Trust
Compliance
WAFollow is built on the official WhatsApp Business Cloud API and designed so that responsible senders can stay inside Meta's policy and data-protection law.
How WAFollow works with Meta
- WAFollow uses the official WhatsApp Cloud API — no unofficial or unauthorised access methods.
- Each customer connects their own WhatsApp Business Account through Meta Embedded Signup.
- Customers explicitly authorise WAFollow before any data is accessed.
- WAFollow never accesses customer data without authorisation and never resells it.
- Customers retain full ownership of their business data and can export or delete it at any time.
- WAFollow complies with Meta Platform Policies and WhatsApp Business Platform Policies.
WhatsApp Business Messaging Policy
Every message sent through WAFollow is sent by you, from your own WhatsApp Business Account, under Meta's policies. The platform includes controls that make policy compliance practical:
- Opt-in tracking: each contact stores consent state, source, and timestamp so you can evidence permission.
- Automatic opt-out handling: STOP-style keywords mark a contact as opted out and exclude them from all future broadcasts and automations.
- Template-only outreach: business-initiated messages must use a template approved by Meta; WAFollow blocks sends on unapproved templates.
- 24-hour window awareness: the inbox shows when free-form replies are allowed and requires a template outside that window.
- Quality signals: delivery, read, and block indicators surface early so you can slow down before your quality rating drops.
- Prohibited content: our terms forbid categories banned by Meta's Commerce Policy, and we act on reports of abuse.
GDPR and India's DPDP Act
- WAFollow is a processor for customer data and a controller for its own account and website data.
- We offer a Data Processing Addendum on request covering purpose limitation, confidentiality, sub-processor terms, and breach notification.
- Data subject requests — access, correction, deletion, portability, objection — are supported in-app and via data deletion.
- International transfers rely on Standard Contractual Clauses or adequacy where applicable.
- We practise data minimisation: WAFollow only stores the contact fields you choose to upload.
- Breach notification: we notify affected customers without undue delay and within 72 hours of confirming a reportable personal data breach.
WAFollow does not currently hold SOC 2, ISO 27001, HIPAA, or PCI certification, and does not claim to. Card data never touches our servers — it is handled by our PCI-compliant payment processor.
Sub-processors
| Provider | Purpose | Processing region |
|---|---|---|
| Meta Platforms, Inc. | WhatsApp Business Cloud API message delivery | Global |
| Managed cloud database & hosting provider | Application hosting, database, authentication, file storage | EU / US regions |
| Payment processor | Subscription billing and invoicing | EU / US |
| Transactional email provider | Account and notification emails | EU / US |
| AI model provider | Optional AI assistant drafting and summarisation | US |
| Error monitoring provider | Crash and performance diagnostics | EU / US |
We notify customers before adding a sub-processor that processes customer personal data. Named provider details are available under NDA on request at legal@wafollow.in.