Privacy Policy
This Privacy Policy explains how whacl handles personal data. whacl is a software platform operated by HEBER HOST ("we", "us"), based in Morocco. It lets a business connect its own WhatsApp Business, Instagram, Facebook Page, or TikTok Business account to an AI assistant that replies to that business's customers, together with a dashboard for reviewing those conversations.
1. Two different roles — please read this first
whacl handles two kinds of personal data, in two different capacities:
- Business account data — the details of the businesses that sign up to use whacl, and of the staff who log into the dashboard. For this data we are the data controller.
- Customer conversation data — the messages sent by the members of the public who contact one of those businesses on its own WhatsApp, Instagram, or Facebook account. For this data the business you messaged is the data controller, and whacl is a data processor acting on that business's instructions. That business decides what the assistant says, how long conversations are kept, and who on its team can read them.
If you are a member of the public who messaged a business and you want your data corrected or deleted, the fastest route is to ask that business directly. You can also contact us (Section 10) and we will pass the request to the business responsible and assist it in acting on the request.
2. What data we collect
From businesses using whacl:
- Account details — business name, workspace name, contact email address, and a securely hashed login password;
- Connection details for the channels the business chooses to connect — WhatsApp Business Account and phone number IDs, Instagram or Facebook Page IDs, TikTok Business Account IDs, ad account IDs, and the access tokens Meta or TikTok issue for them;
- Content the business itself supplies to configure the assistant — its business profile, product and pricing information, and the names, phone numbers and coverage areas of its own sales staff;
- Security and diagnostic records — login times, IP addresses used to sign in, and administrative actions taken in the dashboard.
From members of the public who message a connected business:
- Your phone number on WhatsApp, or the account-scoped identifier Meta or TikTok provides on Instagram, Facebook Messenger, or TikTok Direct Messages;
- Your profile name, as provided by the Meta or TikTok platform you messaged from;
- The content of the messages exchanged between you and the business, including images and other media you send;
- Timestamps and message delivery status;
- If you started the conversation by tapping an advertisement, the reference to that advertisement, so the business knows which of its ads you responded to.
We do not collect payment card information, location data, contact lists, or anything else from your device beyond what the Meta or TikTok platform transmits together with your message.
3. How the data is used
- To generate replies automatically: an incoming message is processed by an artificial intelligence assistant, which writes a reply on behalf of the business;
- To keep a conversation history, so the business can follow up and so a member of its staff can take over from the assistant at any point;
- To produce a short automatic summary of each conversation for the business — what the enquiry is about, which city it came from, which product was discussed, and how likely it looks to convert. These are inferences drawn from the conversation itself, shown only to the business you messaged, and never used to build a cross-business profile of you or shared with advertisers;
- To let the business send service or promotional messages through WhatsApp's approved template system — only to people who have previously contacted it, and always with a way to opt out (see Section 8);
- To show the business aggregate performance figures for its own advertisements, read from Meta's advertising reporting. These figures are counts and totals, not personal data;
- To operate and secure the platform — delivery status, error logs, abuse prevention, and billing the business for its usage.
We do not sell personal data, use it to build advertising profiles, share it with data brokers, or use one business's conversations to serve another business.
4. AI processing
To generate automatic replies and the conversation summaries described above, message content is transmitted to Anthropic, PBC (United States), the provider of the Claude AI model, acting as a subprocessor on our behalf. Content is sent solely to produce that reply or summary. It is handled under Anthropic's commercial data protection terms and is not used to train AI models.
5. Who has access to the data (subprocessors)
| Provider | Role | Location |
|---|---|---|
| Meta Platforms (WhatsApp, Instagram, Messenger) | Messaging platform — transmits messages between you and the business | Per Meta's own privacy policy |
| TikTok (TikTok for Business) | Messaging platform — transmits Direct Messages between you and the business | Per TikTok's own privacy policy |
| HEBER HOST | Server hosting — runs the platform and stores the conversation databases | Morocco |
| Anthropic, PBC | AI processing — generates automatic replies and conversation summaries | United States |
Each business's conversation data is stored in its own separate database, isolated from every other business on the platform. Within our own organisation, access is limited to the small number of personnel who need it to operate and support the service. WhatsApp, Instagram, Messenger, and TikTok are themselves governed by their own providers' terms and privacy policies — Meta's and TikTok's — which apply to your use of those apps independently of this service.
6. Data received from Meta and TikTok
Data we receive through Meta's and TikTok's APIs is used only to provide the service to the business that connected its own account, and for no other purpose. We do not sell it, transfer it to data brokers, use it for advertising or profiling, or combine it across businesses. We handle it in accordance with Meta's Platform Terms and Developer Policies and TikTok's Developer Terms and Policies. When a business disconnects a channel or closes its workspace, the data received for that channel is deleted as described in Section 7. Instagram users can request deletion of data held about them through our data deletion request page.
7. Data retention and deletion
Conversation history is retained while the business's workspace is active, because the business relies on it to follow up on enquiries. When a workspace is closed, its database — including all conversation history — is deleted within 30 days. Individual deletion requests are actioned within 30 days of being verified. Security and billing records may be kept longer where we are legally required to retain them.
8. International data transfers
Data is stored on servers in Morocco (HEBER HOST), and message content is transferred to the United States (Anthropic) to generate replies and summaries. Where required, these transfers are covered by appropriate contractual safeguards with the respective providers.
9. Your rights
Depending on where you live, you have the right to:
- Access the personal data held about you;
- Correct inaccurate data;
- Delete your data ("right to be forgotten");
- Object to or restrict processing;
- Opt out of promotional messages — reply "STOP" to any message from the business, or contact us, and your number will be excluded from future campaigns;
- Lodge a complaint with your data protection authority. In Morocco this is the CNDP (cndp.ma); if you are in the EU or UK, your local supervisory authority.
As explained in Section 1, for conversation data these rights are exercised against the business you messaged, which decides how that data is used. We will always help that business respond to you, and will act directly where the business does not.
10. Security
Data is stored in access-controlled databases on secured servers, one database per business. Dashboard access is password-protected, rate-limited against repeated login attempts, and scoped so that a user of one business can never reach another business's data. Traffic to the platform is served over HTTPS, and webhook traffic from Meta is verified with cryptographic signatures before it is accepted. No system is perfectly secure, but we take these measures seriously and review them as the platform grows.
11. Children
whacl is a tool for businesses and is not directed at children under 16. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy from time to time. The "Last updated" date above reflects the most recent revision. Material changes will be reflected on this page, and businesses using whacl will be notified.
13. Contact
Operator: HEBER HOST (Morocco), operator of the whacl platform.
Email: info@whacl.com
Website: whacl.com