Privacy Policy

Last updated: October 1, 2026

Draft. This document is pending review by a Colombian lawyer and is not a certification of legal compliance. Fields marked [pending] must be completed before final publication.

1. Scope

This policy describes how Veflat SAS processes personal data when you use the Veflat WhatsApp website, application and API, and when one of our business customers uses Veflat WhatsApp to serve its own customers over WhatsApp. It is governed by Colombian Statutory Law 1581 of 2012, Decree 1377 of 2013 (compiled in Decree 1074 of 2015) and other Colombian personal data protection rules (Habeas Data).

2. Who is responsible

  • Legal name: Veflat SAS, NIT 901475872 [pending: confirm the NIT against the certificate of existence and legal representation].
  • Seat: Medellín, Colombia. Physical address for notices: [pending].
  • Contact for inquiries, claims and exercising your rights: soporte@veflat.com.
  • National Database Registry (RNBD) with the Superintendence of Industry and Commerce (SIC): [pending: determine whether it applies and, if so, register].

3. Our roles: controller and processor

Veflat SAS acts in two different roles depending on whose data it is:

  • Data controller (responsable): for the data of people who create a Veflat WhatsApp account (account holders, agents and administrators) and for the organization's billing data.
  • Data processor (encargado): for the data of our business customers' end customers, meaning the people who message the business's WhatsApp number and whose data the business uploads, receives or manages in Veflat WhatsApp. In that case the business customer is the controller. We process that data only to provide the service and following the business's instructions.

Each business customer is responsible for obtaining the prior, express and informed authorization (opt-in) of its own customers to contact them over WhatsApp, for giving them its own data processing notice and for answering their requests. Veflat SAS will reasonably help it do so.

4. What data we process

We only process data that the product actually stores:

  • Account: name, email, password (only an argon2 hash is stored, never the plaintext), role within the organization, and sessions (we store the hash of the refresh token, not the token).
  • Organization and brand: organization and workspace names and, if you set them, product name, logo, color and custom domain.
  • WhatsApp channel: phone number ID and WhatsApp Business Account (WABA) ID, display name, profile picture and granted scopes. The access token is stored encrypted.
  • End customers of the business customer: WhatsApp identifier (which corresponds to their phone number), profile name, the text of messages sent and received with their date and status (sent, delivered, read, failed), a record of the automations that ran, a flag that they asked for a person and, if the business enables Email Gate, the email address the person types in. For media files only a placeholder is stored, not the file.
  • Agent work: conversation assignment, labels and internal notes.
  • Usage events: messages sent, link clicks, leads captured and gates completed. For clicks we store the approximate country and city; the IP address is used only to compute them and is not stored.
  • WhatsApp events as delivered by Meta (webhook payload), needed to process and retry messages.
  • Billing: plan, period, amount, currency, applied exchange rate and customer, subscription and payment identifiers at the payment processor. We do not store card numbers.
  • Audit: a record of who exported contacts and how many rows.

We do not ask for sensitive data or data of minors, and business customers are prohibited from using the service to collect it without the authorization the law requires.

5. Why we use the data

  • Create and manage your account, authenticate you and protect access.
  • Connect your WhatsApp Business number and send and receive messages through Meta's official API.
  • Run the automations you configure (keywords, welcome, out-of-hours, handoff to a person, FAQ), and show the shared inbox and contacts.
  • Measure results (messages, clicks, leads) and enforce the plan's message quota.
  • Charge the subscription and message packs, and meet accounting and tax obligations.
  • Prevent abuse and fraud, keep the service secure and answer support requests.
  • Comply with legal obligations and respond to requests from competent authorities.

We do not sell personal data or use it for third-party advertising.

6. Authorization and legal basis

  • Account holders: we process your data with your prior, express and informed authorization, which you give when you register and accept this policy and the terms of service, and to perform the contract you enter into with us.
  • End customers of a business: the business customer, as controller, obtains authorization before contacting them or receiving their messages. Veflat SAS processes the data as processor under the service contract.
  • Where the law requires it or an authority orders it, we may process or retain data without the data subject's authorization.

You may revoke your authorization or request deletion of your data at any time, except where there is a legal or contractual duty to retain it.

