Privacy Policy
Last Updated: August 2026 • Effective for all WhatZAI Platform Tenants and Connected WhatsApp Integrations.
Our Core Privacy Pledge: Zero Data Selling & Private AI Models
WhatZAI operates with strict Tenant Isolation. We NEVER sell, rent, monetize, or share your business data, customer phone numbers, or WhatsApp conversation histories with third-party advertising networks. Furthermore, your proprietary documents and knowledge base files are never used to train public foundation AI models.
Information We Collect
To deliver high-precision autonomous WhatsApp AI sales agents, WhatZAI collects only the necessary information required for platform operations:
- Account Credentials: Business name, authorized administrator email, hashed passwords, and contact metadata.
- Tenant Knowledge Base Assets: Uploaded PDFs, brochures, pricing sheets, CSVs, FAQs, and custom business prompt directives.
- WhatsApp Cloud API Payloads: Inbound customer phone numbers, message text, media messages, message delivery statuses, and interactive quick-reply responses routed via Meta's official webhooks.
- Integrated CRM / E-Commerce Tokens: Encrypted API credentials and OAuth tokens for Shopify, Zoho, and native custom Webhooks configured by the tenant.
How We Use WhatsApp & AI Data
Data collected through WhatZAI is processed solely to fulfill automated sales workflows on behalf of the business tenant:
- Autonomous Customer Responses: Converting customer questions into semantic vector queries (`pgvector`) to extract accurate facts from the tenant's private knowledge base.
- Commercial Insights & ROI Attribution: Generating executive reports (unpitched demand trends, lead qualification metrics, and conversation velocity) accessible only to the authenticated tenant admin.
- Human Agent Takeover: Rendering live chat threads in the unified SaaS inbox so staff can monitor, pause AI, or take over customer dialogues.
Meta WhatsApp Cloud API Compliance
WhatZAI integrates strictly via Meta's official WhatsApp Business Cloud API. We strictly enforce:
- Compliance with Meta's Business Messaging and Commerce Policies.
- Opt-in verification and opt-out stop triggers for marketing broadcast campaigns.
- End-to-transit HTTPS/TLS 1.3 encryption on all Meta webhook payloads.
Data Security & Storage Architecture
We implement modern enterprise security standards across our infrastructure:
Strict Multi-Tenancy
Database queries and pgvector semantic embeddings are strictly partitioned by tenant ID, preventing cross-tenant leakage.
Encrypted Storage
All API tokens, webhook secrets, and customer data are encrypted at rest with industry-standard cryptographic keys.
Data Retention & Deletion Rights
Business owners retain full sovereignty over their data. You have the permanent right to:
- Delete specific knowledge base documents or individual chat conversation logs at any time from your dashboard.
- Request a complete workspace data purge by contacting our compliance desk at info@whatzai.in. All vector embeddings, files, and customer logs will be permanently deleted within 14 business days.
Contact Our Privacy & Compliance Team
For any questions regarding this Privacy Policy, GDPR/DPDP inquiries, or enterprise security audits, please reach out to: