Privacy Policy
Effective: April 25, 2026 — Version 2.0
1. Data Controller
Wappi Holding LLC (hereinafter "Wappi", "we" or "our") is a limited liability company incorporated under the laws of the State of Wyoming, United States. Wappi acts as the data controller for personal data of platform users (account holders) and as data processor for personal data of end customers that users process through our services.
- Wappi Holding LLC
- Jurisdiction of incorporation: State of Wyoming, United States
- Data Protection Officer (DPO): [email protected]
- Website: https://wappi.chat
This Privacy Policy applies to all services, websites, applications, and communications offered by Wappi. By using our services, you acknowledge that you have read, understood, and accepted the data processing practices described herein.
2. Information We Collect
2.1 Data provided directly by the user
- Full name and surname
- Corporate or personal email address
- Phone number with international dialing code
- Billing data: tax address, tax ID as applicable, card data processed by Stripe (Wappi does not store card data)
- Business information: legal name, industry, number of employees, country of operation
- Third-party integration credentials (WhatsApp Business API, Mastershop, payment gateways), stored with AES-256-GCM encryption at rest
- Content of communications with our support team
2.2 Automatically collected data
- IP address and approximate geolocation derived therefrom
- Device identifiers, browser type, operating system, and screen resolution
- Cookie data and similar tracking technologies (see Cookie Policy)
- Platform activity logs (access logs, actions performed, timestamps)
- Processed message metadata: sender, recipient, timestamp, delivery status (not message content unless required for AI services)
- Performance and diagnostic data: response times, errors, usage metrics
2.3 Data processed through our services (end-customer data)
Wappi is an AI-powered automation and messaging platform. In the course of their activity, our users enter data about their own end customers into the platform. Such data may include:
2.3 Data processed through our services (end-customer data)
Wappi is an AI-powered automation and messaging platform. In the course of their activity, our users enter data about their own end customers into the platform. Such data may include:
- Conversation content through WhatsApp, Telegram, and other integrated channels
- End-customer identification data: name, phone number, email address
- Order history, purchase preferences, and transactional data
- Multimedia files: images, documents, voice notes sent in conversations
- Call recordings and transcriptions from AI voice agents
- Appointment scheduling and calendar data
3. Purpose and Legal Basis for Processing
Each processing activity has a specific purpose and a legal basis justifying it under Article 6 of the GDPR and applicable law:
- Service delivery: operate, maintain, and improve the SaaS platform — Legal basis: performance of contract (Art. 6(1)(b) GDPR)
- Payment processing and billing: manage subscriptions, charges, and invoicing through Stripe — Legal basis: performance of contract
- AI agent operation: process conversations, generate responses, perform semantic searches and intent analysis — Legal basis: performance of contract and user consent when enabling AI features
- Operational communications: send service notifications, security alerts, feature updates — Legal basis: legitimate interest
- Security and fraud prevention: detect unauthorized access, prevent abuse, monitor anomalous activity — Legal basis: legitimate interest (Art. 6(1)(f) GDPR)
- Regulatory compliance: respond to legal requirements, cooperate with competent authorities — Legal basis: legal obligation (Art. 6(1)(c) GDPR)
- Service improvement and internal analytics: analyze aggregated usage metrics, platform performance, and AI agent behavior — Legal basis: legitimate interest with data minimization
- Third-party platform synchronization: connect with Mastershop, n8n, and other integrations configured by the user — Legal basis: performance of contract
4. Data Sharing and Disclosure
4.1 Authorized technology sub-processors
To deliver the service, we share data with the following providers, all subject to data processing agreements (DPAs) and appropriate security measures:
- Meta Platforms Inc. (WhatsApp Cloud API) — Messaging and message delivery — US
- Twilio Inc. — Voice calls, IVR, and phone verification — US
- Stripe Inc. — Payment processing and billing — US
- Supabase Inc. — Database, authentication, file storage, and vector embeddings — US/EU
- OpenAI LLC — Language models for conversational agents (GPT-4o, GPT-4o-mini) — US
- Anthropic PBC — Language models for conversational agents (Claude Sonnet) — US
- Google LLC — Language models (Gemini), text-to-speech (Cloud TTS), calendar (Calendar API) — US
- Groq Inc. — Accelerated inference for open-source AI models (Llama, Gemma, Mistral) — US
- OpenRouter Inc. — Multi-model AI routing and access — US
- Deepgram Inc. — Real-time voice transcription (speech-to-text) — US
- ElevenLabs Inc. — High-fidelity voice synthesis (text-to-speech, optional) — US
- Cartesia AI — Streaming voice synthesis (text-to-speech, optional) — US
- Cloudflare Inc. — Web security and bot prevention (Turnstile) — US
- Mastershop — Product, order, and customer synchronization (e-commerce) — Colombia
- Calendly LLC — Appointment scheduling and availability management (optional) — US
- Twilio SendGrid — Transactional email (optional) — US
- Mailgun Technologies Inc. — Transactional email (optional) — US
- n8n GmbH — Workflow automation and event processing — Germany
- Telegram FZ-LLC — Bot messaging (optional) — United Arab Emirates
4.2 Legal authorities and requirements
We may disclose personal data when strictly necessary to: (a) comply with a legal obligation, court order, or binding administrative process; (b) protect the rights, property, or safety of Wappi, our users, or third parties; (c) detect, prevent, or address fraud, security, or technical issues; or (d) respond to an emergency threatening the life or physical integrity of a person.
