Privacy Policy

Last updated 9 August 2026

Beezila AI, operated by FATEN GROUP LLC (a Florida limited liability company), helps businesses manage WhatsApp conversations with their own customers. This policy explains what we collect, why we hold it, who else sees it, and how to get it deleted. “We” and “us” mean FATEN GROUP LLC.

Two different roles

It matters which data we are talking about, because our responsibilities differ.

  • For our customers' account data — the business that signs up, its team members, its billing details — we are the controller. We decide what is collected and why.
  • For end-customer data — the people who message a business on WhatsApp — we are a processor. The business is the controller. We handle that data on their instructions, and they are responsible for having a lawful basis to message those people.

If you messaged a business and want your data removed, contact that business first; they control it. You can also write to us and we will route the request to them.

What we collect

Account data. Name, email address, hashed password, the organisation you belong to, and your role within it.

WhatsApp connection data. When you connect a number we store your WhatsApp Business Account ID, phone number ID, display number, verified business name, and the access token Meta issues. That token is encrypted at rest with AES-256-GCM and is never sent to your browser.

Contacts. Phone number, name as supplied by WhatsApp or imported by you, tags, pipeline stage, custom attributes you define, opt-in status, the source of that opt-in, and the time of last inbound message.

Messages. The content of messages sent and received through your connected number, including text, media, delivery and read status, and the raw payload Meta delivers. Media files are stored so they remain viewable after Meta's temporary links expire.

Automation data. Bot flows, templates, broadcasts and their results, notes and quick replies your team creates.

Advertising attribution. If a conversation begins from a Click-to-WhatsApp ad, Meta includes a referral block identifying the ad and the click. We store it so you can attribute conversations to campaigns.

Operational logs. Request metadata and error diagnostics. We deliberately exclude message bodies and credentials from logs.

What we do not do

  • We do not sell personal data, and we never have.
  • We do not use your messages or your contacts to train machine-learning models.
  • We do not use your customer data to advertise to them, or to anyone.
  • We do not access your conversations except where you ask us to for support, or where we are legally required to.

Why we hold it

  • To deliver the service you asked for: sending and receiving messages on your number, running your automations, and showing you the results.
  • To meet WhatsApp Business Platform rules — for example, keeping a record of opt-in and opt-out so marketing messages only reach people who agreed to them.
  • To keep the service secure and diagnose faults.
  • To bill you for your subscription.

Who else sees it

We share data only with the parties needed to run the service:

  • Meta Platforms — messages are sent and received through the WhatsApp Business Platform. Meta processes them under its own terms, and bills you directly for messaging.
  • Our infrastructure providers — hosting, database and queue services under contract, used only to operate Beezila.
  • Authorities — where we are legally compelled, and only to the extent required.

Each organisation's data is isolated. Access is scoped to the organisation at the database query layer, not merely by convention in application code.

How long we keep it

  • Account data: while your account is open, then deleted within 30 days of closure.
  • Messages, contacts and automation data: while your account is open, or until you delete them.
  • Operational logs: up to 90 days.
  • Suppression list: retained after account closure only where needed to honour an opt-out — deleting the record of a "stop" request would allow someone to be messaged again.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to processing, or to complain to a regulator. We honour these requests regardless of jurisdiction.

To delete your data, see Delete my data. Contacts can be exported to CSV at any time from the Contacts page.

Security

  • WhatsApp access tokens are encrypted at rest with AES-256-GCM.
  • Meta webhooks are verified by HMAC-SHA256 signature before being processed, so forged callbacks are rejected.
  • The token exchange happens server-side; long-lived credentials never reach a browser.
  • Passwords are stored hashed, never in plain text.

No system is perfectly secure. If we discover a breach affecting your data we will notify you and, where required, the relevant regulator.

International transfers

Our infrastructure may process data outside your country. Where that happens we rely on appropriate safeguards, including standard contractual clauses with our providers.

Children

Beezila is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.

Changes

If we change this policy materially we will notify account holders by email before it takes effect. The date at the top always reflects the current version.

Who we are

Beezila AI is operated by FATEN GROUP LLC, a limited liability company registered in the State of Florida, United States (document no. L26000054208).

7901 4th St N Ste 31527
St Petersburg, FL 33702
United States

Privacy enquiries and data requests: privacy@beezila.com