Privacy Policy
Konomic WhatsApp messaging platform and the “Konomic” app (App ID 1411708813877592)
Last updated: 25 September 2026
Summary
- Konomic develops and maintains a platform that connects a business’s WhatsApp number to Meta’s WhatsApp Business Platform. With it, the business gets conversations, notifications, an AI assistant and a CRM for its staff.
- Each business has its own installation, on servers and services it contracts itself. The data about its customers, contacts and staff belongs to the business: it decides and is the controller. We process that data on its behalf.
- When a business connects its number, we receive from Meta only what is needed to connect it. We do not read or store your Facebook profile.
- When connecting, the platform asks Meta for the address book of the WhatsApp Business app and, if the business agrees, its chat history. Both include people who are not customers of the business.
- The AI assistant runs on Claude, from Anthropic, which stores the data in the United States. Its first reply in each conversation says it is an automated AI assistant.
- No customer names or phone numbers go through Telegram.
- We do not sell data. We do not use it for advertising or to train AI models.
- If you are a customer or contact of a business that uses Konomic, write to that business first. For anything else, write to nik.l@konomic.com. To delete data, follow the data deletion instructions.
1. Who we are and what this policy covers
- Company
- KONOMIC DIGITAL SL
- Tax ID (NIF)
- B22884688
- Registered address
- C/ Santo Domingo, 1, Km. 1, 38003 Santa Cruz de Tenerife, Spain
- Registry
- Registro Mercantil de Santa Cruz de Tenerife, sheet TF-75427, EUID ES38013.000539563
- Activity
- Computer programming (CNAE 62.10)
- Privacy email
- nik.l@konomic.com
This policy covers:
- The Konomic WhatsApp messaging platform. This is the software that connects a client business’s WhatsApp number to Meta’s WhatsApp Business Platform (Cloud API). It also works in “coexistence”: the number stays active in the WhatsApp Business app on the phone. The platform stores conversations, sends notifications and offers an AI assistant, a CRM and a Telegram bot for the business’s staff.
- The “Konomic” app (App ID 1411708813877592), registered by KONOMIC DIGITAL SL on Meta for Developers as a WhatsApp Tech Provider. This is the app shown in Meta’s “Facebook Login for Business” window (Embedded Signup) when a business connects its number.
It does not cover the websites or other services of our client businesses, which have their own policies. It does not cover other Konomic products either.
The rules for businesses using the service are in the Terms of Service.
2. Who decides about the data: your business or us
The business decides (we are a processor, Art. 28 GDPR)
Each business has its own installation of the platform, with its own database, on servers and services it contracts in its own name. One business’s data is never mixed with another’s.
On behalf of the business, and only on its instructions, we process:
- data about its customers and contacts: WhatsApp messages, the chat history and address book synced from the WhatsApp Business app, conversations with the AI assistant, bookings, customer records, vehicles, notifications, photos and documents;
- data about its staff who use the platform: name, CRM account and role, Telegram user ID if they link the bot, the questions they ask the staff assistant, and the record of what they do in the CRM and the bot;
- the data about its WhatsApp connection that we receive from Meta as Tech Provider (section 3).
The business is the controller of all this data. It decides what it is used for, on what legal basis and how long it is kept. Its instructions and our obligations are set out in the data processing agreement (Art. 28 GDPR) we sign with each business. We develop, install, maintain and support the platform, and access the data only for that.
We decide (we are the controller)
We are the controller only of:
- data about our business relationship with each client: name, email, phone number and role of its contact persons, contracts and invoices;
- data about anyone who writes to us for support or to exercise their rights;
- together with Meta, the technical data collected by Meta’s program on the connection page (section 3.1).
We do not use this data for marketing or product analytics.
If you are a customer or contact of a business that uses Konomic, read that business’s privacy policy and contact the business first. If you write to us, we will pass your request to the business and help it respond.
