Legal document

Privacy policy

This document explains what data ربوع قرطاج للتجارة العامة محدودة المسؤولية شركة خاصة collects while operating the Watsy platform, why it collects it, who it is shared with, how long it is kept, and what you may ask of us at any time.

Effective date: 17 August 2026Operated by: ربوع قرطاج للتجارة العامة محدودة المسؤولية شركة خاصةAuthoritative language: Arabic

This English version is a courtesy translation provided for convenience only. The Arabic version is the legally binding text, and in the event of any discrepancy in meaning, the Arabic text prevails.

Contents
  1. A. About this policy
  2. B. The data controller
  3. C. Our roles: controller and processor
  4. D. The data we process
  5. E. How we obtain it
  6. F. Purposes and legal bases
  7. G. Meta platform data
  8. H. The AI assistant
  9. I. Sharing and sub-processors
  10. J. Transfers outside your country
  11. K. Retention periods
  12. L. Security
  13. M. Your rights
  14. N. Cookies and tracking
  15. O. Children
  16. P. Data deletion
  17. Q. Changes to this policy
  18. R. Contacting us

About this policy

Watsy is a software platform that lets businesses manage their customer conversations over Meta's official WhatsApp Business Platform (Cloud API), alongside other messaging channels. This policy applies to our website and to the platform itself.

We write this document in plain language deliberately. Where a legal term is unavoidable, we explain it. And if anything remains unclear, write to us and we will clarify it.

The summary in three lines: your conversation and customer data belongs to you, and we process it on your behalf to operate the service. We do not sell your data, we do not use it for advertising, and we do not use it to train artificial-intelligence models. This website loads no advertising tracker of any kind.

The data controller

The entity responsible for the processing described here is:

  • ربوع قرطاج للتجارة العامة محدودة المسؤولية شركة خاصةربوع قرطاج للتجارة العامة محدودة المسؤولية شركة خاصة
  • Registered address: بغداد/ الامين الثانية/نواب الضباط/م ٧٤١/شارع ٣٨ المرقمة م ١٣/رقم الابواب١٣/٧/١
  • Registration number: م. ش. أ. - 02 - 000004726
  • Country of registration: Iraq
  • Privacy and data protection email: privacy@watsy.pro
  • Legal email: legal@watsy.pro

Our roles: when we are a controller and when we are a processor

This distinction matters because it determines who you should address your request to:

We are the controller

For the data of your own account as our customer: your name, your email, your role in the organization, your subscription and payment history, and your usage of the console. We determine the purposes and means of processing this data.

We are the processor

For the data of our customers' customers: conversation content, phone numbers, media, notes and customer cards. This is determined by the business using Watsy, and we process it solely on its instructions. If you are a customer of a business that uses Watsy and received a message through us, access or deletion requests should be directed to that business first, and we support it in carrying them out.

The data we process

1) Account and organization data

  • Name, email address and password (stored as a cryptographic hash, never as plain text).
  • Organization name, your role within it (owner · manager · agent), and invitations sent and accepted.
  • Subscription status, plan, quotas consumed, payment history and the transfer receipts you upload.
  • Your preferences: time zone, business hours, notification settings.

2) Messaging-platform connection data

  • The WhatsApp Business Account (WABA) identifier and the identifier of the connected phone number.
  • The access token issued by Meta — stored encrypted, and never appearing in plain text in the database or in the logs.
  • Business verification status, template count, and the number's quality rating as reported to us by Meta.
  • For other channels: the Telegram bot token, or the Messenger/Instagram page token — under the same encryption.

3) Conversation data (processed on our customer's behalf)

  • The content of inbound and outbound messages, their timestamps and their status (sent · delivered · read).
  • Media: images, files, voice messages and video — downloaded to our own storage and served through temporary links.
  • Contact data: the name as it appears in WhatsApp, the phone number, and the WhatsApp identifier.
  • Whatever the business adds itself: email, company, city, tags, internal notes, pipeline stage, custom fields, and marketing opt-in status.

4) Technical data

  • IP address and the access logs necessary for service security and rate limiting.
  • Error reports and technical fault diagnostics.
  • An audit log containing send and block decisions and subscription changes, with the reason, the time and the actor.

