Who we are
Digiboffins ("we", "us") provides a platform that lets businesses manage WhatsApp Business conversations with their own customers. This policy explains what data we handle and why. For any questions, contact info@digiboffins.com.
Our role
Businesses that use our platform decide what messages to send and to whom. For that message content we act as a processor on their behalf; they are the controller and their own privacy policy governs their use. We are the controller for the account data of the users who log in to our platform.
What we collect
- Account data — name, email address, and password hash for each user of the platform, plus the workspace they belong to and their role.
- WhatsApp connection data — the WhatsApp Business Account ID, business phone number ID, and access token issued by Meta when a business connects its account. Access tokens are encrypted at rest.
- Message data — messages sent and received through connected WhatsApp Business numbers, including the contact's phone number, profile name, message content, delivery status, and timestamps.
- Operational data — audit logs of significant actions, error reports, and technical logs used to run and secure the service.
How we use it
- To deliver messages to and from WhatsApp via Meta's WhatsApp Business Platform.
- To display conversations, contacts, and templates inside the platform.
- To authenticate users and enforce access controls between workspaces.
- To measure usage against plan limits and to bill for subscriptions.
- To detect, investigate, and fix faults and abuse.
We do not sell personal data, and we do not use message content for advertising.
Sharing
We share data only with providers needed to operate the service:
- Meta Platforms — to send and receive WhatsApp messages.
- Our hosting and database providers — to store and serve the application.
- Our payment processor — to handle subscription billing.
- Error monitoring — to capture diagnostics when something fails.
We may also disclose data where required by law.
Separation between businesses
Every record is tagged with the workspace that owns it, and access is checked on every request. One business cannot read another business's conversations, contacts, or templates.
Retention
We keep message and contact data for as long as the business's account is active, because those are the business's own records of its customer conversations. When an account is closed, its data is deleted within 90 days, except where we must retain records to meet a legal or accounting obligation.
Some data is removed on a shorter, automatic schedule:
- Raw delivery data — the unprocessed copy of each message as it arrives from WhatsApp, which we keep briefly to diagnose delivery problems — is erased after 30 days. The message itself remains in the conversation; only the duplicate raw copy is removed.
- Delivery records — the sent, delivered and read timestamps behind each message — are removed after 90 days.
- Backups roll off within 7 days. Deleted data is gone from those too, and we do not restore deleted data from a backup.
We keep records of significant actions taken in the platform — who changed what, and when — for security and dispute resolution. These identify the account holder who acted, not the content of any message.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, or to object to certain processing. If you were messaged by a business using our platform, please contact that business first, as they control those conversations. You can also write to us at info@digiboffins.com and we will assist.
Deleting your data
To request deletion of data we hold about you, email info@digiboffins.com with the subject "Data deletion request" and the phone number or email address concerned. We will confirm the request and complete it within 30 days.
Full instructions — including what we delete, what we are required to keep, and what to do if you do not know which business holds your data — are on our Data Deletion Instructions page.
Security
Access tokens and other credentials are encrypted at rest. Traffic is served over HTTPS. Access to production systems is limited to staff who need it. No system is perfectly secure, but we work to protect data in line with industry practice.
Changes
If we make a material change to this policy we will update the date above and, where appropriate, notify account administrators.