Privacy Policy
How NotifyWaves collects, uses, stores, shares, and protects personal information – and what we do not do with it. This policy is part of your contract with us.
Effective date: 22 August 2026 · Last updated: 22 August 2026 · Version 1.0
1. Who we are
This Privacy Policy (“Policy”) explains how Azrin Digital Marketing Company, trading as NotifyWaves (“NotifyWaves”, “we”, “us”, or “our”), handles personal data when you use notifywaves.com, app.notifywaves.com, our APIs, demos, forms, and related services (the “Service”).
It forms part of our Terms and Conditions. By using the Service, submitting a form, creating an account, or sending us a message, you acknowledge that you have read this Policy. We publish it on our website so that customers, end users, regulators, and courts can see what we disclosed in advance.
Privacy contact and support: [email protected].
This Policy is written to align with common requirements of the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), India’s Digital Personal Data Protection Act, 2023 (DPDP Act) where it applies, and the EU/UK GDPR where those laws actually apply to a given processing activity. It is not legal advice to you, and it does not mean we undertake every optional certification (for example HIPAA, ISO 27001, or a signed GDPR Article 28 DPA) unless we have agreed that in a separate written contract.
2. Two different roles
It is important to distinguish whose data we are talking about.
2.1 Account and website data – we are the controller / fiduciary
When you visit our website, book a demo, pay us, or create a NotifyWaves login, we decide why and how to process your business-contact data (name, work email, phone, company, billing details, usage logs). For that data we are the data controller (and, where DPDP applies, a data fiduciary).
2.2 Messaging and contact data – you are the controller / fiduciary; we are the processor
When you upload contacts, send or receive WhatsApp messages, run campaigns, use the inbox, Auto Flows, appointments, AI chatbot, or CRM tools, that content and those phone numbers belong to your operation. You are the data controller / data fiduciary. We process that “Customer Data” only to provide the Service on your instructions (including these Terms, this Policy, and your dashboard settings).
End users who message your WhatsApp number should look to your privacy notice, not this Policy, for how you use their data. We do not have a direct customer relationship with those people, we do not obtain opt-in on your behalf unless a specific product feature you enable is designed to record a consent you configured, and we are not responsible for your failure to tell them that you use WhatsApp, NotifyWaves, or Meta.
3. Information we collect
3.1 You give us
- Identity and contact: name, work email, phone, company, job title, team size, country.
- Account: login credentials (stored hashed), roles, workspace name, preferences.
- Billing: plan, invoices, tax IDs, billing address. Card numbers are collected by our payment processor, not stored in full by us.
- Support and sales content: messages you send via forms, email, or WhatsApp to our team.
- Customer Data you choose to put in the product: contact lists, tags, notes, templates, media, campaign audiences, appointment records, flow configurations, AI knowledge files, and message content.
- WhatsApp / Meta connection data: WABA IDs, phone numbers, display names, template statuses, and similar configuration needed to operate the official API.
3.2 We collect automatically
- Device and log data: IP address, browser type, approximate location derived from IP, timestamps, pages viewed, diagnostic and error logs.
- Product usage: features used, send volumes, seat activity, API calls – to operate, bill, secure, and improve the Service.
- Cookies and similar technologies on our website, as described in Section 13.
3.3 Others give us
- Meta / WhatsApp: delivery statuses, quality-related signals they expose to API providers, template review outcomes, and inbound message payloads needed to show your inbox.
- CRMs, calendars, ad platforms, and payment providers you connect.
- Public or commercial sources only if you or a partner provide them; we do not buy consumer contact lists to message on your behalf.
We do not require special-category data (health, religion, biometrics, and similar). If you upload it (for example a clinic putting appointment reasons in chat), you do so at your own risk and you must have a lawful basis. Industry pages about healthcare or finance are use-case examples, not an invitation to treat NotifyWaves as a regulated clinical or banking system of record.
4. How we use information
We use personal data to:
- provide, host, maintain, and improve the Service, including sending and receiving WhatsApp messages you initiate or receive;
- create and secure accounts, authenticate users, prevent abuse, spam, and fraud;
- bill, collect tax, prevent chargebacks, and keep accounting records;
- provide support, onboarding, and service notices (including downtime and policy updates);
- send product, marketing, and educational emails or WhatsApp messages about NotifyWaves to business contacts who have a relationship with us, until they opt out (transactional mail cannot be fully opted out while you have an account);
- analyse usage in aggregated or de-identified form;
- comply with law, enforce our Terms, and establish, exercise, or defend legal claims;
- operate AI features you enable, which may send relevant snippets of your knowledge base and conversation context to a model provider solely to generate a reply for your workspace.
We do not use Customer Data to send our own marketing to your end users. Your campaigns are yours.
5. Legal bases
Where a legal basis is required (including PDPL, DPDP, and GDPR-style rules), we rely on:
- Contract – to provide the Service you asked for (account, hosting, messaging infrastructure, support).
- Legitimate interests – security, product improvement, B2B marketing to existing or prospective business contacts, defending claims. You may object where the law gives you that right.
- Consent – where we ask for it (optional cookies, certain marketing). You may withdraw consent without affecting prior lawful processing.
- Legal obligation – tax, accounting, lawful requests, and sanctions screening.
For Customer Data, you must have a legal basis to collect it and to instruct us to process it. We process as your processor on the basis of our contract with you. If you lack a basis, you must not upload the data.
6. WhatsApp, Meta, and message content
Messages you send and receive through the official WhatsApp Business Platform are processed by Meta / WhatsApp under their terms. We receive copies or payloads needed to display your inbox, logs, and analytics in NotifyWaves. Meta’s own privacy policy applies to processing on Meta’s systems. We do not control Meta’s retention, security, or location of data on WhatsApp infrastructure.
