1. Scope and identity
This policy applies to the public Whatsly website, account and subscription administration, platform operation, support and product analytics. Ignite Solutions Pte. Ltd., Singapore, owns and develops Whatsly and may act as platform operator where it performs the relevant technical activity. The applicable Contracting Entity is identified before purchase.
An Authorized Reseller may separately control local sales, contracting, invoicing, tax and its own support records. For Saudi subscriptions, Brightening Technology Company is the local Contracting Entity. This policy does not imply that every reseller belongs to the same corporate group or automatically has access to Customer messages or workspace data.
This policy does not replace a Customer’s own privacy notice to its contacts, leads, employees or message recipients.
Where a separate data-processing agreement or mandatory law applies, that document or law controls to the extent of a conflict.
2. When Whatsly is a controller and when it is a processor
Ignite Solutions Pte. Ltd. may act as controller for platform security, service operations, abuse prevention, product administration, technical and audit logs, and its own business records. It may act as processor or service provider for Customer-controlled leads, contacts, phone numbers, conversations, message content, campaign recipients, templates, CRM records, media, integration data and related metadata, and may engage infrastructure and technical subprocessors.
An Authorized Reseller may act as an independent controller for its local sales enquiries, contracts, invoicing, payment collection, tax records and its own customer-support records. It may act as an authorized support provider, or as a processor or subprocessor only when it accesses workspace information strictly under the support arrangement, Customer authorization, role-based access, operational necessity and the applicable data-processing agreement. Reseller access to workspace or message data is not automatic.
For Saudi Arabia, Brightening Technology Company may process Saudi sales enquiries, local subscriptions, billing, payments, tax invoices, account administration, onboarding, local support and Customer communications for those activities.
The Customer generally acts as controller for its workspace data and decides whom to contact, what to upload, why it is processed, what messages are sent, how consent is collected, how opt-outs and suppression are handled, and how data-subject requests relating to its campaigns are answered.
A Customer may also act as controller for personal data about its administrators and team users. The exact legal role depends on the facts and applicable law, not only the labels used in this policy.
3. Personal data we collect
We collect information a person provides directly, information created through use of the website or Service, and information received from a Customer, connected service, or authorized integration.
- Identity and account data, such as name, work email, organization, role, user identifier, login and workspace membership.
- Contact and enquiry data, including company, optional phone number, message, demo interests, team size and support correspondence.
- Subscription and billing administration data, such as selected market, sales channel, Contracting Entity, plan, invoices, transaction status, billing contact and tax information. Payment credentials may be handled by the Contracting Entity’s authorized payment provider shown at checkout rather than by this public website.
- Technical and security data, such as IP address, browser, device, operating system, requested URLs, timestamps, authentication events, audit events, rate-limit signals and error records.
- Usage and analytics data, such as pages viewed, feature or CTA interactions, referrer, approximate region derived from technical data, and service activity.
- Customer-controlled data, including contacts, phone numbers, conversations, messages, media, templates, campaign or workflow data, connected-number status, API and webhook activity, and commerce or CRM integration data.
4. Sources of personal data
Data may come from the individual, the Customer that created or manages the workspace, an administrator or team user, a WhatsApp or Meta-connected environment, WooCommerce, Shopify, a Customer API or webhook integration, an authentication or payment service, website hosting and security infrastructure, or an analytics provider enabled as described below.
Customers may upload personal data about people who have no direct relationship with Whatsly. Customers are responsible for having a lawful basis to provide that data and for giving required notices.
5. Purposes and legal bases
Depending on the relationship and applicable law, we rely on performance of a contract, steps requested before entering a contract, legitimate interests, consent, and compliance with legal obligations. Where Saudi Arabia’s Personal Data Protection Law applies, processing will also be assessed under the lawful bases and requirements applicable to that activity; this statement is not a claim of certification or universal compliance.
- Provide, configure, authenticate, support and maintain the website and Service: contract and legitimate operational interests.
- Create accounts and administer subscriptions and trials: contract, pre-contract steps and legitimate operational interests. The applicable Contracting Entity separately administers its invoices, billing, collections and taxes under contract and legal obligations.
- Receive and respond to contact, demo and support requests: consent, pre-contract steps and legitimate interests in answering enquiries.
