Legal

Privacy Policy

How Wassly collects, uses, stores, shares, and protects personal data when businesses connect WhatsApp and other messaging channels to the Wassly platform.

Effective date: 7 June 2026 · Last updated: 7 June 2026

01About Wassly

Wassly (“Wassly,” “the platform,” “we,” “us,” or “our”) is a customer-engagement and messaging platform operated at wassly.com. Wassly enables businesses to manage conversations with their customers across WhatsApp and other channels, including automation, team inboxes, templates, and campaign tools.

Wassly is a limited liability company registered in the Arab Republic of Egypt under Commercial Registration number 291759 (Cairo Investment Commercial Registry Office), with its registered address at Building 15, Group 73, Madinaty, First Settlement, New Cairo, Cairo Governorate, Egypt. This Privacy Policy governs personal data processed through the Wassly platform and the wassly.com website.

Wassly operates on the WhatsApp Business Platform as an approved Meta Tech Provider. Our processing of data obtained through WhatsApp and other Meta products is carried out in accordance with the Meta Platform Terms, the Meta Developer Policies, the WhatsApp Business Messaging Policy, and the WhatsApp Business Solution Terms, in addition to applicable data protection law.

By accessing wassly.com or using the platform, you acknowledge that you have read and understood this Privacy Policy.

02Our role: controller vs. processor

Our role under data protection law depends on how data flows through Wassly.

When Wassly is a data controller

We act as a controller (determining the purposes and means of processing) for:

  • Personal data of visitors to the wassly.com website
  • Account, authentication, and billing data of business customers who subscribe to Wassly
  • Technical and security log data necessary to operate the platform
  • Marketing and business-development contacts

When Wassly is a data processor

We act as a processor (processing on behalf of our business customers, who are the controllers) for end-user conversation data, contacts, media, and message content that businesses route through Wassly — for example, messages exchanged between a business and a consumer who contacts it on WhatsApp.

When we act as a processor, the business customer is the controller responsible for determining lawful bases, obtaining consents, and responding to data-subject requests. We process such data only on the documented instructions of that customer and under our Data Processing Agreement with them. End users whose data is processed through Wassly should contact the business they messaged (the controller); we will support those requests through the customer.

03Personal data we collect

Data you provide directly

  • Account and contact details — name, business name, email address, phone number, job title, country, preferred language
  • Authentication data — passwords (stored hashed), two-factor credentials, API keys and access tokens
  • Billing data — billing address, tax registration numbers, payment method details (handled by third-party processors; we do not store full card numbers)
  • Content you submit — message templates, contact lists you upload, messages you send, media and files you attach, and platform configuration
  • Support communications — content of messages to our support team, feedback, and survey responses

Data we collect automatically

  • Technical data — IP address, device and browser type, operating system, language, time zone
  • Usage data — features used, clicks, session duration, referring URLs, error and delivery logs
  • Cookies — session, security, and preference cookies used by the website and platform

Data processed on behalf of customers

When customers use Wassly, they upload or route data about their own end users — names, phone numbers, message content, media, and similar. We process this data only as instructed by the customer.

04WhatsApp and Meta platform data

When a business connects a WhatsApp Business Account to Wassly through Meta’s Embedded Signup, we receive and process data from the WhatsApp Business Platform (Cloud API) that is necessary to operate the integration, including:

  • WhatsApp Business Account (WABA) identifiers and business phone number identifiers
  • Display name, business profile information, and quality/messaging-limit status
  • Message content, media attachments, and interactive message payloads exchanged between the business and its customers
  • Delivery, read, and status receipts
  • Contact phone numbers and WhatsApp profile names of end users who message the business
  • Template content, status, and category information

We process this data to deliver the messaging features the business has subscribed to. We do not use the content of WhatsApp messages for our own advertising or for training machine-learning models, and we do not sell this data. The WhatsApp and Meta platform terms continue to apply to data on those platforms; this Privacy Policy applies to our processing within Wassly.

05Coexistence (WhatsApp Business app) data sync

Wassly supports Coexistence, which lets a business connect a number that is already in use on the WhatsApp Business app to the WhatsApp Business Platform, so the number can be used in both at the same time. When a business chooses this option and authorizes it during onboarding, Wassly may, with the business’s consent:

  • Synchronize contacts from the connected WhatsApp Business app so they appear in the Wassly inbox
  • Synchronize message history — up to the most recent 180 days of one-to-one chats — where the business explicitly agrees to share it
  • Mirror ongoing messages sent or received from the WhatsApp Business app after onboarding, so conversations stay in sync between the app and Wassly
Consent & control. History synchronization only occurs if the business affirmatively agrees during the connection flow. Group chats are not synchronized. A business can disconnect a number from the Business Platform at any time from the WhatsApp Business app (Settings → Account → Business Platform → Disconnect), after which Wassly stops receiving new data for that number.

Synchronized contacts and message history are processed by Wassly as a processor on behalf of the business customer, under the same terms described in Section 2.

