Privacy Policy & Data Custody
WACRM provides enterprise multi-agent WhatsApp customer support and sales routing infrastructure. We operate on a strict data-custody model: customer contact data and message history are processed solely to facilitate verified two-way business communications via Meta's official WhatsApp Cloud API. We do not sell, monetize, or broker customer data or chat transcripts to third parties.
01.Information We Process
When an organization connects its WhatsApp Business Account (WABA) to WACRM and engages in customer conversations, we process:
- Contact Identifiers: WhatsApp Phone Number, WhatsApp Display Name, Profile Picture URL (as authorized via Meta Cloud API).
- Communication Records: Inbound and outbound message payloads (text, template messages, media attachments, and interactive button clicks).
- Delivery & Operational Metadata: Message IDs, delivery timestamps, read status receipts, agent assignment tags, and SLA response markers.
- Operator Account Data: Staff user names, work email addresses, authentication sessions, and role permissions.
02.Purpose of Data Processing
All processed data is utilized strictly for authorized operational objectives:
Transmitting outbound communications and receiving customer webhooks via Meta Cloud API endpoints.
Distributing inbound inquiries across designated customer service representatives and sales managers.
Enforcing WhatsApp's 24-hour customer service window guidelines to prevent unsolicited messaging.
Maintaining cryptographic, append-only audit trails for authentication and tenant administrative events.
03.Third-Party Data Processors
To operate WhatsApp sales infrastructure, WACRM interfaces with verified technical service providers:
- Meta Platforms, Inc. / WhatsApp LLC: Official provider of the WhatsApp Cloud API. Webhook events and outgoing payloads traverse Meta's sovereign infrastructure governed by the Meta Privacy Policy.
- Cloud Infrastructure & Database Hosting: Isolated, encrypted relational storage (PostgreSQL) hosted in tier-4 data centers with TLS 1.3 in transit and AES-256 at rest.
04.Data Retention & Sovereign Isolation
We retain customer conversation records only as long as necessary to maintain customer service continuity for the tenant organization, or until an authorized deletion request is issued. Each enterprise tenant operates within isolated logical boundaries with multi-tenant query restrictions, preventing cross-tenant leakage.
05. User Data Deletion Instructions (Meta Compliance)
In accordance with Meta Platform Policy, General Data Protection Regulation (GDPR), and global privacy standards, any customer or end user who has communicated with an organization using WACRM has the right to request the complete deletion of their personal data and conversation history.
How to Submit a Data Deletion Request:
- Send an email to privacy@wacrm.com (or your organization's designated compliance contact).
- Set the subject line to:
WhatsApp User Data Deletion Request. - Include your full WhatsApp phone number (with country code, e.g., +1 555 123 4567) and the business name you communicated with.
- Our compliance team will verify the request, confirm receipt within 48 hours, and permanently purge all associated contact records and message transcripts from our active databases and backup queues within 30 days.
06.Contact & Data Protection Officer
For any questions regarding this Privacy Policy, Meta Cloud API integrations, or our data custody practices: