1. Introduction & Overview
This Privacy Policy describes how StraboWats ("StraboWats", "we", "us", or "our") processes personal data and organization communications collected through our enterprise WhatsApp Business Cloud API software-as-a-service (SaaS) platform, APIs, web applications, and related services.
StraboWats acts as a Data Processor on behalf of our corporate customer subscribers ("Customers"), who act as Data Controllers for customer communications routed through our platform.
2. Information We Collect
We collect and process the following categories of information:
- Account & Billing Data: Full name, work email address, company registration, phone number, billing addresses, hashed credentials, and subscription payment logs.
- WhatsApp Messaging Metadata: Phone numbers, WhatsApp display names, message delivery status (sent, delivered, read), timestamp records, error codes, and webhook payload payloads.
- Message Content & Media: Text messages, images, documents, and voice notes transmitted through connected WhatsApp Business Phone Numbers.
- System Technical Telemetry: IP addresses, browser fingerprinting, user-agent details, system log activity, and API latency metrics.
3. Meta WhatsApp Business API Data Handling
Our system integrates directly with Meta Cloud API endpoints. When processing messaging data under Meta's Solution Provider and WhatsApp Business Terms:
Message content is processed strictly to deliver real-time inbox management, AI Copilot automated response generation (via vector RAG), and analytics requested by the account administrator. We do not sell WhatsApp message data, nor do we use WhatsApp conversation content for external model training.
4. How We Use Your Information
Collected data is used strictly for legitimate enterprise software operations:
Routing inbound and outbound messages through multi-agent round-robin queues and FSM state machines.
Executing pgvector context retriever calls for instant customer inquiry response suggestions.
Maintaining SHA-256 tamper-proof audit trails for team agent actions and SLA tracking.
Detecting unauthorized authentication, rate-limit violations, and webhook fraud attacks.
5. Data Sharing & Approved Sub-processors
StraboWats engages trusted third-party infrastructure sub-processors subject to strict Data Processing Agreements (DPAs):
| Sub-processor | Role / Service | Data Location |
|---|---|---|
| Meta Platforms, Inc. | WhatsApp Business Cloud API Infrastructure | USA / EU Regions |
| Google Cloud Platform (GCP) | Cloud Run, PostgreSQL Vector DB, Storage | US-Central / EU-West |
| Google Vertex AI / Gemini API | AI Copilot & Vector Embedding Processing | US-Central / EU-West |
6. Security Architecture & Controls
We enforce multi-layered defense mechanisms:
- Encryption Standards: TLS 1.3 in transit and AES-256 at rest for all databases, vector indices, and customer file stores.
- Access Control & SSO: SAML 2.0 / Okta integration, role-based access control (RBAC), and mandatory two-factor authentication (2FA).
- Isolation Architecture: Logical multi-tenant separation preventing cross-organization query leakages.
7. Data Retention & Deletion
Customer messages and contacts are retained in accordance with subscriber workspace configuration settings (default: 365 days).
Account owners may initiate immediate self-service account purges or request data erasure under our Data Deletion Instructions.
8. Data Subject Rights (GDPR & CCPA)
Depending on your jurisdiction, you possess rights to Access, Rectify, Delete, Restrict Processing, and Export your personal data in standard JSON/CSV formats. Submit requests to info@strabonet.com.
10. Contact Information & Privacy Office
For questions or privacy inquiries, contact our Data Protection Office:
StraboWats Data Protection & Legal Office
General & Privacy Info: info@strabonet.com
Legal & Compliance: legal@strabonet.com