Privacy and data protection
Kolau and WhatsApp Business Platform Integration Privacy Policy
Last updated:
1. Controller and scope
This Privacy Policy governs the processing of data through the Meta application currently named “Clients,” with application ID 961419870330218, operated by Kolau, LLC (“Kolau”), as well as its integration with Meta and WhatsApp Business Platform.
This integration enables Kolau client businesses to connect their own WhatsApp Business accounts, manage message templates and business phone numbers, and send messages to their own customers.
For privacy-related questions or to request access to, correction of, or deletion of data, you may write to:
2. Roles of Kolau and the client business
Kolau acts as a data controller for the data required to create and administer Kolau accounts, manage the contractual relationship, provide support, protect service security, prevent fraud or abuse, and comply with its own legal obligations.
For data that each client business processes through WhatsApp features, including phone numbers, recipients, templates, messages, files, and delivery statuses, the client business acts as the data controller and Kolau acts as a technology provider and data processor.
Kolau processes this data solely to provide the requested service and in accordance with the client business's documented instructions. The data of each client business is kept separate from the data of other client businesses.
The client business determines the purposes of its communications, their recipients, message content, the applicable legal basis, and retention periods. The complete data-processing terms may be governed by the corresponding Data Processing Agreement or Addendum.
3. Permissions used
The application requests only the Meta permissions required to provide the offered WhatsApp features:
- whatsapp_business_management
- Allows access to and management of the WhatsApp Business accounts connected by client businesses, including their business phone numbers, profiles, message templates, and webhook subscriptions.
- whatsapp_business_messaging
- Allows connected business phone numbers to be registered and configured; messages and templates to be sent; sent, delivered, read, and error statuses to be received; and, when the client business enables receiving or reply features, incoming messages and their associated files to be processed.
Kolau does not request, receive, or store the user's Facebook or Meta password. Authentication takes place directly through Meta's systems.
4. Data processed
Depending on the features enabled by the client business, Kolau may process the following categories of data:
Administrator and client business data
- Meta user name and identifier.
- Email address, when provided or authorized.
- The user's role or relationship with the business.
- Meta business portfolio name and identifier.
- Kolau account contact information and settings.
WhatsApp Business asset data
- WhatsApp Business Account or WABA identifier.
- Business phone number and its identifier.
- Business name and display name.
- Business profile information.
- Message templates, content, variables, languages, and approval status.
- Webhook configuration and integration status.
- Temporary authorization codes, business tokens, and permissions granted.
Recipient and communication data
- The recipient's phone number and WhatsApp identifier.
- Profile name, when provided by WhatsApp.
- The template used and the values included in its variables.
- Content of sent and received messages.
- Images, documents, audio, or other files when the corresponding feature is enabled.
- Date and time of communications.
- Message identifiers.
- Sent, delivered, read, and error statuses.
- Opt-out, blocking, or consent-withdrawal requests when managed through Kolau.
Technical and security data
- IP address.
- Browser, device, and operating system.
- Access, authentication, and integration usage logs.
- API requests and responses.
- Technical errors and events required for security, diagnostics, and abuse prevention.
5. Sources of data
Kolau may receive this data:
- Directly from the client business or its authorized users.
- From Meta and WhatsApp through Facebook Login for Business, Embedded Signup, Graph API, WhatsApp Cloud API, and webhooks.
- From recipients when they reply to messages or interact with the client business.
- Automatically through Kolau's technical and security systems.
6. Purposes of processing
Kolau uses this data exclusively to:
- Authenticate the user and verify their authorization to represent the client business.
- Connect the client business's WhatsApp Business account and business phone number.
- Retrieve and manage authorized WhatsApp assets.
- Create, retrieve, update, and delete message templates.
- Send messages requested by the client business.
- Receive and display replies when this feature is enabled.
- Display sent, delivered, read, and error statuses.
- Provide technical support and resolve incidents.
- Protect accounts, tokens, and systems against unauthorized access, fraud, or abuse.
- Maintain records required to comply with contractual, legal, and security obligations.
Kolau does not sell, rent, or license data obtained through Meta or WhatsApp.
Kolau does not use a client business's contacts or messages for its own purposes, to benefit another client business, to create advertising profiles, or to send its own advertising to recipients.
Kolau will not use WhatsApp Business data to create, train, or improve general artificial intelligence models or models intended for third parties. When a client-requested feature uses an artificial intelligence provider as a technical service provider, that provider must act under contract solely to provide the requested feature and must not use the data to train its own models.
7. Legal bases
When Kolau acts as a data controller, processing is based, as applicable, on:
- Performance of a contract or steps requested before entering into a contract.
- Kolau's legitimate interest in managing client relationships, providing support, protecting the service, and preventing fraud or abuse.
- Compliance with legal obligations.
- Consent, when required by applicable law.
When Kolau acts as a data processor, it processes data according to the client business's instructions. The client business is responsible for determining and documenting the legal basis that permits messages to be sent to each recipient.
8. Client business responsibilities
The client business must:
- Have validly obtained the recipient's phone number and authorization or opt-in before initiating communications when required.
