WhatNexisWhatNexis
HomePrivacy PolicyContact

WhatsApp Business API Provider

Privacy Policy

This policy describes how Pathnexis Solutions Pvt. Ltd. collects, uses, stores, shares and protects information when you use the WhatNexis platform, website, APIs and related services.

Effective dateJuly 19, 2026
Last updatedJuly 19, 2026

Contents

  1. Introduction
  2. Our Role as a Tech Provider
  3. What Data We Process
  4. How We Process Data
  5. Purposes for Processing
  6. Prohibited Uses of Platform Data
  7. Embedded Signup and Meta Connections
  8. How We Share Information
  9. How to Request Data Deletion
  10. Your Rights
  11. Data Retention
  12. Data Security
  13. International Transfers
  14. AI Features
  15. White Label and Client Responsibility
  16. Children
  17. Relationship to Meta Terms
  18. Changes
  19. Contact

Introduction

This Privacy Policy explains how Pathnexis Solutions Pvt. Ltd. ("WhatNexis," "we," "our," or "us") Processes information when you use the WhatNexis platform, website, APIs, Embedded Signup flows, and related services (the "Services" or "App"). It is written to meet Meta's Platform Terms, including Section 4 (Privacy Policy) and Section 5 (Service Providers and Tech Providers), so that Users and Meta can clearly understand what data we Process, how we Process it, why we Process it, and how deletion may be requested.

WhatNexis is a Tech Provider for the WhatsApp Business Platform and related Meta products. We enable our business customers ("Clients") to connect and use Meta Platform features through our App. By using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.

Our Role as a Tech Provider

Under Meta's Platform Terms, WhatNexis acts as a Tech Provider. We use Platform and Process Platform Data only on behalf of and at the direction of the Client for whom we access it, and only to help that Client use Platform in accordance with Meta's terms ("Client's Purpose"). We do not Process Platform Data for our own purposes, for another Client's purposes, or for any other entity's purposes.

Platform Data we maintain for one Client is kept separate from Platform Data of other Clients. Clients remain responsible for their own privacy notices, lawful bases, and any notices or consents required before messaging end users. We also maintain an up-to-date list of our Clients and their contact information and will provide it to Meta if requested.

"Platform Data" means any information, data, or other content obtained from Meta through Platform or through our App, whether directly or indirectly. This includes Meta Product access tokens, app secrets, Meta user IDs, WhatsApp Business Account identifiers, phone numbers associated with WhatsApp Business assets, business profile information, message metadata and content Processed to deliver the Services, webhook payloads, and related technical identifiers.

What Data We Process

Depending on how the Services are used, we may Process account and profile information such as name, email address, phone number, and authentication credentials provided when a WhatNexis account is created or managed. We may also Process business information such as company name, business address, tax or billing details, and organization contacts.

When a Client connects Meta or WhatsApp Business assets through Embedded Signup or APIs, we Process Meta Platform Data made available for that connection. This may include WhatsApp Business Account (WABA) IDs, phone number IDs, business portfolio details, access tokens, granted permissions, webhook subscriptions, template metadata, and related configuration data.

To deliver messaging features as directed by a Client, we may Process messaging and customer contact data, including contact details, conversation content, message status events, and related information uploaded by the Client or received through Meta webhooks. We may also Process technical and usage information such as IP address, browser type, device information, cookies, log files, API request metadata, and diagnostics needed to operate and secure the Services; billing and payment details needed to provide the Services; and information shared in support or data-rights requests.

How We Process Data

We Process information by collecting and receiving it from Users, Clients, and Meta; storing and organizing it in our systems and those of our service providers; transmitting it to and from Meta APIs and webhooks; displaying it in Client dashboards and APIs; using it to authenticate, authorize, and configure integrations; logging and monitoring access to secure the Services; and deleting, anonymizing, or restricting it when required by this Privacy Policy, Meta's Platform Terms, or applicable law.

Processing may be automated. Where service providers host or support the Services, they Process Platform Data only to provide the services we request and in a manner consistent with Meta's Platform Terms and this Privacy Policy.