4.3 International data transfers
As Wappi operates from the United States and uses sub-processors in various jurisdictions, personal data may be transferred outside the user's country of residence, including transfers from the European Economic Area (EEA), United Kingdom, and Latin America to the United States. To ensure an adequate level of protection, we implement the following safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Implementing Decision 2021/914)
- Data Processing Agreements (DPAs) with all sub-processors
- Transfer Impact Assessments (TIAs) when required by the legislation of the destination country
- Supplementary technical measures: encryption in transit (TLS 1.2+) and at rest (AES-256-GCM)
- Commitment to notify in the event of government access requests
4.4 No sale of personal data
Wappi does not sell, rent, or trade the personal data of its users or their end customers. Pursuant to Section 1798.140(ad) of the California Consumer Privacy Act (CCPA/CPRA), we expressly declare that we do not engage in the "sale" or "sharing" of personal information as defined therein.
5. Cookies and Tracking Technologies
We use cookies and similar technologies for authentication, user preferences, security, and performance analytics. We do not use advertising cookies or third-party marketing trackers. For detailed information about the cookies we use, their purposes, duration, and how to manage them, please refer to our Cookie Policy.
6. Data Retention
We retain personal data only for as long as strictly necessary to fulfill the purposes described in this policy. Specific retention criteria are:
- User account data: for the duration of the contractual relationship and up to 30 days after definitive account cancellation, unless legally required to retain
- Billing and transaction data: 7 years from the transaction date, in compliance with applicable tax and accounting obligations
- Audit logs and security records: 12 months from generation
- End-customer data (processed as processor): according to the user's (controller's) instructions, with deletion within 30 days of service termination unless legally required
- Conversations and multimedia content: for the duration of the user's account, with the possibility of early deletion upon user request
- Cookie data: according to the specific duration of each cookie (see Cookie Policy)
- Backups: maximum 90 days after deletion of the primary data
7. Information Security
We implement technical, organizational, and administrative security measures designed to protect personal data against unauthorized access, alteration, disclosure, loss, or destruction. These measures include, among others:
7. Information Security
- AES-256-GCM encryption for credentials and sensitive data stored at rest
- TLS 1.2 or higher encryption for all data in transit
- Webhook integrity verification via HMAC-SHA256
- Per-tenant data isolation through Row Level Security (RLS) at the database level
- Role-Based Access Control (RBAC) with the principle of least privilege
- Two-factor authentication (2FA) available for user accounts
- Continuous monitoring of anomalous activity and security alerts
- Periodic security assessments and vulnerability testing
- Documented security incident response plan
8. User Rights
Depending on your jurisdiction of residence, you may exercise the following rights over your personal data:
8.1 Rights under the GDPR (EEA and United Kingdom)
- Right of access: obtain confirmation of whether your data is being processed and a copy thereof (Art. 15 GDPR)
- Right to rectification: correct inaccurate or incomplete data (Art. 16 GDPR)
- Right to erasure ("right to be forgotten"): request deletion of your data when no longer necessary (Art. 17 GDPR)
- Right to restriction of processing: restrict the use of your data in certain circumstances (Art. 18 GDPR)
- Right to data portability: receive your data in a structured, commonly used, machine-readable format (Art. 20 GDPR)
- Right to object: object to processing based on legitimate interests or direct marketing (Art. 21 GDPR)
- Right not to be subject to automated decisions: not be subject to decisions based solely on automated processing with significant legal effects (Art. 22 GDPR)
- Right to lodge a complaint with the competent supervisory authority in your country of residence
8.2 Rights under CCPA/CPRA (California residents, US)
- Right to know: learn what personal information is collected, used, shared, or sold, and for what purpose
- Right to delete: request deletion of your personal information, with certain legal exceptions
- Right to correction: request correction of inaccurate personal information
- Right to opt-out of sale/sharing: Wappi does not sell or share personal information, so this right does not apply in practice
- Right to non-discrimination: not receive differential treatment for exercising your privacy rights
- Right to limit use of sensitive personal information: restrict processing of sensitive data categories
8.3 Exercising your rights
To exercise any of the above rights, send a request to [email protected] with the subject line "Privacy Rights Request", including: (a) your full name and email address associated with your account; (b) the specific right you wish to exercise; and (c) any relevant additional information. We will respond within 30 calendar days of receipt (extendable to 45 days for complex requests under CCPA, or 90 days under GDPR, with prior notification). We may request identity verification before processing the request.
