Privacy Policy
What the platform collects, why it holds it, and what you can ask us to do with it.
Last updated: 30 September 2026
This policy covers the VertexBytes Core platform, the software organizations use to run their operations. It is separate from the policy published on our company website, which covers that site's visitors and enquiry forms.
It applies to everyone whose data reaches the platform: the people who work in an organization that uses it, and the customers those organizations communicate with through it.
VertexBytes Solutions, registered at Kosovë, Prishtinë, Rr. REXHEP MALA, 28, operates the platform. Questions about this policy, and any request described in it, can be sent to [email protected].
For the accounts of people who log in to the platform, we decide what is collected and why. We are the controller of that data.
For the data an organization puts into the platform about its own customers, including WhatsApp conversations, the organization decides what is collected and why. We only process it on their instructions, as their processor. If you are a customer of one of those organizations, they are the right first point of contact about your data.
The platform holds the following categories of data.
- Account data: name, email address, password hash, role and organization membership, plus sign-in metadata such as session times and IP addresses used for security controls.
- Organization data: the records an organization creates while using the platform, such as employees, clients, appointments, projects, documents and support tickets.
- Activity logs: a record of actions taken in the platform, who took them and when, so administrators can audit their own organization.
- Technical data: error reports, performance measurements and server logs generated while the platform runs.
An organization can connect its WhatsApp Business account so the platform can message that organization's customers. When it does, we receive and store the following from the WhatsApp Business Platform.
- The WhatsApp Business Account identifier, and the phone numbers on it together with their display names and quality ratings.
- An access token that lets the platform send messages on that organization's behalf.
- The content of messages exchanged between the organization and its customers, the customers' phone numbers, and the profile names WhatsApp reports for them.
- Delivery and read receipts, and error reports for messages that could not be delivered.
This data is used only to operate the messaging features the organization enabled: sending the messages it configures, showing its staff the replies, and reporting whether a message arrived. It is never used for advertising, never sold, and never combined across organizations.
Where an organization keeps using the WhatsApp Business app on the same number, we also receive copies of the messages its staff send from that app, so its inbox in the platform reflects the whole conversation.
- To provide the platform and the features an organization has enabled.
- To keep accounts secure, detect abuse and investigate incidents.
- To answer support requests from the organizations that use the platform.
- To diagnose faults and improve reliability and performance.
- To meet legal obligations and enforce our agreements.
We do not use personal data for advertising, we do not sell it, and we do not use the content of an organization's customer conversations for any purpose other than delivering that organization's own messaging.
- Performance of a contract, for everything needed to provide the platform to an organization and its users.
- Legitimate interests, for security, fraud prevention, and improving reliability.
- Legal obligation, where retention or disclosure is required by law.
- Consent, where it is asked for explicitly and can be withdrawn at any time.
Credentials that an organization connects, including WhatsApp access tokens, are encrypted before they are stored and are never sent to a browser. The settings screen shows only a masked fragment, which is enough to recognise what is stored and not enough to use it.
Traffic is encrypted in transit. Access to data inside the platform is limited by an organization's own roles and permissions, and access by our staff is limited to what is needed to operate the service or answer a support request.
Incoming messages from the WhatsApp Business Platform are cryptographically verified before they are stored, so a third party cannot write into an organization's inbox.
Message content and conversations are kept for 12 months by default, and up to 36 months where an organization chooses a longer period, unless the organization asks for them to be removed sooner.
Account and organization records are kept for 90 days after an organization stops using the platform, after which they are deleted or irreversibly anonymised. Connected account credentials are deleted as soon as the connection is removed.
We do not sell personal data. We share it only with the providers needed to run the platform, each bound to process it on our instructions.
- Meta Platforms, for delivering and receiving WhatsApp messages.
- Our hosting and database providers, which store the platform's data.
- Our email provider, for transactional messages such as sign-in and notification emails.
We may also disclose data where we are legally required to, and we will tell the affected organization unless we are prohibited from doing so.
Some of the providers above operate outside the country where an organization is established. Where data is transferred internationally, it is done under the safeguards the applicable law requires.
Depending on where you live, you may have the right to:
- Ask what data we hold about you and receive a copy of it.
- Have inaccurate data corrected.
- Ask for your data to be deleted.
- Ask us to restrict or object to certain processing.
- Receive your data in a portable format.
- Complain to your data protection authority.
Write to [email protected] to exercise any of these. If your data reached us through an organization that uses the platform, we will pass the request to them and act on their instruction, because the data is theirs to decide about.
How to request deletion, what can be deleted and how long it takes are set out on our data deletion page.
The platform is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, write to [email protected] and we will remove it.
We update this policy when the platform changes. The date at the top of the page shows when it last changed, and we will tell organizations directly about changes that materially affect them.
This policy is published in several languages for convenience. The English version is the authoritative one, and prevails if a translation differs from it.