3. What data we receive from Meta, and why
3.1 When a business connects its number
The person connecting the number opens Meta’s window from their business’s CRM, logs in to Meta and accepts the permissions Meta shows. We use those permissions only to manage the connected WhatsApp Business account and to send and receive its messages, on the business’s behalf.
| Data | Why | Stored? |
|---|---|---|
| One-time authorization code | To exchange it once with Meta for the business’s access token. | No. It is used on the spot and discarded. |
| Identifiers sent by Meta’s window when it finishes: WhatsApp Business Account ID (WABA) and phone number ID | To know which account and which number to connect. | Yes, in the connection record of the business’s installation. |
| The business’s access token (business integration system-user token) | To finish the connection and then send and receive messages on the business’s behalf. | Not in the database, the technical logs or the audit log. Only in the protected configuration of the business’s server. |
| WhatsApp Business accounts that the token gives access to (a query to Meta about the token) | To check which account the token gives access to and pick the right one. | Only the ID of the chosen account. |
| Result of subscribing the Konomic app to the account (yes or no) | To receive the account’s automatic notifications (webhooks). | Yes, in the audit log. |
| The account’s phone numbers: ID, display number, verified name, platform type, status, and whether the number is on the WhatsApp Business app | To find the number that runs both on the phone and on the platform. | Only the ID and the display number of the connected number. |
| Response to the request to sync contacts and history | To track progress and meet the 24-hour deadline set by Meta. | Only the status, the dates and, if it fails, Meta’s error text. |
| Account status notices: disconnection or reconnection, reason, and who started it | To mark the number as disconnected or reconnected and alert administrators. | Yes, in the connection record and the audit log. |
The connection record also stores the date and the internal ID of the user who made the connection. If the person cancels, or an error occurs in Meta’s window, the step or the error message is shown on screen only and is not sent to the server.
Your Facebook profile. We do not read or store your Facebook profile (name, email, user ID, picture or friends). From Meta’s window, the page takes only the one-time code and the connection identifiers.
Meta’s program on the connection page. To open Meta’s window, the connection page loads Meta’s JavaScript SDK in the browser. When it loads, the browser sends Meta technical data: IP address, browser and device type, the referring page and, if you are logged in to Facebook in that browser, Meta’s cookies, which let Meta link that data to your account. We are joint controllers (Art. 26 GDPR) with Meta Platforms Ireland Limited for that collection and its transmission to Meta, under the controller addendum of Meta’s Business Tools Terms. The essence of that arrangement is:
- we inform you about this collection and are responsible for its legal basis: our legitimate interest in letting your business connect its number with the tool Meta requires (Art. 6(1)(f) GDPR);
- Meta is responsible for what it does with the data afterwards, under its privacy policy, and may process it outside the EEA;
- you can exercise your rights against either of us; if you write to us, we pass your request on to Meta.
We do not receive that technical data. Only administrators can use the connection page.
3.2 After the connection (on the business’s behalf)
Meta sends this data to the business’s installation through automatic notifications (webhooks). It is processed only to provide the service to the business.
| Data | Why |
|---|---|
| Messages the business receives: sender’s number, text (up to 4,000 characters), date and message ID | To keep them as context for the assistant and for handing the conversation to a person, recognise the opt-out and opt-in words (STOP, BAJA, ALTA), avoid duplicates, and limit abuse and costs. |
| The sender’s WhatsApp profile name | If the assistant registers a booking request and there is no other name, it is saved as the customer’s name. It is not sent through Telegram. |
| Replies that staff send from the WhatsApp Business app on the phone: recipient’s number and text | To keep the conversation complete and pause the assistant in that conversation (12 hours by default). |
| Delivery status of the messages sent: delivered, read or failed, and the reason for a failure | To know whether the message arrived and, if it failed, send an SMS. |
| Chat history from the WhatsApp Business app, if the business agrees to share it when connecting: for each chat, the other person’s number and, for each message, the text, direction, original date and ID | To give context to the conversation. Meta decides how much history it sends (according to Meta, up to 180 days); the platform applies no further limit. It includes all one-to-one chats in the app, including chats with people who are not customers. The assistant does not reply to these messages, but if that person writes later, they are part of the recent messages it uses as context. |
| Address book of the WhatsApp Business app, which the platform requests from Meta as soon as the number is connected, with no further step by the business: number, full name, first name, and whether the contact was added or removed | To link a number to a customer record that already exists. All contacts are stored, including those that match no record. It never creates new records and is never used to send messages. |
WhatsApp photos, voice notes, videos, documents and stickers are not downloaded or stored: only a marker such as “[image message]” is kept. According to Meta, group chats are not synced.
