Privacy Policy

Delta Whaty · Last updated: August 2026

Delta (“we”, “us”, “our”) operates Delta Whaty, a WhatsApp Business messaging and CRM platform (the “Service”) built on the official WhatsApp Business Platform provided by Meta Platforms, Inc. (“Meta”). This Privacy Policy explains what personal data we collect, how we use and share it, how long we keep it, and the rights and choices you have. It applies to the businesses that use Delta Whaty and to the end-customers those businesses communicate with through it. By accessing or using the Service, you agree to this Policy. If you do not agree, please do not use the Service.

1. Who this Policy covers

  • Customers (businesses) — organizations and their team members (Admins, Managers, Agents) who use Delta Whaty.
  • End-customers (contacts) — people who message, or are messaged by, a business through WhatsApp using Delta Whaty.

2. Information we collect

From the business and its users: name, work email, hashed password, organization name and role; and the WhatsApp Business Account (WABA) connection data obtained through Meta — WhatsApp Business Account ID, phone number ID, display phone number, verified name, quality rating, and the access tokens used to send and receive messages on the business’s behalf. We also store content the business creates: message templates, campaigns, chatbot flows, notes, and settings.

From end-customers (through the WhatsApp Business Platform): phone number (WhatsApp ID) and WhatsApp profile name; the content and media of messages exchanged with the business (text, images, documents, voice, orders) and their delivery/read status; and contact attributes the business adds (tags, lead stage, custom fields) and opt-in/opt-out status.

Automatically: limited technical and usage data needed to operate the Service (timestamps, message IDs, error logs).

We do not collect or store payment card numbers within the Service. Subscription billing is handled by our payment processor, and WhatsApp conversation charges are billed by Meta.

3. How we use information

  • Provide the Service — a shared team inbox, contacts/CRM, campaigns, chatbots, automation, and analytics.
  • Send and receive WhatsApp messages that the business composes or automates, via the official WhatsApp Business Platform.
  • Manage the business’s own WhatsApp assets on their instruction (read phone numbers, create and sync message templates, subscribe to webhooks).
  • Secure the Service, prevent abuse and spam, provide support, and comply with law and Meta’s policies.

We only help businesses message end-customers who have provided valid opt-in. A customer can opt out at any time by replying STOP or UNSUBSCRIBE, which the Service honors automatically, and opted-out contacts are excluded from future campaigns. We enforce the WhatsApp 24-hour customer service window — outside it, only approved template messages are sent.

4. Data obtained through Meta and WhatsApp

Data we access through the WhatsApp Business Platform and Meta APIs — including thewhatsapp_business_messaging andwhatsapp_business_management permissions — is used solely to provide the Service to the connected business, in accordance with the Meta Platform Terms, the WhatsApp Business Terms, and the WhatsApp Messaging Policy. We do not use this data for advertising, and we do not sell it.

5. How we share information

  • With Meta / WhatsApp — to deliver and receive messages and manage the business’s WABA.
  • With service providers — infrastructure (database, hosting, message queue) that process data on our behalf under confidentiality obligations.
  • With the business — conversations and contact data belong to the business that runs the chat; its authorized team members can view them.
  • Legal — where required by law or to protect rights, safety, and the integrity of the Service.

We do not sell, rent, or lease personal data to third parties.

6. Data retention

We keep data for as long as the business’s account is active and as needed to provide the Service. When an account is closed, or on a valid deletion request, we delete or anonymize the associated personal data within a reasonable period, except where retention is required by law.

7. Your rights and choices

  • Access & export — businesses can view and export their contacts and data in the Service.
  • Correction & deletion — businesses can edit or delete contacts, disconnect their WhatsApp number, or request full account deletion.
  • Opt-out — end-customers can reply STOP to stop receiving messages.
  • Data deletion request — see our instructions and status page at /data-deletion. If you remove our app from your Facebook settings, Facebook notifies us and we process the deletion, providing a confirmation code you can use to check the status.
  • Depending on your location (for example, the EU/UK under GDPR), you may have additional rights; contact us to exercise them.

8. Security

Access is scoped by role (Admin / Manager / Agent) and isolated per organization. Passwords are hashed, session tokens rotate, API keys can be revoked at any time, webhook payloads are signature-verified, and access to WhatsApp assets is limited to the connecting business. No method of transmission or storage is completely secure, but we apply commercially reasonable safeguards.

9. Children

The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal data from children.

10. Changes to this Policy

We may update this Policy from time to time. Material changes will be posted here with a new “Last updated” date and, where appropriate, notified in-app. Continued use of the Service after changes take effect constitutes acceptance.

11. Governing law and contact

This Policy is governed by the laws of the United Arab Emirates. For privacy questions or to exercise your rights, contact us at privacy@deltainstitutions.com.