You acknowledge and accept that:
- connecting a number requires sharing business and phone-number details with Meta;
- template bodies, media, and contact phone numbers will pass through Meta and through our hosting in order to be delivered or displayed;
- WhatsApp end-to-end encryption models for Cloud API are defined by Meta, not by us, and do not mean we cannot store a copy in your dashboard – we can and do store Customer Data so the product works;
- we cannot retrieve chats from the WhatsApp Business app, consumer app, or device backups, and we cannot migrate dashboard chats to another app or BSP (see our Terms, Section 4).
8. What we do not do with data
To avoid later dispute, you acknowledge that we do not:
- sell your Customer Data or your end users’ phone numbers to data brokers;
- migrate chat history into NotifyWaves from WhatsApp apps, backups, or other providers;
- migrate chat history, media, or full threads from NotifyWaves to any other application, BSP, or third party as a service (any export button is limited and not a portability guarantee for the entire history);
- act as your HIPAA business associate, your GDPR representative, or your DPDP consent manager unless a separate signed agreement says so;
- guarantee that Meta, Google, or a CRM will keep data in a particular country;
- guarantee deletion from Meta’s systems when you delete a thread in our dashboard – we delete our copy subject to backups and legal holds; Meta has its own retention;
- monitor the lawfulness of each campaign you send;
- provide a public directory of your customers.
9. Retention
We keep account and billing data for as long as you have a workspace and thereafter for a period required for tax, accounting, dispute, and fraud prevention (typically up to seven (7) years where those laws apply, or shorter if the law requires).
Customer Data (contacts, messages, media) is kept while the workspace is active and for a short period after termination or cancellation (typically up to 30 days) so you can request an available export if the product supports one, unless you ask us to delete sooner or law requires us to keep or erase sooner. Backups may persist for a limited rotation window. After that, we delete or irreversibly anonymise the data from systems we control, except where a legal hold applies.
We are not a permanent archive. If you need records for healthcare, finance, employment, or consumer-law retention, you must export and store them in your own system of record. We are not liable if you fail to do so and the data is later deleted.
10. Security
We use reasonable technical and organisational measures appropriate to a cloud SaaS messaging dashboard (including access controls, encryption in transit, and hashed passwords). No internet transmission or storage is 100% secure. You are responsible for seat-level access, strong passwords, and not sharing logins.
You must notify [email protected] promptly of a suspected unauthorised access to your workspace. We may suspend access to contain an incident. Security measures are not a warranty that a breach cannot occur. Our liability for a personal-data incident is limited as stated in the Terms and Conditions, except where mandatory law says otherwise.
11. International transfers
We serve customers in the UAE, wider GCC, India, and other countries. Personal data may be processed in those regions and in countries where our subprocessors (including Meta and cloud providers) operate, which may include the United States and the European Union.
Where a law requires a transfer mechanism (for example standard contractual clauses, or DPDP-compliant contractual terms), we use an appropriate mechanism for our processor relationships. Meta’s transfers are governed by Meta’s terms. By using the Service you instruct us to make the transfers necessary to operate WhatsApp Business Platform and the hosting we use.
12. Your rights
Depending on your location and the role (controller vs processor), you or your end users may have rights to access, correct, delete, withdraw consent, restrict or object to processing, and (where provided by law) data portability or nomination of a successor. You may also lodge a complaint with a competent authority (for example the UAE Data Office, India’s Data Protection Board, or an EU supervisory authority).
If you are our customer (account holder): email [email protected] from the address on the account. We may need to verify identity. We will respond within the period required by applicable law.
If you are an end user of a business that uses NotifyWaves: contact that business. We will redirect you or assist the customer as processor. We will not disclose a customer’s full contact database to an unverified third party.
Portability, where required, applies to personal data you provided to us in a structured form we hold. It does not require us to recreate WhatsApp device chat history, to migrate threads to a competitor, or to produce data we do not store. Those limitations are also stated in our Terms and are part of this Policy.
We may refuse requests that are unfounded, excessive, or that would infringe others’ rights, and we may charge a reasonable fee where the law allows.
14. Children
The Service is a business product. It is not directed at children under 18. We do not knowingly collect account data from children. If you believe a child has created an account, contact us and we will delete it. You must not use the Service to message children in a way that is unlawful in the child’s country.
15. Your duties as a NotifyWaves customer
You agree that you, not NotifyWaves, are responsible for:
- publishing an accurate privacy notice to your customers and WhatsApp contacts;
- collecting and recording opt-in / consent and honouring STOP / opt-out;
- the lawfulness of contact lists you import (including purchased lists – we strongly advise against messaging purchased lists and Meta may ban you);
- configuring team access so that only authorised staff see chats;
- not uploading data you are not allowed to process (including another company’s chats);
- responding to end-user rights requests that concern Customer Data;
- any healthcare, financial, or employment records you choose to put in chat – NotifyWaves is a messaging layer, not your official record;
- backing up anything you are legally required to keep, because we do not migrate chats to another app and we delete data after the retention window.
If an end user, regulator, or Meta brings a claim because of your processing, you will indemnify us as stated in the Terms and Conditions. This Policy will be shown as evidence that those duties were disclosed on our website before you used the Service.
16. Changes
We may update this Policy by posting the new version on this page and changing the effective date. Material changes may also be notified by email or in-product. Continued use after the effective date is acceptance where permitted by law. If you do not agree, stop using the Service and request account closure.
17. Contact
Privacy questions, rights requests, and notices: [email protected].
Related documents: Terms and Conditions · Contact us.
Azrin Digital Marketing Company, trading as NotifyWaves.
Still have a question?
If you want to exercise a data right, or anything here is unclear, email us from the address on your account.