Last updated 27 August 2026

Privacy Policy

Woozi handles business conversations, which means it handles personal data belonging to people who never signed up with us. This page explains what we collect, why, who we share it with, and what you can ask us to do about it.

01Who we are

Woozi is a trading name of Tonmoy Hashmi, entrepreneur individuel trading under the name Woozi, established at 54 rue Diderot, Asnières-sur-Seine, France and registered under SIREN [your SIREN number]. TVA non applicable, article 293 B du CGI. This policy covers the Woozi website at www.woozi.cloud and the Woozi application.

Because Woozi is operated as an entreprise individuelle, the data controller for the purposes of Regulation (EU) 2016/679 (GDPR) and the French Loi Informatique et Libertés is Tonmoy Hashmi personally, in the circumstances set out in the next section.

For anything in this policy, including requests about your personal data, contact us at hashmitonmoy454@gmail.com.

02Two different roles, and why it matters

Woozi handles personal data in two distinct capacities, and your rights differ depending on which one applies to you.

  • As a controller, for the account holders who sign up and use Woozi. We decide how and why we process your name, email address and usage of the service.
  • As a processor, for the people your business messages on WhatsApp. Their phone numbers, names and message content belong to you, our customer. You are the controller. We process that data only on your documented instructions, which are the actions you take in the product.

If you are a customer of a business that uses Woozi and you want your data corrected or deleted, contact that business directly. They control it, and we will support them in acting on your request.

03What we collect

Account data, which you give us directly:

  • Your name, email address and a securely hashed password. Authentication is handled by Supabase Auth; we never see or store your password in readable form.
  • Your account name, your team members, and the role assigned to each of them.
  • Invitation records, which store a hash of the invite link rather than the link itself.

Connection credentials, which you provide when you link a WhatsApp number:

  • Your WhatsApp phone number ID and WhatsApp Business Account ID.
  • Your Meta access token and webhook verify token. Both are encrypted with AES-256-GCM before they are written to our database and are never returned to a browser or written to logs.
  • Any AI provider key you choose to add, which is encrypted the same way. Woozi has no provider key of its own; the AI features use yours or they do not run.

Conversation data, which reaches us through the WhatsApp Business Platform when your customers message you or you message them:

  • Phone numbers, WhatsApp profile names, message content, and any media sent or received, including images, documents, audio and voice notes.
  • Message timestamps and delivery, read and failure statuses.
  • Contact records built from those conversations, including any tags, custom fields, notes and pipeline deals you or your team add.

Technical data, collected automatically:

  • Your IP address, used for rate limiting and abuse prevention.
  • Server logs recording requests and errors, used to keep the service working.
  • A session cookie that keeps you signed in, and a small amount of browser storage holding interface preferences such as your chosen theme.

We do not use advertising cookies, analytics trackers or third-party marketing pixels.

04How we use it

  • To provide the service: sending and receiving your WhatsApp messages, building contact records, running the automations and broadcasts you configure, and showing you your inbox.
  • To secure the service: authenticating you, enforcing account isolation, applying rate limits and investigating abuse.
  • To support you: responding when you contact us, and diagnosing faults you report.
  • To meet legal obligations, including responding to lawful requests from authorities.

We do not sell personal data. We do not use the content of your customers' messages to train any machine-learning model, ours or anyone else's.

06Who we share it with

We share personal data only with the providers needed to run the service. Each is bound by a data processing agreement.

  • Meta Platforms, for the WhatsApp Business Platform. All message delivery runs through Meta, and their handling of that data is governed by their own terms and privacy policy.
  • Supabase, for database, authentication and file storage.
  • Our hosting provider, which runs the application servers.
  • Your chosen AI provider, if and only if you enable the AI assistant. In that case, excerpts of the relevant conversation are sent to OpenAI or Anthropic under your own API key so a reply can be drafted. If you do not add a key, no message content leaves for this purpose.

We may also disclose data where we are legally required to, or to establish or defend legal claims. If our business is ever transferred, personal data may transfer with it, and we will tell you before that happens.

07International transfers

We are established in France, so the GDPR applies to everything described here. Some of our providers process data outside the European Economic Area, including in the United States.

Where data leaves the EEA, the transfer is covered either by an adequacy decision of the European Commission, such as the EU-US Data Privacy Framework, or by Standard Contractual Clauses together with supplementary safeguards. You can ask us for details of the mechanism relied on for any given provider.

08How long we keep it

  • Conversation and contact data is kept for as long as your account is active, because it is the working record you rely on.
  • If you delete a contact or a conversation in the product, it is removed from our live database.
  • When an account is closed, we delete its data within 90 days, except where we are required to retain records for longer by law.
  • Server logs are kept for a short period for security and diagnostics, then deleted.
  • Invitation records are kept as hashes, and expired invitations cannot be redeemed.

09How we protect it

  • Every WhatsApp access token, webhook verify token and AI provider key is encrypted with AES-256-GCM before storage, using a key held only in our server environment and never in the database.
  • Accounts are isolated at the database level with row-level security, so one customer's queries cannot reach another customer's data.
  • Public API keys are stored only as hashes and are shown to you exactly once, at creation. We cannot recover a lost key, only revoke it and issue a new one.
  • All traffic runs over TLS, and inbound webhooks are verified against a cryptographic signature before they are accepted.
  • Access to production systems is limited to the people who need it.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant supervisory authority as the law requires.

10Your rights

Under the GDPR and the French Loi Informatique et Libertés you have the right to:

  • Access the personal data we hold about you, and receive a copy of it.
  • Have inaccurate data corrected.
  • Have your data deleted.
  • Restrict or object to certain processing.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent where our processing relies on it, without affecting processing already carried out.
  • Give directions about what happens to your personal data after your death, either generally or specifically, as provided by article 85 of the Loi Informatique et Libertés.

To exercise any of these, email hashmitonmoy454@gmail.com. We will respond within one month, extendable by two further months for complex requests, in which case we will tell you why. We may need to verify your identity first.

If you are not satisfied with our response, you can lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or at cnil.fr. If you live in another EU or EEA country, you can complain to your own national supervisory authority instead.

11Children

Woozi is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, contact us and we will delete it.

12Changes to this policy

We may update this policy as the product changes. The date at the top of this page always reflects the current version. If a change materially affects how we handle your data, we will tell account holders directly rather than relying on you to notice.

13Contact us

Questions, requests or complaints about this policy: hashmitonmoy454@gmail.com, or write to Tonmoy Hashmi at 54 rue Diderot, Asnières-sur-Seine, France.