What's App Sender Social Panel

Privacy Policy

Last updated 28 July 2026

This policy explains what Twinfusion does with personal data when you use What's App Sender Social Panel (“the Service”), a platform that lets businesses talk to their customers over WhatsApp.

1. Who is responsible for your data

The Service is operated by Twinfusion, Nairobi, Kenya.

Our role depends on whose data it is, and the distinction matters:

  • For our business customers (the people who hold an account with us) we are the data controller. We decide what account data we need and why.
  • For their customers (the people they message on WhatsApp) we are a data processor. The business decides who to contact and what to say; we only store and transmit those messages on their instructions. If you were messaged by a business using our Service and want your data removed, the business is your first point of contact — though you can also write to us directly and we will act on it.

2. What we collect

From account holders

  • Name, email address and role
  • A one-way hash of your password — never the password itself
  • Sign-in times, IP address and browser user agent, kept for security
  • Your workspace’s WhatsApp Business credentials, encrypted at rest

From WhatsApp conversations

  • The customer’s WhatsApp phone number and profile name
  • Message content, including text, images, documents and audio they send
  • Delivery and read receipts returned by WhatsApp
  • Any name, email or other details a business imports about its own contacts
  • Tags, notes and custom fields the business records against a contact

What we do not collect

  • We do not read your WhatsApp messages for advertising or profiling
  • We do not sell personal data, and never have
  • We do not use conversation content to train machine-learning models
  • We place no advertising or third-party tracking cookies

3. Why we process it

  • To deliver the Service — sending, receiving and displaying messages
  • To keep accounts secure — authentication, and detecting misuse
  • To meet WhatsApp’s rules — such as honouring opt-outs and the 24-hour messaging window
  • To support you — diagnosing faults you report

Our lawful bases are performance of a contract (running the Service you signed up for), legitimate interests (security and reliability), and consent where a customer has opted in to marketing messages.

4. WhatsApp and Meta

The Service is built on the WhatsApp Business Platform. Messages are transmitted through Meta Platforms Ireland Limited, and their handling of that data is governed by the WhatsApp Business Data Transfer Addendum and the WhatsApp Privacy Policy. Sending a message through the Service necessarily means sending it through Meta’s infrastructure.

5. Who else sees the data

We share personal data only with:

  • Meta Platforms — to actually deliver WhatsApp messages
  • Our hosting provider — which stores the database on our behalf
  • Authorities — where we are legally required to, and no further

Every business account is isolated from every other. One customer of ours cannot read, export or modify another’s contacts or conversations; this is enforced in the database and on every request, not by convention.

6. How long we keep it

  • Conversations and contacts — for as long as the business keeps its account, or until it deletes them
  • Raw webhook logs — a short operational window, then discarded
  • Application logs — typically 30 days
  • Closed accounts — deleted within 30 days of the account being closed

7. Security

  • All traffic is encrypted in transit over HTTPS
  • WhatsApp access tokens and app secrets are encrypted at rest with AES-256-GCM
  • Passwords are stored as bcrypt hashes and cannot be reversed
  • Incoming webhooks are rejected unless they carry a valid Meta signature
  • Access is role-based, and each workspace’s data is scoped to that workspace

No system is perfectly secure. If we discover a breach affecting your data, we will tell you and the relevant regulator without undue delay.

8. Your rights

Under Kenya’s Data Protection Act 2019 — and the GDPR where it applies — you may ask us to give you a copy of your data, correct it, delete it, restrict or object to its use, or export it in a portable format. You may also complain to your data protection authority; in Kenya that is the Office of the Data Protection Commissioner.

Write to privacy@twinfusion.co.ke and we will respond within 30 days. See also our data deletion instructions.

9. Opting out of messages

Reply STOP to any message and that business will stop contacting you through the Service. The opt-out is recorded against your number and campaigns skip it automatically. You can also block the business in WhatsApp itself, which prevents delivery regardless of what we do.

10. Children

The Service is for business use and is not directed at children under 18. We do not knowingly collect their data; if you believe we have, contact us and we will delete it.

11. International transfers

Data may be processed outside Kenya, including in the European Union and the United States, because Meta’s infrastructure is global. Such transfers rely on standard contractual clauses or an equivalent safeguard.

12. Changes

We will update this page when our practices change and revise the date at the top. Material changes will be notified to account holders by email.

13. Contact

Twinfusion
Nairobi, Kenya
privacy@twinfusion.co.ke