Helix Globe Helix Globe

Data Policy & Security

Data Policy & Security

Effective Date : 28 August 2026

We are committed to protecting the privacy, confidentiality, and security of customer data processed through our WhatsApp API services. This Data Policy & Security statement explains how we handle, protect, and process information when customers use our WhatsApp API platform.

1. Data We Process

Depending on the services used, we may process:

* Customer name, phone number, email address, and business information.
* WhatsApp messages and communication content submitted through the API.
* WhatsApp Business Account (WABA) and phone number information.
* Message templates, media files, documents, and other content submitted by customers.
* Delivery, read, failed, and message status information.
* API logs, technical information, IP addresses, and system activity required for security and troubleshooting.
* CRM, lead, customer, or contact information that the customer chooses to integrate with our platform.

We only process data that is necessary to provide, maintain, secure, and improve our services.

2. WhatsApp API Data

Our platform may integrate with the **WhatsApp Business Platform provided by Meta**. WhatsApp-related data may be processed through Meta's infrastructure and APIs in accordance with the applicable Meta and WhatsApp Business terms and policies.

Customers are responsible for ensuring that their use of WhatsApp API complies with applicable WhatsApp Business policies, Meta policies, privacy laws, and applicable regulations.

3. Data Security

We implement reasonable technical and organizational security measures designed to protect customer data against unauthorized access, alteration, disclosure, loss, or destruction.

Security measures may include:

* Encrypted communication using HTTPS/TLS.
* Secure authentication and authorization mechanisms.
* Access controls based on user roles and permissions.
* Restricted access to customer information.
* Secure database and server configurations.
* Monitoring and logging of system activity.
* Regular security updates and maintenance.
* Backup and recovery procedures.
* Protection against unauthorized API access.
* Secure handling of API credentials, tokens, and authentication information.

4. Access Control

Access to customer data is limited to authorized personnel and systems that require access to perform legitimate business or technical functions.

Employees, contractors, and service providers with access to confidential information are expected to maintain appropriate confidentiality and security obligations.

5. API Credentials & Tokens

Customers are responsible for maintaining the confidentiality of their API credentials, access tokens, passwords, webhook verification tokens, and other authentication information.

Customers should:

* Never share API tokens publicly.
* Immediately notify us if credentials are compromised.
* Use secure passwords and authentication methods.
* Regularly review connected applications and user permissions.

We will never intentionally request sensitive authentication credentials through unsecured communication channels.

6. Data Storage & Retention

Customer data is retained only for as long as reasonably necessary to provide the services, meet contractual requirements, maintain security, resolve disputes, comply with legal obligations, or fulfill legitimate business purposes.

When data is no longer required, it may be deleted, anonymized, or securely disposed of in accordance with our applicable retention procedures.

Certain technical logs and records may be retained for a reasonable period for security, fraud prevention, troubleshooting, auditing, and legal compliance.

7. Data Sharing

We do not sell customer data.

Customer information may be shared with or processed by:

* Meta/WhatsApp, where required for WhatsApp Business API functionality.
* Hosting and cloud infrastructure providers.
* Payment processors, where applicable.
* Technical service providers required to operate our platform.
* Professional advisers or authorities where legally required.

Third-party service providers are expected to handle information only for authorized purposes and maintain appropriate security measures.

8. Customer Responsibility

Customers are responsible for:

* Obtaining appropriate consent before sending promotional or other communications where required.
* Using WhatsApp API in accordance with applicable laws and WhatsApp/Meta policies.
* Providing accurate and lawful customer data.
* Protecting their account credentials.
* Ensuring that sensitive or confidential information is handled appropriately.
* Maintaining their own privacy policy where required.

Our platform should not be used to unlawfully collect, disclose, or distribute personal information.

## 9. Sensitive Information

Customers should avoid sending highly sensitive personal information through WhatsApp or our platform unless such processing is necessary, lawful, and appropriately protected.

Examples may include passwords, financial account credentials, authentication codes, or other information that could create significant risk if compromised.

10. Data Breach & Security Incidents

If we become aware of a security incident that materially affects customer data, we will take reasonable steps to investigate, contain, and remediate the incident.

Where required by applicable law or contractual obligations, affected customers or relevant authorities will be notified within the applicable timeframe.

11. International Data Processing

Depending on the infrastructure and third-party services used, customer information may be processed or stored in locations outside the customer's country.

Where applicable, we take reasonable measures to ensure that such processing is conducted in accordance with applicable data protection requirements.

12. Data Deletion Requests

Customers may request deletion of their data, subject to applicable contractual, legal, regulatory, security, and operational requirements.

Requests may be reviewed and processed within a reasonable period after verification of the requester's identity and authority.

13. Security Limitations

Although we take reasonable measures to protect information, no internet-based service, API, database, or electronic transmission can be guaranteed to be completely secure.

Customers acknowledge that they use the service at their own risk and should implement appropriate security controls within their own systems and integrations.

14. Policy Updates

We may update this Data Policy & Security statement from time to time to reflect changes in our services, technology, security practices, legal requirements, or third-party integrations.

The updated version will be made available through our website or platform.

15. Contact Us

If you have questions regarding data privacy, security, data deletion, or this policy, please contact our support or privacy team through the contact details provided on our website.

Contact : info@helixglobe.in

Important : This policy describes our general security practices and does not replace the applicable Meta/WhatsApp Business Platform terms, privacy requirements, or any legally required privacy notice.
← Back to Helix Globe