Effective date: April 14, 2026
This Privacy Policy explains how Cimplify ("we", "us", or "our") collects, uses, shares, and protects your personal information when you use our platform, websites, mobile applications, APIs, and related services (collectively, the "Services"). By accessing or using the Services, you agree to the practices described in this policy.
Industry-standard encryption for data in transit and at rest
Role-based access, audit logs, and principle of least privilege
Clear disclosure of what we collect and why
Compliant handling of WhatsApp and other channel data
Safeguards for cross-border data movement
Access, correct, delete, or export your data at any time
1.1 Information you provide directly
1.2 Information collected automatically
1.3 Information from third parties
We process your personal data only where we have a lawful basis to do so. The legal bases we rely on are: performance of a contract with you, your consent, our legitimate interests, and compliance with legal obligations.
Specifically, we use your information to:
We do not sell your personal data to third parties. We do not use message content for advertising purposes.
Cimplify operates as a Business Solution Provider (BSP) for the WhatsApp Business Platform and also integrates with Instagram Messaging, Telegram Bot API, email (SMTP/IMAP), and SMS gateways. This section describes how messaging data is handled.
3.1 What messaging data we collect
3.2 How messaging data flows
When a business uses Cimplify to communicate with customers via WhatsApp, messages are routed from the business through our servers to Meta's WhatsApp Business API, and vice versa. Cimplify acts as a data processor on behalf of the business (the data controller). Meta processes message data according to its own privacy policies once messages enter the WhatsApp network.
3.3 Opt-in and consent
Businesses using Cimplify are required to obtain valid opt-in consent from their customers before sending WhatsApp messages, as mandated by Meta's WhatsApp Business Policy. Cimplify provides tools to capture and record opt-in consent, but the business remains responsible for ensuring compliance. Opt-in records are stored alongside the customer profile and are available for audit.
3.4 Message content handling limitations
Cimplify does not use the content of private messages between businesses and their customers for advertising, marketing to unrelated third parties, or training machine-learning models. AI features that analyse message content (such as suggested replies) operate solely within the business's own conversation context at inference time and are not shared across businesses.
We may access message content when required by law, to enforce our Terms of Service, or to investigate reports of abuse or policy violations. Access is logged and restricted to authorised personnel.
We share personal data with the following categories of third-party service providers, each of which is contractually obligated to protect your data:
| Sub-Processor | Purpose | Data Shared |
|---|---|---|
| Meta Platforms, Inc. (WhatsApp Business API) | Message delivery, business account management, Embedded Signup | Phone numbers, message content, business profile data, delivery metadata |
| Meta Platforms, Inc. (Instagram Messaging API) | Message delivery for Instagram DMs | Instagram user IDs, message content, delivery metadata |
| Telegram (Bot API) | Message delivery for Telegram conversations | Telegram user IDs, message content, delivery metadata |
| Cloud infrastructure providers | Hosting, storage, compute | All data stored on the platform (encrypted at rest) |
| Payment processors | Payment processing, settlement, fraud detection | Transaction amounts, currency, payer identity, bank/mobile money details |
| SMS gateway providers | SMS delivery | Phone numbers, message content |
| Email delivery providers | Transactional and support email delivery | Email addresses, email content, delivery metadata |
| AI model providers | AI-powered customer support (suggested replies, automation) | De-identified or pseudonymised conversation context as needed for inference; not used for model training |
| Analytics providers | Usage analytics, error tracking | Anonymised or pseudonymised usage data, device metadata, error reports |
We may also disclose personal data when required by law, court order, or governmental authority, or when necessary to protect the rights, property, or safety of Cimplify, our users, or the public.
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law.
When data is no longer needed, it is either permanently deleted or irreversibly anonymised so that it can no longer be associated with you.
Our websites and applications use cookies, local storage, and similar technologies. Below is a summary of the cookies we use:
6.1 Strictly necessary cookies
These cookies are essential for the Services to function. They handle session management, authentication, and security. They cannot be disabled without breaking core functionality.
6.2 Analytics cookies
We use analytics tools to understand how visitors use our websites. These cookies collect information in aggregate form and help us improve the user experience. You may opt out via your browser settings or our cookie banner.
6.3 Meta / Facebook SDK cookies
Our website loads the Meta (Facebook) SDK to support the WhatsApp Embedded Signup flow and Facebook Login. The Meta SDK may set cookies on your device, including but not limited to:
These cookies are governed by Meta's Privacy Policy. You can manage Meta cookies through your Facebook ad preferences or by using browser-level cookie controls.
6.4 How to manage cookies
Most browsers allow you to refuse or delete cookies. Note that disabling strictly necessary cookies may impair the functionality of the Services. For more information, visit your browser's help pages or allaboutcookies.org.
We implement technical and organisational measures designed to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If you become aware of a security vulnerability, please contact us immediately at [email protected].
Depending on your location and applicable law (including the EU General Data Protection Regulation, the UK GDPR, Ghana's Data Protection Act 2012, Nigeria's NDPR, and South Africa's POPIA), you may have the following rights:
To exercise any of these rights, contact our Data Protection Officer at [email protected]. We will respond to your request within 30 days (or sooner if required by applicable law). We may ask you to verify your identity before processing your request.
Cimplify operates globally and your data may be transferred to, and processed in, countries other than the country in which you reside. These countries may have data protection laws that differ from those in your jurisdiction.
When we transfer personal data outside the European Economic Area (EEA), United Kingdom, or other regions with data transfer restrictions, we rely on one or more of the following safeguards:
Sub-processors such as Meta Platforms, Inc. are based in the United States and may process data subject to US law. Meta relies on its own data transfer mechanisms as described in its privacy policy.
The Services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us at [email protected] and we will take steps to delete that information promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
Your continued use of the Services after the effective date constitutes your acceptance of the updated policy.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:
If you are located in the European Union and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. If you are located in Ghana, you may contact the Data Protection Commission. If you are located in Nigeria, you may contact the Nigeria Data Protection Commission (NDPC).
This Privacy Policy was last updated on April 14, 2026. For questions, reach out to [email protected].