1. Responsibility for use
Customer is responsible for all use of its workspace and connected channels, including use by employees, contractors, agencies, team members, integrations, APIs, automations, AI-assisted features, and anyone given access by Customer.
Customer must know its recipients, secure its credentials and devices, supervise authorized users, and ensure every message and workflow complies with law, the Terms and this Policy.
The Platform Owner and applicable Contracting Entity may each enforce this Policy within their technical or commercial authority. Product-level controls may be applied by the Platform Owner even when an Authorized Reseller sold the subscription.
2. Consent and lawful basis
Customer may contact a person only where it has a valid lawful basis, any consent required by applicable law, and permission required by WhatsApp, Meta, or another selected channel. Customer must provide required privacy notices and retain evidence of marketing consent where required.
A spreadsheet upload, CRM synchronization, manual contact entry, public phone number, third-party list, or prior transaction does not by itself prove permission for marketing. Whatsly does not verify or approve Customer’s legal basis.
3. Purchased, scraped and generated contacts
Do not upload, import, synchronize, or message purchased lead lists, rented databases, scraped or harvested phone numbers, generated or guessed numbers, numbers taken from public directories without a lawful basis, or contacts transferred by another business without proper authorization.
Do not use number enumeration, sequential dialing, automated discovery, scraping, harvesting, or similar techniques to identify or test WhatsApp accounts or contactable numbers.
4. Anti-spam and messaging restrictions
Do not send spam, unsolicited bulk messages, repetitive unwanted messages, or communications materially different from what the recipient reasonably expected. Message frequency, timing, identity, purpose, and content must be fair, transparent, and lawful.
Do not disguise the sender, conceal a commercial purpose where disclosure is required, use misleading subject matter or claims, or pressure a recipient through repeated contact.
5. Opt-outs and suppression
Customer must provide a reasonable opt-out method, monitor responses, promptly honor withdrawals and stop requests, maintain do-not-contact records, and apply suppression across users, campaigns, automations, APIs, integrations, agencies, and imported lists.
The Customer must not send, or permit the Service to send, messages to a recipient who has opted out, withdrawn consent, or requested not to be contacted. Suppressed contacts must not be re-imported and messaged.
Whatsly suppression or opt-out tools, where available, assist Customer but do not assume Customer’s legal duty.
6. Prohibited content and conduct
Do not use Whatsly for unlawful, harmful, deceptive, abusive, or rights-infringing activity.
- Harassment, threats, intimidation, hate, exploitation or unwanted surveillance.
- Fraud, phishing, impersonation, deceptive offers, false identity or misleading messages.
- Malware, malicious links, credential theft, unauthorized tracking or compromise.
- Illegal products or services, or content that facilitates illegal conduct.
- Content that infringes intellectual-property, privacy, publicity, confidentiality or consumer rights.
- Messages or activity that expose Whatsly, recipients, infrastructure providers or third-party platforms to material legal, security or reputational harm.
7. Security and infrastructure abuse
Do not probe, scan, disrupt, overload, reverse engineer, circumvent, or gain unauthorized access to Whatsly, another workspace, a connected device, or a third-party platform. Do not share credentials outside authorized use or use compromised accounts, devices, API keys, tokens, or webhook secrets.
Do not introduce malware, automate abusive traffic, interfere with rate limits, falsify events, replay signed requests, or use the Service in a way that degrades availability for others.
8. Meta and WhatsApp rules; no enforcement evasion
Customer must comply with all applicable Meta and WhatsApp terms, business and commerce policies, messaging rules, template requirements, technical limits, and enforcement decisions.
Do not bypass sending limits, rotate or repeatedly replace blocked numbers to continue prohibited activity, reconnect a suspended account through unauthorized means, manipulate quality signals, evade template review, or otherwise attempt to avoid Meta or WhatsApp enforcement.
Whatsly cannot guarantee continued access to any account, number, device, session, template, or sending limit and is not responsible for third-party enforcement decisions.
9. Campaigns, automations, AI and integrations
Customer must test configurations, set appropriate audience and frequency controls, review templates and AI-assisted output, and prevent a workflow from contacting an unintended or suppressed recipient. Automation does not reduce Customer’s responsibility.
APIs, webhooks, commerce connectors, CRMs, agencies and other integrations may initiate messages only within the authority and consent Customer has established. Customer must immediately disable a faulty or compromised workflow.
10. Monitoring and evidence
Whatsly is not required to pre-screen every message, contact, file, or workflow. We may use automated and manual signals to protect the Service, investigate complaints, and identify potential abuse.
The Platform Owner or applicable Contracting Entity may request evidence of contact origin, consent, privacy notice, opt-out handling, campaign purpose, identity, licensing or compliance. Customer must provide accurate information within a reasonable period. Failure to provide adequate evidence may result in restriction.
11. Enforcement
Where the Platform Owner or applicable Contracting Entity reasonably suspects or identifies a violation, either may within its authority warn Customer, apply sending or usage limits, pause or stop a campaign, block content, disconnect a channel or integration, restrict functionality, preserve relevant records, suspend or terminate access, and cooperate with valid legal or platform requests.
Action may be taken without advance notice where reasonably necessary to prevent harm, address a security event, comply with law or a third-party platform, or protect recipients, Whatsly, the Platform Owner, an Authorized Reseller, infrastructure or the public. Enforcement does not replace Customer’s liability or compliance duties.
12. Reporting abuse
Suspected spam, phishing, unlawful messages, account compromise, or other misuse may be reported through the Whatsly contact page or to the contact identified by the applicable Contracting Entity. Include the sender identity or number, relevant date, a description, and supporting evidence where safe to do so. Do not include unnecessary sensitive information.
13. Changes to this Policy
We may update this Policy to address legal requirements, new abuse patterns, product changes, or third-party platform rules. The version and updated date will identify the current published version. Material changes will be communicated where reasonably required.