Legal
Privacy policy
Effective date: 2026-07-17
This policy explains how Argo Navis ("Argo Navis", "we", "us") collects, uses, stores, shares, and deletes data in connection with the Argo Navis Platform, a WhatsApp business-messaging platform operated at wa.argo-navis.net(the "Service"). The Service is used by business customers ("business customers", "you", when addressed directly in this policy) to connect their own WhatsApp Business Account and send and receive messages with their own end customers.
Contact: jason@argo-navis.net.
1. Scope
This policy covers data processed by the Service itself: the Argo Navis dashboard, the underlying messaging infrastructure, and the associated API endpoints. It applies to (a) business customers who create an account and connect a WhatsApp Business Account ("WABA"), and (b) the end customers those business customers message via WhatsApp. It does not cover WhatsApp, Facebook, or Instagram themselves — those services are operated by Meta Platforms, Inc. and governed by Meta's own privacy policy and terms.
2. Information we collect
2.1 Dashboard account data
When a business customer creates an account, we collect the account holder's name, email address, and a password hash (we never store passwords in plain text). If the account is created or linked via Facebook Login, we also store the associated Facebook profile ID.
2.2 WhatsApp Business Account assets
When a business customer connects their WhatsApp Business Account through Meta's Embedded Signup flow, we store the identifiers and credentials needed to act on that account on the business's behalf: the WABA ID, connected phone number IDs and display numbers, message template configurations, webhook configuration, and long-lived access tokens issued by Meta. Access tokens are encrypted at rest (envelope encryption; the platform never stores an access token in plain text in any datastore or log).
2.3 Message content and metadata
To provide the Service, we process the content and metadata of WhatsApp messages sent and received on behalf of a business customer: message body (text, media references, template variables), timestamps, delivery and read status, and sender/recipient phone numbers. Message content is routed to and stored for the business customer that owns the conversation; we do not read, analyze, or use message content for any purpose other than delivering the Service (e.g. displaying it in the business's inbox, running the business's own configured automations, and analytics scoped to that business).
2.4 Contact phone numbers
We store the phone numbers and any associated profile names of the people a business customer communicates with via WhatsApp (the business customer's own end customers or contacts), along with any labels or notes the business customer adds. This data belongs to, and is controlled by, the business customer — we process it as their processor, not as an independent controller.
2.5 Usage logs
We collect standard operational logs: authentication events, API request logs, IP addresses, browser/device metadata, and error/diagnostic logs. These are used for security, abuse prevention, and reliability, and are retained on a shorter cycle than message data (see §5).
2.6 Facebook Login data
If a business customer signs in or connects their account with Facebook Login, we request only the public_profile and emailpermissions — that is, the person's name, profile picture, and email address as provided by Meta. We do not request or store any other Facebook or Instagram data through Facebook Login.
3. How we use this information (purposes)
- Operate and maintain the Service: authenticate accounts, route messages, run configured automations, render the dashboard.
- Provide analytics scoped to a business customer's own data (delivery rates, response times, automation activity).
- Detect, prevent, and investigate fraud, abuse, and security incidents.
- Comply with Meta's WhatsApp Business Messaging Policy and platform requirements.
- Respond to support requests and data subject requests (see §7).
- Meet legal, tax, and regulatory obligations.
We do not sell personal data, and we do not use business customers' message content or contact data to train machine learning models, for advertising, or for any purpose unrelated to operating the Service.
4. Legal bases for processing
Where the GDPR or a similar framework applies, we rely on the following legal bases:
- Contract — processing dashboard account data and WABA assets is necessary to provide the Service the business customer signed up for.
- Legitimate interests — security monitoring, fraud prevention, service reliability, and product analytics scoped to a business's own account, balanced against the individual's rights.
- Legal obligation — retention required by tax, accounting, or law-enforcement requests.
- Consent — where a business customer's end customer has opted in to receive WhatsApp messages, that consent (obtained and managed by the business customer) is the legal basis for the business customer's own messaging; our legal basis for processing on their behalf is the contract with the business customer acting as controller.
For most end-customer data (contacts, message content), the business customer is the data controller and Argo Navis is the data processor. For dashboard account data (the business customer's own login), Argo Navis is the data controller.
5. Retention
Retention is configurable per business customer in account settings. Absent a configured preference, message content and contact data are retained for as long as the business customer's account remains active, and are deleted or anonymized within 90 days of account closure or a valid deletion request (see §9). Usage and security logs are retained for up to 12 months for security-investigation purposes and then deleted. Dashboard account data is retained until the account is deleted.
6. Who we share data with
We share data only as necessary to operate the Service, with the following categories of recipients:
- Meta Platforms, Inc. — messages and account-management API calls are transmitted to and from the WhatsApp Business Platform and, where relevant, Facebook Login, because that is the underlying network the Service operates on.
- Hosting provider — our application and database infrastructure is hosted with a third-party infrastructure provider under a data processing agreement.
- Cloudflare, Inc. (R2 object storage) — media attachments (images, documents, audio/video sent or received via WhatsApp) are stored in Cloudflare R2 object storage.
We do not share data with any other third party for their own marketing purposes. Any additional subprocessor added in the future will be reflected in an update to this policy (see §11).
7. International data transfers
Our infrastructure providers and Meta operate data centers in multiple countries, which may include locations outside the country where a business customer or their end customers are located. Where this involves a transfer out of the European Economic Area, United Kingdom, or Switzerland, we rely on the transfer mechanisms our processors provide (such as Standard Contractual Clauses) to ensure an equivalent level of protection.
8. Security
We apply technical and organizational measures appropriate to the sensitivity of the data we process, including: encryption in transit (TLS) for all dashboard and API traffic; encryption at rest for WhatsApp access tokens using envelope encryption with a dedicated master key; password hashing using a modern adaptive hashing algorithm; role-based access control limiting internal access to production data; and webhook signature verification (X-Hub-Signature-256) on every inbound message from Meta to prevent spoofed traffic.
9. Your rights
Depending on your location, you may have the right to access, correct, export, restrict, object to, or delete your personal data, and the right to lodge a complaint with a supervisory authority. To exercise these rights, contact jason@argo-navis.net.
Business customers can access, export, or delete most of their own account data directly from account settings, or by emailing the address above.
End customers of a business customer (people messaging a business on WhatsApp) should generally direct data requests to that business first, since the business controls its own contact and conversation data. If you are unable to reach the business directly, or your request concerns data held only by Argo Navis (such as message routing logs), email us at the address above and we will coordinate with the relevant business customer or respond directly where we act as the data controller. See also our data deletion instructions for the fastest path to a deletion request, including deletion requests initiated through Facebook.
10. Facebook Login data handling
As noted in §2.6, Facebook Login is used solely to authenticate business customer accounts and, where relevant, to help identify the WhatsApp Business Account being connected. We request only public_profile and email. We do not post to Facebook on a user's behalf, do not access their friends list, and do not use Facebook Login data for advertising. If a user removes the Argo Navis app from their Facebook account, we receive a deauthorization callback and treat the dashboard account as disconnected from Facebook Login (the account itself, if it has a separate password, is unaffected).
11. Changes to this policy
We may update this policy as the Service evolves or as legal requirements change. Material changes will be reflected by updating the effective date at the top of this page. Continued use of the Service after an update constitutes acceptance of the revised policy.
12. Contact
Questions about this policy or how your data is handled: email jason@argo-navis.net. See also our terms of service and data deletion instructions.