Privacy Policy

Last updated: August 2026

Draft document. This page is a template covering the topics a WhatsApp SaaS platform like this one typically needs to address - it has not been reviewed by a lawyer and leaves placeholders (in [brackets]) for details specific to your registered business. Have it reviewed before relying on it.

This Privacy Policy explains how Slyker Tech Web Services Private Limited ("AutoWhats", "we") handles information when you use AutoWhats. It covers two kinds of data: information about you and your business account, and the WhatsApp conversation data your business processes through the Service on behalf of your own customers.

1. Information we collect

  • Account information: your name, email, phone number, and password (stored hashed, never in plain text).
  • Business information: whatever you enter about your business - description, hours, policies, knowledge base entries, and your WhatsApp Business account details.
  • Your customers' conversation data: messages, contact details, and media your business's customers send through WhatsApp, stored so your team (and your AI assistant) can respond to them.
  • Payment information: subscription payments are processed by Paynow - we store the resulting payment record (amount, status, reference) but not full card or mobile-money credentials.
  • Usage and technical data: login timestamps, IP address, and basic error/webhook logs used to keep the Service running and secure.

2. Controller and processor roles

Data protection law distinguishes who decides why and how personal data is processed (the "controller") from who processes it on that party's instructions (the "processor"). AutoWhats plays both roles, depending on whose data it is:

  • Your account and billing data (your own name, email, password, and subscription/payment records) - AutoWhats is the controller. This policy's sections on your rights (§7) apply directly to this data.
  • Your customers' conversation data (the WhatsApp messages, contacts, and media that flow through your account) - your business is the controller, since your business decides what to collect, from whom, and why. AutoWhats is a processor, handling that data only to provide the Service and only on your instructions (as configured through your dashboard).

If you operate a business on AutoWhats, this means you are responsible for having a lawful basis to collect your own customers' data (e.g. their WhatsApp opt-in) and for responding to their data protection requests about it - AutoWhats supports that by keeping data isolated and deletable per tenant, but the underlying obligation is yours as the controller of that data.

3. How we use information

  • To provide the Service: routing WhatsApp messages, generating AI replies grounded in your knowledge base, processing payments, and showing your team the dashboard.
  • To bill your subscription and communicate about your account.
  • To maintain security, investigate abuse, and enforce our Terms of Service.
  • Never to train a shared AI model on your data, and never to answer another tenant's customers with your business's information - each tenant's data is isolated.

4. Who we share information with

We use the following services (sub-processors) to operate AutoWhats, each processing only what it needs to do its job, under its own data protection terms:

  • Meta (WhatsApp Business Cloud API) - to send and receive the WhatsApp messages your business exchanges with its customers.
  • Google (Gemini API) - to generate your AI assistant's replies, grounded in the business information and knowledge base you provide.
  • Paynow - to process subscription payments and, for your own customers, in-chat payments you request through the Service.
  • [Cloud/hosting provider] - the infrastructure our servers and database run on.

Using established infrastructure and payment providers doesn't change who is responsible for your data under this policy - AutoWhats remains accountable for what happens to it, and requires each sub-processor to protect it under an appropriate data protection agreement.

We don't sell personal information, and we don't share it with anyone else except where required by law or to protect the rights and safety of AutoWhats and our users.

5. Data isolation and storage

Each business's data is stored in its own separate database schema - there is no shared table that mixes one tenant's customer conversations with another's. Account and billing information (which tenant belongs to which subscription) is stored separately from that tenant-specific conversation data. Data is hosted with reputable infrastructure providers under industry-standard physical and network security controls (see §4).

6. Data retention

  • While your account is active, we keep your data for as long as you use the Service.
  • If you cancel, we retain your data for [retention period, e.g. 30 days] in case you want to reactivate or export it, then delete it.
  • Payment records are kept longer where required for accounting/tax purposes.

7. Your rights

Depending on where you're located, you may have rights to access, correct, export, or delete the personal information we hold about you. Contact us using the details below to exercise these rights for your own account information (§2 above); requests about a business's customer data should go to that business directly, since they are the controller of it.

8. Cookies and local storage

The dashboard stores your login session (an access token) in your browser's local storage so you stay signed in - this isn't a tracking cookie and isn't shared with any third-party advertiser. We don't currently use third-party analytics or ad-tracking cookies.

9. Children's privacy

The Service is intended for business use and isn't directed at children. We don't knowingly collect account information from anyone under 18.

10. Security

We use industry-standard measures - encrypted connections, hashed passwords, per-tenant data isolation, and encrypted storage for sensitive credentials - to protect information, but no method of transmission or storage is 100% secure.

11. Changes to this policy

We may update this Privacy Policy from time to time. We'll update the "Last updated" date above, and for material changes we'll make a reasonable effort to notify account owners directly.

12. Contact

Questions about this policy or your data: [privacy contact email].