06How we use personal data

  • To provide the platform — create and maintain accounts, authenticate users, route and store messages, deliver subscribed features
  • To operate our infrastructure — monitor performance, diagnose issues, provide support, maintain security, and prevent fraud and abuse
  • To bill and collect payments — process subscription fees, issue invoices, meet tax obligations
  • To communicate — send service notifications and administrative messages, and, with consent where required, marketing about our products
  • To improve the platform — analyze usage to identify improvements and generate aggregated, anonymized statistics
  • To comply with law — meet legal obligations and respond to lawful requests from competent authorities

We do not sell personal data, and we do not use customer message content for our own marketing, advertising, or model-training purposes.

07Legal bases for processing

Where the EU/UK GDPR applies, we rely on: contract performance (Art. 6(1)(b)) to deliver the platform; legitimate interests (Art. 6(1)(f)) to secure our infrastructure, prevent abuse, and improve the platform; consent (Art. 6(1)(a)) for marketing and non-essential cookies; and legal obligation (Art. 6(1)(c)) for tax, accounting, and anti-fraud requirements.

Where the Egyptian Personal Data Protection Law (Law No. 151 of 2020) applies, we process personal data on lawful grounds recognized under that law, including consent, performance of a contract, compliance with a legal obligation, and the legitimate interests of the controller where not overridden by the rights of the data subject.

You may withdraw consent at any time where consent is the basis for processing; withdrawal does not affect processing carried out before withdrawal.

08How we share personal data

Service providers (sub-processors)

We use trusted providers to operate the platform, bound by contractual data-protection obligations and processing data only for purposes we specify, including: cloud hosting (e.g. Google Cloud Platform, Amazon Web Services), content delivery and security (e.g. Cloudflare), messaging platform providers (Meta Platforms, Inc.), email delivery, payment processors, and analytics/error-monitoring tools. A current sub-processor list is available to customers on request.

At your direction

When you invite team members, share content, or route messages, the relevant personal data is shared as needed to fulfil your request.

Legal reasons and business transfers

We may disclose data where required by law, court order, or lawful authority request, or to protect our rights and the safety of any person. If Wassly is involved in a merger, acquisition, or asset sale, data may transfer as part of that transaction, with prior notice where required.

We do not sell personal data and do not share it with third parties for their own independent marketing.

09International data transfers

Wassly may store and process personal data in data centers located in Egypt, the GCC region, the European Union, and other jurisdictions, depending on configuration and operational requirements. Where data is transferred across borders, we rely on appropriate safeguards — for GDPR transfers, the European Commission’s Standard Contractual Clauses or an adequacy decision where applicable; for transfers subject to Egyptian Law 151/2020, the lawful transfer conditions recognized under that law. Customers may request information about the regions in which their data is processed.

10Data retention

  • Account and customer data — for the duration of the subscription and a reasonable period thereafter (typically up to 24 months) for disputes, audits, and legal obligations
  • Billing and tax records — for the period required by applicable tax law (generally five years in Egypt)
  • Customer content, including synced WhatsApp contacts and history — per the customer’s configuration and our Data Processing Agreement; on termination we delete or return such content within a commercially reasonable period, typically ninety (90) days, unless retention is legally required
  • Security and system logs — typically up to 12 months
  • Support communications — up to 36 months after last contact

We may retain anonymized or aggregated data, which cannot reasonably identify you, for longer periods.

11Your rights

Subject to applicable law, you may have the right to access, rectify, erase, restrict, or object to processing of your personal data; to data portability; to withdraw consent; and to lodge a complaint with a competent supervisory authority.

To exercise these rights, contact us using the details in Section 15. We may need to verify your identity before acting. If your data is processed by Wassly on behalf of a business customer (for example, you messaged a business that uses Wassly), we will forward your request to that customer, who is the controller responsible for responding; you may also contact that business directly.

12Data deletion

Business customers can delete content within the platform and may request deletion or return of their data on termination, as described in Section 10. To request deletion of personal data we hold about you, contact us at the address in Section 15 or use the request mechanism at wassly.com/data-deletion. Where Wassly acts only as a processor, deletion requests for end-user data are fulfilled through the business customer who controls that data.

13Security

We maintain technical and organizational measures designed to protect personal data, including encryption in transit (TLS 1.2 or higher), encryption of sensitive data at rest where appropriate, role-based access controls and least-privilege principles, network segmentation, security patching and vulnerability management, and logging, monitoring, and incident-response procedures. No method of transmission or storage is completely secure; if we become aware of a personal data breach affecting you, we will notify you as required by applicable law.

14Children

Wassly is not directed at children under the age of 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

15Contact us

For questions, requests, or complaints about this Privacy Policy or our processing of your personal data, contact:

Wassly
Attn: Privacy Officer
Commercial Registration No. 291759
Building 15, Group 73, Madinaty
First Settlement, New Cairo
Cairo Governorate, Egypt
Email: [email protected]

16Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the “Last updated” date above and, where required by law, provide additional notice. Your continued use of Wassly after the effective date of a revised Privacy Policy constitutes acceptance of the changes, to the extent permitted by applicable law.

This Privacy Policy was prepared in English. An Arabic translation may be provided for convenience; in the event of any conflict, the English version prevails unless applicable law requires otherwise.

© 2026 Wassly · CR 291759 · Built in Cairo