Legal
Privacy Policy
Last updated: September 27, 2026
DeskBees WAO ("we", "us") provides a WhatsApp Business Platform for teams. This policy explains what data we collect, why, and the choices you have. By using the platform you agree to the practices below.
1. Data we collect
- Account data — name, work email, password hash, timezone and authentication settings (including two-factor secrets).
- Workspace data — organisation names, member roles, WhatsApp connection settings (App ID, phone number ID, WABA ID and API tokens you provide).
- Message content — messages, media, templates and delivery receipts processed through your connected WhatsApp number, stored so your team can serve customers.
- CRM data you import — contacts, labels, notes and follow-ups you create or upload.
- Usage data — pages visited, actions taken, device and log data used for security and product improvement.
- Website analytics — aggregated visits to our marketing pages.
2. How we use it
- Operate your workspace: routing messages, running automations, storing history.
- Authenticate you and enforce workspace roles and permissions.
- Send service notices (deliverability issues, security alerts, billing).
- Improve reliability and detect abuse. We do not sell your data or your customers' data.
3. WhatsApp and Meta
Messages flow through Meta's WhatsApp Business Platform under your own Meta app credentials and are additionally subject to Meta's terms and data policy. End customers' data is processed on your behalf as a processor; you remain responsible for having a lawful basis (consent or legitimate interest) to message them, including opt-ins and honouring STOP requests.
4. Sharing
We share data only with infrastructure subprocessors (hosting, email delivery, payment processing) under contract, and when required by law. A current subprocessor list is available on request at support@deskbees.com.
5. Retention and deletion
- Workspace data is kept while your account is active and for 30 days after closure for recovery, then deleted.
- Clearing a chat or deleting a conversation removes its messages from our systems (Meta-side copies follow Meta's retention).
- Backups age out within 90 days.
6. Security
Encryption in transit (TLS), encrypted secrets at rest, hashed passwords, scoped API tokens, optional two-factor authentication and per-workspace role isolation. No system is perfect — report suspected incidents to support@deskbees.com immediately.
7. Your rights
Depending on your jurisdiction (including India's DPDP Act), you may access, correct, export or delete your personal data, and withdraw consent for marketing. Workspace owners can export or delete workspace data from Settings; individuals can write to support@deskbees.com and we respond within 30 days.
8. Cookies
We use strictly necessary cookies for login, security and preferences. Details live in our Cookie Policy. We do not use advertising trackers inside the application.
9. Changes
We will post material changes here and notify workspace owners by email at least 15 days before they take effect.
10. Contact
DeskBees WAO · support@deskbees.com — Data Protection queries to the same address with subject "Privacy".