KONOMIC DIGITAL SL

Privacy Policy

Konomic WhatsApp messaging platform and the “Konomic” app (App ID 1411708813877592)

Last updated: 25 September 2026

Summary

1. Who we are and what this policy covers

Company
KONOMIC DIGITAL SL
Tax ID (NIF)
B22884688
Registered address
C/ Santo Domingo, 1, Km. 1, 38003 Santa Cruz de Tenerife, Spain
Registry
Registro Mercantil de Santa Cruz de Tenerife, sheet TF-75427, EUID ES38013.000539563
Activity
Computer programming (CNAE 62.10)
Privacy email
nik.l@konomic.com

This policy covers:

It does not cover the websites or other services of our client businesses, which have their own policies. It does not cover other Konomic products either.

The rules for businesses using the service are in the Terms of Service.

2. Who decides about the data: your business or us

The business decides (we are a processor, Art. 28 GDPR)

Each business has its own installation of the platform, with its own database, on servers and services it contracts in its own name. One business’s data is never mixed with another’s.

On behalf of the business, and only on its instructions, we process:

The business is the controller of all this data. It decides what it is used for, on what legal basis and how long it is kept. Its instructions and our obligations are set out in the data processing agreement (Art. 28 GDPR) we sign with each business. We develop, install, maintain and support the platform, and access the data only for that.

We decide (we are the controller)

We are the controller only of:

We do not use this data for marketing or product analytics.

If you are a customer or contact of a business that uses Konomic, read that business’s privacy policy and contact the business first. If you write to us, we will pass your request to the business and help it respond.

3. What data we receive from Meta, and why

3.1 When a business connects its number

The person connecting the number opens Meta’s window from their business’s CRM, logs in to Meta and accepts the permissions Meta shows. We use those permissions only to manage the connected WhatsApp Business account and to send and receive its messages, on the business’s behalf.

DataWhyStored?
One-time authorization codeTo exchange it once with Meta for the business’s access token.No. It is used on the spot and discarded.
Identifiers sent by Meta’s window when it finishes: WhatsApp Business Account ID (WABA) and phone number IDTo know which account and which number to connect.Yes, in the connection record of the business’s installation.
The business’s access token (business integration system-user token)To finish the connection and then send and receive messages on the business’s behalf.Not in the database, the technical logs or the audit log. Only in the protected configuration of the business’s server.
WhatsApp Business accounts that the token gives access to (a query to Meta about the token)To check which account the token gives access to and pick the right one.Only the ID of the chosen account.
Result of subscribing the Konomic app to the account (yes or no)To receive the account’s automatic notifications (webhooks).Yes, in the audit log.
The account’s phone numbers: ID, display number, verified name, platform type, status, and whether the number is on the WhatsApp Business appTo find the number that runs both on the phone and on the platform.Only the ID and the display number of the connected number.
Response to the request to sync contacts and historyTo track progress and meet the 24-hour deadline set by Meta.Only the status, the dates and, if it fails, Meta’s error text.
Account status notices: disconnection or reconnection, reason, and who started itTo mark the number as disconnected or reconnected and alert administrators.Yes, in the connection record and the audit log.

The connection record also stores the date and the internal ID of the user who made the connection. If the person cancels, or an error occurs in Meta’s window, the step or the error message is shown on screen only and is not sent to the server.

Your Facebook profile. We do not read or store your Facebook profile (name, email, user ID, picture or friends). From Meta’s window, the page takes only the one-time code and the connection identifiers.

Meta’s program on the connection page. To open Meta’s window, the connection page loads Meta’s JavaScript SDK in the browser. When it loads, the browser sends Meta technical data: IP address, browser and device type, the referring page and, if you are logged in to Facebook in that browser, Meta’s cookies, which let Meta link that data to your account. We are joint controllers (Art. 26 GDPR) with Meta Platforms Ireland Limited for that collection and its transmission to Meta, under the controller addendum of Meta’s Business Tools Terms. The essence of that arrangement is:

We do not receive that technical data. Only administrators can use the connection page.

3.2 After the connection (on the business’s behalf)

Meta sends this data to the business’s installation through automatic notifications (webhooks). It is processed only to provide the service to the business.

