About this policy
Watsy is a software platform that lets businesses manage their customer conversations over Meta's official WhatsApp Business Platform (Cloud API), alongside other messaging channels. This policy applies to our website and to the platform itself.
We write this document in plain language deliberately. Where a legal term is unavoidable, we explain it. And if anything remains unclear, write to us and we will clarify it.
The summary in three lines: your conversation and customer data belongs to you, and we process it on your behalf to operate the service. We do not sell your data, we do not use it for advertising, and we do not use it to train artificial-intelligence models. This website loads no advertising tracker of any kind.
The data controller
The entity responsible for the processing described here is:
- ربوع قرطاج للتجارة العامة محدودة المسؤولية شركة خاصة — ربوع قرطاج للتجارة العامة محدودة المسؤولية شركة خاصة
- Registered address: بغداد/ الامين الثانية/نواب الضباط/م ٧٤١/شارع ٣٨ المرقمة م ١٣/رقم الابواب١٣/٧/١
- Registration number: م. ش. أ. - 02 - 000004726
- Country of registration: Iraq
- Privacy and data protection email: privacy@watsy.pro
- Legal email: legal@watsy.pro
Our roles: when we are a controller and when we are a processor
This distinction matters because it determines who you should address your request to:
We are the controller
For the data of your own account as our customer: your name, your email, your role in the organization, your subscription and payment history, and your usage of the console. We determine the purposes and means of processing this data.
We are the processor
For the data of our customers' customers: conversation content, phone numbers, media, notes and customer cards. This is determined by the business using Watsy, and we process it solely on its instructions. If you are a customer of a business that uses Watsy and received a message through us, access or deletion requests should be directed to that business first, and we support it in carrying them out.
The data we process
1) Account and organization data
- Name, email address and password (stored as a cryptographic hash, never as plain text).
- Organization name, your role within it (owner · manager · agent), and invitations sent and accepted.
- Subscription status, plan, quotas consumed, payment history and the transfer receipts you upload.
- Your preferences: time zone, business hours, notification settings.
2) Messaging-platform connection data
- The WhatsApp Business Account (WABA) identifier and the identifier of the connected phone number.
- The access token issued by Meta — stored encrypted, and never appearing in plain text in the database or in the logs.
- Business verification status, template count, and the number's quality rating as reported to us by Meta.
- For other channels: the Telegram bot token, or the Messenger/Instagram page token — under the same encryption.
3) Conversation data (processed on our customer's behalf)
- The content of inbound and outbound messages, their timestamps and their status (sent · delivered · read).
- Media: images, files, voice messages and video — downloaded to our own storage and served through temporary links.
- Contact data: the name as it appears in WhatsApp, the phone number, and the WhatsApp identifier.
- Whatever the business adds itself: email, company, city, tags, internal notes, pipeline stage, custom fields, and marketing opt-in status.
4) Technical data
- IP address and the access logs necessary for service security and rate limiting.
- Error reports and technical fault diagnostics.
- An audit log containing send and block decisions and subscription changes, with the reason, the time and the actor.
How we obtain this data
- Directly from you when you register, set up your organization, or write to us.
- Through Google sign-in if you choose it — we receive only your name and email, and never see your password.
- Through Meta's official connection flow (Embedded Signup) when you connect a WhatsApp number.
- From Meta via webhooks — inbound messages and delivery status updates; we verify the signature of every request before accepting it.
- Automatically while you use the platform — counters and technical logs.
Purposes of processing and legal bases
| Purpose | Legal basis |
|---|---|
| Operating the platform and sending and receiving messages | Performance of the contract with you |
| Managing the account, the team and permissions | Performance of the contract |
| Billing and collecting the subscription | Performance of the contract + legal obligation (accounting records) |
| Service security, abuse prevention and rate limiting | Legitimate interest in protecting the service and its users |
| Improving the product and resolving faults | Legitimate interest |
| Service alerts (quota reached, subscription expiring, connection lost) | Performance of the contract |
| Running the AI assistant on your knowledge | Performance of the contract, once you enable the feature |
| Responding to legal requests | Legal obligation |
Wherever we rely on legitimate interest, we have balanced it against your rights, and you may object to the processing — see the your rights section.
Meta platform data — express undertakings
When you connect your number, we receive data from the WhatsApp Business Platform. We undertake the following in respect of it, and treat it as a binding part of this policy:
- We use Meta platform data solely to provide the service to the business that connected the number, and on its instructions.
- We do not sell Meta platform data, nor licence it, nor trade in it in any form.