Purposes for Processing

We Process information to create, authenticate, and manage Client and user accounts; to provide the WhatNexis platform, APIs, and messaging features as directed by the applicable Client; to enable Meta Embedded Signup and manage connected WhatsApp Business assets; and to deliver, receive, route, and display WhatsApp messages and related status events for the Client that owns those assets.

We also Process information to provide customer support and respond to data requests; to secure the platform, prevent abuse, debug issues, and maintain service integrity; to generate aggregated or de-identified analytics needed to operate and improve the Services without using Platform Data for prohibited profiling; to process billing; to comply with legal obligations; and to send service-related notices.

We Process Platform Data only as clearly described in this Privacy Policy and in accordance with applicable law, Meta's Platform Terms, Developer Policies, Developer Docs, and other applicable Meta terms. We do not Process Platform Data for purposes other than the permitted purposes set out in Meta's Developer Docs.

Prohibited Uses of Platform Data

Consistent with Meta's Platform Terms on Prohibited Practices, we will not Process Platform Data to discriminate or encourage discrimination based on protected personal attributes; to make eligibility determinations about people, including for housing, employment, insurance, education, credit, government benefits, or immigration status; or to perform, facilitate, or provide tools for surveillance.

We will not sell, license, or purchase Platform Data. We will not Process Platform Data without valid User consent in order to build or augment user profiles. We will not attempt to decode, circumvent, re-identify, de-anonymize, unscramble, unencrypt, reverse hash, or reverse-engineer Platform Data provided in protected form. We will not materially change the App's core functionality or the scope of Processing of previously collected Platform Data without first re-submitting the App and receiving Meta approval through App Review where required.

Embedded Signup and Meta Connections

When a Client connects a Meta Business Account or WhatsApp Business assets through Embedded Signup, we receive only the information necessary to configure, authenticate, and manage those connected assets for that Client. We use this information solely to provide the requested Services for that Client's Purpose.

Use of WhatsApp Business Platform features remains subject to Meta's and WhatsApp's applicable terms and policies. Clients are responsible for accepting those terms and for complying with messaging and consent requirements applicable to their end users.

How We Share Information

We do not sell personal information or Platform Data. As a Tech Provider, we share Platform Data only as permitted by Meta's Platform Terms: with the applicable Client, after contractually prohibiting that Client from Processing Platform Data in a way that would violate Meta's terms; to the extent required under applicable law or regulation; with our service providers solely to the extent necessary for the applicable Client's Purpose; or with a Client's service provider solely when that Client expressly directs us to do so for the Client's Purpose.

We may also share information with Meta where required for WhatsApp Business Platform or Meta Platform functionality, and with competent authorities where legally required. When we use service providers in connection with Platform Data, they must first agree in writing to Process such data solely for us and at our direction, only to provide the services we requested, and not for their own purposes. If a service provider engages a sub-service provider, that sub-service provider must be held to the same written requirements. When we stop using a service provider, we ensure they cease Processing Platform Data and promptly delete it.

How to Request Data Deletion

All Users who can access our App, and our Clients, have the right to request deletion of their Platform Data and other personal information we Process. Meta's Platform Terms require us to honor deletion requests even where local law does not independently require deletion, unless a law prevents us from complying. Users also have an easily accessible way to ask for their Platform Data to be modified.

To submit a deletion or modification request, email privacy@whatnexis.com or info@pathnexis.in with the subject line "Data Deletion Request." Include the email address associated with your WhatNexis account, your full name, your company name if applicable, and a clear description of the data you want deleted or modified. If you are an end user of a Client rather than a direct WhatNexis account holder, tell us which Client or business you interacted with and any WhatsApp phone number or conversation identifiers you can provide, because we Process messaging data on that Client's behalf and may need to coordinate with them.

We may request reasonable information to verify your identity and authority. After verification, we will delete or de-identify the relevant Platform Data and personal information from our systems as soon as reasonably possible, and will ask our service providers to do the same, unless retention is required by applicable law or needed to complete outstanding legal, security, or billing obligations. We will confirm completion by email. If we cannot fully delete certain data because of a legal requirement, we will explain what we retained and why.

We also update or delete Platform Data promptly after receiving a valid request from Meta or from a User, and when a Client closes its account with us, except for data that has been aggregated, obscured, or de-identified so it cannot be associated with a particular User, browser, or device.

