Applicable Privacy Laws
We comply with applicable privacy laws and regulations, including:
GDPR (General Data Protection Regulation)
- Applies to: Users located in the European Union
- Legal Basis: Contract performance (providing services), Consent (AI training), Legitimate interest (service improvements)
- Data Protection Officer: Not required
- EU Representative: Not applicable
CCPA (California Consumer Privacy Act)
- Applies to: California residents
- Categories of Data: Personal identifiers, commercial information, internet activity
- Sale of Data: We do not sell personal information
- Third-Party Sharing: Limited to service providers (Google Gemini API)
Mexican Privacy Laws (LFPDPPP)
- Applies to: Our operations in Mexico and Mexican users
- Compliance: Privacy notice provided (this document), user consent mechanisms implemented for data collection, data subject rights procedures established
- INAI Registration: Not required for our scale of data processing operations
Sensitive & Professional Data (Doctors, Lawyers)
- Applies to: Users who use role-based CRMs for regulated professions, such as doctors and lawyers
- Our Commitment: We handle and safeguard data entered by professional users in accordance with the applicable data-protection regulations that govern it, including Mexican health-data norms for doctors, and apply appropriate security controls
- Your Responsibility: As the professional using the CRM, you are responsible for obtaining any consent required from your patients or clients and for meeting your own professional confidentiality and data-protection obligations
Data Roles: You Are the Data Controller of Your Patient & Client Data
For the personal data of your patients, clients, and contacts that you store in the CRM — whether entered manually or populated by our AI at your request — you act as the data controller ("responsable") and WhatsBizPro acts only as a service provider that processes such data on your behalf and under your instructions ("encargado"). You are solely responsible for: having a lawful basis to process that data; providing your own privacy notice to your patients or clients; obtaining any required consent (including express consent for sensitive data such as health information); ensuring the accuracy of the information you store; and using it lawfully and in accordance with your professional obligations.
⚠️ AI-Populated Data Accuracy
Fields populated by our AI are automated suggestions and may contain errors, omissions, or misattributed information. You are solely responsible for reviewing, correcting, and verifying AI-populated information before saving or relying on it. The CRM is an administrative tool only — it is not an official clinical record (expediente clínico) or professional system of record — and we do not warrant the accuracy of AI-extracted data.
Sales CRM Lead & Prospect Data (LFPDPPP)
If you use the Sales CRM, the lead and prospect information you store (including contact details, social media profiles, deal information, and notes) is personal data of third parties for which you act as the data controller. You are solely responsible for: collecting that information lawfully; having a lawful basis to store and use it; complying with the Mexican Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and any other law that applies to you, including consent, privacy-notice, and opt-out requirements for marketing or promotional communications; and honoring requests from your contacts to access, correct, or delete their information. WhatsBizPro processes this data only on your behalf and under your instructions.
Age Restrictions
Minimum Age: You must be at least 18 years old to use WhatsBizPro.
We do not knowingly collect personal information from individuals under 18. If we become aware that we have collected such information, we will delete it immediately.
International Data Transfers
Your data may be transferred to and processed in countries outside your residence, including:
- United States (Google Gemini): AI conversation analysis, response generation, document processing, and chat insights (data processed temporarily and immediately deleted)
- United States (Stripe): Payment processing for subscription billing
- United States (Railway): Cloud hosting infrastructure where our servers and MySQL databases are located
We ensure appropriate safeguards are in place for such transfers through:
- Service agreements with providers that include data protection commitments
- Industry-standard encryption for data in transit and at rest
- Compliance with applicable data transfer regulations (GDPR adequacy decisions, standard contractual clauses)
- Regular security assessments of our third-party providers
Note: The majority of your personal data (contacts, scheduled messages, extension settings) remains stored locally on your device and is never transferred internationally.