- Protect accounts, investigate abuse, enforce terms, prevent fraud and maintain logs: legitimate interests and legal obligations.
- Measure website and product usage using optional analytics: consent where required and, where law permits, legitimate interests subject to appropriate choice.
- Send service notices and requested product communications: contract and legitimate interests. Separate marketing communications rely on consent or another valid basis where permitted.
- Comply with court orders, lawful requests, tax, accounting and regulatory duties: legal obligations and legal claims.
- Process Customer-controlled data according to the Customer’s documented instructions: the Customer’s lawful basis, under a processor or service-provider relationship.
6. Website forms and Whatsly communications
The contact and demo forms collect name, work email, company, optional phone number, message, and—where relevant—team size and business goal. The website adds a submission time and source, performs validation and basic abuse prevention, and delivers the submission to the webhook destination configured by Whatsly. This repository does not store submissions in a database.
A sales or demo enquiry may be routed to the Platform Owner or the Authorized Reseller serving the selected market or sales channel. The recipient controls its own enquiry, follow-up and sales records and should identify itself in its response.
Form information is used to answer the request, prepare a demo, maintain necessary business records, and protect the form from abuse. It is not permission to send unrelated marketing indefinitely. A person may withdraw marketing consent using the method in the communication or by contacting us.
7. Customer contacts, recipients and messages
Customers may upload, synchronize, or generate personal data about leads, contacts, recipients, and other individuals. Whatsly processes that data to provide the shared inbox, message history, reusable messages, connected workflows, integrations, APIs, webhooks, security, and support requested by the Customer.
The Customer is responsible for deciding whom to contact, establishing a lawful basis, providing privacy notices, obtaining and recording consent where required, and honoring opt-outs. Campaign consent and unsubscribe requests should normally be directed to the business that sent the message.
Whatsly does not independently verify how a Customer obtained a contact or whether a particular communication is lawful. Individuals may contact Whatsly about Whatsly’s own processing, to identify the relevant Customer where reasonably possible, or where applicable law requires Whatsly to assist.
8. Cookies, local storage and analytics
The current public website code does not create an advertising profile, load advertising pixels, or include a support chat widget. It stores an analytics preference in the visitor’s browser only when optional analytics is configured. Operational hosting infrastructure may process standard request data needed to deliver and secure the site.
Google Analytics is optional and loads only after the visitor allows optional analytics. If enabled and accepted, Google may use analytics cookies or similar technologies and receive page and interaction data under Google’s own terms and privacy practices.
PostHog event capture is optional. The current implementation sends configured interaction events, the current page URL, and a website-anonymous identifier to the configured PostHog host only after analytics consent. It does not load the PostHog browser library. Provider configuration may change, and this policy will be updated if the practice changes materially.
Rejecting optional analytics does not prevent use of the public website. A visitor can change the stored choice by clearing site storage. A dedicated preference control may be added as analytics configuration develops.
9. Sharing and subprocessors
The Platform Owner, applicable Contracting Entity and Authorized Reseller share personal data with one another only as reasonably necessary for the relevant sale, onboarding, account administration, authorized support, platform operation, security, Customer instructions, legal compliance or protection of rights and safety. A reseller does not receive unrestricted workspace access merely because it sold a subscription.
Relevant provider categories may include website and application hosting, infrastructure, authentication, communications, form delivery, support, payment processing, analytics, security, storage, and connected platforms selected by a Customer. The production hosting provider and form-webhook recipient are deployment configuration and are not identified in this repository.
Optional analytics providers referenced in the code are Google Analytics and PostHog. Meta and WhatsApp, WooCommerce, Shopify, payment services shown at checkout, and Customer-selected integrations may process data as independent controllers or under their own agreements. A current subprocessor list should be confirmed before final publication and made available on request or through a published list.
10. Legal disclosures and business transfers
We may preserve or disclose information where reasonably necessary to comply with applicable law, a binding legal process, or a valid government request; enforce agreements; investigate fraud, abuse, or security incidents; protect recipients or the public; or establish, exercise, or defend legal claims.
If the Whatsly business or Service is involved in a merger, financing, reorganization, acquisition, or sale of assets, personal data may be disclosed under appropriate confidentiality and transferred subject to applicable law and continued protection.
