Who we are
The company responsible for this website and for the service described on it is:
OCTATECH SOLUTIONS LLC
8 The Green, Suite 16165
Dover, Delaware 19901-3618, United States
Phone: +1 754 294 9576
Email: [email protected]
Referred to below as "Octatech" or "we". We use "business client" for the company that hires us and owns a WhatsApp Business account, and "consumer" for the person who messages that company on WhatsApp.
Our role: we act on behalf of the business client
Octatech is a Tech Provider on WhatsApp Business Platform. With respect to the conversations that take place on a business client's number, Octatech acts as a processor (also called a "service provider"): we process that data following the business client's documented instructions and solely to deliver the service they contracted.
The business client is the controller of its own conversations and of the relationship with the consumers who message it. If you are a consumer and want to know why a particular business keeps your messages, that business has the answer; you can still write to us and we will route the request, as described in § 10.
Octatech acts as a controller only for its own administrative data: the contact details of the people who work at a business client and use our panel, billing records, and commercial enquiries we receive at [email protected].
What data we process
Data received through Meta's platforms
- Message content exchanged on the business client's WhatsApp number: text and, where the consumer sends them, images, audio, documents and locations.
- The consumer's phone number and the identifier WhatsApp assigns to that conversation.
- The public profile name the consumer has set in WhatsApp.
- Message metadata: date and time, direction (inbound or outbound), delivery and read status, message type, and — when the conversation originates from a Click to WhatsApp ad — the ad and campaign identifiers.
- Business account information obtained during connection: the WhatsApp Business Account (WABA) identifier, associated phone numbers, business display name, message templates, number quality rating and messaging limits, and the advertising account identifier where the business also contracts campaign management.
Data the business client gives us directly
- Business information uploaded so the assistant can answer: catalogue, prices, stock, opening hours, delivery policies, frequently asked questions.
- Panel user data: name, email, phone, role and activity log within the panel.
- Billing and administrative contact details.
Technical data from this website
This site is static. It uses no cookies and contains no analytics, no tracking pixels, no third-party scripts and no external fonts. The web server records standard access data (IP address, date and time, requested resource, user agent) for operation and security, and those logs are kept for a maximum of 30 days.
Why we use the data
We process the data described above for a single purpose: to deliver the service the business client contracted. Specifically:
- Receiving messages addressed to the business's number and sending replies on its behalf.
- Generating the assistant's reply from the business's own information.
- Displaying conversations in the panel so the business's team can read, answer and escalate them.
- Producing that business's results reports, including ad-to-conversation attribution where the business contracts campaign management.
- Operating, maintaining and securing the service: technical logs, error diagnosis, backups and abuse prevention.
- Complying with applicable legal obligations.
The basis for processing conversation data is the performance of the service agreement with the business client and its instructions. For our own administrative data, the basis is performance of the contract and our legitimate interest in managing the commercial relationship. We do not use platform data for our own advertising, to build profiles of individuals, or for any purpose unrelated to the service.
What we do not do
These commitments are unconditional:
- We do not sell data. Not consumer data, not business client data, to anyone, under any circumstances.
- We do not share data with third parties beyond what is strictly necessary to deliver the service, as set out in § 6, and what a legal obligation requires.
- We never combine data from different business clients. Each business is logically isolated from the rest. One client's conversations are not used to answer, analyse or evaluate another's.
- We do not train models on the data. We do not use conversation content to train or fine-tune AI models, our own or third parties', and we contract model providers under terms that exclude that use.
- We do not use Meta platform data for advertising and we do not cross-reference it with external sources to enrich profiles.
Providers involved in the service
To deliver the service we rely on a limited set of providers acting as sub-processors, always under contract, bound by confidentiality and with no right to use the data for their own purposes. The categories are:
- Meta Platforms, as the operator of WhatsApp Business Platform and of the advertising platforms. It is the origin of the messages and the channel through which replies are sent.
- Cloud infrastructure providers: the servers, databases and storage where the platform runs and where conversations are held.
- AI model providers: they process the text needed to generate the assistant's reply. They are contracted under enterprise terms that exclude training on the data submitted.
- Transactional email providers, for panel notifications and alerts.
- Monitoring and error-logging tools, required to keep the service running.
We do not publish the named list of providers on this page because it can change. Any business client can request the current, up-to-date list by writing to [email protected], and we will provide it.
How we obtain access, and how it ends
The business client connects its own WhatsApp Business account through Meta's official Embedded Signup flow. It is an OAuth authorisation: the business signs in to Meta and grants the permission. Octatech neither receives nor requests passwords or verification codes.
The WhatsApp Business account and the phone number remain the property of the business client. The business can revoke Octatech's access at any time from its own Meta Business settings, without asking us and without notice. From that moment we stop receiving messages and lose access to the account. Step-by-step instructions are on the data deletion page.
How long we keep the data
- Conversations and their metadata: for as long as the agreement with the business client is in force, and at most 12 months from the last message in that conversation, unless the business client instructs a shorter period in writing. Any business client may ask us for a shorter retention period.
- On termination: we delete or return that business's data within 90 days, at the business's choice.
- Individual deletion requests: executed within 30 days, as described in § 10.
- Backups: they rotate and are overwritten within a maximum of 35 days. Data deleted from the live system disappears from backups within that cycle.
- Billing records: kept for as long as applicable accounting and tax rules require.
- Web server access logs: 30 days.
Security and data location
We apply technical and organisational measures that are reasonable and proportionate to the service: encryption in transit (TLS) on all connections, role-based access control with individual credentials in the panel, logical isolation of each business client's data, staff access limited to those who need it to operate the service, activity logging, and encrypted backups.
Octatech is a United States company and its infrastructure is hosted in provider data centres in the United States and the European Union. Data relating to consumers in Argentina and other countries is transferred to and processed in those locations in order to deliver the service, on the basis of the agreement with the business client and the contractual clauses we sign with our providers.
No system is infallible. Should a security breach affecting personal data occur, we will notify the affected business clients without undue delay and support the notifications they are required to make.
Your rights: access, correction and deletion
Anyone can ask to access the data we hold about them, correct it, have it deleted, object to its processing, or receive a copy. Requests go to [email protected].
The full procedure, including what to include in the request, is on the Data deletion page. We answer every request within 30 days.
Where the request concerns conversations belonging to a business client, Octatech acts as a processor: we forward the request to that business and carry out the deletion on its instruction, within the same 30-day window. There is no charge for this.
If you believe we have not handled your request properly, you can complain to the data protection authority in your country of residence.
Minors
The service is aimed at businesses and their communication with adult customers. It is not intended for people under 16, and we do not knowingly collect data about minors. If we discover, or are informed, that we hold a minor's data without a basis for doing so, we delete it.
Changes to this policy
If we amend this policy we update the date in the heading and publish the new version at this same address. Where a change materially affects how we process data, we notify business clients by email before it takes effect.
Contact
OCTATECH SOLUTIONS LLC
8 The Green, Suite 16165
Dover, Delaware 19901-3618, United States
[email protected] · +1 754 294 9576