- Inform recipients about the processing of their data.
- Use templates and messages for lawful and legitimate purposes.
- Immediately honor opt-out, objection, or blocking requests.
- Comply with applicable law and WhatsApp Business policies.
- Not include unnecessary, unlawful, or particularly sensitive data without a legal basis and appropriate safeguards.
This Kolau policy does not replace the privacy policy that each client business must provide to its own recipients.
9. Recipients and service providers
To provide the service, data may be processed by or disclosed to:
- Meta and WhatsApp
- As providers of WhatsApp Business Platform, Cloud API, Embedded Signup, and the corresponding authentication and messaging infrastructure.
- Service providers engaged by Kolau
- Hosting, infrastructure, security, monitoring, and support providers, only when necessary to provide the service and subject to contractual confidentiality, security, and limited-processing obligations.
- Authorities and advisers
- Public authorities, courts, or professional advisers when necessary to comply with a legal obligation or defend legitimate rights.
Kolau does not share one client business's data with other client businesses.
Processing by Meta and WhatsApp is also governed by their applicable terms, including the WhatsApp Business Data Processing Terms:
https://www.whatsapp.com/legal/business-data-processing-terms
10. International transfers
Providing the service may involve processing data outside the user's country or outside the European Economic Area, including in the United States.
Where the General Data Protection Regulation applies, Kolau will use the applicable valid transfer mechanism, such as an adequacy decision, Standard Contractual Clauses, or another safeguard recognized by applicable law.
You may request additional information about applicable safeguards by writing to soporte@kolau.com.
11. Retention
Kolau retains data only for as long as necessary for the purposes described:
- Temporary authorization codes are used to complete the connection and are not retained longer than necessary for that process.
- Tokens are retained while the integration remains active or until they are revoked, replaced, or no longer needed.
- Recipient, message, template, and status data is retained according to the client business's instructions and settings and for as long as needed to provide the service.
- Technical and security logs are retained for the period necessary to investigate incidents, protect the service, and comply with obligations.
- Contractual data or data required by law may be restricted and retained for applicable limitation periods.
When data is no longer needed, the service ends, Meta requests its deletion, or the user or client business requests erasure, Kolau deletes or anonymizes it without undue delay unless a documented legal retention obligation applies.
Residual backup copies remain protected and isolated until overwritten through the ordinary backup cycle.
12. Security
Kolau applies technical and organizational measures that are reasonable and proportionate to the risk, including:
- Encryption of communications in transit.
- Encryption of data and credentials at rest where appropriate.
- Access controls and the principle of least privilege.
- Logical separation of each client business's data.
- Protection and rotation of credentials and tokens.
- Logging, monitoring, and review of access.
- Security incident management procedures.
No Internet-connected system can guarantee absolute security.
13. Data deletion and disconnection
All users who may access the application, including client businesses, their administrators, and message recipients, may request complete deletion of their personal data collected through the application.
To submit a request, send an email to:
Use the following subject line:
Request for deletion of Meta/WhatsApp data
Include, where possible:
- The requester's name.
- The business related to the request.
- The email address used with Kolau or Meta.
- The affected phone number.
- The WABA identifier or business phone number identifier, if known.
- A description of the data requested for deletion.
Kolau may request additional information that is strictly necessary to verify identity and prevent fraudulent deletions.
Once the request has been verified, Kolau will:
- Confirm receipt of the request.
- Disconnect or revoke the corresponding access where appropriate.
- Delete or anonymize personal data and data obtained through Meta or WhatsApp that is no longer needed.
- Inform the requester of the action taken or of any data that must be retained due to a legal obligation.
Kolau will respond within the applicable legal period and, where the GDPR applies, within one month of receiving the request.
If the request concerns data that Kolau processes on behalf of a client business, Kolau will work with that business to address it. The recipient may also contact the business that sent the message directly.
Revoking the application's permissions in Meta prevents future access, but does not replace an express request to delete data that Kolau has already stored.
14. Rights
Where applicable, a data subject may request:
- Access to their data.
- Correction of inaccurate data.
- Erasure.
- Restriction of processing.
- Objection.
- Data portability.
- Withdrawal of consent, without affecting processing carried out before withdrawal.
Requests may be sent to soporte@kolau.com.
Individuals in Spain or the European Economic Area may lodge a complaint with the Spanish Data Protection Agency or the relevant supervisory authority:
15. Minors and automated decisions
The application is intended for businesses and authorized adult users. Kolau does not direct this integration to minors or intentionally collect minors' data for its own purposes.
Kolau does not make decisions that produce legal or similarly significant effects on a person based solely on automated processing of data obtained through Meta or WhatsApp.
16. Changes to this policy
Kolau may update this policy when the integration, offered features, service providers, or applicable law changes.
The current version will always be available at this URL and will show its last-updated date. When a change is material, Kolau will provide reasonable notice to affected client businesses.
17. Contact
For any question about this policy, data processing, or a deletion request:
Kolau, LLCEmail: soporte@kolau.com