DataWhy
Messages the business receives: sender’s number, text (up to 4,000 characters), date and message IDTo keep them as context for the assistant and for handing the conversation to a person, recognise the opt-out and opt-in words (STOP, BAJA, ALTA), avoid duplicates, and limit abuse and costs.
The sender’s WhatsApp profile nameIf the assistant registers a booking request and there is no other name, it is saved as the customer’s name. It is not sent through Telegram.
Replies that staff send from the WhatsApp Business app on the phone: recipient’s number and textTo keep the conversation complete and pause the assistant in that conversation (12 hours by default).
Delivery status of the messages sent: delivered, read or failed, and the reason for a failureTo know whether the message arrived and, if it failed, send an SMS.
Chat history from the WhatsApp Business app, if the business agrees to share it when connecting: for each chat, the other person’s number and, for each message, the text, direction, original date and IDTo give context to the conversation. Meta decides how much history it sends (according to Meta, up to 180 days); the platform applies no further limit. It includes all one-to-one chats in the app, including chats with people who are not customers. The assistant does not reply to these messages, but if that person writes later, they are part of the recent messages it uses as context.
Address book of the WhatsApp Business app, which the platform requests from Meta as soon as the number is connected, with no further step by the business: number, full name, first name, and whether the contact was added or removedTo link a number to a customer record that already exists. All contacts are stored, including those that match no record. It never creates new records and is never used to send messages.

WhatsApp photos, voice notes, videos, documents and stickers are not downloaded or stored: only a marker such as “[image message]” is kept. According to Meta, group chats are not synced.

To deliver messages, the platform also sends data to Meta: the customer’s number with the assistant’s reply, or with a notification or a marketing message (section 4.2). For example: order number, service, date and time, vehicle inspection (ITV) due date, the text of a workshop recommendation, or a personal link to check the status.

3.3 What we do not ask for or deliberately keep

The platform uses no analytics or trackers of its own. The only third-party program is Meta’s, on the connection page (section 3.1). These legal pages use no cookies or scripts.

4. What data is used for, and the legal bases

4.1 Data for which we are the controller

PurposeDataLegal basis
Managing our relationship with each client business: contract, invoicing and notices about the serviceName, email, phone number and role of the contact persons; contract and invoice dataIf the client is a sole trader, the contract with them (Art. 6(1)(b) GDPR). For people acting for a business, our legitimate interest in dealing with it (Art. 6(1)(f) GDPR and Art. 19 of the Spanish data protection act, LOPDGDD). Invoices and accounting, legal obligation (Art. 6(1)(c) GDPR).
Collection of technical data by Meta’s program on the connection page, as joint controllers with MetaIP address, browser and device, referring page and Meta’s cookiesLegitimate interest in letting the business connect its number with the tool Meta requires (Art. 6(1)(f) GDPR).
Answering support requestsName, email and whatever you tell usIf you write on behalf of a client business, our legitimate interest in helping the people who act for it (Art. 6(1)(f) GDPR and Art. 19 LOPDGDD). If you yourself are the client, as a sole trader, the contract with you (Art. 6(1)(b) GDPR). If you are not a client, our legitimate interest in replying to you (Art. 6(1)(f) GDPR).
Handling data protection requestsThe data in the requestLegal obligation (Art. 6(1)(c) GDPR).

Without the authorisation in Meta’s window the number cannot be connected. The data in a support or rights request is needed to answer it and to check who is asking; if it is missing, we may not be able to handle the request.

Where the basis is legitimate interest, you can object (see section 8).

4.2 Data we process on the business’s behalf

On behalf of the business and following its instructions (Art. 28 GDPR), the platform uses the data in section 3.2 and in the business’s CRM to:

The business decides the legal basis for this processing and explains it in its own privacy policy. One example from a car workshop: when the assistant registers a booking request, the customer record is marked as agreeing to receive WhatsApp messages about that visit, because the request came through that channel. Marketing, by contrast, needs separate consent that the business collects.

Neither we nor the assistant make decisions based solely on automated processing that produce legal effects on anyone or similarly significantly affect them (Art. 22 GDPR). The business’s staff handle the booking requests the assistant registers.

5. Who receives data

The platform works with third-party services. Almost all of them are contracted by each business directly, in its own name: they are its own processors, and the business is responsible for those contracts and their safeguards. By signing the data processing agreement, the business instructs us to use those services with its data. A few services are used by us (section 5.3).

