Privacy Policy

This policy explains what personal data [BUSINESS NAME] collects when you contact us on WhatsApp, why we collect it, how long we keep it, and the choices you have. It applies to the WhatsApp Business number [WHATSAPP NUMBER] and to this website.

Effective

1. Who is responsible for your data

The data controller is [REGISTERED LEGAL NAME], trading as [BUSINESS NAME].

DetailValue
Registered name[REGISTERED LEGAL NAME]
Address[FULL BUSINESS ADDRESS]
Privacy contact[PRIVACY EMAIL]
Phone[BUSINESS PHONE]
WhatsApp Business number[WHATSAPP NUMBER]
Website[https://your-domain.com]

We decide why and how your personal data is processed. If you have any question about this policy, contact us using the details above and we will respond within 14 days.

2. What this policy covers

This policy covers conversations you have with us through WhatsApp using the WhatsApp Business Platform (Cloud API) provided by Meta, and your use of this website.

WhatsApp itself is operated by Meta, not by us. Your use of the WhatsApp application is also governed by the WhatsApp Privacy Policy. We are responsible only for what we do with messages once they reach us.

3. What data we collect

When you send a message to our WhatsApp Business number, Meta delivers the following to our systems:

  • Your phone number in international format, which WhatsApp calls your WhatsApp ID.
  • Your WhatsApp profile name, if your privacy settings make it visible to businesses.
  • The content of your message: text, images, video, audio, documents, stickers, location, contact cards, reactions and replies.
  • Message metadata: the message identifier, the time it was sent, whether it is a reply, and delivery and read status of messages we send you.
  • Group context, where the message was sent in a WhatsApp group created by our business number. In that case we also receive the group identifier and can see which participants are members.

When you use this website, we also process a small amount of technical data: cookies that remember your interface theme and sidebar state, and, for staff accounts, an authentication session. We do not use advertising or cross-site tracking cookies.

We do not ask for and do not want payment card numbers, passwords, government identity numbers, or health information over WhatsApp. Please do not send them. If you do, we will delete them.

4. Why we use it, and our legal basis

PurposeLegal basis
Replying to your enquiry and providing the service you asked forPerformance of a contract, or steps taken at your request before entering one
Routing your message to the right team internallyLegitimate interest in handling enquiries efficiently
Sending you service updates about an order or request you madePerformance of a contract
Sending you promotional messagesYour consent, which you may withdraw at any time
Keeping records of conversations for dispute resolution and accountingLegal obligation and legitimate interest
Protecting our systems against abuse and fraudLegitimate interest in security

We process your data under Indonesian Law No. 27 of 2022 on Personal Data Protection (UU PDP). Where the General Data Protection Regulation applies to you, we rely on the equivalent bases in Article 6 of that regulation.

5. Automated handling and internal forwarding

You should know that some handling of your message is automatic:

  • Automatic read receipts. Incoming messages may be marked as read automatically.
  • Automatic replies. You may receive an acknowledgement message generated by our system rather than written by a person.
  • Internal forwarding. Based on rules we configure, the content of your message, together with your phone number and profile name, may be relayed automatically into an internal WhatsApp group used by our staff, so that the right colleague can respond.

Internal forwarding means people on our team beyond the person you first messaged may read your message. We only forward into groups operated by our own business number, and only to staff who need the information to do their job. We never forward your message to another customer or to any group we do not control.

None of this automated handling produces a legal or similarly significant decision about you. A human is always responsible for the substance of our response.

6. Who we share it with

We do not sell your personal data and we do not share it for anyone else’s marketing. We share it only with the following categories of recipient:

RecipientWhyWhere
Meta Platforms, Inc. and Meta Platforms Ireland LtdThey operate WhatsApp and the Cloud API that carries every message between you and usUnited States, Ireland and other countries
Our hosting providerRuns the server that stores the conversation recordSee section 8
Our own staffTo read and answer your messageIndonesia
Professional advisers, auditors and authoritiesOnly where we are legally required, or to establish or defend a legal claimIndonesia

Meta processes your messages as part of delivering WhatsApp. Their handling is described in the WhatsApp Privacy Policy and the WhatsApp Business Data Processing Terms.

7. International transfers

Because WhatsApp is operated by Meta, your messages are processed on servers outside Indonesia, including in the United States and the European Union. Under Article 56 of UU PDP, we transfer personal data abroad only where the receiving country provides an adequate level of protection or where appropriate safeguards are in place. For Meta, those safeguards are the contractual terms referenced above.

8. How long we keep it

We keep personal data only as long as we need it. Our systems enforce the following limits automatically:

DataRetention
Message content and conversation historyKept up to a fixed maximum number of most recent messages, after which the oldest are permanently deleted. Current limit: 5,000 messages.
Technical delivery logs from MetaCurrent limit: the 2,000 most recent events, then automatically deleted.
Your phone number and profile name in our contact recordFor as long as you remain an active contact, then deleted on request or when no longer needed.
Records needed for tax and accountingAs long as Indonesian law requires, generally 10 years for accounting records.
Website cookiesInterface preference cookies persist until you clear them. Staff session cookies expire on sign out.

When a retention period ends, data is deleted from our active systems. Backups, if any, are overwritten on their normal cycle.

9. How we protect it

  • All traffic between Meta and our servers travels over HTTPS.
  • Every message notification we receive from Meta is cryptographically verified before we accept it, so a third party cannot inject fake messages into our systems.
  • API credentials are stored as server-side environment variables and are never sent to a browser.
  • Access to the staff dashboard requires authentication, and our internal API requires a separate secret key.
  • Access to conversation records is limited to staff who need it.

No system is perfectly secure. If a personal data breach occurs that is likely to create a risk to you, we will notify you and the relevant authority within 72 hours, as Article 46 of UU PDP requires.

10. Your rights

Under UU PDP you have the right to:

  • Be told what data we hold about you and get a copy of it.
  • Have inaccurate or incomplete data corrected.
  • Have your data deleted, subject to records we must keep by law.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Object to processing, and to ask us to restrict it while a dispute is resolved.
  • Receive your data in a structured, commonly used format.
  • Complain to the supervisory authority.

To exercise any of these, email [PRIVACY EMAIL] or send a WhatsApp message to [WHATSAPP NUMBER]. We may need to confirm you control the phone number in question before we act. We respond within 14 days.

If you are not satisfied with our response, you may complain to the Ministry of Communication and Digital Affairs of the Republic of Indonesia (Komdigi).

11. How to stop receiving messages

You are always in control of whether we can message you.

  • Reply STOP or BERHENTI at any time and we will stop sending you non-essential messages.
  • You can block or report our number directly inside WhatsApp.
  • You can leave any WhatsApp group we invited you to at any time.
  • WhatsApp policy already prevents us from messaging you outside a 24 hour window unless you contacted us first or previously accepted a message template.

12. Deleting your data

You can ask us to erase your conversation history and contact record at any time. Full step by step instructions, including what we can and cannot delete, are on our data deletion page.

13. Children

Our service is not directed at children. WhatsApp requires users to be at least 13 years old, and under Article 25 of UU PDP processing a child’s data requires parental consent. We do not knowingly collect data from children. If you believe a child has sent us personal data, contact us and we will delete it.

14. Changes to this policy

We may update this policy as our service changes. The effective date at the top of this page always reflects the current version. If a change materially affects your rights, we will tell you before it takes effect, through the WhatsApp number you contacted us on or by a notice on this website.

15. Contact us

Questions, requests or complaints about this policy go to [PRIVACY EMAIL], or by post to [REGISTERED LEGAL NAME], [FULL BUSINESS ADDRESS].