11. Data location and international transfers
The repository does not establish a guaranteed data-residency location. Platform data may be processed or accessed by Ignite Solutions Pte. Ltd. or its configured technical subprocessors outside Saudi Arabia. Data may also be processed where the applicable Contracting Entity, authorized support provider, connected platform or Customer-selected integration operates.
International processing or access is handled subject to applicable legal requirements and contractual safeguards. Where law requires a transfer mechanism or other protection, the responsible controller or processor must use an available lawful measure. Customers must assess transfers caused by their own connected services and recipient communications. This policy does not promise Saudi-only, GCC-only, EU-only or any other exclusive data residency.
12. Retention, backups and account deletion
We retain controller data only for as long as reasonably needed for the stated purpose, account or subscription administration, security, dispute handling, legal claims, accounting, and legal obligations. Retention depends on the data type, account status, sensitivity, contractual requirements, and mandatory limitation or recordkeeping periods.
Customer-controlled data is retained according to the Customer’s subscription, instructions, applicable data-processing agreement, technical deletion cycle, and legal preservation requirements. After account closure, data may remain for a limited period in backups or protected archives until overwritten or safely deleted.
Account deletion may not immediately remove data that must be retained for security, billing, fraud prevention, legal compliance, disputes, or valid legal requests. Customers should export information they need and disconnect third-party channels before closure. A final retention schedule and backup deletion period require confirmation before counsel approval.
13. Security and personal-data breaches
We use reasonable technical and organizational measures appropriate to the nature of the Service and the risks presented. These may include access controls, scoped credentials, signed webhook events, workspace separation, logging, and operational monitoring. No method of storage or transmission is perfectly secure, and we do not promise perfect security or end-to-end encryption.
Customers are responsible for securing their users, devices, connected numbers, credentials, API keys, webhook secrets, and integrations. If we become aware of a personal-data breach that triggers contractual or legal notification duties, we will investigate and notify affected Customers or authorities as required by the applicable framework.
14. Individual rights and requests
Depending on applicable law, an individual may have rights to be informed, access personal data, obtain a copy, correct inaccurate data, request deletion, restrict or object to processing, withdraw consent, and complain to a competent authority. Some rights are subject to exceptions, identity verification, legal preservation, and the role in which Whatsly processes the data.
We may request information reasonably necessary to verify identity, authority, and the relevant account. We will not use verification data for unrelated purposes. Withdrawing consent does not affect processing already lawfully completed.
For Customer-controlled contact or message data, the relevant Customer usually handles the request as controller. We will assist the Customer as required by contract and law. We may direct the requester to the Customer unless law requires us to respond directly.
15. Saudi PDPL and complaints
Where the Saudi Personal Data Protection Law and its implementing regulations apply, individuals may have rights and complaint routes provided by that framework. The applicability of the law depends on the processing context. This policy does not claim regulatory certification or compliance with every jurisdiction.
For Saudi commercial records, Brightening Technology Company may be the appropriate controller contact. For platform security, operations or Customer-controlled workspace processing, Ignite Solutions Pte. Ltd. or the relevant Customer may be the appropriate recipient depending on the activity. Requests may be routed after reasonable identity and relationship checks.
We encourage individuals to contact us first so the concern can be understood and addressed. An individual may also complain to the competent data-protection authority where applicable. Customer contacts should normally raise message consent, opt-out, and campaign complaints with the business that sent the communication.
16. Children’s privacy
Whatsly is a business service and is not directed to children. A person who cannot lawfully enter a business contract should not create an account. Customers must not use Whatsly to collect or communicate with children’s data unless they have a valid legal basis, appropriate notices and permissions, and comply with heightened protections required by law.
17. Changes to this policy
We may update this policy when the Service, providers, legal requirements, or processing practices change. We will revise the version and last-updated date and provide additional notice where a material change or applicable law requires it.
18. Privacy contact
Privacy enquiries may be submitted through the Whatsly contact page.
Please describe the relationship, relevant workspace or sender, the right being exercised, and enough information to locate the data. Do not send passwords, full payment credentials, or unnecessary identity documents through the general contact form.