How we protect your data
Your customers’ conversations pass through this software. Here is where they are held, who can reach them, how long we keep them, and what you can check for yourself without asking us.
Last verified 2026-10-03 — against the running service and the privacy policy, which is the authority for every retention figure below.
Where your data is
In the European Union.
The service runs on Amazon Web Services in a European Union region, on infrastructure we operate. Messages, contacts, media files and configuration are held there.
Backups are held in the same region, with a disaster-recovery copy in a second European Union region. No part of the service, and no backup, is held outside the EU.
Messages themselves necessarily pass through Meta: on the WhatsApp Business Platform Meta delivers them and reports delivery and read status back, under its own terms with you. That is the platform, not a choice we make on your behalf.
Encryption
In transit, at rest, and one layer above that.
In transit
HTTPS everywhere, with HSTS on every response — so a browser that has visited once will not be downgraded to plain HTTP on a hostile network. You can see the header on this page.
At rest
The database and its backups are encrypted at rest. Media files are encrypted in object storage with a managed key, held outside any public web root, and served only through short-lived signed links.
And one layer above
The most sensitive values — WhatsApp connection credentials and Bitrix24 authorisation tokens — are encrypted by the application with AES-256-GCM before they reach the database, so a database copy on its own does not yield them.
Who can reach what
Four roles, and a hard tenant boundary.
- Roles. Administrator, manager, agent and viewer. A number can be owned by one person or shared, so a sales number need not be visible to everyone.
- The tenant boundary is structural, not a filter. Which account a request belongs to comes from the verified session and never from anything in the request. A conversation that belongs to another account answers not found, not forbidden — so a probe cannot even confirm that it exists.
- API keys are stored only as a hash. A key cannot be read back out of the product by anyone, including us. Every key carries scopes, and every failure — unknown, revoked, expired, malformed — answers identically, so a failed attempt cannot be used to learn that a key once existed.
- Our own staff access is for support and is logged. Account-level actions taken from the administration console are written to an activity log on your account.
What we keep, and for how long
The same figures as the privacy policy.
- While you are a customer: conversations, contacts, media and configuration, so the product works.
- After you uninstall or close the account: everything we hold for that account is deleted automatically after 30 days. The 30 days exist so that reinstalling within the month does not lose your history.
- Backups: database backups are kept 35 days; the disaster-recovery copy of those backups in a second EU region is kept 120 days; both then expire automatically. When a media file is deleted, it is deleted from the replica too and removed from it for good after 30 days.
- Earlier deletion on request. An administrator can ask for earlier deletion, a copy of the account’s data, or correction of inaccurate data, at any time. How to ask.
Who else touches your data
A short list, named.
- Meta Platforms — delivers messages on the WhatsApp Business Platform and reports delivery and read status back.
- Bitrix24 — where the integration is used, message content and contact data are written into your own portal’s Open Channels and CRM. That is the purpose of the integration.
- Amazon Web Services — hosting, in the EU.
- Stripe — billing. Card details are entered directly with Stripe and are never seen or stored by us.
We do not sell or trade personal data, and there is no advertising network, analytics provider or data broker in that list. The full statement, including requests from public authorities, is in the privacy policy.
What you can check yourself, right now
On this page, in ten seconds.
Open your browser’s developer tools on this page and look at the network tab.
- Zero third-party requests. No font CDN, no analytics script, no tag manager, no pixel, no remote image, no cookie banner — because there is nothing to consent to. The typeface is served from this domain.
- No cookie at all on this website. We do not count you, and the page you are reading does not need to know who you are.
- HSTS on every response, and no
Content-Encodingsurprises: it is one HTML document and one stylesheet.
That is worth checking on the other vendors you are evaluating too. Across this category it is common for a marketing page to ship every visitor’s IP address to a font CDN and an analytics provider, including for companies selling into the EU, and for the marketing host to carry no framing protection and no HSTS at all.
Inside the product the rules are tighter rather than looser: the sign-in pages refuse to be framed at all, and the application’s own pages are served with instructions not to be indexed.
Reporting a vulnerability
Tell us, and we will answer.
If you believe you have found a security problem, write to privacy@saabsoft.com — the same mailbox the privacy policy publishes — with enough detail to reproduce it. We will acknowledge it, tell you what we find, and credit you if you would like us to.
Please do not test against a customer’s live account or a real WhatsApp number that is not yours. If you need an account to test against, ask us and we will arrange one.
We do not run a paid bounty programme today, and we would rather say so than let you assume one.
Questions
The ones buyers ask in procurement.
Do you have ISO 27001 or SOC 2?
Not today, and we will not imply otherwise. What we can give you is this page, the privacy policy, and a direct conversation with the people who operate the service — ask us and you will reach them rather than a form.
Can we sign a data processing agreement?
Yes. For the conversation data in your account we are the processor and you are the controller, which the privacy policy states. Ask us for the agreement.
Where exactly is the data, down to the region?
In an Amazon Web Services region in the European Union, with the disaster-recovery copy in a second EU region. We will name both regions to a customer under an agreement; we do not publish the exact region names here, for the same reason we do not publish our infrastructure topology.
What happens to our data if we stop paying?
Nothing is deleted because an invoice failed. Sending stops when a subscription has genuinely lapsed; data is deleted 30 days after the account is closed or the application is uninstalled, which is a deliberate act and not a billing event.
Do you train anything on our conversations?
No. Your conversations are not used to train any model, ours or anyone else’s.
Read the rest of it
The privacy policy is the authority on retention and on who processes what. It is short, and it is written to be read.