To deliver messages, the platform also sends data to Meta: the customer’s number with the assistant’s reply, or with a notification or a marketing message (section 4.2). For example: order number, service, date and time, vehicle inspection (ITV) due date, the text of a workshop recommendation, or a personal link to check the status.
3.3 What we do not ask for or deliberately keep
- Your Facebook profile.
- The business’s access token in the database, the technical logs or the audit log.
- WhatsApp media files.
- Payment data, identity documents or passwords: the platform does not ask for them. If someone types them in a message, they are stored as part of the text.
- Message text in the application’s technical logs: only its length and a fingerprint (hash).
- From delivery statuses, the recipient ID and Meta’s pricing data.
The platform uses no analytics or trackers of its own. The only third-party program is Meta’s, on the connection page (section 3.1). These legal pages use no cookies or scripts.
4. What data is used for, and the legal bases
4.1 Data for which we are the controller
| Purpose | Data | Legal basis |
|---|---|---|
| Managing our relationship with each client business: contract, invoicing and notices about the service | Name, email, phone number and role of the contact persons; contract and invoice data | If the client is a sole trader, the contract with them (Art. 6(1)(b) GDPR). For people acting for a business, our legitimate interest in dealing with it (Art. 6(1)(f) GDPR and Art. 19 of the Spanish data protection act, LOPDGDD). Invoices and accounting, legal obligation (Art. 6(1)(c) GDPR). |
| Collection of technical data by Meta’s program on the connection page, as joint controllers with Meta | IP address, browser and device, referring page and Meta’s cookies | Legitimate interest in letting the business connect its number with the tool Meta requires (Art. 6(1)(f) GDPR). |
| Answering support requests | Name, email and whatever you tell us | If you write on behalf of a client business, our legitimate interest in helping the people who act for it (Art. 6(1)(f) GDPR and Art. 19 LOPDGDD). If you yourself are the client, as a sole trader, the contract with you (Art. 6(1)(b) GDPR). If you are not a client, our legitimate interest in replying to you (Art. 6(1)(f) GDPR). |
| Handling data protection requests | The data in the request | Legal obligation (Art. 6(1)(c) GDPR). |
Without the authorisation in Meta’s window the number cannot be connected. The data in a support or rights request is needed to answer it and to check who is asking; if it is missing, we may not be able to handle the request.
Where the basis is legitimate interest, you can object (see section 8).
4.2 Data we process on the business’s behalf
On behalf of the business and following its instructions (Art. 28 GDPR), the platform uses the data in section 3.2 and in the business’s CRM to:
- store conversations as context for the assistant and for handing the conversation to a person. Staff read the chats in the WhatsApp Business app on the phone or in the CRM;
- run the AI assistant. Its first reply in each conversation starts with a fixed notice that it is an automated AI assistant and that a person from the team takes over on request. It answers questions, looks up the information the business makes available to it (at a car workshop, for example: vehicles, bookings, order status, catalogue and free slots), registers booking requests, and hands the conversation to a person when needed;
- recognise the opt-out and opt-in words (STOP, BAJA, ALTA). Opting out withdraws the customer’s permissions to receive messages. Opting back in restores only messages about their visits, never marketing, which needs new express consent. This is recorded in the audit log and confirmed by WhatsApp;
- send service notifications by WhatsApp (templates) when the status of a booking or an order changes, and a reminder 24 hours before each booking. If WhatsApp fails, they are sent by SMS;
- send the business’s marketing messages, only on its instructions and only to customers who gave marketing consent. At a car workshop, for example:
- a review request after payment, at most one every 180 days;
- a notice that the vehicle inspection (ITV) is due soon, with the date and the plate;
- a reminder of a workshop recommendation, with its text;
- a message to customers with no visit in 12 months.
