WHATSAPP & OMNICHANNEL PRIVACY POLICY
Last Updated: August 18, 2026 | Effective Date: August 18, 2026
1. Introduction & Regulatory Framework
This WhatsApp & Omnichannel Privacy Policy governs the processing of personal data, message content, identifiers, and telemetry data acquired through Arrow Reach Digital's Omnichannel Communication Platform and WhatsApp Business Cloud API infrastructure.
We operate strictly in accordance with Meta's Developer Data Policy, the WhatsApp Business Terms, and international data protection standards, including the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and Sri Lanka Personal Data Protection Act (PDPA).
2. Data We Process via WhatsApp API & Webhook Infrastructure
When business clients and end-users communicate via our WhatsApp Business API integration, webhooks, or multi-channel inbox, we collect and process the following data categories:
A. WhatsApp Identifiers & Profile Data
International Phone Numbers in E.164 format (e.g., +94XXXXXXXXX), WhatsApp User Identifiers (WAID), display names, profile photo URLs (when made publicly available by the user), and country origin codes.
B. Message Telemetry & Delivery Metadata
Message IDs (`wamid`), delivery status timestamps (sent, delivered, read, failed), template namespace parameters, error codes, HTTP webhook payload headers, and webhook verification signatures (`X-Hub-Signature-256`).
C. Message Payload & Media Attachments
Inbound and outbound text body, interactive quick-reply selections, flow responses, audio voice notes (OGG format), document attachments (PDFs, DOCX), images (JPEG/PNG), and video files transmitted during active customer conversations.
D. Opt-In & Consent Audit Records
Consent timestamps, IP addresses, opt-in source URLs, web form submission records, and opt-out suppression list logs.
3. Purpose & Legal Basis of Processing
We process data solely under the following legal bases:
- Contractual Necessity: To route WhatsApp messages via Meta Graph APIs, deliver real-time webhook notifications, and provide multi-agent customer support inboxes.
- Explicit Consent: To send authorized business-initiated transactional alerts, 2FA security OTPs, and opted-in marketing communications.
- Legal & Compliance Obligations: To maintain consent audit logs, prevent fraudulent activity, verify Meta App Review compliance, and process recipient opt-outs.
4. Strict Zero Data Selling & Monetization Guarantee
Absolute Guarantee Against Data Monetization
Arrow Reach Digital DOES NOT AND WILL NEVER sell, rent, trade, lease, broker, or monetize user phone numbers, WhatsApp message histories, recipient lists, or metadata to third-party data brokers, ad networks, or AI model trainers under any circumstances.
Data is transmitted strictly through encrypted APIs directly to Meta Platforms servers for WhatsApp message delivery, or stored temporarily on secure cloud infrastructure hosting our verified platform.
5. Technical Security & Encryption Standards
We employ enterprise-grade security controls to safeguard WhatsApp data:
- Encryption in Transit: All HTTP API requests, Meta Graph API endpoints, and webhook relays mandate TLS 1.3 / HTTPS encryption.
- Encryption at Rest: Database tables, system user access tokens, and stored media files are encrypted using AES-256 standards.
- Webhook Authentication: All incoming WhatsApp webhook payloads are authenticated using HMAC-SHA256 signatures (`X-Hub-Signature-256`) against secret keys to prevent spoofing.
- Least-Privilege RBAC: Multi-agent inbox access is locked down with Role-Based Access Control and session expiration.
6. Data Retention Schedule & Automated Erasure
In accordance with Meta Developer Data Policies, we enforce strict data retention windows:
- System Telemetry & Logs: Raw webhook logs and API delivery receipts are retained for 30 to 90 days for operational debugging before automated purging.
- Media Files: Cached images, audio notes, and PDFs transmitted via WhatsApp are deleted automatically after 30 days.
- Opt-Out Suppression Records: Unsubscribe lists (phone numbers) are maintained permanently to prevent accidental re-contacting.
7. Data Subject Rights & Deletion Protocol (GDPR)
Every end-user and client has the right to:
- Request access to all WhatsApp profile and messaging data linked to their phone number.
- Request immediate data erasure ("Right to be Forgotten") across our active databases and backup logs.
- Withdraw consent for WhatsApp communications at any time by replying
STOPor contacting our privacy desk.
8. WhatsApp Data Privacy Office & Contact Information
To submit data subject requests, inquire about Meta Developer Data Policy compliance, or request permanent data deletion, please contact our dedicated Data Protection Desk:
WhatsApp Data Protection & Privacy Desk
whatsapp@arrowreachdigital.com