WhatsApp Business Data Policy
How Suarify handles personal data on the WhatsApp Business Platform, for calling and messaging. This supplements our Privacy Policy and Terms of Service. Where they differ on WhatsApp specifically, this page governs.
Last updated: 11 September 2026
1. Who we are, and our role
Suarify provides AI voice agents that answer and place telephone calls, and — through the WhatsApp Business Platform — WhatsApp calls and messages on behalf of businesses that use our platform.
We act as a processor. Each business using Suarify is the controller of its own customers' data. They decide who is contacted, what is said, and whether calls are recorded. We process that data only to provide the service they have asked for, on their instructions.
We are not a reseller of WhatsApp messaging or calling, and we do not aggregate or resell data gathered across our customers.
SUARify SDN. BHD. (1680778-A)
Bangsar South, Jalan Bangsar South Kerinchi 3,
59200 Kuala Lumpur, Malaysia
Privacy contact: meta-support@suarify.my — for privacy questions, data access, correction and deletion requests.
2. What we collect through WhatsApp
Only what is needed to connect a call or deliver a message.
| Data | Why |
|---|---|
| WhatsApp ID / phone number of the person on the call, and the display name WhatsApp provides | To place or receive the call, and to show the business who it was with |
| Call metadata — direction, start and end time, duration, outcome (answered, declined, no answer) and the failure reason | Call history, troubleshooting and billing |
| Call permission (consent) status, when it was requested, granted or withdrawn | To honour consent and enforce WhatsApp's calling rules |
| Call audio, and recordings or transcripts only where the business has enabled them | To let the AI agent hold the conversation; if enabled, for the business's own quality review. Normally kept no more than 90 days |
| Message content and media, where messaging is used | To deliver the message and any reply the business asked for |
| The business's own WhatsApp credentials — access token, phone number ID, WhatsApp Business Account ID | To act on that business's behalf via Meta's APIs |
We do not collect WhatsApp contact lists, group membership, or any message not sent to or from the business's own number. We do not read a user's WhatsApp account beyond the conversation with that business.
3. Consent before we call anyone
A business cannot call a WhatsApp user through Suarify unless that user has agreed to be called. We implement Meta's call permission model directly:
- Before a first outbound call, a call permission request is sent and the call is held until the user responds.
- The user may accept (once, or always) or decline. A temporary acceptance lasts 7 days.
- A user may withdraw permission at any time from within WhatsApp, and the change takes effect immediately.
- Permission requests are rate limited — at most one per 24 hours and two per 7 days per user — so a person who ignores a request is not asked repeatedly.
- Repeated unanswered calls cause permission to lapse automatically.
Consent state is recorded per user, per business, with timestamps for when it was granted and withdrawn. Meta's record is authoritative; where ours disagrees, the call is refused by WhatsApp regardless of what we hold.
If a user declines, the business may have configured a fallback to an ordinary phone call. That call is governed by ordinary telephone consent and marketing rules, not by WhatsApp's, and remains the business's responsibility.
4. Recording and transcription
Recording and transcription are off unless the business turns them on, and are configured per number.
Where enabled, an announcement is played at the start of the call in the language the business configures, so the person knows before they speak. Businesses using Suarify are responsible for meeting the notice and consent requirements of their own jurisdiction — in Malaysia, the PDPA.
Recordings and transcripts belong to the business. We do not use them to train models, and we do not sell them.
5. AI providers and subprocessors
The conversation is handled by an AI speech model chosen by the business. Call audio, and text derived from it, is sent to the selected provider to generate the reply:
- OpenAI
- Google (Gemini)
- Alibaba Cloud (Qwen)
- ElevenLabs, for voice synthesis where selected
Each processes data under its own terms. Businesses choose the provider that suits their compliance requirements, and can change it.
Other subprocessors: Supabase (database and storage) and our hosting provider for the servers running the platform. A current subprocessor list is available on request.
We share personal data with no one else, except where required by law.
6. Retention and deletion
Call recordings, transcripts and message content are kept no longer than needed for the purpose the business collected them for — normally no more than 90 days. A business may ask us to delete any call or message sooner, and may ask us to keep records longer where its own compliance obligations or the law require it.
Call metadata — who was called, when, for how long, and the outcome — and consent records are kept while the business's account is active. Consent has to outlive any single call to mean anything, and billing records have to be auditable.
Deletion. A WhatsApp user may ask for their data to be deleted by emailing meta-support@suarify.my, or by asking the business they dealt with. We action verified requests within 30 days and confirm when done. Where we act as processor, we will also notify the business concerned.
When a business closes its Suarify account, its WhatsApp credentials are deleted and its call data is removed or anonymised.
Withdrawing call permission is immediate and does not require contacting us: it is done from within WhatsApp.
7. Security
- WhatsApp access tokens and app secrets are encrypted at rest (AES-256-GCM) and are never returned to a browser in full.
- Call signalling to Meta uses SIP over TLS, and call audio is encrypted in transit with SRTP.
- All platform and API traffic is over HTTPS.
- Incoming Meta webhooks are verified by signature before they are acted on.
- Each business's data is isolated by account, and API access is authenticated per business.
No system is perfect. If we discover a breach affecting WhatsApp data we will notify affected businesses without undue delay, and the relevant authority where the law requires it.
8. Your rights
If you were called or messaged by a business using Suarify, you may:
- ask what data we hold about you;
- ask for it to be corrected or deleted;
- withdraw call permission at any time, from within WhatsApp;
- object to being contacted again;
- complain to your data protection authority.
Write to meta-support@suarify.my. We may need to verify your identity, and where the data belongs to one of our business customers we will pass the request to them and assist.
9. Platform compliance
Businesses using Suarify on WhatsApp must comply with the WhatsApp Business Messaging Policy and the WhatsApp Commerce Policy. Our terms require it, and we suspend accounts that breach them.
In particular, businesses may not use Suarify to:
- contact people who have not consented, or who have opted out;
- send messages or place calls in prohibited categories;
- upload contact lists obtained without a lawful basis;
- misrepresent who is calling, or conceal that the caller is an AI agent when asked.
10. Changes
We update this page when the service changes. The date at the top always reflects the current version, and material changes are notified to affected businesses.
App review reference
- Privacy Policy
- https://suarify.my/meta-whatsapp-policy.html
- General Privacy
- https://suarify.my/ttnc.html#privacy
- Terms of Service
- https://suarify.my/ttnc.html#terms
- Data Deletion
- https://suarify.my/meta-whatsapp-policy.html#retention
- Contact
- meta-support@suarify.my