WhatsApp Connector

Privacy policy

Last updated: 2 October 2026. This policy explains how AS2 Technologies (Private) Limited (“AS2”, “we”) handles data in WhatsApp Connector. Draft — to be reviewed by a lawyer before launch.

Who is responsible

Our clients (businesses) decide which customers they message and why; for that customer data they are the controller and AS2 is the processor. For client account data (names, emails, billing), AS2 is the controller.

What we process

  • Client account data: name, email, company name, team members, invoices.
  • Customer data the client uploads or receives: phone numbers, names, custom fields, opt-in records, message content and media.
  • Data from Meta’s WhatsApp Business Platform: WhatsApp Business Account and phone number identifiers, message delivery statuses, quality ratings and an access token to send messages on the client’s behalf.
  • Technical logs: IP addresses, webhook logs (kept 30 days).

Why

To provide the service: sending and receiving WhatsApp messages for the client, showing them in the inbox, running broadcasts and integrations, billing, security and support. We do not sell data and do not use message content for advertising.

Retention

Messages are kept for 12 months by default (configurable), webhook logs for 30 days. When a client deletes a contact, a number’s history or the account, data and media are permanently deleted within 30 days.

Sharing

Message content is sent to Meta Platforms to deliver WhatsApp messages. We use hosting and storage providers bound by confidentiality. We disclose data when required by law.

Security

HTTPS everywhere; access tokens and secrets are encrypted at rest (AES-256); each client’s data is isolated; access is logged.

Your rights

Customers of our clients should contact the business that messaged them. Clients can export or delete their data from the dashboard. For anything else, including requests under GDPR or Pakistan’s data protection law, email privacy@as2techs.com. See also data deletion.