1.Who we are
Sendrix is a WhatsApp messaging platform. For the account you create with us, we are the data controller. For the contacts and messages you put into it, you are the controller and we are your processor: they are your customers, not ours, and we act only on your instructions.
Sendrix is a Meta Tech Provider. Your WhatsApp Business Account is yours, connected to Meta through us rather than rented from us.
2.What we collect
Three things, kept apart:
- Your account. Name, email, password hash, workspace name, and who on your team has what role. Used to sign you in and to say who did what.
- Your customers. Phone numbers, names and any attributes you import, plus the messages sent and received and their delivery status. We hold these to send on your behalf and to show you what landed.
- Operational records. An activity log of actions taken in your workspace, and a log of API requests your integration makes. Both exist so questions about what happened have answers.
We do not sell any of it, we do not use your customers’ data to train anything, and we do not use it for our own marketing.
3.How it is kept apart
Every workspace’s data is isolated at the database level, not merely by a filter in our code. Each request runs inside a scope tied to one workspace, and the database refuses to return another workspace’s rows even if a query asks for them. A bug in our application cannot leak your data to another customer, because the layer that would have to be bypassed sits underneath it.
Your WhatsApp access tokens and app secrets are encrypted before they are stored, and are never returned by any interface, including our API.
4.Who else sees it
- Meta.Message content and recipient numbers go to WhatsApp, because that is what sending a WhatsApp message means. Meta’s own terms apply to what they do with it.
- Our infrastructure providers. Hosting, database and storage, plus an email provider for account emails such as password resets. They process data on our instructions and hold it no longer than we do.
- Your own webhook. If you configure one, we send message events to the URL you give us. Where that goes next is your decision.
Sendrix staff can enter a workspace to provide support. When that happens it is recorded in that workspace’s own activity log, attributed to the person, so you can always see when we were inside.
5.How long we keep it
- Contacts, messages and campaign history: as long as your account is open.
- API request logs: 90 days.
- Webhook delivery history: 30 days.
- Idempotency keys: 24 hours.
- Activity logs: the life of the account. They are append-only and cannot be edited, including by us, which is what makes them worth having.
Close your account and we delete your data within 30 days, except anything we are required to keep for tax or legal reasons.
6.Your customers' rights
Anyone you message can reply STOP, or the equivalent, and Sendrix records that as an opt-out immediately and refuses to send to them again, whether from a campaign or through the API. You do not have to do anything for this to work, and you cannot switch it off.
If one of your customers asks you to delete their data, removing the contact from your workspace removes it from ours. If they contact us directly we will point them to you, because they are your customer.
7.Your rights
You can export your contacts and message history from the console at any time, correct anything wrong from the same place, and delete your workspace. If you would rather we did any of that for you, email us.
Depending on where you live you may also have rights to object to processing or to complain to a data protection authority. Nothing here takes those away.
8.Security
Data is encrypted in transit. Credentials and secrets are encrypted at rest. API keys and webhook signing secrets are stored only as hashes, so they cannot be read back out by anyone, including us. Access to production is limited and logged.
If a breach affects your data, we will tell you what happened, what was involved, and what we did about it, without waiting to be asked.
9.Changes
If we change this in a way that matters, we will say so in the console before it takes effect rather than quietly changing the date at the top. The date is there so you can tell.
Questions, or a request about your data, go to [email protected]. See also our Terms.