- alert staff through Telegram to what needs their attention, without customer data, and let them look up orders, vehicles and bookings in the Telegram bot without customers’ names or phone numbers (section 5.4). Contact details are looked up in the CRM;
- read with AI the photos of supplier invoices, expenses and parts that staff send from the bot or the CRM;
- sync the address book of the WhatsApp Business app and import the chat history if the business agrees to share it.
The business decides the legal basis for this processing and explains it in its own privacy policy. One example from a car workshop: when the assistant registers a booking request, the customer record is marked as agreeing to receive WhatsApp messages about that visit, because the request came through that channel. Marketing, by contrast, needs separate consent that the business collects.
Neither we nor the assistant make decisions based solely on automated processing that produce legal effects on anyone or similarly significantly affect them (Art. 22 GDPR). The business’s staff handle the booking requests the assistant registers.
5. Who receives data
The platform works with third-party services. Almost all of them are contracted by each business directly, in its own name: they are its own processors, and the business is responsible for those contracts and their safeguards. By signing the data processing agreement, the business instructs us to use those services with its data. A few services are used by us (section 5.3).
5.1 Services the business contracts (standard setup)
| Service | What for | What data | Where |
|---|---|---|---|
| Vultr (The Constant Company, LLC) | The server the installation runs on | All the data of the installation, technical logs and local backups | Servers in Frankfurt (Germany, EU); the company behind Vultr is in the United States (section 6) |
| Amazon Web Services (S3) | Off-server backups and CRM files | A full daily copy of the database; intake, handover and work photos (including those sent from the bot), signatures and PDF records | Spain (region eu-south-2) |
| Anthropic (Claude API): WhatsApp assistant | Answering customers | Instructions with the business’s information and the date; the last 30 messages with that number, including imported history and staff replies; and what the assistant looks up to answer: at a car workshop, the customer’s vehicles (make, model, version, year, plate and ITV due date), the workshop’s 3 most recent recommendations for each vehicle, active bookings, order number and status, personal status link, catalogue and free slots. The instructions do not include the phone number or the profile name, although they may appear if the person writes them. | Anthropic stores the data in the United States (section 6) |
| Anthropic (Claude API): staff | Answering staff in the Telegram assistant and reading photos of supplier invoices, expenses and parts | Staff questions and what the assistant looks up (orders, vehicles and bookings, without customers’ names or phone numbers); the photos and PDFs staff send | Anthropic stores the data in the United States (section 6) |
| Esendex | SMS when a WhatsApp message fails | Number and message text in the customer’s language (order number, service, date, ITV due date, text of a recommendation, personal status link, link to leave a review). Never chat content. Assistant replies are never sent by SMS. | Esendex’s Spanish platform (esendex.es) |
| Sentry (Functional Software, Inc.) | Error detection | Error reports and a 10% sample of the server’s requests, without request bodies or local variables, and with phone numbers, emails, tax IDs and keys masked. The same for the Telegram bot. A report may include other data if it appears in the text of an error. | Sentry’s EU data region; the company is in the United States (section 6) |
| Telegram (Telegram Messenger Inc.) | Staff messaging: alerts and bot | See section 5.4. No customers’ names or phone numbers. | Outside the EEA (section 6) |
5.2 Meta: the business’s own provider
Meta Platforms Ireland Limited provides the WhatsApp Business Platform (Cloud API and Graph API). When it connects its number, the business accepts the WhatsApp Business terms directly with Meta, and Meta charges the business directly for messages that have a cost. According to Meta, for the Cloud API it acts as the business’s processor.
Meta sends the account’s notifications and delivers the messages: what section 3 describes, and customers’ numbers with replies, notifications and marketing messages. According to Meta, it keeps messages for up to 30 days and processes them in its data centres, including outside the EU (section 6).
Meta’s own privacy policy applies to the data of the Meta accounts of the business and its users, and to what Meta does with the data its program receives on the connection page (section 3.1).
