1. Scope and Wazzl’s role
This policy applies to Wazzl’s website, account services, shared WhatsApp inbox, support channels, and related operational systems.
Two different data roles matter. Wazzl acts as a controller for account administration, website, support, security, and service-operation data. For contacts, messages, media, notes, and other content a workspace customer places in Wazzl, that customer normally determines the purpose and means of processing and Wazzl acts as its processor.
If you are a customer’s contact or team member and your question concerns workspace content, the relevant workspace customer is usually the first point of contact. Wazzl will assist that customer as appropriate.
2. Data we handle
Account and workspace administration
Name, email address, password hash, workspace membership, role, invitations, profile settings, authentication sessions, and account or workspace lifecycle records.
Customer conversation content
Contact names and phone numbers, WhatsApp identifiers, messages, supported media, message and delivery status, notes, tags, assignments, conversation history, and related workspace activity. This is processed on the workspace customer’s instructions.
Technical, security, and operational data
IP address and request metadata, authentication and audit events, browser or device information made available in network requests, webhook and provider event metadata, error diagnostics, availability checks, and records needed to prevent abuse and operate the service.
Support and communications
The name, work email, company, team-size range, weekly-enquiry range, and contact consent a person chooses to provide for a workflow review, plus chat details and other information a person chooses to provide when asking for support, reporting a security issue, or making a privacy request. Do not send passwords, access tokens, WhatsApp messages or media, contact data, phone numbers, Meta identifiers, or inbox screenshots through public forms, support chat, or email.
Optional first-party acquisition measurement
After permission, Wazzl can count a finite set of client-observed page, acquisition-action, workflow-review, and signup stages. A record contains only an allowlisted event, page and step; a sanitized campaign code; client and server timestamps; and a random measurement-session reference. Raw UTM values, click identifiers, referrers, URLs, form values, names, email addresses, phone numbers, IP addresses, device fingerprints, provider identifiers, account tokens, workflow-review receipt keys, user identifiers, and workspace identifiers are not accepted into this measurement store. Measurement sessions are not joined to leads, users, workspaces, conversations, or workflow-review submissions.
3. Where data comes from
- Directly from account holders, workspace owners, team members, and support requesters.
- From a workspace customer when it adds contacts, team members, notes, or other workspace data.
- From Meta’s WhatsApp Business Platform when messages and delivery events are sent to or from a connected number.
- Automatically from browsers, devices, network requests, security controls, error reporting, and availability monitors.
- From a browser’s observable public-page actions after optional first-party measurement permission; browser privacy signals can withhold that permission.
4. Why data is used
- Provide accounts, workspace access, contacts, assignments, conversation history, and WhatsApp messaging functions.
- Authenticate users, manage roles and invitations, secure sessions, detect misuse, and investigate incidents.
- Deliver service messages such as invitations, password resets, and deletion-request verification.
- Answer workflow-review, support, privacy, security, and operational enquiries.
- Monitor availability, diagnose errors, maintain backups, and improve reliability.
- With permission, understand which public acquisition steps are observed so Wazzl can improve outreach and page usability without measuring message, lead, or workspace content.
- Comply with applicable law, enforce service terms, and establish or defend legal claims where necessary.
Depending on the relationship and applicable law, controller processing may rely on performance of a contract, legitimate interests in providing and securing the service, consent where requested, or legal obligations. Workspace content is processed under the relevant customer’s instructions and agreement.
6. International processing
Wazzl and its providers may process data in countries other than the country where a user or contact is located. Where applicable law requires a transfer mechanism or additional safeguard, Wazzl and the relevant provider or workspace customer are responsible for putting that mechanism in place for their role.
7. Retention
Data is kept for as long as needed to provide and secure the service, answer an enquiry, follow workspace instructions, resolve disputes, and meet legal obligations. Retention varies by data type and account state. Operational logs, security records, provider receipts, emails, and backups may follow different schedules from active workspace content. Wazzl’s database does not store the raw workflow-review fields: it keeps only a random-salted payload fingerprint, the browser-generated idempotency key, and acceptance timestamps needed to prevent duplicate delivery. Resend transmits the submitted fields to the monitored destination; while the privacy-address fallback is active, that destination is hosted by Google/Gmail.
Each optional acquisition event and its content-free immutable retry receipt is deleted after 90 days from server receipt. A measurement session with no event is deleted after 90 days from consent. Because the session is the parent of its events, it can remain only until its latest retained child expires—at most about 91 days from consent—while collection still stops 24 hours after consent. Revocation stops later collection and scheduled cleanup deletes events before their parent sessions.
After the required identity and authority verification has completed, Wazzl targets eligible active-system content within 24 hours. Requests that still need those checks have not yet entered eligible active processing. This is not a promise that every copy disappears within 24 hours: backup copies and narrowly retained legal or security records can persist until their applicable retention process completes.
A restore can reintroduce content from an earlier backup snapshot. Wazzl must reapply verified deletion handling before or while restored data returns to active use; the current system does not promise an automatic re-purge.
Workspace deletion remains subject to workspace-owner authority, safeguards for other members, and the applicable cooling-off or operator process. See data deletion for the exact request paths.
9. Choices and rights
Depending on applicable law and Wazzl’s role, a person may be able to ask for access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Rights are not absolute and identity or authority checks may be required.
The “Privacy choices” control on eligible public acquisition pages grants or revokes optional measurement. A Global Privacy Control signal or Do Not Track value of 1 withholds measurement and triggers revocation; a person can also keep measurement off explicitly. Browser collection stops immediately on denial, while a failed server confirmation is retried without storing the session token or queued events in browser storage.
Account holders can correct certain profile information in Wazzl. To request deletion, use the verified deletion page. For other privacy questions, email moustafamohsen1@gmail.com. If the request concerns a workspace customer’s contact or message content, identify the workspace without sending message content; Wazzl may refer the request to that customer.
10. Security
Wazzl uses workspace-scoped access controls, defined member roles, HTTPS in production, one-way password hashing, session protections, webhook signature checks, restricted infrastructure access, monitoring, error reporting, backups, and recovery procedures. No online service is risk-free. More detail and a reporting channel are available on the security page.
11. Children
Wazzl is a business service and is not directed to children. Workspace customers are responsible for ensuring that their use of Wazzl and WhatsApp is lawful for the people they communicate with.
12. Changes and contact
Material changes will be posted on this page with a revised effective date. Questions about this policy or Wazzl’s controller processing can be sent to moustafamohsen1@gmail.com.