Privacy Policy
Prime Connect Ltd ("we", "us", "our") operates a Meta Business Solution Provider console that helps our business customers ("Customers") onboard, manage, and message through WhatsApp Business Accounts ("WABAs") on the Meta WhatsApp Business Platform. A WABA may be customer-owned through Meta Embedded Signup or provider-managed by us under a separate managed-WABA agreement. This Privacy Policy explains what personal information we process when Customers use our service and when end users interact with our Customers on WhatsApp, why we process it, who we share it with, and the rights individuals have over that information.
1. Who this policy applies to
This policy applies to:
- Customer users — the employees and agents of our Customers who sign in to the Prime Connect Ltd provider console.
- End users — individuals who message a Customer's WhatsApp Business number that is managed through Prime Connect Ltd. For end-user data, Prime Connect Ltd acts as a data processor on behalf of the Customer, who is the data controller and operates their own privacy policy.
- Visitors — anyone who visits our public web pages.
2. Information we process
2.1 Customer account data
- Identity and contact data for Customer users (name, work email, organization, role).
- Authentication data managed by our identity provider (Clerk).
- Meta Business Portfolio, WhatsApp Business Account, and phone number identifiers that the Customer authorizes us to manage via Meta's Embedded Signup flow or that we manage under a provider-managed WABA agreement.
- Delegated or provider-managed access tokens issued by Meta. Tokens are encrypted at rest using AES-GCM with provider-managed keys and are never exposed to client browsers.
2.2 Messaging metadata and content
- Message templates submitted to Meta for approval.
- Message identifiers, delivery and read receipts, and webhook events delivered by Meta.
- Message body content that the Customer sends or receives through the platform, processed solely to deliver the messaging service the Customer has requested.
- End-user WhatsApp phone numbers (in hashed and, where required for delivery, plaintext form).
2.3 Operational and security data
- Audit logs of onboarding events, configuration changes, API calls, and webhook receipts.
- Request logs, IP addresses, user agents, and error traces used for security monitoring and abuse prevention.
2.4 Google account data (optional Google Contacts sync)
A Customer administrator may optionally connect their own Google account to import their Google
Contacts into their Prime Connect Ltd workspace. This connection is initiated by the administrator and
can be disconnected at any time. When connected, we access the following Google user data through the
Google People API, using the read-only scope
https://www.googleapis.com/auth/contacts.readonly together with the sign-in scopes
openid and email:
- The names and phone numbers of the contacts in the connected Google account, used solely to create or update contacts in the Customer's Prime Connect Ltd workspace so the Customer can message them on WhatsApp.
- The email address of the connected Google account, used only to display which account is connected.
- An OAuth refresh token issued by Google, stored encrypted at rest using AES-GCM with provider-managed keys and never exposed to client browsers, used only to perform contact syncs the administrator requests.
We request the minimum scope necessary and never request write access to Google Contacts, Gmail, Google Drive, or any other Google data. Google Contacts data is used only to populate the Customer's own contact list and is not sold, used for advertising, or used to build user profiles. When the administrator disconnects Google, or on account termination, we revoke the token and delete the stored Google connection.
Limited Use disclosure. Prime Connect Ltd's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. How and why we use information
We process personal information to:
- Provide, secure, and operate the Prime Connect Ltd provider console and the Customer's WhatsApp messaging integration.
- Authenticate Customer users and enforce role-based access within the Customer organization.
- Submit, store, and act on the Customer's instructions to Meta's Graph API on the Customer's behalf.
- Detect, prevent, and respond to fraud, abuse, security incidents, and policy violations.
- Comply with applicable laws and Meta platform requirements, including the Meta Platform Terms, the WhatsApp Business Solution Terms, and the WhatsApp Business Messaging Policy.
- Maintain audit trails and respond to legitimate legal requests.
We do not use Business Solution Data or messages exchanged on the WhatsApp Business Platform to build, append to, or augment profiles of individual WhatsApp users, and we do not sell, license, or share that data with third parties except as described in this policy.
4. Legal bases for processing (EEA/UK)
Where the EU/UK GDPR applies, we rely on the following legal bases:
- Contract — to perform our agreement with the Customer.
- Legitimate interests — for security, fraud prevention, audit logging, and improving the service, balanced against the rights of the individual.
- Legal obligation — for tax, accounting, and lawful information requests.
- Consent — where required, for example before sending marketing communications to a Customer user.
5. How we share information
We share personal information only with:
- Meta Platforms, Inc. — required to operate the WhatsApp Business Platform integration. Data sent to Meta is governed by Meta's privacy policies.
- Service providers acting on our behalf and bound by written agreements, including our hosting provider (Vercel), our database provider (Neon), and our identity provider (Clerk).
- The Customer organization — Customer users can see information related to their own organization's WABAs, phone numbers, and messaging activity.
- Authorities — when required by law, court order, or to protect the rights, property, or safety of Prime Connect Ltd, our Customers, or others.
- Successors — in connection with a merger, acquisition, or sale of assets, subject to equivalent privacy protections.
We do not sell personal information and we do not share personal information for cross-context behavioral advertising.
6. Data retention
We retain Customer account data for as long as the Customer maintains an active account with us, plus a limited period needed for legal, accounting, and security purposes. Webhook event payloads are retained for a rolling retention window (configurable per Customer, default 30 days). Audit logs are retained for up to 24 months. Encrypted access tokens are deleted promptly after a Customer disconnects an asset, deauthorizes the app from Meta, or terminates their account.
7. International transfers
Prime Connect Ltd operates from, and uses service providers located in, the United States and other jurisdictions. Where personal information is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (or equivalent UK transfer mechanisms) together with appropriate supplementary safeguards.
8. Your rights
Subject to applicable law, individuals have the right to:
- Access the personal information we hold about them.
- Request correction of inaccurate or incomplete information.
- Request deletion of personal information.
- Object to or restrict certain processing, including direct marketing.
- Receive a portable copy of their information.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with a supervisory authority.
End users whose data is processed through a Customer's WhatsApp Business number should contact that Customer directly to exercise their rights, because the Customer is the controller of that data. We will support our Customers in fulfilling those requests.
9. How to request data deletion
You can request deletion of data associated with the Meta integration in two ways:
- Remove the Prime Connect Ltd app from your Meta Business Settings. Meta will send us a signed deauthorization callback, and we will delete the corresponding access tokens and PII within 30 days.
- Submit a deletion request at /privacy/data-deletion or email legal@primeconnect.co.uk. We will respond with a confirmation code and complete the deletion within 30 days.
- To remove imported Google Contacts data, disconnect Google from Settings → Integrations in your Prime Connect Ltd workspace. This revokes our access token with Google and deletes the stored Google connection. You may also revoke Prime Connect Ltd's access from your Google account permissions page.
10. Security
We use encryption in transit (TLS) and encryption at rest for sensitive credentials, role-based access controls, audit logging, signed webhook verification, tenant isolation, and least-privilege service accounts. No system is perfectly secure; if we learn of a breach affecting your personal information, we will notify you and the relevant authorities as required by law.
11. Children's privacy
Prime Connect Ltd is a business-to-business service and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify Customer users by email or through the console, and update the effective date at the top of this page. Continued use of the service after changes take effect constitutes acceptance.
13. Contact us
For privacy questions or to exercise your rights, contact us at legal@primeconnect.co.uk.