How we obtain this data

  • Directly from you when you register, set up your organization, or write to us.
  • Through Google sign-in if you choose it — we receive only your name and email, and never see your password.
  • Through Meta's official connection flow (Embedded Signup) when you connect a WhatsApp number.
  • From Meta via webhooks — inbound messages and delivery status updates; we verify the signature of every request before accepting it.
  • Automatically while you use the platform — counters and technical logs.

Purposes of processing and legal bases

Purposes of processing and the legal basis for each
PurposeLegal basis
Operating the platform and sending and receiving messagesPerformance of the contract with you
Managing the account, the team and permissionsPerformance of the contract
Billing and collecting the subscriptionPerformance of the contract + legal obligation (accounting records)
Service security, abuse prevention and rate limitingLegitimate interest in protecting the service and its users
Improving the product and resolving faultsLegitimate interest
Service alerts (quota reached, subscription expiring, connection lost)Performance of the contract
Running the AI assistant on your knowledgePerformance of the contract, once you enable the feature
Responding to legal requestsLegal obligation

Wherever we rely on legitimate interest, we have balanced it against your rights, and you may object to the processing — see the your rights section.

Meta platform data — express undertakings

When you connect your number, we receive data from the WhatsApp Business Platform. We undertake the following in respect of it, and treat it as a binding part of this policy:

  1. We use Meta platform data solely to provide the service to the business that connected the number, and on its instructions.
  2. We do not sell Meta platform data, nor licence it, nor trade in it in any form.
  3. We do not use it for advertising targeting, nor to build advertising profiles, nor to determine eligibility for any financial or insurance product.
  4. We do not use it to train general or cross-customer artificial-intelligence models. Each business's knowledge remains isolated within its own organization.
  5. We share it only with the sub-processors listed in section I, under processing agreements binding them to the same standard.
  6. We delete it upon the customer's request, upon termination of the service, or when it is no longer needed — whichever comes first — unless a legal obligation to retain it exists.
  7. We apply the access controls and encryption described in section L, and maintain an audit log of sensitive decisions.

A business's use of WhatsApp through Watsy is also subject to Meta's policies and the WhatsApp Business Terms, which are terms between that business and Meta directly.

The AI assistant — how your knowledge is processed

The AI assistant is an optional feature that you enable yourself. When you enable it:

  • The documents and text you upload are split and converted into vector representations stored within your own isolated database.
  • When a question arrives from your customer, the question is sent together with the relevant passages from your own knowledge to a language-model provider to generate the reply.
  • We select providers who undertake contractually not to use the content sent to them to train their models.
  • One business's knowledge is never mixed with another's, and is never used to improve the service of a different customer.
  • You can disable or delete any document at any time, and switch the assistant off entirely.

When the assistant finds no reliable answer in your knowledge, it is designed to stop and hand over to a human agent rather than generate an unverified answer.

Sharing and sub-processors

We do not sell your data and we do not share it for marketing purposes. We share it only with the service providers we need in order to operate the platform, under processing agreements that bind them to the limits of what we ask:

Sub-processors, their purposes and the data types involved
ProviderPurposeData type
Meta PlatformsSending and receiving WhatsApp, Messenger and Instagram messages, and managing templatesMessage content, customer identifiers and numbers
TelegramSending and receiving Telegram messagesMessage content and customer identifiers
HetznerHosting the platform servers and job queuesAll account and conversation data
SupabaseDatabase and authenticationAll account and conversation data
Cloudflare R2Storage of conversation mediaImages, files and voice messages
SentryTechnical fault monitoringTechnical and diagnostic data
ResendOperational email and alertsName and email address
Payment gatewaysCollecting the subscription (Qi Card · PayTR · LemonSqueezy)Transaction data — we never see your card details
Language-model providerGenerating the AI assistant's replies — only when it is enabledThe customer's question and the relevant passages from your knowledge

We may also disclose data in response to a court order or a binding legal obligation, or to protect our rights and the rights of our users. In the event of a merger or acquisition, data transfers to the successor entity under the same safeguards, and we notify you in advance.

The sub-processor list is current as at the effective date of this document. We notify our customers before adding a material new sub-processor.