Your Rights

Subject to applicable law, you may request access, correction, deletion, or portability of your personal information, or object to certain processing, by contacting privacy@whatnexis.com. We will promptly notify a Client of any communication from Meta concerning a User's request regarding Processing of that User's Platform Data, including requests to exercise data subject rights.

Data Retention

We retain information only for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Unless applicable law requires longer retention, we delete Platform Data as soon as reasonably possible when retention is no longer necessary for a legitimate business purpose consistent with Meta's Platform Terms and this Privacy Policy; when we stop operating the product or service through which the Platform Data was acquired; when Meta requests deletion for the protection of Users; when a User or Client requests deletion, or a Client no longer has an account with us; when required by applicable law; or as otherwise required under Meta's compliance, suspension, or termination provisions.

If we are required by law to keep Platform Data, we retain proof of that requirement and will provide it to Meta if asked. If Platform Data is received in error, we will report it to Meta as required, delete it, and provide proof of deletion if requested.

Data Security

We maintain administrative, physical, and technical safeguards that meet or exceed industry standards given the sensitivity of Platform Data and that are designed to prevent unauthorized Processing, including unauthorized access, destruction, loss, alteration, disclosure, distribution, or compromise. These safeguards include HTTPS encryption, authentication controls, access management, monitoring, backups, and secure development practices. No system is completely secure.

People may report security vulnerabilities in our App by emailing privacy@whatnexis.com or info@pathnexis.in. We promptly address identified deficiencies. We may use Meta Products to authenticate users, but we do not separately request or collect Meta user login credentials. We protect Meta user IDs, access tokens, and app secrets and do not transfer, share, or solicit them except with a service provider who helps us build, run, or operate the App under appropriate controls.

If there is unauthorized Processing of Platform Data, or an incident reasonably likely to compromise the security, confidentiality, or integrity of our systems or those of our service providers, we will notify Meta as required, begin remediation immediately, and cooperate with Meta regarding impact and corrective actions.

International Transfers

Where applicable, information may be Processed in jurisdictions where we or our service providers operate. We implement appropriate safeguards required by applicable law for such transfers. Processing of Platform Data remains subject to Meta's Platform Terms, including applicable international transfer terms for EEA, UK, and other transfers.

AI Features

If AI features are enabled by a Client, message content may be Processed to generate requested responses or automations solely for that Client's Purpose. Unless expressly agreed in writing, customer content and Platform Data are not used to train public AI models.

White Label and Client Responsibility

Where WhatNexis is deployed as a white-label platform, each Client remains responsible for its users, privacy notices, consents, and legal compliance. WhatNexis Processes Platform Data only according to Client instructions and contractual arrangements, consistent with Meta's Platform Terms. If Meta requests that we terminate a Client's use of Meta Products, Platform, or Platform Data through our App because of violation or harm risk, we will do so promptly.

Children

The Services are intended for businesses and authorized users, not for children. We do not knowingly collect personal information from children in violation of applicable law, including COPPA where it applies. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

Relationship to Meta Terms

This Privacy Policy does not supersede, modify, or conflict with Meta's Platform Terms or other terms and policies applicable to Platform Data. If there is any conflict regarding Platform Data, Meta's applicable terms control to the extent they are more restrictive on us or more protective of Meta and Users. We Process Platform Data only as described in this Privacy Policy and as permitted by those terms.

Changes

We may update this Privacy Policy periodically. The latest version will always be published at this publicly available URL with an updated effective date. Material changes may also be communicated through the Services or by email where appropriate.

Contact

For questions about this Privacy Policy, our data practices, security reports, or access, correction, or deletion requests, contact Pathnexis Solutions Pvt. Ltd. (WhatNexis) at privacy@whatnexis.com or info@pathnexis.in. This Privacy Policy is available at https://whatnexis.com/privacy.

WhatNexisWhatsApp Business API Technology Provider

Home · Privacy Policy · Contact privacy@whatnexis.com

© 2026 WhatNexis. All rights reserved.

WhatNexisWhatNexis
FeaturesPricingFAQsContactPrivacy Policy
© 2026 WhatNexis. All rights reserved.