5.1 Services the business contracts (standard setup)

ServiceWhat forWhat dataWhere
Vultr (The Constant Company, LLC)The server the installation runs onAll the data of the installation, technical logs and local backupsServers in Frankfurt (Germany, EU); the company behind Vultr is in the United States (section 6)
Amazon Web Services (S3)Off-server backups and CRM filesA full daily copy of the database; intake, handover and work photos (including those sent from the bot), signatures and PDF recordsSpain (region eu-south-2)
Anthropic (Claude API): WhatsApp assistantAnswering customersInstructions with the business’s information and the date; the last 30 messages with that number, including imported history and staff replies; and what the assistant looks up to answer: at a car workshop, the customer’s vehicles (make, model, version, year, plate and ITV due date), the workshop’s 3 most recent recommendations for each vehicle, active bookings, order number and status, personal status link, catalogue and free slots. The instructions do not include the phone number or the profile name, although they may appear if the person writes them.Anthropic stores the data in the United States (section 6)
Anthropic (Claude API): staffAnswering staff in the Telegram assistant and reading photos of supplier invoices, expenses and partsStaff questions and what the assistant looks up (orders, vehicles and bookings, without customers’ names or phone numbers); the photos and PDFs staff sendAnthropic stores the data in the United States (section 6)
EsendexSMS when a WhatsApp message failsNumber and message text in the customer’s language (order number, service, date, ITV due date, text of a recommendation, personal status link, link to leave a review). Never chat content. Assistant replies are never sent by SMS.Esendex’s Spanish platform (esendex.es)
Sentry (Functional Software, Inc.)Error detectionError reports and a 10% sample of the server’s requests, without request bodies or local variables, and with phone numbers, emails, tax IDs and keys masked. The same for the Telegram bot. A report may include other data if it appears in the text of an error.Sentry’s EU data region; the company is in the United States (section 6)
Telegram (Telegram Messenger Inc.)Staff messaging: alerts and botSee section 5.4. No customers’ names or phone numbers.Outside the EEA (section 6)

5.2 Meta: the business’s own provider

Meta Platforms Ireland Limited provides the WhatsApp Business Platform (Cloud API and Graph API). When it connects its number, the business accepts the WhatsApp Business terms directly with Meta, and Meta charges the business directly for messages that have a cost. According to Meta, for the Cloud API it acts as the business’s processor.

Meta sends the account’s notifications and delivers the messages: what section 3 describes, and customers’ numbers with replies, notifications and marketing messages. According to Meta, it keeps messages for up to 30 days and processes them in its data centres, including outside the EU (section 6).

Meta’s own privacy policy applies to the data of the Meta accounts of the business and its users, and to what Meta does with the data its program receives on the connection page (section 3.1).

5.3 Our own providers

ProviderWhat forWhat dataWhere
Google (Google Workspace)Our emailThe messages you send us and those we send to client businessesSee section 6
Anthropic (AI tools for development and support)Developing the platform and handling incidentsWhen we handle an incident or maintain a business’s installation, these tools may see the data needed for that task. The business authorises this in the data processing agreement.United States (section 6)

5.4 Telegram: the messaging service of the business’s staff

The business can use Telegram so that its staff receive alerts and look up the workshop’s work from their phones. Telegram Messenger Inc. carries those messages and handles them under its own terms and privacy policy. What goes through Telegram:

Only employees with an active CRM account can use the bot, and they link it with a one-time code. Authorised staff of each business access only their own business’s data. We give data to no one else, except to authorities when the law requires it.

6. Data that leaves the European Economic Area

Some services process data outside the European Economic Area (EEA), or are companies established outside it even though they store the data in the EU. For the services the business contracts, the business chooses and signs the safeguards; here we describe what each provider offers.

You can ask us for a copy of the safeguards of our own providers by writing to nik.l@konomic.com. For the services the business contracts, ask the business.

7. How long data is kept

The business decides how long it keeps its data and sets this in the data processing agreement. These are the periods the platform works with:

