This Privacy Policy explains how PaaS ("we", "us" or "our") collects, uses, discloses and protects information in connection with the PaaS platform, our websites, and related services (together, the "Service"). By using the Service, you agree to the practices described here.
Our commitment on connected platforms. PaaS accesses and processes data from Meta products — including the WhatsApp Business Platform and Instagram — only through Meta's official APIs. We keep our integrations up to date and handle all Platform Data in accordance with Meta's Platform Terms, Developer Policies, and applicable product terms and instructions. We do not use unofficial or unauthorised methods to access any platform.
Contents
1. Information we collect
We collect information in the following ways:
Information you provide
Account and contact details (such as name, business name, email address and phone number), the configuration you set up (services, pricing, messages and rules), billing information, and any content you submit to us, including support requests.
Information from your customers' conversations
When you connect a messaging channel, we process the messages and related information exchanged between your business and the people who contact it — for example, message content, sender profile information made available by the platform, timestamps and delivery status — so that the Service can respond, qualify and route enquiries on your behalf.
Information from connected platforms
With your authorisation, we receive information from the platforms you connect (for example, business account identifiers, message webhooks and delivery receipts) through those platforms' official APIs.
Information collected automatically
When you use our websites and dashboard, we collect usage data, device and browser information, IP address and similar technical data, including through cookies and comparable technologies.
2. How we use information
- To provide, operate, maintain and improve the Service;
- To answer, qualify, route and follow up on conversations as you have configured;
- To authenticate users, manage accounts and process payments;
- To provide support and communicate with you about the Service;
- To monitor, secure and troubleshoot the Service and prevent abuse;
- To comply with legal obligations and enforce our terms.
We do not sell personal information, and we do not use the content of your customers' conversations to train third-party models.
3. Data from Meta platforms ("Platform Data")
Where you connect a Meta product, PaaS accesses and processes Platform Data exclusively through Meta's official APIs (including the WhatsApp Business Platform / Cloud API and the Instagram messaging API). We:
- use Platform Data only to provide and improve the features you have enabled;
- process Platform Data in accordance with Meta's Platform Terms, Developer Policies and applicable product terms, and follow Meta's instructions and technical requirements;
- keep our integrations current with the official APIs and deprecate unsupported methods;
- do not sell Platform Data, and do not share it except as needed to provide the Service or as required by law;
- retain Platform Data only as long as necessary for the purposes above, and delete it in line with platform requirements and the retention and deletion terms below.
Your use of each connected platform is also governed by that platform's own terms and privacy policy.
4. Legal bases for processing
Where applicable law requires a legal basis, we rely on: performance of a contract with you; your consent (and that of the individuals who message your business, obtained by you where required); our legitimate interests in operating and securing the Service; and compliance with legal obligations. You may withdraw consent at any time where processing is based on consent.
5. How we share information
We share information with: service providers and sub-processors who help us run the Service (such as hosting, infrastructure and payment processing) under appropriate confidentiality and data-protection obligations; the platforms and integrations you choose to connect; and authorities or third parties where required by law or to protect rights, safety and security. In the event of a merger, acquisition or asset sale, information may be transferred subject to this policy.
6. Data retention
We retain personal information for as long as necessary to provide the Service, comply with our legal obligations, resolve disputes and enforce our agreements. When information is no longer needed, we delete or anonymise it. Retention of Platform Data additionally follows the requirements of the relevant platform.
7. Data security
We use reasonable technical and organisational measures designed to protect the information we hold. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. International transfers
We may process and store information in countries other than where you are located. Where we transfer personal data internationally, we use appropriate safeguards as required by applicable law.
9. Your rights
Depending on your location, you may have the right to access, correct, delete or port your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us using the details below. If we process information on behalf of a business customer (as a processor), we will refer your request to that customer.
10. Data deletion
You can request deletion of your personal information, and businesses using PaaS can request deletion of the Platform Data associated with their account, at any time.
- Account holders: email pooyashams.b@gmail.com from your registered address with the subject "Data Deletion Request", or use the deletion option in your account settings. We will delete or anonymise the relevant data within 30 days, subject to legal retention requirements.
- People who messaged a business using PaaS: contact that business directly, or email us at pooyashams.b@gmail.com and we will forward your request to the relevant business and assist with deletion.
- Disconnecting a Meta account: removing PaaS from your Meta Business settings, or disconnecting the channel in your dashboard, revokes our access; the associated Platform Data is then deleted in accordance with platform requirements.
This section also serves as our data-deletion instructions for connected platform accounts.
11. Children's privacy
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us so we can remove it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact us
If you have questions about this Privacy Policy or our data practices, contact us at:
PaaS
Dubai, United Arab Emirates
Email: pooyashams.b@gmail.com
This Privacy Policy is provided for general information only and does not constitute legal advice.