Autopilot My Business

WhatsApp Web Integration — Privacy Policy

Autopilot My Business — autopilotmybusiness.com

WhatsApp Web Addendum
Effective Date: 17 June 2026 Last Reviewed: 17 June 2026 Applies To: WhatsApp Web feature only Controller: Autopilot My Business (B2B SaaS)

1. Scope and Purpose

This document is a feature-specific privacy addendum to the Autopilot My Business Platform Privacy Policy. It governs the collection, storage, processing, and deletion of data associated exclusively with the WhatsApp Web integration built into the platform.

This feature allows registered business tenants ("Tenants") on the Autopilot My Business platform to link their personal or business WhatsApp accounts, send and receive messages, manage contacts, run broadcast campaigns, and access a shared CRM inbox — all within the platform.

Important: The WhatsApp Web integration operates via the WhatsApp Web protocol and is not affiliated with, endorsed by, or officially supported by Meta Platforms, Inc. or WhatsApp LLC. Use of this feature is at the Tenant's own risk with respect to WhatsApp's Terms of Service.

2. Who We Are

Autopilot My Business is a multi-tenant B2B SaaS platform that provides business management tools including CRM, HR, Inventory, and Marketing automation. The registered business entity operating this platform can be contacted at:

For the purposes of data protection law, Autopilot My Business acts as the Data Processor on behalf of its Tenants. Each Tenant is the Data Controller for end-user data (contacts, customers) processed through the WhatsApp integration.

3. Data We Collect and Store

The following categories of data are collected specifically by the WhatsApp Web integration:

3.1 WhatsApp Session Credentials

To maintain a persistent WhatsApp Web connection, the integration generates authentication credentials equivalent to those stored in a WhatsApp Web browser session. These include cryptographic keys, signal protocol state, and registration identifiers. This data is stored encrypted in our database under the WhatsappSession collection, isolated per Tenant (tenantId) and per registered device (deviceId).

Session credentials are functionally equivalent to a WhatsApp Web "logged-in browser session." Deleting a device from the platform revokes and purges all associated session data.

3.2 Messages (Inbox Data)

All messages sent or received through a connected WhatsApp device are stored in our database under the WhatsappMessage collection. Each message record may contain:

Field Description Example
jidWhatsApp contact or group identifier[email protected]
contentText body of the message"Hi, following up on your order"
messageTypeType: text, image, video, audio, document, location, contact, sticker, reactionimage
mediaUrlURL of uploaded media (stored in cloud storage)Google Drive link
senderNameWhatsApp Push Name of the sender"John Doe"
isFromMeWhether the message was sent by the connected devicetrue
statusDelivery status: PENDING, SENT, DELIVERED, READ, ERRORDELIVERED
timestampUTC timestamp of the messageISO-8601 datetime
sourceOrigin: app, phone, or automationautomation
connectedPhoneNumberPhone number of the linked WhatsApp account+91XXXXXXXXXX

3.3 Contact Identity Cache

When contacts interact with or are messaged by a connected device, the system caches their identity data in the WhatsappContact collection to resolve display names. This includes:

3.4 Groups and Participants

For WhatsApp group messaging, the platform stores group metadata including:

3.5 Message Logs (Delivery Audit)

Every outgoing message action is logged in the WhatsappLog collection for audit and deliverability tracking:

3.6 Bulk Campaign Data

When a Tenant runs a broadcast campaign, the following is stored:

3.7 Outbound Message Queue

Messages awaiting delivery (due to rate limiting, offline devices, or scheduled sends) are stored in a durable message queue (WhatsappQueue) containing the full message payload, recipient identity, scheduled time, retry count, and processing status.

3.8 Account Health Metrics

To protect connected WhatsApp numbers from being banned, the platform tracks per-device messaging statistics:

3.9 Device Connection Events

Connection lifecycle events (device connected, disconnected, QR scanned) are logged for operational monitoring. On a manual disconnection (WhatsApp logout or ban), the platform sends an email alert to the Tenant's administrator and creates an in-platform notification. The email contains the device name and business display name — no message content is included.

4. How We Use the Data

PurposeData UsedLegal Basis
Maintaining an active WhatsApp Web session for the Tenant Session credentials Contract (service provision)
Displaying the CRM inbox (received and sent messages) Message content, JID, sender name, timestamps Contract (service provision)
Sending messages on behalf of the Tenant Recipient JID, message content, media, delivery status Contract + Tenant's instruction
Resolving contact display names across the CRM Contact identity cache (push name, JID, phone) Legitimate interest (UX consistency)
Rate limiting / preventing WhatsApp account bans Daily message counts, interaction ratio, account age Legitimate interest (platform stability)
Running broadcast campaigns Recipient list, message template, delivery outcomes Contract + Tenant's instruction
Delivering notifications when a device disconnects Device ID, admin email, business name Legitimate interest (operational alert)
Audit logging for support and dispute resolution Message logs (from/to numbers, status) Legitimate interest (accountability)
No advertising use: Data processed through the WhatsApp integration is never used for advertising, sold to third parties, or combined with external datasets for profiling end users.

