Privacy Policy
WA Platform עמוד הבית כניסה לקונסולה

Privacy Policy

Last updated: September 28, 2026 · גרסה בעברית (הנוסח המחייב)

This Privacy Policy explains how WA Platform, Israeli registration no. 208273706 ("we", "us", "the Service") collects, uses, shares, and protects data when a business connects its WhatsApp Business account to our platform and communicates with its own customers using our AI assistant and messaging tools. Questions: support@waplatforms.com. The binding version of this policy is the Hebrew version; this English text is provided for convenience.

1. Roles - who controls the data

Each connected business ("Client") is the controller of its own customers' data. We act as a processor on the Client's behalf and process data only to provide the Service. Each Client's data is strictly isolated per tenant and is never shared between businesses.

2. Data we process

3. Why we process it (purposes)

4. How data is shared

Messages are transmitted via the WhatsApp Cloud API and Messenger/Instagram APIs operated by Meta Platforms and are encrypted in transit. Message content may be processed by our AI provider (Anthropic) solely to generate replies; media files (voice notes, images, videos, documents) a customer sends may be processed by Google (Gemini API) solely to transcribe or describe them for the reply. Card payments are processed by PayPlus, a PCI DSS compliant card processor (we never store full card numbers). Infrastructure sub-processors: MongoDB Atlas (storage) and Render (hosting). We do not sell personal data and do not use it for advertising. Client data is never used to train shared or multi-tenant AI models.

4a. Gmail / Google user data (Limited Use)

Where a Client chooses to connect its own Gmail mailbox, we access it through Google OAuth with the gmail.modify scope, solely to run the Client's customer-service inbox on the platform. Specifically, we: (1) read new incoming customer emails to show them in the Client's inbox and generate a reply; (2) send the reply in the same thread from the Client's own address; and (3) mark handled emails as read and label them, so the Client can see in Gmail what was already answered. We only read emails received after the mailbox was connected; newsletters, automated notifications and spam are filtered out and are not processed.

Our use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: Gmail data is used only to provide and improve the inbox feature for the Client who connected the mailbox; it is not used for advertising, is not sold, and is not used to train AI models. Email content is sent to Anthropic's API only to generate the reply for that customer, under terms that prohibit its use for model training. No person at WA Platform reads a Client's Gmail data except with the Client's explicit consent for support, when required for security or abuse investigation, or as required by law.

OAuth tokens are stored encrypted at rest (AES-256-GCM) and are deleted immediately when the Client disconnects the mailbox in the platform or revokes access in their Google Account (myaccount.google.com/permissions). Email content already shown in the inbox is retained as part of the Client's conversation history under section 6 and is deleted on request.

4b. Google Calendar user data (Limited Use)

Where a Client chooses to connect its business Google Calendar, we access it through Google OAuth with the calendar.readonly and calendar.events scopes, solely so that the AI assistant can schedule appointments with the Client's customers. Specifically, we: (1) query the calendar's free/busy information to offer customers only genuinely free slots within the business hours the Client configured; (2) create a "pending approval" event when a customer picks a slot, so the slot is held; and (3) update that same event to "confirmed" or delete it when the Client approves or cancels the appointment. We do not read the titles, descriptions or attendees of existing events, never show them to anyone, and never modify or delete events that were not created by the platform.

Our use of information received from Google Calendar adheres to the Google API Services User Data Policy, including the Limited Use requirements: the data is used only to provide the scheduling feature for the Client who connected the calendar; it is not used for advertising, is not sold, is not transferred to third parties and is not used to train AI models. Free/busy results are kept in memory for at most 60 seconds and are never persisted. Calendar OAuth tokens are stored encrypted at rest (AES-256-GCM), per Client, and are deleted immediately when the Client disconnects the calendar in the platform or revokes access in their Google Account. Booked appointment details (name, phone, time) are retained as part of the Client's data under section 6 and are deleted on request.

5. Access tokens & security

WhatsApp access tokens obtained through Meta Embedded Signup (or system-user tokens) are stored encrypted at rest (AES-256-GCM) and used only to send/receive and manage messaging on the connecting Client's behalf. Webhook requests are verified with an HMAC signature. Access to production data is restricted.

6. Data retention

Conversation history is retained only as needed to provide the Service and is limited per contact. Tokens and Client data are deleted upon request. Upon deauthorization, stored access tokens are revoked immediately.

After a Client's subscription ends: data remains available to the Client in read-only mode for export; approximately 90 days after the subscription ends, stored conversations, contacts and CRM data are permanently deleted. The Client receives reminder notices before deletion.

7. Your rights & choices

8. International transfers

Data may be processed in countries other than yours (including where Meta, Anthropic, MongoDB Atlas, and Render operate). We rely on appropriate safeguards for such transfers.

9. Children

The Service is for businesses and is not directed to children under 16. We do not knowingly collect data from children.

10. Changes to this policy

We may update this policy; the "Last updated" date reflects the latest version. Material changes will be communicated to Clients.

11. Contact

WA Platform · Registration no. 208273706 · WhatsApp: +972-50-4354477 · support@waplatforms.com · Israel.