model owned by us without separate explicit consent. Avoid submitting sensitive data without legal and security assessment.

9. Cookies and similar technologies

We use necessary cookies for login, security, and sessions; preference cookies for language and interface; and may use analytics or marketing cookies after consent where required. You can manage cookies through the browser or consent tool. Disabling necessary cookies may prevent the Service from working. A current cookie list or consent-management tool should be published if non-essential analytics or advertising technologies are enabled.

10. Sharing personal data

We do not sell personal data. We may share the minimum necessary data with:

  • Hosting, storage, networking, security, email, support, and analytics providers.
  • Payment, accounting, tax, and fraud-prevention providers.
  • Integrations selected by Customer to execute Customer instructions.
  • AI providers when their features are used.
  • Professional advisers, auditors, group companies, or prospective acquirers under appropriate safeguards.
  • Authorities or legal parties where required by valid law or to protect rights and safety.

11. Subprocessors

We use subprocessors to operate the Service. We will maintain or provide on request a current list stating provider, purpose, and processing location. Providers are bound by confidentiality and data-protection obligations appropriate to their role, and we manage them as required by applicable law.

12. International transfers

Data may be processed outside your country due to hosting or integrations. Where law requires transfer safeguards, we use appropriate mechanisms such as adequacy decisions, standard contractual clauses, approved arrangements, or a lawful exception, together with additional technical and organisational safeguards where appropriate.

13. Retention

Category General retention
Account and profile data For the active account and a reasonable period for closure, disputes, and compliance
Customer Content and messages According to Customer settings and plan, until deletion or contract end, followed by a limited deletion and backup cycle
OAuth tokens Until disconnect, account termination, or revocation, then deletion/disablement with temporary backup remnants
Security and operational logs Usually up to 12 months, longer for an incident, dispute, or legal duty
Support communications Usually up to 3 years after ticket or account closure
Invoices and tax records For the statutory period required by applicable law
Marketing data Until opt-out or purpose expiry, with a limited suppression record to respect opt-out

Retention may vary by plan, contract, law, or investigation. We delete or de-identify data when no longer needed, subject to backup cycles.

14. Security

We use risk-appropriate safeguards such as encryption in transit, role-based access, protection of secrets and tokens, monitoring and audit logs, backups, patching, reasonable security testing, and logical tenant separation. No system is 100% secure. Users must protect credentials and devices and promptly report suspected compromise.

15. Security incidents

We investigate confirmed incidents and take containment and remediation measures. We will notify Customers, authorities, or individuals where required by law and within applicable timelines. We may require Customer cooperation where Customer is controller for affected individuals.

16. Your rights

Depending on your location and applicable law, you may have rights to:

  • Be informed and access a copy of your personal data.
  • Correct inaccurate or incomplete data.
  • Request deletion where legally available.
  • Restrict or object to processing, particularly direct marketing.
  • Withdraw consent without retroactive effect.
  • Receive portable data where applicable.
  • Obtain safeguards concerning significant automated decisions.
  • Complain to a competent data-protection authority.

To exercise rights, contact privacy@whatsbot.at. We may verify identity. If the request concerns an end customer of our Customer, we may refer it to Customer as controller. We charge no fee unless legally permitted for an excessive or repetitive request.

17. Marketing

You may opt out through the unsubscribe link, account settings, or by contacting us. Necessary operational and security messages may continue. We do not use Customer end-customer data to market WhatsBot.

18. Automated decision-making

The Service may use rules or AI for categorisation, routing, automated responses, or abuse detection, but we do not ordinarily make solely automated final decisions with significant legal effects about direct users. If this changes, we will provide legally required information and rights.

19. Children

The Service is business-focused and intended for users aged 18 or older. We do not knowingly collect children’s data for direct accounts. If Customer processes a minor’s data, Customer is responsible for a lawful basis, consent, and safeguards. Contact us if you believe a child created an account without permission.

20. Deletion and disconnecting integrations

  • Canva, Google, Meta, and other integrations can be disconnected in account settings or the provider’s settings.
  • Disconnecting stops future access but does not necessarily delete content stored by the provider.
  • You can request account deletion through settings or email.
  • We may retain limited data for legal compliance, fraud prevention, and transaction proof, with restricted use.

21. Third-party sites

This Policy does not cover independent third-party processing. Review each provider’s privacy policy before connecting it. We do not control their practices merely because a link or integration appears in the Service.

22. Changes to this Policy

We may update this Policy for product or legal changes. We will post the updated date and provide prominent notice for material changes. Where a new use requires consent, we will obtain it before beginning.

23. Regional supplements

23.1 Bahrain

Where Bahrain’s Personal Data Protection Law applies, we process data in accordance with its requirements concerning lawful and transparent processing, security, data-subject rights, and transfers, and provide a channel for rights requests.

23.2 Saudi Arabia

Where the Saudi Personal Data Protection Law and Implementing Regulations apply, we define processing purposes, minimise and secure data, support data-subject rights, and apply relevant requirements for transfers outside the Kingdom, retention, destruction, and compliance controls.

23.3 United Kingdom and EEA

Where UK GDPR or GDPR applies, we identify a lawful basis, provide rights of access, rectification, erasure, restriction, objection, portability, and complaint, and use approved international-transfer safeguards where needed. Contact us regarding a representative or data protection officer if appointment is legally required.

24. Contact and complaints

Privacy contact:WhatsBot LTD
Email: privacy@whatsbot.at
Support: info@whatsbot.at
Phone: +973 3649 4642
You may also complain to the competent data-protection authority in your jurisdiction.