Privacy Policy
Last updated: 19 June 2026
This document is a working draft. The data controller's details and the bracketed references must be completed, and the whole text should be reviewed by a legal advisor before final use.
This policy describes how Whaiz processes personal data under Regulation (EU) 2016/679 (the “GDPR”). It covers your account and Service-usage data, as well as Whaiz's role with respect to your WhatsApp conversation data.
1. Data controller
The data controller for account and Service-usage data is [Legal entity], VAT [VAT no.], with registered office at [address], email [contact email].
2. Categories of data subjects and data
Data subjects: the registered users of the Service and, limited to the data processed on the user's instructions, the subjects of the handled WhatsApp conversations (contacts and group participants).
Account data: email address, display name, password in encrypted form or sign-in provider identifier (e.g. Google), language and preferences.
Payment data: handled through Stripe. We do not store full card numbers; we process transaction metadata (amounts, outcomes, identifiers).
Usage and technical data: access and system logs, IP address, diagnostic data, needed for operation and security.
WhatsApp conversation data: contacts, groups and messages that you choose to import or handle (see section 8). None of this data is imported automatically.
3. Purposes and legal bases
Providing the Service and performing the contract (Art. 6(1)(b) GDPR): creating and managing the account, connecting WhatsApp, generating and sending the Bot's replies.
Administrative, accounting and tax obligations and payment management (Art. 6(1)(b) and 6(1)(c) GDPR).
Security, abuse prevention and improvement of the Service (Art. 6(1)(f) GDPR, legitimate interest).
Service communications and, where applicable, the data subject's consent (Art. 6(1)(a) GDPR).
4. Processing methods and retention
Data is processed with IT and electronic tools, with appropriate security measures, solely for the stated purposes and for the time strictly necessary to achieve them.
We keep account data for the duration of the relationship and, thereafter, for the time needed to meet legal obligations or to defend rights. Conversation data imported at your request is kept as long as you keep the relevant configuration or session active; when you delete the session or account, the associated data is removed or made inaccessible within the technically necessary timeframes.
5. Security measures
We adopt technical and organisational measures appropriate under Art. 32 GDPR to protect data against unauthorised access, loss or disclosure, including encryption in transit, access controls, environment segregation and infrastructure hosted on servers in the European Union.
6. Recipients and disclosure
Data may be processed, as processors or sub-processors, by providers that support us in delivering the Service: the AI-model provider (Anthropic, “Claude” models), the payment provider (Stripe), the hosting and infrastructure provider in the European Union and the email-delivery service.
Data may also be disclosed to administrative or judicial authorities in the cases provided for by law. We do not sell personal data to third parties.
7. Transfers to third countries
The application infrastructure is hosted on servers in the European Union. Any transfers to third countries (for example to the AI-model provider) take place only with adequate safeguards under Art. 44 et seq. GDPR, such as adequacy decisions or standard contractual clauses (SCCs).
8. Roles, data import and artificial intelligence
For account, payment and usage data, Whaiz acts as data controller. For the data of your contacts, groups and WhatsApp conversations, you are the controller and Whaiz acts as a processor on your behalf under the Data Processing Agreement (DPA).
For privacy, when you connect WhatsApp we do not automatically import or store any contact, group or conversation: the data WhatsApp makes available remains temporarily in volatile memory. Importing contacts and groups happens only at your explicit request; a chat's history is stored only when you enable the Bot on that specific contact or group, with your consent and only for the time window you choose.
To generate the Bot's replies, the necessary conversation content is sent to the AI-model provider, which processes it as a processor/sub-processor to deliver the result and does not use it to train its own models.
9. Data subject rights
You can exercise your rights of access, rectification, erasure, restriction, portability and objection, as well as withdraw consent where applicable, by writing to [contact email]. You also have the right to lodge a complaint with the competent data protection authority.
If you are a data subject of a conversation handled by a Service user, the primary point of contact for exercising your rights is the user who controls that processing; we may assist them as a processor.
11. Changes
We may update this policy. Material changes will be communicated through appropriate means, and the date at the top indicates the latest revision.