User Data Deletion Policy
Effective: May 5, 2026 — Version 1.0
1. Data Controller and purpose of this policy
Wappi Holding LLC (hereinafter "Wappi", "we" or "our") is a limited liability company incorporated under the laws of the State of Wyoming, United States. This User Data Deletion Policy establishes the procedures, timelines, legal bases, and safeguards that Wappi applies when a data subject or a third-party platform (Meta Platforms, Inc.) requests the deletion of personal information stored in our systems.
- Wappi Holding LLC
- Jurisdiction of incorporation: State of Wyoming, United States
- Data Protection Officer (DPO): [email protected]
- Website: https://wappi.chat
This policy is supplementary to our Privacy Policy, Data Processing Agreement (DPA), and Terms of Service. In the event of a conflict, the provision offering the greatest protection to the data subject shall prevail. This policy applies to all platform users, regardless of their jurisdiction of residence.
2. Legal basis for deletion
The right to erasure of personal data is grounded in the following legal provisions directly applicable to Wappi's operations:
- Article 17 of the General Data Protection Regulation (GDPR) of the European Union — Right to erasure ("right to be forgotten"): the data subject has the right to obtain the erasure of personal data where the data is no longer necessary for the purposes for which it was collected, where consent is withdrawn, or where the data subject objects to the processing
- Section 1798.105 of the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA) — Right to request the deletion of personal information collected by a business
- Article 18 of the Lei Geral de Protecao de Dados (LGPD) of Brazil — Right of the data subject to request the deletion of personal data processed with their consent, subject to the exceptions provided in Art. 16
- Article 8(e) of Statutory Law 1581 of 2012 of Colombia (Habeas Data) and Article 6 of Regulatory Decree 1377 of 2013 — Right of the data subject to revoke authorization and request the deletion of personal data
- Section 3.2 of the Meta Platform Data Policy — Obligation for applications using Facebook Login to provide a data deletion mechanism and a verifiable callback URL
- Protection of Personal Information Act (POPIA) of South Africa, Section 24 — Right to request the correction or deletion of personal information
3. Categories of data subject to deletion
When Wappi processes a valid data deletion request, a comprehensive deletion process is executed covering the following categories of personal information:
3.1 Data permanently deleted
- Account and authentication data: user profile, access credentials, session tokens, federated identity records (Facebook, Google), and authentication metadata
- Organizational data: organizations, stores, business configurations, roles, and permissions associated with the data subject's account
- Communications data: WhatsApp conversation history, messages, templates, labels, and interaction metadata stored on the platform
- Artificial intelligence configurations: conversational agents, automated workflows, model parameters, training history, and associated vector embeddings
- Integration credentials: access tokens and secrets for third-party integrations, encrypted with AES-256-GCM, including API keys from user-configured providers
- Media files: profile avatars, store logos, product images, attached documents, and any files uploaded to platform storage
- Commercial data: order records, product catalogs, price lists, campaigns, and CRM data (contacts, opportunities, segments)
- Billing and subscription data: plan information, subscription history, and payment methods (tax records are governed by Section 3.2)
3.2 Data subject to mandatory legal retention
In compliance with mandatory legal obligations applicable to Wappi as an entity incorporated in the United States with operations across multiple jurisdictions, the following data may be retained in anonymized or pseudonymized form for the minimum periods required by law:
- Security audit logs: retained for a minimum period of 12 months in accordance with information security best practices, Law 1273 of 2009 (Colombia), and SOC 2 Type II standards. These records do not contain identifiable personal data after anonymization
- Tax and billing records: retained for a period of 5 years pursuant to the Colombian Tax Code (Art. 632), the U.S. Internal Revenue Code (26 U.S.C. § 6001), and EU Directive 2006/112/EC. Data is limited to information strictly necessary for tax compliance
- Data required by court or administrative order: retained for the period and under the conditions established by the competent authority. Wappi will notify the data subject when legislation permits
