SW
StraboWats
Legal & Governance
Effective Date: July 30, 2026 · Version 2.4

Privacy Policy

At StraboWats, protecting business communication data and maintaining transparency under GDPR, CCPA, and Meta WhatsApp Business Platform policies is fundamental to our platform engineering.

AES-256 Encrypted SOC2 Type II Certified GDPR & Meta Compliant

1. Introduction & Overview

This Privacy Policy describes how StraboWats ("StraboWats", "we", "us", or "our") processes personal data and organization communications collected through our enterprise WhatsApp Business Cloud API software-as-a-service (SaaS) platform, APIs, web applications, and related services.

StraboWats acts as a Data Processor on behalf of our corporate customer subscribers ("Customers"), who act as Data Controllers for customer communications routed through our platform.

2. Information We Collect

We collect and process the following categories of information:

  • Account & Billing Data: Full name, work email address, company registration, phone number, billing addresses, hashed credentials, and subscription payment logs.
  • WhatsApp Messaging Metadata: Phone numbers, WhatsApp display names, message delivery status (sent, delivered, read), timestamp records, error codes, and webhook payload payloads.
  • Message Content & Media: Text messages, images, documents, and voice notes transmitted through connected WhatsApp Business Phone Numbers.
  • System Technical Telemetry: IP addresses, browser fingerprinting, user-agent details, system log activity, and API latency metrics.

3. Meta WhatsApp Business API Data Handling

Our system integrates directly with Meta Cloud API endpoints. When processing messaging data under Meta's Solution Provider and WhatsApp Business Terms:

Strict Meta API Rules Enforced

Message content is processed strictly to deliver real-time inbox management, AI Copilot automated response generation (via vector RAG), and analytics requested by the account administrator. We do not sell WhatsApp message data, nor do we use WhatsApp conversation content for external model training.

4. How We Use Your Information

Collected data is used strictly for legitimate enterprise software operations:

Core Messaging Operations

Routing inbound and outbound messages through multi-agent round-robin queues and FSM state machines.

AI & Vector Intelligence

Executing pgvector context retriever calls for instant customer inquiry response suggestions.

Platform Governance

Maintaining SHA-256 tamper-proof audit trails for team agent actions and SLA tracking.

Security & Abuse Defense

Detecting unauthorized authentication, rate-limit violations, and webhook fraud attacks.

5. Data Sharing & Approved Sub-processors

StraboWats engages trusted third-party infrastructure sub-processors subject to strict Data Processing Agreements (DPAs):

Sub-processorRole / ServiceData Location
Meta Platforms, Inc.WhatsApp Business Cloud API InfrastructureUSA / EU Regions
Google Cloud Platform (GCP)Cloud Run, PostgreSQL Vector DB, StorageUS-Central / EU-West
Google Vertex AI / Gemini APIAI Copilot & Vector Embedding ProcessingUS-Central / EU-West

6. Security Architecture & Controls

We enforce multi-layered defense mechanisms:

  • Encryption Standards: TLS 1.3 in transit and AES-256 at rest for all databases, vector indices, and customer file stores.
  • Access Control & SSO: SAML 2.0 / Okta integration, role-based access control (RBAC), and mandatory two-factor authentication (2FA).
  • Isolation Architecture: Logical multi-tenant separation preventing cross-organization query leakages.

7. Data Retention & Deletion

Customer messages and contacts are retained in accordance with subscriber workspace configuration settings (default: 365 days).

Account owners may initiate immediate self-service account purges or request data erasure under our Data Deletion Instructions.

8. Data Subject Rights (GDPR & CCPA)

Depending on your jurisdiction, you possess rights to Access, Rectify, Delete, Restrict Processing, and Export your personal data in standard JSON/CSV formats. Submit requests to info@strabonet.com.

9. Cookies & Telemetry

We use strictly essential session cookies for authentication, CSRF security, and tenant state preservation. We do not place third-party advertising cookies inside our enterprise software.

10. Contact Information & Privacy Office

For questions or privacy inquiries, contact our Data Protection Office:

StraboWats Data Protection & Legal Office

General & Privacy Info: info@strabonet.com

Legal & Compliance: legal@strabonet.com