5. Data Retention Policy

Data CategoryMinimum RetentionMaximum RetentionDeletion Method
WhatsApp session credentials Until device is removed Until device is removed Purged on device disconnection/logout
Message content (inbox) 6 months 12 months Automated batch deletion nightly at 03:30 UTC
Contact identity cache Duration of Tenant subscription Duration of Tenant subscription + 30 days Purged on account termination
Group metadata & participant lists Duration of Tenant subscription Duration of Tenant subscription + 30 days Purged on account termination
Message delivery logs 12 months 12 months Automated deletion
Campaign data Duration of Tenant subscription Duration of Tenant subscription + 90 days Purged on account termination
Message queue entries Until processed or failed 90 days (stuck entries) Automated reaper job
Account health metrics (aggregated) Derived from message data Deleted with messages Computed on demand; no separate store

The default retention thresholds (6-month keep floor and 12-month delete ceiling) are configurable via environment variables WHATSAPP_RETENTION_MIN_KEEP_MONTHS and WHATSAPP_RETENTION_DELETE_MONTHS. These values can only be lowered (more aggressive deletion), never raised beyond the limits stated above, by platform administrators.

6. Security Measures

The following technical and organisational measures are applied specifically to the WhatsApp Web service:

6.1 Authentication & Authorisation

6.2 Tenant Isolation

6.3 Transport Security

6.4 Rate Limiting & Anti-Abuse

6.5 Session & Credential Protection

6.6 Stack Trace Suppression

6.7 Message Retention Enforcement

7. Data Sharing and Third Parties

7.1 WhatsApp / Meta Platforms

By using this feature, messages are transmitted over WhatsApp's infrastructure via the WhatsApp Web protocol. Meta Platforms, Inc. processes these messages in accordance with WhatsApp's own Privacy Policy. Autopilot My Business has no control over Meta's data practices. Tenants and their end-users are also subject to WhatsApp's Terms of Service.

7.2 Cloud Infrastructure

The platform's servers, databases (MongoDB), and media storage are hosted on cloud infrastructure (VPS / cloud provider). Data is stored within the provider's data centres. Infrastructure providers operate under their own data processing agreements and do not have independent access to Tenant message data.

7.3 Media Storage

Media files (images, documents, videos, audio) received or sent via WhatsApp may be uploaded to Google Drive and the resulting web-view link stored in the message record. Access to these files is controlled by the Tenant's Google Drive account permissions.

7.4 No Sale of Data

Autopilot My Business does not sell, rent, or share personal data processed through the WhatsApp integration with any advertising networks, data brokers, or marketing analytics providers.

7.5 Sub-Processors

Where sub-processors are engaged, appropriate Data Processing Agreements (DPAs) are in place. Tenants may request a list of current sub-processors by emailing [email protected].

8. Tenant Responsibilities

As Data Controllers for their end-user data, Tenants who enable the WhatsApp Web integration accept the following obligations:

Service Continuity Notice: The WhatsApp Web integration operates via the WhatsApp Web protocol. Meta may, at any time, change its protocol in ways that affect service availability, or may restrict numbers using third-party WhatsApp Web clients. Autopilot My Business is not liable for any number restrictions, service disruptions, or data loss resulting from Meta's enforcement actions.

9. Rights of End-Users (Data Subjects)

End-users whose personal data (phone number, message content, contact details) is processed through a Tenant's WhatsApp integration may exercise the following rights under applicable data protection law (GDPR, PDPB, or equivalent):

These requests should be directed to the Tenant (the business that messaged the end-user), who is the Data Controller. If a Tenant fails to respond, end-users may contact Autopilot My Business at [email protected] and we will facilitate the request within our technical capability.

End-users may also exercise their rights directly within WhatsApp (block sender, delete messages, report spam) without needing to contact the Tenant.

10. Children's Data

The WhatsApp Web integration and the Autopilot My Business platform are intended exclusively for B2B use. We do not knowingly collect or process data relating to individuals under the age of 13 (or the applicable minimum age in the user's jurisdiction). Tenants must not use the integration to contact minors without appropriate legal basis and parental consent.

11. International Data Transfers

Data may be stored on servers located outside the Tenant's jurisdiction depending on the cloud infrastructure region selected. Where data is transferred across borders, we ensure appropriate safeguards are in place (Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms). Tenants requiring data residency in a specific region should contact [email protected] before enabling the feature.

12. Data Breach Notification

In the event of a personal data breach affecting the WhatsApp integration, Autopilot My Business will:

  1. Contain the breach and assess its scope within 24 hours of detection.
  2. Notify affected Tenants within 72 hours of becoming aware of the breach, in accordance with applicable law.
  3. Provide details of the categories and approximate volume of data affected, likely consequences, and remedial measures taken.

Tenants are responsible for notifying their own end-users and relevant supervisory authorities where required by applicable law.

13. Cookies and Local Storage

The WhatsApp Web feature uses the following browser-side storage:

14. Limitations and Disclaimers

15. Changes to This Policy

We may update this policy as we add new capabilities to the WhatsApp integration or in response to changes in applicable law. Material changes will be communicated to Tenant administrators via in-platform notification and/or email at least 14 days before they take effect. Continued use of the WhatsApp integration after the effective date constitutes acceptance of the revised policy.

The version history of this document is maintained in our changelog. Tenants may request previous versions by contacting [email protected].

16. Contact and Complaints

For questions, data requests, or complaints related to this policy:

If you are an end-user (contact of a Tenant) and believe your data has been processed unlawfully, you also have the right to lodge a complaint with your local data protection supervisory authority (e.g., the Information Commissioner's Office in the UK, the Data Protection Board of India, or your national equivalent).