- Aggregated and anonymized metrics: statistical data that does not allow direct or indirect identification of natural persons, in accordance with Recital 26 of the GDPR
4. Procedure and deletion timelines
Wappi has implemented an automated data deletion system that ensures timely processing of requests in compliance with the strictest applicable legal timelines:
- Requests via Meta (Facebook): automated immediate processing through a verified callback with HMAC-SHA256 signature. The system issues a unique confirmation code and provides a verifiable status URL. Maximum confirmation time: 24 hours
- Direct requests from the platform (portal.wappi.chat/settings): immediate and irreversible deletion of all personal data, with email confirmation sent to the data subject
- Requests by email ([email protected]): identity verification of the requester and processing within 15 business days (Art. 15, Law 1581 of 2012, Colombia), or 30 calendar days (Art. 12.3, GDPR), whichever is shorter
- CCPA/CPRA timeline: 45 calendar days from receipt of the verified request, with the possibility of a 45-day extension upon reasoned notice to the requester (Section 1798.105(b))
- LGPD timeline: immediate processing or within a reasonable period, in accordance with the guidelines of the Autoridade Nacional de Protecao de Dados (ANPD) of Brazil
- Backup copies: the data subject's data will be purged from backup systems within a maximum of 90 calendar days following deletion from active systems
5. Channels to request data deletion
The data subject may exercise their right to erasure through any of the following channels, all equally valid and with identical legal effect:
5.1 Through Meta (Facebook)
Access your Facebook account settings → Settings & Privacy → Settings → Apps and Websites → Locate "Wappi" → Select "Remove". Meta will automatically notify Wappi through a signed_request signed with HMAC-SHA256. The system will process the request automatically and issue a UUID confirmation code allowing the data subject to verify the deletion status at https://portal.wappi.chat/eliminacion-datos.
5.2 From the Wappi administration panel
Sign in to portal.wappi.chat → Settings → Account → Danger Zone → Delete Account. This process executes the complete and irreversible deletion of all personal data of the data subject, including organizations, stores, conversations, agent configurations, and media files. Explicit confirmation is required before execution.
5.3 By written communication
Send a formal communication to [email protected] with the subject "Data deletion request — [GDPR/CCPA/Law 1581/LGPD]" (indicate the regulation applicable to your jurisdiction). The request must include: (a) full name of the data subject; (b) email address or phone number associated with the account; (c) description of the request; (d) jurisdiction of residence of the data subject; and (e) identity document or means of identity verification. Wappi will acknowledge receipt within 48 business hours and process the request within the timelines established in Section 4.
6. Data subject rights
In addition to the right to erasure, the data subject may exercise the following complementary rights in relation to their personal data, in accordance with the legislation applicable to their jurisdiction of residence:
6.1 Rights under the GDPR (European Economic Area and United Kingdom)
- Right of access: obtain confirmation of whether personal data is being processed and a copy thereof in structured format (Art. 15 GDPR)
- Right to rectification: correct inaccurate data or complete incomplete data without undue delay (Art. 16 GDPR)
- Right to restriction of processing: restrict the use of personal data while a challenge is being resolved (Art. 18 GDPR)
- Right to data portability: receive personal data in a structured, commonly used, and machine-readable format, and transmit it to another controller (Art. 20 GDPR)
- Right to object: object to processing based on legitimate interests or for direct marketing purposes (Art. 21 GDPR)
- Right not to be subject to automated decisions: not be subject to decisions based solely on automated processing with significant legal effects (Art. 22 GDPR)
- Right to lodge a complaint with the competent supervisory authority in your country of residence
6.2 Rights under CCPA/CPRA (California residents, USA)
- Right to know: learn what personal information is collected, used, shared, or sold, the categories of sources, and the purposes of processing
- Right to correction: request the rectification of inaccurate personal information that Wappi maintains about the data subject
- Right to opt-out of sale/sharing: Wappi declares that it does not sell or share personal information with third parties for marketing purposes