9. Children's Privacy
Wappi's services are not directed at individuals under 18 years of age. We do not intentionally collect personal data from minors. If you become aware that a minor has provided personal data to Wappi without the consent of their legal guardian, please contact us at [email protected] and we will promptly delete such information. Pursuant to the Children's Online Privacy Protection Act (COPPA) of the United States, we do not collect data from children under 13 under any circumstances.
10. Third-Party Services and Integrations
Our platform integrates with third-party services (WhatsApp/Meta, Telegram, e-commerce platforms, AI providers, among others) according to the user's chosen configuration. Each third-party service operates under its own privacy policies, over which Wappi has no control or responsibility. We strongly recommend that users review the privacy policies of each service they integrate.
11. California-Specific Disclosures ("Shine the Light")
Pursuant to Section 1798.83 of the California Civil Code, California residents have the right to request information about the disclosure of personal data to third parties for direct marketing purposes. Wappi does not disclose personal data to third parties for direct marketing purposes.
12. Data Deletion Request
To request complete deletion of your personal data, send an email to [email protected] with the subject line "Data Deletion Request", including your full name and the email address associated with your account. We will process your request within 30 calendar days. Once deletion is confirmed: (a) your account data will be removed from our active systems; (b) end-customer data processed on your behalf will be deleted; (c) backups containing your data will be purged within a maximum of 90 days. Certain data may be retained where a legal obligation to preserve exists (e.g., tax records).
13. Changes to This Policy
We reserve the right to update this Privacy Policy at any time to reflect changes in our practices, legal obligations, or service features. For material changes, we will notify users at least 30 days in advance through: (a) a prominent notice on the platform; (b) email notification; and (c) update of the effective date at the beginning of this document. Continued use of the service after the effective date of the changes constitutes acceptance thereof.
14. Contact and Complaints
For any inquiry, request, or complaint related to this Privacy Policy or the processing of your personal data, please contact our data protection team: [email protected] — https://wappi.chat. If you believe that the processing of your personal data violates applicable law, you have the right to lodge a complaint with the competent data protection authority in your country of residence.
15. Google API Services User Data Disclosure
WAPPI's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Below we detail how we access, use, store, and share data obtained from Google services.
15.1 Scopes and data accessed
- Google Calendar (calendar.events, calendar.readonly): reading and writing calendar events for the AI scheduling agent functionality. We only access calendars explicitly authorized by the user.
- Google Ads (adwords): read advertising campaign data for conversation attribution and ROAS measurement in the CRM. We only access the account explicitly linked by the user.
15.2 Limited use of Google data
- We only use Google data to provide and improve user-facing features authorized by the user.
- We do not transfer Google data to third parties, except: (a) when necessary to provide the functionality requested by the user; (b) for security purposes (abuse, vulnerability investigation); (c) as required by law; or (d) with explicit user consent.
- We do not use Google data for advertising, including retargeting, personalized advertising, or interest-based advertising.
- We do not allow humans to read Google data, except: (a) with explicit user consent; (b) for security or legal compliance; or (c) when data has been aggregated and anonymized for internal operations.
- We do not use data obtained from Google APIs to train or improve AI or machine learning models, except user-specific custom models exclusively for the authorizing user.
15.3 Storage and security of Google data
Google OAuth access tokens are stored encrypted with AES-256-GCM in our database. Communications with Google APIs are conducted exclusively through encrypted channels (TLS 1.2+). Tokens are limited to the minimum scopes required for the requested functionality.
15.4 Revocation and deletion
Users can revoke WAPPI's access to their Google data at any time from Settings > Integrations in the platform, or directly from their Google account security settings (https://myaccount.google.com/permissions). Upon revocation, WAPPI deletes stored access tokens and ceases all access to the user's Google data.
View the complete Google API Services User Data Disclosure →