Trust

Compliance

WAFollow is built on the official WhatsApp Business Cloud API and designed so that responsible senders can stay inside Meta's policy and data-protection law.

How WAFollow works with Meta

  • WAFollow uses the official WhatsApp Cloud API — no unofficial or unauthorised access methods.
  • Each customer connects their own WhatsApp Business Account through Meta Embedded Signup.
  • Customers explicitly authorise WAFollow before any data is accessed.
  • WAFollow never accesses customer data without authorisation and never resells it.
  • Customers retain full ownership of their business data and can export or delete it at any time.
  • WAFollow complies with Meta Platform Policies and WhatsApp Business Platform Policies.

WhatsApp Business Messaging Policy

Every message sent through WAFollow is sent by you, from your own WhatsApp Business Account, under Meta's policies. The platform includes controls that make policy compliance practical:

  • Opt-in tracking: each contact stores consent state, source, and timestamp so you can evidence permission.
  • Automatic opt-out handling: STOP-style keywords mark a contact as opted out and exclude them from all future broadcasts and automations.
  • Template-only outreach: business-initiated messages must use a template approved by Meta; WAFollow blocks sends on unapproved templates.
  • 24-hour window awareness: the inbox shows when free-form replies are allowed and requires a template outside that window.
  • Quality signals: delivery, read, and block indicators surface early so you can slow down before your quality rating drops.
  • Prohibited content: our terms forbid categories banned by Meta's Commerce Policy, and we act on reports of abuse.

GDPR and India's DPDP Act

  • WAFollow is a processor for customer data and a controller for its own account and website data.
  • We offer a Data Processing Addendum on request covering purpose limitation, confidentiality, sub-processor terms, and breach notification.
  • Data subject requests — access, correction, deletion, portability, objection — are supported in-app and via data deletion.
  • International transfers rely on Standard Contractual Clauses or adequacy where applicable.
  • We practise data minimisation: WAFollow only stores the contact fields you choose to upload.
  • Breach notification: we notify affected customers without undue delay and within 72 hours of confirming a reportable personal data breach.

WAFollow does not currently hold SOC 2, ISO 27001, HIPAA, or PCI certification, and does not claim to. Card data never touches our servers — it is handled by our PCI-compliant payment processor.

Sub-processors

ProviderPurposeProcessing region
Meta Platforms, Inc.WhatsApp Business Cloud API message deliveryGlobal
Managed cloud database & hosting providerApplication hosting, database, authentication, file storageEU / US regions
Payment processorSubscription billing and invoicingEU / US
Transactional email providerAccount and notification emailsEU / US
AI model providerOptional AI assistant drafting and summarisationUS
Error monitoring providerCrash and performance diagnosticsEU / US

We notify customers before adding a sub-processor that processes customer personal data. Named provider details are available under NDA on request at legal@wafollow.in.