- We do not use it for advertising targeting, nor to build advertising profiles, nor to determine eligibility for any financial or insurance product.
- We do not use it to train general or cross-customer artificial-intelligence models. Each business's knowledge remains isolated within its own organization.
- We share it only with the sub-processors listed in section I, under processing agreements binding them to the same standard.
- We delete it upon the customer's request, upon termination of the service, or when it is no longer needed — whichever comes first — unless a legal obligation to retain it exists.
- We apply the access controls and encryption described in section L, and maintain an audit log of sensitive decisions.
A business's use of WhatsApp through Watsy is also subject to Meta's policies and the WhatsApp Business Terms, which are terms between that business and Meta directly.
The AI assistant — how your knowledge is processed
The AI assistant is an optional feature that you enable yourself. When you enable it:
- The documents and text you upload are split and converted into vector representations stored within your own isolated database.
- When a question arrives from your customer, the question is sent together with the relevant passages from your own knowledge to a language-model provider to generate the reply.
- We select providers who undertake contractually not to use the content sent to them to train their models.
- One business's knowledge is never mixed with another's, and is never used to improve the service of a different customer.
- You can disable or delete any document at any time, and switch the assistant off entirely.
When the assistant finds no reliable answer in your knowledge, it is designed to stop and hand over to a human agent rather than generate an unverified answer.
Transfers outside your country
Some of our providers operate their infrastructure outside your country of residence. Where data is transferred internationally, we rely on one of the recognised mechanisms: an adequacy decision, the Standard Contractual Clauses, or your explicit consent where the law requires it. And we require from every provider a level of protection no lower than this policy commits to.
Retention periods
- Media (images, audio, video, documents): deleted automatically when your plan's retention period ends — 3, 6 or 12 months — by a scheduled daily job.
- Conversation text and customer cards: retained for as long as your account exists, and deleted when it is closed or upon your request.
- Account and organization data: retained throughout the contractual relationship.
- Technical logs: a short period sufficient for diagnostics and security, then deleted.
- The audit log and billing records: retained for the period required by accounting and legal obligations, even after the account is closed.
Expiry of your subscription does not delete your data. Only sending stops, and your conversations remain readable until you renew or request deletion.
Security
- Access tokens encrypted with AES-256-GCM at rest — never readable as plain text from the database.
- Transport encryption over TLS for every connection to the platform.
- Row-level isolation in the database preventing any organization from reaching another's data, enforced in the database itself and not in the application alone.
- Webhook signature verification against the raw body before accepting any inbound message.
- Rate limiting to repel abuse attempts.
- Strict security headers on the website and the API, and role-based permission controls.
- Temporary links for media instead of exposed permanent URLs.
- Periodic backups of the database.
No system is entirely impregnable. If a breach occurs that is likely to affect your rights, we notify you and the competent supervisory authority within the period required by the applicable law.
Your rights
You hold — subject to the law applicable to you — the following rights:
- Access: to know what we process about you and to obtain a copy of it.
- Rectification: to correct what is inaccurate or incomplete.
- Erasure: to request deletion of your data where no legitimate ground for retaining it remains.
- Restriction of processing in specified circumstances.
- Portability: to receive your data in a structured, machine-readable format.
- Objection to processing founded on legitimate interest.
- Withdrawal of consent whenever you wish, without affecting the lawfulness of processing carried out before withdrawal.
- Complaint to the competent supervisory authority in your country.
To exercise any of these rights, write to us at privacy@watsy.pro. We respond within thirty days at the latest, and we may ask for proof of your identity to protect your account. We charge no fee for reasonable requests and we do not discriminate against you for exercising your rights.
Children
Watsy is a service directed at businesses. We do not offer it to anyone under sixteen, and we do not knowingly collect their data. If we learn of an account created for a minor, we delete it. And if you are a parent or guardian and believe your child has provided us with their data, write to us and we will delete it.
Data deletion
We maintain a dedicated page explaining exactly what is deleted, how to delete it yourself from your console, how to request full deletion, and how long it takes:
Changes to this policy
We may update this policy as the service or the law changes. The date at the top of the page is the effective date of the current version. For any material change, we notify our customers by email or inside the console a reasonable period before it takes effect. Your continued use after it takes effect constitutes your acceptance.
Contacting us
- Privacy and data protection: privacy@watsy.pro
- Legal matters: legal@watsy.pro
- Technical support: support@watsy.pro
- Postal address: بغداد/ الامين الثانية/نواب الضباط/م ٧٤١/شارع ٣٨ المرقمة م ١٣/رقم الابواب١٣/٧/١
