Customer data protection

Data Security

How identity, organisation access controls, protected integrations and cloud infrastructure help safeguard information processed through Whapp.

Updated 9 September 2026

Overview

Whapp provides a shared workspace for business messaging, customer collaboration and optional automation. Our security approach combines identity verification, organisation-based access controls, protected integrations and established cloud infrastructure services. This overview explains how those layers help protect customer information and how security responsibilities are shared between Whapp, its customers and service providers.

How Whapp works with Meta

Whapp exchanges supported messaging and business-asset information with Meta through authorised APIs and webhooks. This can include messages, delivery events, WhatsApp Business Account details, phone-number information and message templates.

Customers retain control of their Meta business assets and grant Whapp defined access through Meta’s authorisation flow. Whapp does not need a customer’s Facebook password to connect authorised assets.

Meta synchronisation does not make Whapp a complete mirror or backup of a customer’s Meta account. History, media availability and delivery of changes remain subject to Meta’s supported interfaces, permissions and retention rules. Deletion in one service should not be assumed to delete independent copies held by another service.

Information processed by Whapp

Meta-synchronised records

•

Messaging records can include supported inbound and outbound messages, sender or recipient identifiers, timestamps and delivery or read events.

•

Connected business assets can include account identifiers, phone numbers, display names, templates and supported Facebook or Instagram assets where those integrations are enabled.

•

Message records can contain Meta media identifiers. Authorised attachment requests are checked against the customer organisation before media is retrieved from Meta.

Whapp-created records

•

Collaboration records can include organisation membership, assigned roles, invitations, conversation ownership and operational records used to coordinate a team.

•

Business workflow records can include knowledge documents or extracted content, AI instructions, calendar bookings, reminders, quotations and reports, depending on enabled features.

•

Security and operational records can include protected connection credentials, configuration, selected audit events, troubleshooting logs and terms-acceptance evidence.

Integrations and automation

Where a customer enables integrations or automation, relevant information may also be processed by the selected services. These may include n8n workflows, AI providers, calendar services and realtime updates. The services and data flows used for a customer depend on the functionality enabled for that organisation.

Whapp processes readable message content where required to provide the shared inbox and selected automation features. Encryption in transit or at rest does not mean content is inaccessible to the authorised service while it is being processed.

Cloud infrastructure and service providers

Hosting and data storage

Whapp uses Auth0 for hosted identity and sign-in services, Vercel for application hosting and server routes, and Neon PostgreSQL for persistent application records. DigitalOcean may support additional infrastructure workloads. The services involved depend on the deployed Whapp functionality.

Auth0 processes identity and session information while Whapp applies its own organisation permissions. Whapp’s application database does not need to store users’ plaintext login passwords.

Vercel publishes encryption-in-transit, encryption-at-rest and platform DDoS protections. Neon publishes mandatory encrypted database connections and encryption at rest. DigitalOcean operates under a shared-responsibility model for its underlying infrastructure and customer-managed workloads.

Provider assurance

Provider certifications and published security features apply to each provider’s stated service scope. Whapp remains responsible for its application permissions, secrets, deployment access, configuration and the information returned by its endpoints.

Application security controls

Identity and access management

Protected actions require a signed-in user with an active organisation membership and an authorised role. Available roles include owner, admin, supervisor, agent and billing viewer. Administrative functions control who can invite members, change roles or revoke access.

Invitation acceptance validates the invitation token, expiry, status and signed-in email. Revoking a member disables that organisation membership, records the selected audit event and cancels outstanding invitations for that member in the organisation.

Organisation isolation and multi-tenancy

Whapp is a multi-tenant platform. Customer information is logically separated through organisation-scoped access controls. Protected application routes resolve the signed-in user to an active organisation membership and use the organisation identifier to scope access to customer records. Users are not granted access to another organisation merely because they hold a valid Whapp identity.

Logical tenant separation does not mean that every customer receives a physically separate database. Customers should maintain individual user accounts, apply least-privilege access and promptly revoke access for staff who leave or change roles.

Encryption and protected credentials

Inspected integration-token storage paths use AES-256-GCM authenticated encryption with a random nonce. Encryption keys are loaded from server-side environment configuration, and encrypted records include a key-version field.

Authorised server-side integration operations use access tokens only within the permissions granted through the relevant customer and provider connection.

Request validation and audit records

Inspected Meta webhook handlers verify HMAC request signatures against the application secret. Selected internal integration endpoints also validate shared credentials. Authorised attachment retrieval checks the message organisation before an appropriate Meta token is used.

Whapp records selected security and administration events, including invitation activity, role changes and access revocation. Terms-acceptance records include identity snapshots, the accepted terms version, a content hash and a timestamp.

Data lifecycle and offboarding

Retention, backups and recovery

Retention and deletion controls apply to relevant synchronised records, Whapp-created records, integration payloads, logs and backups. Information is retained only while required for service delivery, security, legal, accounting or other lawful purposes, and is deleted or de-identified under the applicable retention process when no longer required.

Protected backup copies may remain for their normal retention cycle. Backup and recovery arrangements depend on the deployed database, supporting workloads and the customer’s service configuration. Unless separately agreed in writing, Whapp does not promise a specific recovery time or zero-data-loss outcome.

When a customer leaves Whapp, access to the Whapp platform ends on the effective termination date. Customers should contact Whapp before termination to confirm available access or export options for Whapp-only information such as assignments, reports and automation records that may not appear in the WhatsApp Business App.

For eligible Coexistence configurations, ending the Whapp service does not itself transfer ownership of the customer’s WhatsApp Business number or instruct Meta to delete WhatsApp Business App history. History availability, synchronisation, exports and migration remain subject to Meta’s supported functionality and the customer’s configuration.

Shared security responsibilities

Customer responsibilities

Customers should use individual accounts, protect their devices and sign-in methods, assign only the access each team member needs and promptly revoke departing users. Customers remain responsible for the lawful collection and use of their customer information, including applicable consent, marketing and opt-out obligations.

Customers should also protect access to their Meta business assets and connected third-party systems. Information exported or copied to customer-controlled devices and services remains subject to the customer’s own security controls.

Security concerns and contact

Report suspected unauthorised access or security concerns to hello@whapp.co.za and include the affected organisation, approximate time and observed symptoms. Do not send passwords, access tokens or other secrets by email.

Whapp assesses reported issues and takes reasonable steps to contain, investigate and address confirmed incidents. Response and notification obligations are handled in accordance with applicable law and any written service commitments.

Evidence and provider references

This overview is based on a review of relevant Whapp application controls, including authentication and authorisation, organisation membership, invitation routes, Meta webhook validation, integration-token storage, attachment retrieval and the release workflow. It is not an independent certification or guarantee that no security incident can occur.

1.Auth0 data security

2.Vercel security

3.Neon security overview

4.DigitalOcean shared responsibility model

For related information, see Whapp’s Privacy Policy, Terms of Service and Data Deletion guidance, or contact hello@whapp.co.za.