Operational backups: we keep a backup copy of conversation media for at most 14 days, so that we can recover from an accidental deletion or a technical fault. A file you delete — or one whose retention period expires — may therefore remain in that backup for up to 14 days after it disappears from the service, and is then erased from it permanently and automatically. The backup is isolated, is not read during normal operation, and is used only for recovery.

Transfers outside your country

Some of our providers operate their infrastructure outside your country of residence. Where data is transferred internationally, we rely on one of the recognised mechanisms: an adequacy decision, the Standard Contractual Clauses, or your explicit consent where the law requires it. And we require from every provider a level of protection no lower than this policy commits to.

Retention periods

  • Media (images, audio, video, documents): deleted automatically when your plan's retention period ends — 3, 6 or 12 months — by a scheduled daily job.
  • Conversation text and customer cards: retained for as long as your account exists, and deleted when it is closed or upon your request.
  • Account and organization data: retained throughout the contractual relationship.
  • Technical logs: a short period sufficient for diagnostics and security, then deleted.
  • The audit log and billing records: retained for the period required by accounting and legal obligations, even after the account is closed.

Expiry of your subscription does not delete your data. Only sending stops, and your conversations remain readable until you renew or request deletion.

Security

  • Access tokens encrypted with AES-256-GCM at rest — never readable as plain text from the database.
  • Transport encryption over TLS for every connection to the platform.
  • Row-level isolation in the database preventing any organization from reaching another's data, enforced in the database itself and not in the application alone.
  • Webhook signature verification against the raw body before accepting any inbound message.
  • Rate limiting to repel abuse attempts.
  • Strict security headers on the website and the API, and role-based permission controls.
  • Temporary links for media instead of exposed permanent URLs.
  • Periodic backups of the database.

No system is entirely impregnable. If a breach occurs that is likely to affect your rights, we notify you and the competent supervisory authority within the period required by the applicable law.

Your rights

You hold — subject to the law applicable to you — the following rights:

  • Access: to know what we process about you and to obtain a copy of it.
  • Rectification: to correct what is inaccurate or incomplete.
  • Erasure: to request deletion of your data where no legitimate ground for retaining it remains.
  • Restriction of processing in specified circumstances.
  • Portability: to receive your data in a structured, machine-readable format.
  • Objection to processing founded on legitimate interest.
  • Withdrawal of consent whenever you wish, without affecting the lawfulness of processing carried out before withdrawal.
  • Complaint to the competent supervisory authority in your country.

To exercise any of these rights, write to us at privacy@watsy.pro. We respond within thirty days at the latest, and we may ask for proof of your identity to protect your account. We charge no fee for reasonable requests and we do not discriminate against you for exercising your rights.

Cookies and tracking

We use strictly necessary cookies only: the session cookie that keeps you signed in, and the language-preference cookie. Without these the platform does not work.

This website loads no advertising pixel, no third-party analytics tool and no retargeting network. No Google Analytics, no Meta Pixel, none of it. That is why you find no cookie consent banner here — because there is nothing for you to consent to.

You may delete cookies from your browser settings at any time, bearing in mind that deleting the session cookie signs you out of your account.

Children

Watsy is a service directed at businesses. We do not offer it to anyone under sixteen, and we do not knowingly collect their data. If we learn of an account created for a minor, we delete it. And if you are a parent or guardian and believe your child has provided us with their data, write to us and we will delete it.

Data deletion

We maintain a dedicated page explaining exactly what is deleted, how to delete it yourself from your console, how to request full deletion, and how long it takes:

Data deletion instructions →

Changes to this policy

We may update this policy as the service or the law changes. The date at the top of the page is the effective date of the current version. For any material change, we notify our customers by email or inside the console a reasonable period before it takes effect. Your continued use after it takes effect constitutes your acceptance.

Contacting us

  • Privacy and data protection: privacy@watsy.pro
  • Legal matters: legal@watsy.pro
  • Technical support: support@watsy.pro
  • Postal address: بغداد/ الامين الثانية/نواب الضباط/م ٧٤١/شارع ٣٨ المرقمة م ١٣/رقم الابواب١٣/٧/١