1. Data Controller
Flowauxi acts as the Data Controller for all Platform Data received from Meta, including WhatsApp Business API data. We determine the purposes and means of processing this data to provide our WhatsApp Business messaging services.
Location: India
2. Data Processors / Service Providers
The following third-party service providers process Platform Data on our behalf:
| Service Provider | Services | Location |
|---|
| Supabase Inc. | Database hosting, authentication | United States |
| Google Firebase | Authentication, push notifications | United States |
| Vercel Inc. | Application hosting, edge functions | United States |
All data processors:
- Process data only on our documented instructions
- Maintain strict confidentiality obligations
- Implement appropriate technical and organizational security measures
- Do not sub-process data without authorization
- Assist with data subject access requests
3. Platform Data We Process
| Data Type | Purpose | Retention |
|---|
| Meta User ID | Account linking | Duration of service + 30 days |
| WhatsApp Business Account ID | API communication | Duration of service + 30 days |
| Phone Number IDs | Message routing | Duration of service + 30 days |
| Message Template Names | Template management | Duration of service + 30 days |
| Access Tokens (encrypted) | API authentication | Until token expiry |
Data We Do Not Store
- End customer phone numbers beyond immediate conversation context
- Personal data not required for service operation
Analytics Data
Analytics data is aggregated and anonymized. Analytics data cannot be used to reconstruct individual conversations.
4. Government & Public Authority Requests
Requests received in past 12 months: Zero (0)
4.1 Our Policy on Government Requests
- Legal Review Requirement: All requests for user data from government or public authorities will be reviewed by legal counsel before any disclosure.
- User Notification: Where legally permitted, we will notify affected users of any government request for their data.
- Narrow Disclosure: We will only provide the minimum data necessary to comply with a valid legal order.
- Request Logging: All government requests and our responses are logged and documented.
- Jurisdictional Limits: We require proper legal process appropriate to our jurisdiction (India) before complying with requests.
4.2 Request Handling Process
- Receive request in writing
- Verify authenticity and authority of requester
- Review scope and legal validity with counsel
- Challenge overly broad or invalid requests
- Provide only data legally required
- Document and log the interaction
5. Data Security Measures
- Encryption at Rest: All Platform Data is encrypted using AES-256
- Encryption in Transit: TLS 1.3 for all API communications
- Access Controls: Role-based access controls (RBAC) for team members
- Token Security: Access tokens are encrypted before storage
- Audit Logging: All data access is logged and monitored
- Regular Reviews: Quarterly security reviews and updates
6. Data Subject Rights
Users and their customers can exercise the following rights:
- Access: Request a copy of their data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of their data
- Portability: Receive data in machine-readable format
- Objection: Object to certain processing activities
To exercise these rights, contact us at contact@flowauxi.com