W WhatsBotAI
  • Features
  • How It Works
  • Use Cases
  • Security
Login / Register

GDPR Compliance

Last Updated: February 2, 2026

Your Data, Your Rights

At WhatsBot AI, we are fully committed to protecting your personal data and complying with the General Data Protection Regulation (GDPR). This page explains your rights under GDPR and how we fulfill our obligations as both a data controller and data processor.

1. What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It applies to all organizations that process personal data of individuals in the European Union, regardless of where the organization is located. GDPR gives individuals more control over their personal data and imposes strict obligations on organizations that collect and process this data.

2. Our Role Under GDPR

As a Data Controller

When we collect your personal data for our own purposes (account registration, billing, marketing), we act as a data controller. We determine how and why your data is processed.

As a Data Processor

When processing your customers' data through our WhatsApp automation platform, we act as a data processor on your behalf. You remain the data controller for your customers' data.

3. Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

You can request a copy of all personal data we hold about you. We will provide this within 30 days of receiving your request.

Right to Rectification

If your personal data is inaccurate or incomplete, you have the right to have it corrected. You can update most information directly in your dashboard.

Right to Erasure

Also known as the "right to be forgotten," you can request deletion of your personal data under certain circumstances.

Right to Restrict Processing

You can request that we limit how we use your data while we address concerns you have raised.

Right to Data Portability

You can request your data in a structured, commonly used format (JSON/CSV) to transfer to another service.

Right to Object

You can object to processing of your data for direct marketing or processing based on legitimate interests.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that significantly affects you.

Right to Withdraw Consent

Where processing is based on consent, you can withdraw that consent at any time without affecting prior processing.

4. Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Contract: Processing necessary to fulfill our service agreement with you
  • Consent: Marketing communications and optional features (you can withdraw anytime)
  • Legitimate Interest: Security monitoring, fraud prevention, service improvement
  • Legal Obligation: Tax records, regulatory compliance, law enforcement requests

5. Data Processing Agreement

When you use WhatsBot AI to process your customers' data, we act as your data processor. Our Data Processing Agreement (DPA) covers:

  • The subject matter and duration of processing
  • Nature and purpose of data processing
  • Categories of personal data processed
  • Your rights and obligations as data controller
  • Our obligations as data processor
  • Sub-processor authorization and notification
  • Data breach notification procedures
  • Audit rights and compliance verification
Download our Data Processing Agreement

6. International Data Transfers

When transferring personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for countries with equivalent data protection
  • Binding Corporate Rules for intra-group transfers
  • Your explicit consent for specific transfers (when applicable)

7. Data Retention

We retain personal data only for as long as necessary:

Data Type Retention Period
Account information Duration of account + 30 days
Conversation logs According to your plan settings (default: 90 days)
Billing records 7 years (legal requirement)
Support tickets 2 years after resolution
Marketing data Until consent is withdrawn
Analytics data 26 months (aggregated)

8. Security Measures

We implement appropriate technical and organizational measures to protect your data:

  • End-to-end encryption for all data in transit (TLS 1.3)
  • AES-256 encryption for data at rest
  • Multi-factor authentication options
  • Regular security audits and penetration testing
  • Access controls and employee training
  • Incident response and data breach procedures
  • SOC 2 Type II certification
  • Regular backup and disaster recovery testing

9. Data Breach Notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms:

  • We will notify you within 72 hours of becoming aware of the breach
  • Our notification will describe the nature of the breach
  • We will provide contact details for our Data Protection Officer
  • We will describe likely consequences and measures taken
  • We maintain detailed records of all security incidents

10. How to Exercise Your Rights

You can exercise your GDPR rights in several ways:

Dashboard

Access, edit, and export your data directly from your account settings

Email Request

Send a detailed request to dpo@whatsbot.ai

Data Request Form

Complete our online data subject request form

Customer Support

Contact our support team for assistance

We will respond to all requests within 30 days. Complex requests may take up to 60 days, and we will inform you if an extension is needed.

11. Data Protection Officer

Our Data Protection Officer oversees GDPR compliance:

Data Protection Officer

Email: dpo@whatsbot.ai

Address: 123 Innovation Street, Tel Aviv, Israel

12. Supervisory Authority

If you are not satisfied with our response to your request or believe we are processing your data unlawfully, you have the right to lodge a complaint with a supervisory authority in your country of residence. For users in Israel, this is the Privacy Protection Authority (PPA).

Exercise Your Rights

Request access, deletion, or export of your personal data.

Submit Data Request
W WhatsBotAI

Transforming business communication with intelligent WhatsApp automation.

Product

  • Features
  • Use Cases
  • Security
  • Pricing

Company

  • About Us
  • Blog
  • Careers
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • GDPR

© 2026 WhatsBot AI. All rights reserved.