DataPeriod
One-time authorization codeNot stored.
The business’s access tokenIn the business’s server configuration while it uses the platform. It is removed when the business leaves, or earlier if it asks. If the business revokes the app’s access in Meta, it withdraws the permissions it gave.
Connection record (account and number IDs, statuses and dates)While the business uses the platform; after that, whatever the business decides (see below).
Audit log6 years from each entry; then it is deleted automatically. It records who did what, when and from which interface. For changes to customer records, vehicles and buyer profiles it stores only which fields changed, not their values. When a customer record is erased, that customer’s personal data is deleted from older entries. Some entries keep a plate (for example, that of a booking registered by the assistant), text written by staff (such as the reason for a visit or a recommendation) or the IP address from which the customer approves an estimate, as proof of the approval. Never the text of WhatsApp messages. Administrators consult it for the security of the service and to handle or defend claims. Work-order status changes are also used to compute mechanics’ productivity, visible to administrators and managers.
Messages, conversations and imported historyNo automatic deletion: the business decides the period. They are deleted when the business erases the customer record (the messages stored under the customer’s current number) and when the business asks us to delete them.
Synced address bookThe same as messages. If a contact is removed on the phone, it is marked as removed, but its number and name are kept until the business erases the matching customer record or asks us to delete it. When the record is erased, the name is deleted and the number is kept only as a block marker, so it is not imported again.
Notifications and marketing messages sent, with their delivery status and their data (service, date, order number, ITV due date with the plate, or recommendation text)No automatic deletion. When the customer record is erased, pending ones are cancelled and ones already sent are kept as the business’s record.
Customer records and booking requestsUntil the business erases the record. Then the name, phone number, email, tax ID and notes are deleted; the record keeps no contact details but stays linked to the vehicles, invoices and bookings that the business must keep.
Intake, handover and work photos, signatures and PDF records4 years from upload, locked against deletion in storage: they are evidence of the vehicle’s condition and of what the customer signed. They are kept after the customer record is erased as well.
Staff conversations with the Telegram assistantDeleted after 30 days.
Internal system events (status changes of bookings, orders and the connection)Deleted 90 days after they are processed.
Server technical logsRotated by size (20 MB × 5 files per service): old entries are overwritten automatically. The application’s logs contain no message text and show phone numbers with only 3 digits; they may contain what staff search for in the CRM, for example a name or a plate. The database’s logs record only technical errors, which may include the value that caused the error.
Error reports (Sentry)As set by the business’s Sentry plan.
Data sent to the Anthropic APIAnthropic deletes it within 30 days. It may keep it longer if the law requires it or if it detects use that breaks its usage policy (up to 2 years).
BackupsA full daily copy of the database. Copies on the server are deleted after 7 days; copies in AWS S3 expire after 90 days. So deleted data can remain in backups for up to 90 days. If a backup is restored, the deletions made since then are applied again.
Our data: business relationship with each client (contacts, contracts and invoices)For the length of the contract and 6 years after, because the law requires us to keep business records (Art. 30 of the Spanish Commercial Code).
Our data: support emailsUp to 2 years after the request is closed.
Our data: rights requestsWe keep a record of the request and our reply for 3 years, so we can show that we handled it.

Any of our own data that we must keep by law after deleting it is blocked (Art. 32 LOPDGDD): nobody uses or consults it, except to make it available to courts, the public prosecutor or the AEPD until the related liabilities expire. Then it is destroyed.

When a business leaves the platform

The installation’s data is in the services the business contracts, in its own name, and stays under its control. If the business disconnects its WhatsApp number, the platform stops receiving its messages; what is already stored is kept until the business decides to delete it.

When the service ends, within the following 30 days we remove our access, the WhatsApp access token from the configuration and the Konomic app’s subscription to its account, and delete any copy of its data that we hold ourselves. If the business asks, we first help it export its data, and then delete its installation or leave it in place, as it instructs.

8. Your rights

You can ask us for:

How to exercise them

Tell us your name, what you are asking for and what it relates to (for example, the WhatsApp number or the business you talked to). If we cannot tell that the request is yours, we will ask only for what we need to check it. It is free.

If the data is ours, we reply within one month of receiving your request. If it is complex, or there are many requests, this can be extended by two more months; if so, we will tell you within the first month.

If the data belongs to a business that uses Konomic, the business decides: contact it first. If you write to us, we pass your request to the business without delay; the business replies to you within the period the law gives it, and we do what it instructs.

Complaints: if you think your data has not been handled properly, you can complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD): www.aepd.es, C/ Jorge Juan 6, 28001 Madrid, Spain.

To delete data, follow the data deletion instructions.

9. How we protect data

No system is infallible. If a security breach affects data we process on behalf of a business, we will tell the business without undue delay and help it handle the breach (Art. 33(2) GDPR); the business decides whether to notify the AEPD and the people affected. If it affects data for which we are the controller, we will notify the AEPD within 72 hours unless the breach is unlikely to result in a risk to people, and we will tell you if it is likely to result in a high risk to you (Arts. 33 and 34 GDPR).

10. What we do not do

11. Minors

The platform is for businesses and is used by adults acting for them. It is not aimed at minors. In Spain, children under 14 need their parents or guardians to consent to the processing of their data (Art. 7 LOPDGDD). If a minor wrote to a business that uses Konomic, their parents or guardians can ask that business, or us, to delete their data.

12. Changes

If we change this policy, we will publish the new version here with its date. If the change significantly affects how data is used, we will tell client businesses first.

13. Contact

KONOMIC DIGITAL SL
C/ Santo Domingo, 1, Km. 1, 38003 Santa Cruz de Tenerife, Spain
nik.l@konomic.com

The Spanish version of this policy is available at legal.konomic.io/privacidad.