5.3 Our own providers
| Provider | What for | What data | Where |
|---|---|---|---|
| Google (Google Workspace) | Our email | The messages you send us and those we send to client businesses | See section 6 |
| Anthropic (AI tools for development and support) | Developing the platform and handling incidents | When we handle an incident or maintain a business’s installation, these tools may see the data needed for that task. The business authorises this in the data processing agreement. | United States (section 6) |
5.4 Telegram: the messaging service of the business’s staff
The business can use Telegram so that its staff receive alerts and look up the workshop’s work from their phones. Telegram Messenger Inc. carries those messages and handles them under its own terms and privacy policy. What goes through Telegram:
- Automatic alerts. New booking requests, conversations the assistant hands over to a person, assistant failures or limits, the morning summary, and alerts about the number’s connection. They say what happened and what to do, with a link to the CRM. They include no customers’ names, phone numbers, plates, notes or message text. The buttons carry only an internal reference.
- The staff’s work. Orders, vehicles with their plate, bookings and parts that staff look up, and the work photos and recommendations they send. The bot shows no customers’ names, phone numbers or emails, none of their comments and no WhatsApp conversations: all of that is looked up in the CRM. Names, phone numbers, emails and tax IDs are removed from the order reason staff write before it is shown, and the CRM warns staff that this text is visible in Telegram. Whatever staff type to the bot or to the staff assistant also goes through Telegram.
Only employees with an active CRM account can use the bot, and they link it with a one-time code. Authorised staff of each business access only their own business’s data. We give data to no one else, except to authorities when the law requires it.
6. Data that leaves the European Economic Area
Some services process data outside the European Economic Area (EEA), or are companies established outside it even though they store the data in the EU. For the services the business contracts, the business chooses and signs the safeguards; here we describe what each provider offers.
- Anthropic (Claude API). For customers in the EEA, the contract is with Anthropic Ireland, Limited. Anthropic stores the data in the United States, and the model that writes the replies may run in any country where Anthropic has infrastructure. Its data processing terms include the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).
- Meta. According to Meta, message content may be processed in its data centres around the world, including the United States. For those transfers Meta relies on the EU-U.S. Data Privacy Framework (an adequacy decision, Art. 45 GDPR) and may also use the standard contractual clauses, under its WhatsApp Business data transfer terms, which the business accepts when connecting.
- Vultr. The servers are in Frankfurt (Germany, EU). The Constant Company, LLC, the company behind Vultr, is in the United States and may access them to provide the service. According to Vultr, its data processing agreement, which it signs at the customer’s request, includes the standard contractual clauses.
- Sentry. Reports are stored in Sentry’s EU data region, but Functional Software, Inc. is in the United States. According to its privacy policy, it participates in the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and also uses the standard contractual clauses.
- Amazon Web Services. The data is stored in Spain. AWS belongs to a group based in the United States; its data processing agreement includes the standard contractual clauses for any access from outside the EEA.
- Telegram. Telegram Messenger Inc. is not established in the EEA, and there is no adequacy decision for it. Telegram does not sign data processing agreements or standard contractual clauses with those who run bots, so there are no Art. 46 GDPR safeguards for what goes through Telegram. According to its privacy policy, it stores data of accounts registered from the EEA in the Netherlands, and its EU representative is the European Data Protection Office (EDPO), in Brussels. That is why no customer names or phone numbers go through Telegram (section 5.4).
- Our providers. Google may process our email outside the EEA, including in the United States, under the standard contractual clauses in its data processing terms. The Anthropic AI tools we use process data in the United States, under the standard contractual clauses in its commercial terms.
You can ask us for a copy of the safeguards of our own providers by writing to nik.l@konomic.com. For the services the business contracts, ask the business.
