Last Updated: February 2, 2026
At WhatsBot AI, we are fully committed to protecting your personal data and complying with the General Data Protection Regulation (GDPR). This page explains your rights under GDPR and how we fulfill our obligations as both a data controller and data processor.
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It applies to all organizations that process personal data of individuals in the European Union, regardless of where the organization is located. GDPR gives individuals more control over their personal data and imposes strict obligations on organizations that collect and process this data.
When we collect your personal data for our own purposes (account registration, billing, marketing), we act as a data controller. We determine how and why your data is processed.
When processing your customers' data through our WhatsApp automation platform, we act as a data processor on your behalf. You remain the data controller for your customers' data.
Under GDPR, you have the following rights regarding your personal data:
You can request a copy of all personal data we hold about you. We will provide this within 30 days of receiving your request.
If your personal data is inaccurate or incomplete, you have the right to have it corrected. You can update most information directly in your dashboard.
Also known as the "right to be forgotten," you can request deletion of your personal data under certain circumstances.
You can request that we limit how we use your data while we address concerns you have raised.
You can request your data in a structured, commonly used format (JSON/CSV) to transfer to another service.
You can object to processing of your data for direct marketing or processing based on legitimate interests.
You have the right not to be subject to decisions based solely on automated processing that significantly affects you.
Where processing is based on consent, you can withdraw that consent at any time without affecting prior processing.
We process personal data under the following lawful bases:
When you use WhatsBot AI to process your customers' data, we act as your data processor. Our Data Processing Agreement (DPA) covers:
When transferring personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place:
We retain personal data only for as long as necessary:
We implement appropriate technical and organizational measures to protect your data:
In the event of a data breach that is likely to result in a risk to your rights and freedoms:
You can exercise your GDPR rights in several ways:
Access, edit, and export your data directly from your account settings
Send a detailed request to dpo@whatsbot.ai
Complete our online data subject request form
Contact our support team for assistance
We will respond to all requests within 30 days. Complex requests may take up to 60 days, and we will inform you if an extension is needed.
Our Data Protection Officer oversees GDPR compliance:
Data Protection Officer
Email: dpo@whatsbot.ai
Address: 123 Innovation Street, Tel Aviv, Israel
If you are not satisfied with our response to your request or believe we are processing your data unlawfully, you have the right to lodge a complaint with a supervisory authority in your country of residence. For users in Israel, this is the Privacy Protection Authority (PPA).