Privacy Policy

Last updated: 2026-05-06

1. Who we are

WazzCon (operated by Athena Metrics) is a multi-tenant SaaS for managing customer messaging across WhatsApp, Instagram DM, Telegram, and a web chat widget. Each operator (organization) connects their own messaging channels via their own credentials (Bring Your Own App model).

2. What data we collect

  • Operator account data: name, email, password hash, organization details, optional locale/timezone/title.
  • Connected channel credentials: API keys, access tokens, app secrets, webhook verify tokens. Stored AES-256-GCM encrypted at rest; never displayed back in the UI.
  • Conversation data: inbound and outbound messages, contact identifiers (phone number, IGSID, Telegram user ID), profile names/avatars, message timestamps, read/delivery receipts.
  • AI module artifacts: sentiment scores, conversation summaries, automated reply drafts. Generated by AI providers (e.g. Google Gemini) configured by the operator; message bodies are sent to the provider only when the relevant module is enabled.

3. How we use it

  • To deliver the messaging service (route inbound to UI, dispatch outbound).
  • To compute optional analytics (No-Churn sentiment alerts, Voice of Customer).
  • To trigger optional AI-assisted features (AI Agent replies, conversation summaries) — operator opts in per module.
  • We do not sell data, share it with advertisers, or use it to train external models.

4. Third-party processors

  • Meta Platforms (WhatsApp Cloud API, Instagram Graph API, Messenger): operator's own Meta App handles their channel — WazzCon proxies requests using the operator's credentials.
  • AI providers (Google Gemini, OpenAI, Anthropic): message bodies sent only when the operator enables AI modules and only with the operator's own provider key.
  • Hosting: project-managed cloud infrastructure (region: EU). Database, object storage, queue.

5. Data retention & deletion

  • Conversation data is retained while the connected channel instance exists.
  • Operators can delete an instance at any time from the panel — new inbound is rejected; historical messages remain in the DB for audit and may be hard-deleted by org admins on request.
  • Account closure (organization deletion) triggers cascade delete of all related data within 30 days.

6. Security

TLS in transit. Sensitive fields (tokens, secrets, message bodies, profile push names, customer signals) AES-256-GCM encrypted at rest. Multi-tenant isolation enforced at every data-access path; cross-org reads/writes are not possible.

7. WhatsApp-specific disclosures

WazzCon operates as a Solution Partner of WhatsApp Business Platform. Operators may onboard their WhatsApp Business account via three flows:

  • Bring Your Own App (BYOA): operator pastes their own Meta App credentials. No third-party popups; the operator retains full Meta-side control.
  • Embedded Signup — Migration: operator registers a number to Cloud API via Meta's official popup. The number is unregistered from the WhatsApp Business mobile application.
  • Embedded Signup — Coexistence: operator links an existing WhatsApp Business mobile app number to Cloud API via QR scan. Both the mobile app and the API run in parallel. As required by Meta, the following features are permanently disabled in 1:1 chats on this number after Coexistence setup: Broadcast Lists, Disappearing Messages, View Once, and Live Location. Group chats remain in the mobile app and do not sync to the API. Operators are shown this disclosure before activating Coexistence.

WazzCon complies with the WhatsApp Business Messaging Policy and the WhatsApp Business Platform Terms. Operators are responsible for obtaining customer consent before initiating conversations or sending templated messages.

8. AI training disclosure

Customer message content is neverused to train WazzCon-owned models. When an operator enables AI features (AI Agent, Sentiment, Voice of Customer), message excerpts are sent to the operator's own chosen AI provider (e.g. Google Gemini) using the operator's own provider key. We respect each provider's no-training terms; for Google Gemini, requests are made through the no-data-retention API tier when available.

9. Contact

For data subject requests (access, correction, deletion) or privacy questions, contact: info@athenametrics.com