7. How long data is kept
The business decides how long it keeps its data and sets this in the data processing agreement. These are the periods the platform works with:
| Data | Period |
|---|---|
| One-time authorization code | Not stored. |
| The business’s access token | In the business’s server configuration while it uses the platform. It is removed when the business leaves, or earlier if it asks. If the business revokes the app’s access in Meta, it withdraws the permissions it gave. |
| Connection record (account and number IDs, statuses and dates) | While the business uses the platform; after that, whatever the business decides (see below). |
| Audit log | 6 years from each entry; then it is deleted automatically. It records who did what, when and from which interface. For changes to customer records, vehicles and buyer profiles it stores only which fields changed, not their values. When a customer record is erased, that customer’s personal data is deleted from older entries. Some entries keep a plate (for example, that of a booking registered by the assistant), text written by staff (such as the reason for a visit or a recommendation) or the IP address from which the customer approves an estimate, as proof of the approval. Never the text of WhatsApp messages. Administrators consult it for the security of the service and to handle or defend claims. Work-order status changes are also used to compute mechanics’ productivity, visible to administrators and managers. |
| Messages, conversations and imported history | No automatic deletion: the business decides the period. They are deleted when the business erases the customer record (the messages stored under the customer’s current number) and when the business asks us to delete them. |
| Synced address book | The same as messages. If a contact is removed on the phone, it is marked as removed, but its number and name are kept until the business erases the matching customer record or asks us to delete it. When the record is erased, the name is deleted and the number is kept only as a block marker, so it is not imported again. |
| Notifications and marketing messages sent, with their delivery status and their data (service, date, order number, ITV due date with the plate, or recommendation text) | No automatic deletion. When the customer record is erased, pending ones are cancelled and ones already sent are kept as the business’s record. |
| Customer records and booking requests | Until the business erases the record. Then the name, phone number, email, tax ID and notes are deleted; the record keeps no contact details but stays linked to the vehicles, invoices and bookings that the business must keep. |
| Intake, handover and work photos, signatures and PDF records | 4 years from upload, locked against deletion in storage: they are evidence of the vehicle’s condition and of what the customer signed. They are kept after the customer record is erased as well. |
| Staff conversations with the Telegram assistant | Deleted after 30 days. |
| Internal system events (status changes of bookings, orders and the connection) | Deleted 90 days after they are processed. |
| Server technical logs | Rotated by size (20 MB × 5 files per service): old entries are overwritten automatically. The application’s logs contain no message text and show phone numbers with only 3 digits; they may contain what staff search for in the CRM, for example a name or a plate. The database’s logs record only technical errors, which may include the value that caused the error. |
| Error reports (Sentry) | As set by the business’s Sentry plan. |
| Data sent to the Anthropic API | Anthropic deletes it within 30 days. It may keep it longer if the law requires it or if it detects use that breaks its usage policy (up to 2 years). |
| Backups | A full daily copy of the database. Copies on the server are deleted after 7 days; copies in AWS S3 expire after 90 days. So deleted data can remain in backups for up to 90 days. If a backup is restored, the deletions made since then are applied again. |
| Our data: business relationship with each client (contacts, contracts and invoices) | For the length of the contract and 6 years after, because the law requires us to keep business records (Art. 30 of the Spanish Commercial Code). |
| Our data: support emails | Up to 2 years after the request is closed. |
| Our data: rights requests | We keep a record of the request and our reply for 3 years, so we can show that we handled it. |
Any of our own data that we must keep by law after deleting it is blocked (Art. 32 LOPDGDD): nobody uses or consults it, except to make it available to courts, the public prosecutor or the AEPD until the related liabilities expire. Then it is destroyed.
When a business leaves the platform
The installation’s data is in the services the business contracts, in its own name, and stays under its control. If the business disconnects its WhatsApp number, the platform stops receiving its messages; what is already stored is kept until the business decides to delete it.
When the service ends, within the following 30 days we remove our access, the WhatsApp access token from the configuration and the Konomic app’s subscription to its account, and delete any copy of its data that we hold ourselves. If the business asks, we first help it export its data, and then delete its installation or leave it in place, as it instructs.
8. Your rights
You can ask us for:
- access: to know what data about you we process and get a copy;
- rectification: to correct inaccurate data;
- erasure: to delete your data;
- objection: to stop processing it where the basis is our legitimate interest;
- restriction: to keep your data without using it while we check whether it is accurate or whether your objection is justified; when the processing is unlawful but you prefer that we do not delete it; or when we no longer need it but you need it for a legal claim;
- portability: to receive the data you gave us in a structured, commonly used and machine-readable format, and to have us send it to another controller where technically feasible. It applies when the processing is based on your consent or on a contract and is carried out by automated means;
- to withdraw your consent where that is the basis, without affecting what was done before.
