Privacy Policy
1. Who we are
This Privacy Policy explains how H TECH For Modern Programming, a software development company registered in Egypt, collects, uses, stores and protects information in connection with WS OTP (the "Application"), our application built on the WhatsApp Business Platform.
Registered address: 224 Elhoriah St, Ibrahimaih - Alexandria, Egypt
Contact for privacy matters: support@htech-eg.net
2. What the Application does
The Application uses the WhatsApp Business Platform (Cloud API) provided by Meta Platforms, Inc. to send and receive WhatsApp messages on behalf of businesses. Typical uses include one-time passcodes, transactional notifications such as order and appointment updates, and customer support conversations.
We act as a data processor on behalf of the businesses that use the Application (our "Customers"). Those businesses are the data controllers for the end-user data they process through it. Where we handle information about our Customers themselves, we act as a controller.
3. Information we collect
| Category | Examples | Why |
|---|---|---|
| WhatsApp identifiers | Phone numbers of message recipients, WhatsApp IDs (wa_id), display names as provided by
WhatsApp |
To route messages to the correct recipient and match replies to conversations |
| Message content | Text, images, documents, audio, location and interactive replies sent to or from the business number | To deliver messages and display conversation history to the business |
| Message metadata | Message IDs, timestamps, delivery and read statuses, error codes, conversation and pricing categories | To confirm delivery, diagnose failures and produce usage reports |
| Account and credentials | WhatsApp Business Account (WABA) IDs, phone number IDs, business profile details, access tokens | To connect the Application to the business's WhatsApp account and authorise API calls |
| Customer account data | Name, business name, email address, billing contact of the businesses using the Application | Account administration, support and billing |
| Technical logs | IP address, request timestamps, API responses, diagnostic error logs | Security, abuse prevention, and troubleshooting |
We do not knowingly collect special categories of personal data (such as health, biometric, religious or political data). We ask Customers not to transmit such data through the Application.
4. How we use information
- To deliver, receive and display WhatsApp messages on behalf of our Customers.
- To authenticate users and deliver one-time passcodes requested by our Customers.
- To provide delivery reports, conversation history and usage analytics to the relevant Customer.
- To operate, secure, monitor and improve the Application.
- To provide technical support and respond to enquiries.
- To comply with legal obligations and with the WhatsApp Business Messaging Policy.
We do not sell personal data. We do not use message content for advertising, and we do not use it to train machine-learning models.
5. Legal bases for processing
Where the GDPR or comparable law applies, we rely on:
- Performance of a contract — to provide the Application to our Customers.
- Legitimate interests — to secure the service, prevent abuse and improve reliability.
- Consent — where an end user has opted in to receive WhatsApp messages from a business.
- Legal obligation — where retention or disclosure is required by law.
End users must have opted in before a business sends them messages. Obtaining and recording that opt-in is the responsibility of the Customer operating the WhatsApp Business Account.
6. Sharing and disclosure
| Recipient | Purpose |
|---|---|
| Meta Platforms, Inc. | Message delivery over the WhatsApp Business Platform. Meta's handling of this data is governed by its own WhatsApp Business Data Processing Terms and privacy policies. |
| Hosting and infrastructure providers | Hosting the Application and storing data, under contractual confidentiality and security obligations. |
| The Customer business | Conversations and delivery reports are visible to the business the end user is messaging. |
| Legal and regulatory authorities | Where disclosure is required by applicable law or valid legal process. |
7. WhatsApp-specific disclosures
- Messages sent through WhatsApp are subject to WhatsApp's own terms and privacy practices.
- We access only the WhatsApp Business Accounts and phone numbers that a business has explicitly connected to the Application.
- Access tokens obtained during onboarding are used solely to operate that business's WhatsApp account, and are revoked when the business disconnects the Application.
- We do not access an end user's personal WhatsApp account, contacts or chats with other businesses.
8. Data retention
- Message content and metadata — retained for as long as the Customer's account is active, or for the shorter period the Customer configures. Deleted within 30 days of account termination.
- One-time passcodes — retained only for the validity period of the code, then deleted.
- Access tokens — deleted immediately upon disconnection or revocation.
- Technical logs — retained up to 90 days for security and diagnostics.
- Billing records — retained as required by applicable Egyptian tax and commercial law.
9. How to request deletion of your data
Deletion request
To request deletion of personal data held about you, email support@htech-eg.net with the subject line "Data Deletion Request" and include:
- the WhatsApp phone number concerned, in international format;
- the name of the business you were messaging, if known;
- a brief description of what you would like deleted.
We acknowledge requests within 7 days and complete verified requests within 30 days. We may ask for information to verify your identity before acting. Where we process data on behalf of a business, we will forward your request to that business and assist them in fulfilling it.
Businesses using the Application may delete their account and all associated data at any time by contacting us at the same address.
10. Security
- All data in transit is encrypted using TLS.
- Access tokens and credentials are stored encrypted at rest.
- Access to production systems is restricted to authorised personnel and logged.
- Webhook payloads are verified using cryptographic signature validation before processing.
- We apply the principle of least privilege across systems and staff accounts.
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security.
11. International transfers
We are based in Egypt. Meta Platforms and our infrastructure providers may process data in other countries, including the United States and the European Union. Where required, such transfers are made under appropriate safeguards such as Standard Contractual Clauses.
12. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- request erasure of your data (see section 9);
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time, including by replying STOP to a WhatsApp message or blocking the business number;
- lodge a complaint with your local data protection authority.
To exercise any of these rights, contact support@htech-eg.net.
13. Children
The Application is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be communicated to affected Customers by email.
15. Contact us
H TECH
Email: support@htech-eg.net
Website: https://htech-eg.net
Address: 224 Elhoria St, Al Ibrahimyah , Alexnadria , Egypt