- Right to non-discrimination: not receive differential treatment in pricing, quality, or level of service for exercising privacy rights
6.3 Rights under Law 1581 of 2012 (Colombia)
- Right to know, update, and rectify personal data (Art. 8, sections a and b)
- Right to request proof of the authorization granted, except for exceptions provided by law (Art. 8, section c)
- Right to file complaints with the Superintendence of Industry and Commerce (SIC) for violations of the law (Art. 8, section d)
- Right to revoke authorization and request data deletion (Art. 8, section e)
- Right to access personal data that has been subject to processing free of charge (Art. 8, section f)
7. Applicable legal and regulatory framework
This policy and the data deletion procedures implemented by Wappi are governed by and comply with the following international regulatory framework:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation — GDPR), in particular Articles 5, 12, 17, and 25
- California Consumer Privacy Act (CCPA, Cal. Civ. Code § 1798.100 et seq.), as amended by the California Privacy Rights Act (CPRA, effective January 2023)
- Lei Geral de Protecao de Dados (LGPD, Law No. 13.709/2018) of the Federative Republic of Brazil, in particular Articles 15, 16, and 18
- Statutory Law 1581 of 2012 of the Republic of Colombia (General Data Protection Regime), Regulatory Decree 1377 of 2013, and Law 1273 of 2009 (Information and data protection)
- Meta Platforms, Inc. Platform Data Policy, Section 3.2 — Data Deletion, and Facebook Login requirements
- Protection of Personal Information Act (POPIA, Act 4 of 2013) of the Republic of South Africa
- Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §§ 6501-6506) of the United States — Wappi does not collect data from children under 13 under any circumstances
8. Security measures in the deletion process
Wappi's data deletion process incorporates the following technical and organizational measures to ensure the integrity, confidentiality, and traceability of the procedure:
- Cryptographic verification: requests from Meta are validated using HMAC-SHA256 signature with timing-safe comparison to prevent timing attacks
- Immutable audit log: each request generates a record in the data_deletion_requests table with UUID confirmation code, processing status, timestamp, and operation result
- Cascading deletion: the process follows a deterministic order that ensures complete deletion of all dependent data before the deletion of the main record
- Immediate session revocation: all active sessions of the data subject are invalidated immediately at the start of the deletion process
- Multitenant isolation: PostgreSQL Row Level Security (RLS) ensures that the deletion process only affects data belonging to the requesting data subject, with no risk of cross-organization impact
9. Request status verification
Data subjects who have requested the deletion of their data through Meta (Facebook) receive a UUID confirmation code that allows them to check the processing status in real time. The verification page is available at https://portal.wappi.chat/eliminacion-datos?code=[code]. Possible statuses are: (a) "Pending": the request has been received and is queued for processing; (b) "Processing": data deletion is being executed; (c) "Completed": all personal data has been deleted from active systems; (d) "No data found": no personal data was found associated with the provided identifier; (e) "Error": an error occurred during processing and the engineering team has been notified for resolution.
10. Changes to this policy
Wappi reserves the right to update this Data Deletion Policy to reflect changes in applicable legislation, Meta policies, or internal platform procedures. In the event of material changes, users will be notified at least 30 days in advance through: (a) a prominent notice on the platform; (b) an update to the effective date at the beginning of this document. Continued use of the service after the effective date of changes constitutes acceptance thereof.
11. Contact and complaints
For data deletion requests, exercise of rights, or complaints related to this policy, please address your communication to:
- Wappi Holding LLC
- Jurisdiction: State of Wyoming, United States
- Data Protection Officer (DPO): [email protected]
For formal requests, please include in your communication: full name of the data subject, registered email or phone number, regulation under which you exercise your right, detailed description of the request, and jurisdiction of residence. Wappi will acknowledge receipt within 48 business hours and provide a substantive response within the legally established timelines.