7. Third parties, transmissions and international transfers

To provide the service we share or transmit data with these providers, some of them outside Colombia:

  • Meta Platforms (WhatsApp Business Platform / WhatsApp Cloud API): receives and delivers messages and is the source of events. It has its own privacy policy and terms.
  • Hosting provider (VPS server where the application and database run): [pending: provider name and data center country].
  • Cloudflare (network and security): [pending: confirm whether it is active in production].
  • Payment processors: Mercado Pago and Wompi (Colombia, payments in pesos) and PayPal (international payments in dollars). They receive the data needed to charge; we do not see or store card data.
  • Google Fonts: the interface loads fonts from Google servers, which may receive your IP address when loading them.
  • OpenAI (AI drafts): NOT active today. If it is enabled in the future, we will update this policy before sending data to that provider.

When data travels to a country other than Colombia, we do so based on the data subject's authorization or on transmission agreements and the provider's terms, in line with Law 1581 of 2012 [pending: legal review of transmission and international transfer clauses].

8. Retention

  • We keep data while your account is active and for as long as needed to provide the service.
  • Today there is no automatic purge by age of messages and contacts: they are deleted when a deletion request or account closure is handled [pending: define retention periods per data category].
  • Billing, accounting and tax records are kept for the period required by Colombian law [pending: confirm period].
  • Event and security logs are kept as long as needed for security, support and defense against claims.
  • Backups are removed through rotation [pending: state the period].

9. Security

We apply the following measures, which exist in the product today:

  • Channel access tokens, webhook secrets and refresh tokens are stored encrypted or hashed, and are never written to logs or returned to the browser.
  • Passwords are stored with an argon2 hash and refresh tokens are rotated on every use.
  • We only accept events from Meta, Mercado Pago, Wompi and PayPal with a valid signature; an event without a valid signature is rejected and not stored.
  • Each organization and workspace can only access its own data; requesting a resource from another organization returns not found.
  • The IP address of link clicks is not stored.

No system is completely invulnerable. If we detect an incident affecting your data, we will act as the law requires and, where appropriate, inform affected people and the competent authority.

10. Data subject rights

As a data subject you have the right to:

  • Know the data we process and how we use it.
  • Update and rectify it when it is inaccurate or incomplete.
  • Request proof of the authorization you gave.
  • Be informed, on request, of how your data has been used.
  • Revoke the authorization and request deletion of your data, when there is no legal or contractual duty to retain it.
  • File complaints with the Superintendence of Industry and Commerce (SIC) for violations of the law, after exhausting the inquiry or claim process with us.

How to exercise them: write to soporte@veflat.com with your name, a contact method, the data your request refers to and what you are asking for. We may ask for information to verify your identity.

  • Inquiries (consultas): we answer within 10 business days of receipt. If that is not possible, we will tell you why and give a new date, which will not exceed 5 additional business days.
  • Claims (reclamos: correction, update, deletion or revocation): we answer within 15 business days from when the request is complete. If that is not possible, we will tell you why and give a new date, which will not exceed 8 additional business days. If the claim is incomplete, we will tell you within 5 days so you can complete it.

If you are an end customer of a business that uses Veflat WhatsApp, you can contact that business first, as it is responsible for your data; you can also write to us and we will forward your request to the business. For step-by-step deletion, see the Data Deletion page.

11. Data deletion

Full instructions to request deletion of your data are at Data Deletion. In short: email soporte@veflat.com with the subject line "Data deletion" from your account email, or specifying your WhatsApp Business number, and we will answer within 15 business days.

12. Cookies and local storage

We use the minimum necessary and we do not use advertising or third-party analytics cookies:

  • NEXT_LOCALE cookie: remembers the language you chose; lasts up to 1 year.
  • Browser session storage (sessionStorage): keeps your signed-in session and the active workspace; it is cleared when you close the tab.
  • Local storage (localStorage): remembers the period selected in the analytics dashboard.

13. Children

Veflat WhatsApp is intended for businesses and people over 18. We do not knowingly collect data from children and teenagers. If you believe a minor gave us data, write to soporte@veflat.com so we can delete it. Business customers must not process minors' data without their legal representatives' authorization and compliance with the applicable special rules.

14. Changes to this policy

If we update this policy, we will post the new version on this page with its date. For material changes we will let you know by a reasonable means, for example the email on your account. See also the Terms of Service.

15. Contact

Veflat SAS, Medellín, Colombia. Email: soporte@veflat.com.

Privacy Policy | Veflat WhatsApp