Privacy Policy
How KanalPro handles data on the WhatsApp Business Platform
Version of 23 August 2026
KanalPro (individual entrepreneur) ("we", "KanalPro") provides businesses with a software panel for exchanging WhatsApp messages through the official WhatsApp Business Platform (Cloud API) operated by Meta. This policy explains what data passes through the service, why we need it, how long we keep it, who we share it with, and how to request its deletion.
1. Who processes the data, and in which role
The service acts in two distinct roles, and responsibility for the data depends on the role.
- We act as a controller for our own business records. Information about our business customers (company name, contact person, e-mail address, WhatsApp Business account identifiers, billing records) is processed in our own name and for purposes we determine.
- We act as a processor on behalf of our business customers. Conversations with end users, their phone numbers and message content are processed solely on the instructions of the business that connected its number to the panel. That business determines the purpose and the scope; we follow its instructions and this policy.
If you messaged a company on WhatsApp and your message reached this service, that company is the controller of your data. We provide the technical delivery and store the messages on its behalf. You may nevertheless send a deletion request directly to us; the procedure is described in section 8 and on the Data Deletion page.
Legal details: KanalPro (individual entrepreneur), Republic of Kazakhstan. Contact e-mail: [email protected].
2. What data we process
2.1. End-user data from WhatsApp
- The WhatsApp phone number (wa_id). A message cannot be delivered without it.
- The WhatsApp profile name, when the user has made it visible in WhatsApp settings.
- Message content: text, button taps and list selections, captions of attachments.
- Attachment metadata: file type and the Cloud API media identifier. We do not store the files themselves.
- Technical identifiers and delivery states: message ID, timestamp, and the sent, delivered, read and failed states.
- Conversation state within a service scenario: the current step, selected items, and the address or time supplied by the user, where the customer’s scenario requires it.
2.2. Business customer data
- Company name and contact person, e-mail address and phone number.
- Meta identifiers: WhatsApp Business Account ID (WABA ID), phone number ID, business portfolio ID, and the display sender number.
- Access token, app secret and webhook verify token. These are account credentials rather than personal data; they are stored in separate files with restricted permissions and are never displayed in full anywhere in the interface.
2.3. Service telemetry
- A Graph API call log: request path, response code, duration, error text. Secrets are never written to the log and phone numbers are truncated in it.
- Records of received webhooks and the outcome of signature verification.
We do not collect device location, we do not read address books, we place no advertising or analytics trackers on the panel, and we use no tracking cookies. The public pages (this one, Terms of Service and Data Deletion) open without a login and set no cookies.
3. Where the data comes from
- From Meta, through the WhatsApp Cloud API webhook: inbound messages and delivery statuses.
- From the business customer’s operator, who enters the recipient number and the message text in the panel.
- From the business customer itself, when connecting its number in the Connection screen.
We do not buy contact lists, we do not import contacts from third-party sources, and we do not compile recipient lists ourselves. The business customer is responsible for the lawfulness of its recipient list and for obtaining opt-in consent as required by the WhatsApp Business Messaging Policy.
4. Why we process the data
| Purpose | Data used | Legal basis |
|---|---|---|
| Delivering outbound messages and templates | Recipient number, message text, variable values | Contract with the business customer; consent obtained by that customer from the recipient |
| Receiving inbound messages and showing them to the operator | Sender number, profile name, message text | Contract with the business customer |
| Showing delivery status and diagnosing failures | Message ID, status, error code | Legitimate interest in a working service |
| Running the service scenario (orders, bookings, support) | Conversation state, selected items | Instruction of the business customer |
| Managing message templates | Template name, language, body text, review status | Contract with the business customer |
| Technical support and incident resolution | Graph API log, webhook records | Legitimate interest |
| Preventing spam and abuse | Sending frequency, complaints, number quality rating | Legitimate interest; Meta platform requirements |
| Complying with statutory duties | Accounting and billing records | Legal obligation |
We do not use conversation content to train machine-learning models, we do not sell or transfer data to advertising networks or data brokers, and we do not build advertising profiles from it.
5. How long we keep the data
| Category | Retention period |
|---|---|
| Content of inbound and outbound messages | 180 days from receipt or sending |
| Delivery statuses and message identifiers | 180 days |
| State of an unfinished scenario conversation | 30 days after the user’s last action |
| Graph API call log | 90 days |
| Connection settings and business customer records | Term of the agreement plus 12 months |
| Accounting and billing documents | The period required by the law of Republic of Kazakhstan |
Records are deleted automatically once the period expires; no request is needed. Early deletion on request follows section 8. Backup copies are rotated within 30 days, so a record disappears from backups up to 30 days after it is removed from the live system.
6. Who we share the data with
- Meta Platforms Ireland Limited, the operator of the WhatsApp Business Platform. This transfer is inherent to the service: without it a message cannot be delivered. Meta processes the data under its own terms published on whatsapp.com and business.whatsapp.com.
- The business customer on whose behalf the conversation is conducted; it sees its own conversations in the panel.
- Our hosting provider, to the extent required to run the servers. The provider is not granted access to message content.
- Public authorities, only on a duly issued lawful request.
No other third parties receive the data. We do not sell data under any circumstances.
7. International transfers and security
Meta’s servers are located outside Republic of Kazakhstan, so delivering a message involves an international transfer. We transfer the minimum necessary: the recipient number and the message content.
Safeguards in place:
- access to the panel is restricted; only the legal pages are public;
- all traffic to Meta and to the panel uses HTTPS;
- the access token, app secret and verify token are kept in separate files readable only by the process owner and are never shown in full: the interface displays the last four characters only;
- inbound webhooks are validated against the app signature, and events with an invalid signature are rejected;
- secrets are stripped from log entries before they are written to disk.
No technical measure is absolute. In the event of a breach likely to harm the rights of data subjects, we notify the affected business customers without undue delay.
8. Your rights and how to request deletion
You have the right to:
- obtain information about the data we process about you;
- have inaccurate data corrected;
- request deletion of your data;
- withdraw consent to receive messages, after which we stop sending;
- object to the processing and lodge a complaint with the competent data protection authority.
How to exercise these rights: send an e-mail to [email protected] with the subject "Personal data", stating the WhatsApp phone number used in the conversation and what you are asking for. We reply within 30 calendar days. A dedicated page with the full procedure and the request form is available at https://geo-theatre-footwear-aims.trycloudflare.com/data-deletion?lang=en.
You can also stop messages directly in WhatsApp by replying STOP to the sender number. Full deletion of a conversation requires a written request, because we must verify that the request comes from the owner of the number.
9. Minors
The service is intended for business communication and is not directed at persons under 18. We do not knowingly collect data about minors. If data about a child has entered the system without a lawful basis, it will be deleted upon a request sent to [email protected].
10. Changes to this policy
The current version is always published at https://geo-theatre-footwear-aims.trycloudflare.com/privacy?lang=en. For material changes we notify business customers by e-mail at least 14 days before the change takes effect. The version date is shown at the top of this page.
11. Contact
E-mail: [email protected]
Phone and WhatsApp: +7 707 560 8652
Operator: KanalPro (individual entrepreneur), Republic of Kazakhstan
Terms of Service: https://geo-theatre-footwear-aims.trycloudflare.com/terms?lang=en
Data Deletion: https://geo-theatre-footwear-aims.trycloudflare.com/data-deletion?lang=en
KanalPro is not part of Meta and is not affiliated with it. WhatsApp is a trademark of Meta Platforms, Inc.