Data protection
GDPR & data protection
whatsappx.si is GDPR-ready: your workspace runs on servers in the EU, and owners, admins and every user can export, delete and limit their data themselves in the app.
Data location
Hosted in the EU (Helsinki, Finland)
The whatsappx.si application servers, database and stored files run on Hetzner servers in Helsinki, Finland, in the EU.
Database and app servers
Accounts, workspaces, conversations, messages and contacts are stored in a database on Hetzner in Helsinki, Finland.
WhatsApp sessions and media
The linked-device sessions of your WhatsApp numbers and the media files they receive are stored on the same servers.
Other providers
Some features use providers that may process data outside the EU, such as email delivery, payments and AI. They are listed under Sub-processors below.
HTTPS everywhere
All traffic to the website, app and API is encrypted in transit with HTTPS (TLS).
Hashed passwords
Passwords are at least 12 characters and stored only as bcrypt hashes.
Hashed tokens and API keys
Session and password-reset tokens are stored only as hashes. API keys are stored only as SHA-256 hashes and shown once.
Encrypted Meta credentials
Access tokens and app secrets for Meta’s WhatsApp Business Platform are encrypted at rest with AES-256-GCM.
Role-based access
Owner, admin and agent roles. Agents can be limited to the chats assigned to them, and each workspace’s data is kept separate.
Security audit log
Records who sent, exported or changed what. Entries cannot be edited, cannot be deleted while younger than 30 days, and are kept 180 days by default.
Sign-in history and alerts
See your sign-ins and active sessions. Email alerts for a sign-in from a new device or country, repeated failed sign-ins, unusually large data access, a new admin, a new API key, and an API key used from a new IP address.
API key IP allowlists
Limit an API key to the IP addresses you list.
Leaked-key blocking
Automatic blocking of leaked API keys is being added.
Your rights
Export and delete your data in the app
You do not have to email us to get a copy of your data or to delete it: sign in and open Settings → Privacy & data.
Export all workspace data
Owners and admins
- Open Settings → Privacy & data.
- Start a workspace export, and choose whether to include media files.
- We build the ZIP file in the background and email you when it is ready.
- Download it while signed in. The link works for 24 hours.
The ZIP holds conversations, messages (JSON and CSV), contacts, members, settings, scheduled messages and the last 180 days of the security audit log. Up to 2 exports per day, one at a time.
Export my personal data
Every user
- Open Settings → Privacy & data.
- Start a personal data export.
- We email you when it is ready; download it while signed in within 24 hours.
It holds your profile, your workspace memberships, your sign-in history, your sessions and the messages you sent through the app.
Delete a workspace
The workspace owner
- Open Settings → Privacy & data and choose to delete the workspace.
- Confirm with your password. If you only sign in with Google, you must have signed in within the last 15 minutes.
- For 14 days you can cancel. We email the owners and admins when the deletion is scheduled and 1 day before it happens.
- Then messages, conversations, contacts, media files, the WhatsApp session (the linked number is logged out first), scheduled messages, API keys and uploaded files are permanently deleted.
Kept: billing and invoice records, which the law requires us to keep, and security audit entries until their normal retention ends.
Delete my account
Every user
- Open Settings → Privacy & data and choose to delete your account.
- If you are the only owner of a workspace, first delete that workspace or make someone else its owner.
- You are removed from all your workspaces and your sessions are deleted.
Your name and email address are replaced in the records we must keep. Sign-in records are kept 30 days for security, then deleted.
If you messaged a business that uses whatsappx.si, that business decides what it keeps about you, so please contact it first. For anything you cannot do in the app, use the Contact page.
Retention
How long data is kept
Each workspace can turn on “Automatically delete messages and files older than N days” in Settings → Privacy & data, with a choice of 30, 90, 180 or 365 days. It is off by default and runs every night.
Messages and files
Kept until you delete them or the workspace, or until your automatic deletion setting removes them.
Deleted workspaces
Can be cancelled for 14 days, then permanently deleted.
Security logs
The security audit log, sign-in history and security alerts are kept 180 days by default.
Data exports
The download link works for 24 hours.
AI processing
AI features are optional
Each workspace has the setting “Allow AI features (sends message text to Google Gemini)”. It is on by default and can be turned off for the workspace.
When it is on
The AI Assistant, scheduled AI messages and the marketing assistant send the message text they work with to Google Gemini. Voice notes for the AI Assistant are transcribed by Deepgram.
When it is off
No message content from the workspace is sent to Google Gemini or Deepgram. The AI Assistant, scheduled AI messages and the marketing assistant stop.
No AI involved
Keyword automations and the knowledge base never use AI, whatever the setting.
Sub-processors
Who processes data for us
Hetzner is the only provider whose region we state. Every other provider may process data outside the EU (see the provider's terms).
| Provider | Purpose | Data | Region | When |
|---|---|---|---|---|
| Hetzner | Hosting: application servers, database and stored files | All workspace and account data | EU (Helsinki, Finland) | No extra condition |
| Google (Gemini API) | AI features: AI Assistant replies, scheduled AI messages, marketing assistant | The message text and context the AI feature works with | May process data outside the EU (see the provider's terms) | Only while “Allow AI features” is on for the workspace |
| Deepgram | Voice-note transcription for the AI Assistant | Voice notes the owner sends the assistant | May process data outside the EU (see the provider's terms) | Only while “Allow AI features” is on for the workspace |
| SendGrid | Email delivery (sign-in, security, billing and export emails) | Email address, name and the email’s content | May process data outside the EU (see the provider's terms) | No extra condition |
| Stripe | Card payments (outside India) | Billing name, email and payment details | May process data outside the EU (see the provider's terms) | No extra condition |
| Razorpay | Payments in India | Billing name, email, phone and payment details | May process data outside the EU (see the provider's terms) | No extra condition |
| Meta (WhatsApp Business Platform) | Numbers connected through Meta’s official WhatsApp Business Platform | Messages and contacts of those numbers | May process data outside the EU (see the provider's terms) | Only for numbers connected through the official platform |
| Google (Sign in with Google) | Optional sign-in | Name and email address | May process data outside the EU (see the provider's terms) | Only if you choose “Continue with Google” |
| Ravan Workspace (workspace.ravan.ai) | In-app support chat | User ID, name, email and what you write in the chat | May process data outside the EU (see the provider's terms) | No extra condition |
| Meta (Pixel and Conversions API) | Advertising measurement on the public website | Pages viewed, sign-up and payment events, hashed email | May process data outside the EU (see the provider's terms) | Only after you accept cookies; never inside the app |
Agreements and incidents
Data Processing Agreement
A Data Processing Agreement is available on request via the Contact page.
If there is a data breach
If a breach affects your data, we notify affected customers without undue delay.
Frequently asked questions
Where is my data stored?
Does whatsappx.si hold a GDPR certification?
Is a Data Processing Agreement available?
How do I export or delete our data?
Can we stop message text being sent to AI providers?
Are stored messages encrypted?
What happens to my WhatsApp number when a workspace is deleted?
Bring your team into one WhatsApp inbox
Create a workspace, connect your WhatsApp by QR code, and invite your teammates.