Data Handling Policy

Last Updated: December 25, 2024

1. Data Controller

Flowauxi acts as the Data Controller for all Platform Data received from Meta, including WhatsApp Business API data. We determine the purposes and means of processing this data to provide our WhatsApp Business messaging services.

Location: India

2. Data Processors / Service Providers

The following third-party service providers process Platform Data on our behalf:

Service ProviderServicesLocation
Supabase Inc.Database hosting, authenticationUnited States
Google FirebaseAuthentication, push notificationsUnited States
Vercel Inc.Application hosting, edge functionsUnited States

All data processors:

  • Process data only on our documented instructions
  • Maintain strict confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Do not sub-process data without authorization
  • Assist with data subject access requests

3. Platform Data We Process

Data TypePurposeRetention
Meta User IDAccount linkingDuration of service + 30 days
WhatsApp Business Account IDAPI communicationDuration of service + 30 days
Phone Number IDsMessage routingDuration of service + 30 days
Message Template NamesTemplate managementDuration of service + 30 days
Access Tokens (encrypted)API authenticationUntil token expiry

Data We Do Not Store

  • End customer phone numbers beyond immediate conversation context
  • Personal data not required for service operation

Analytics Data

Analytics data is aggregated and anonymized. Analytics data cannot be used to reconstruct individual conversations.

4. Government & Public Authority Requests

Requests received in past 12 months: Zero (0)

4.1 Our Policy on Government Requests

  1. Legal Review Requirement: All requests for user data from government or public authorities will be reviewed by legal counsel before any disclosure.
  2. User Notification: Where legally permitted, we will notify affected users of any government request for their data.
  3. Narrow Disclosure: We will only provide the minimum data necessary to comply with a valid legal order.
  4. Request Logging: All government requests and our responses are logged and documented.
  5. Jurisdictional Limits: We require proper legal process appropriate to our jurisdiction (India) before complying with requests.

4.2 Request Handling Process

  1. Receive request in writing
  2. Verify authenticity and authority of requester
  3. Review scope and legal validity with counsel
  4. Challenge overly broad or invalid requests
  5. Provide only data legally required
  6. Document and log the interaction

5. Data Security Measures

  • Encryption at Rest: All Platform Data is encrypted using AES-256
  • Encryption in Transit: TLS 1.3 for all API communications
  • Access Controls: Role-based access controls (RBAC) for team members
  • Token Security: Access tokens are encrypted before storage
  • Audit Logging: All data access is logged and monitored
  • Regular Reviews: Quarterly security reviews and updates

6. Data Subject Rights

Users and their customers can exercise the following rights:

  • Access: Request a copy of their data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of their data
  • Portability: Receive data in machine-readable format
  • Objection: Object to certain processing activities

To exercise these rights, contact us at contact@flowauxi.com

7. Contact Information

Email: contact@flowauxi.com

Data Protection Contact: Flowauxi Data Protection Team

Location: India