Privacy Policy
Last updated: 2026-07-12
Who we are
WhatIO ("we", "us") provides multi-channel campaign and workflow software. Contact [email protected] for privacy or data-protection requests. Our designated Data Protection contact can be reached at the same address.
Data we collect
- Account data: email, name, password hash, workspace membership, role.
- Service data: contacts you import, templates, campaigns, workflow configs, delivery logs.
- Integration credentials: OAuth tokens and API secrets stored encrypted at rest.
- Technical logs: IP address, user agent, request paths, error diagnostics.
- Billing metadata required to process subscriptions via our payment provider.
Legal basis for processing
We rely on the following legal bases under applicable data-protection law:
- Contract performance — processing necessary to provide the service you signed up for, including authentication, campaign delivery, and billing.
- Legitimate interests — security monitoring, fraud prevention, abuse detection, and improving service reliability, balanced against your rights.
- Legal obligation — retaining records required by applicable law.
- Consent — optional analytics and session-recording features activated only when you accept non-essential cookies.
How we use data
We process data to authenticate users, deliver messaging and automation features, enforce entitlements, prevent abuse, improve reliability, and meet legal obligations. We do not sell personal data.
Subprocessors
We engage the following categories of subprocessors under data-processing agreements:
- Cloud hosting & infrastructure — servers, databases, and storage that run the platform.
- Transactional email delivery — used to send account verification and notification emails.
- Payment processing — billing and subscription management; cardholder data is handled directly by the payment provider under PCI-DSS compliance.
- Error monitoring & observability — captures application errors and performance data to maintain reliability. Session recording is only enabled with full consent.
- Message delivery providers — Meta WhatsApp Cloud API, Google (Gmail/Workspace), and Slack, used only when you connect those integrations.
Retention
- Account and workspace data: retained while your account is active.
- Campaign and message logs: retained for up to 12 months after campaign completion.
- Billing records: retained as required by applicable law (typically 7 years).
- Encrypted backups and soft-deleted account records may persist for up to 30 days after deletion requests are processed (see backend disaster-recovery runbook).
- Error and diagnostic logs: retained for up to 90 days.
International transfers
Depending on your workspace configuration, data may be processed in regions where our infrastructure and subprocessors operate. We apply appropriate safeguards — including standard contractual clauses where required — for cross-border transfers.
Your rights (GDPR & equivalents)
Subject to applicable law, you may exercise the following rights by emailing [email protected]:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your personal data (subject to legal retention obligations). You can also delete your account directly from Account settings.
- Portability — receive your data in a machine-readable format via the "Download my data" export in Account settings.
- Restriction — ask us to limit processing in certain circumstances.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — change cookie preferences at any time via the cookie banner.
We will respond to requests within 30 days. You also have the right to lodge a complaint with your local data-protection supervisory authority.
Sharing
Data may be shared with subprocessors needed to run the product under contractual confidentiality. Message content is sent to connected providers you authorize (for example Meta WhatsApp Cloud API). We do not share data with third parties for advertising purposes.
Security
We apply encryption in transit (TLS) and at rest for sensitive credentials. Access controls, audit logging, and session management are enforced across the platform. To report a security issue email [email protected].
Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice at least 14 days before they take effect.