How to exercise them
- By email to nik.l@konomic.com, with the subject “Data protection”.
- By post to KONOMIC DIGITAL SL, C/ Santo Domingo, 1, Km. 1, 38003 Santa Cruz de Tenerife, Spain.
Tell us your name, what you are asking for and what it relates to (for example, the WhatsApp number or the business you talked to). If we cannot tell that the request is yours, we will ask only for what we need to check it. It is free.
If the data is ours, we reply within one month of receiving your request. If it is complex, or there are many requests, this can be extended by two more months; if so, we will tell you within the first month.
If the data belongs to a business that uses Konomic, the business decides: contact it first. If you write to us, we pass your request to the business without delay; the business replies to you within the period the law gives it, and we do what it instructs.
Complaints: if you think your data has not been handled properly, you can complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD): www.aepd.es, C/ Jorge Juan 6, 28001 Madrid, Spain.
To delete data, follow the data deletion instructions.
9. How we protect data
- Public addresses work only over an encrypted connection (HTTPS), and browsers remember never to use an unencrypted one. They also use security headers.
- Of the platform, only the web server is open to the internet; the server is administered over SSH with key-only access. The database and internal services do not accept connections from outside.
- Every notification is checked to really come from Meta: Meta signs it with a secret that only Meta and the server know, and those that do not match are rejected.
- Each person logs in with their own account. The WhatsApp connection tools and the erasure of customer records are available to administrators only.
- The business’s access token is not written to the database, the technical logs or the audit log.
- The application’s technical logs mask phone numbers (only 3 digits remain), emails, tax IDs and keys, and never contain message text.
- Error reports from the server and the bot include no request bodies or local variables, and mask phone numbers, emails and keys.
- The AI assistant is instructed not to reveal internal data and to treat customers’ messages as data, not as commands. Its tools return only information that can be shown to the customer. It has limits: 20 messages per hour per number, plus daily caps per number and overall.
- The database prevents changing or deleting audit log entries. It allows it, in a controlled way, only to delete a customer’s personal data when their record is erased and to delete entries older than 6 years.
- The AWS S3 storage blocks public access. The server’s key can write and read but not delete. Each backup is checked when it is made, and restoring is documented and rehearsed.
- WhatsApp media files are not downloaded.
No system is infallible. If a security breach affects data we process on behalf of a business, we will tell the business without undue delay and help it handle the breach (Art. 33(2) GDPR); the business decides whether to notify the AEPD and the people affected. If it affects data for which we are the controller, we will notify the AEPD within 72 hours unless the breach is unlikely to result in a risk to people, and we will tell you if it is likely to result in a high risk to you (Arts. 33 and 34 GDPR).
10. What we do not do
- We do not sell, license or buy data obtained through Meta’s platform or WhatsApp, including anonymised, aggregated or derived data, and we do not pass it to anyone except the recipients in section 5 to provide the service.
- We do not use data for advertising or to build advertising profiles. The business’s marketing messages (section 4.2) are sent only on its instructions and only to customers who gave their consent.
- We do not use the data that comes through Meta’s platform for anything other than providing the service to the connected business. We do not use it to surveil people, to discriminate against them, or to decide on their access to housing, employment, insurance, education, credit or public benefits.
- We do not use the data, or let it be used, to build, develop, train or improve AI models. Anthropic’s commercial terms prohibit it from training its models on it.
11. Minors
The platform is for businesses and is used by adults acting for them. It is not aimed at minors. In Spain, children under 14 need their parents or guardians to consent to the processing of their data (Art. 7 LOPDGDD). If a minor wrote to a business that uses Konomic, their parents or guardians can ask that business, or us, to delete their data.
12. Changes
If we change this policy, we will publish the new version here with its date. If the change significantly affects how data is used, we will tell client businesses first.
13. Contact
KONOMIC DIGITAL SL
C/ Santo Domingo, 1, Km. 1, 38003 Santa Cruz de Tenerife, Spain
nik.l@konomic.com
The Spanish version of this policy is available at legal.konomic.io/privacidad.