HiperXomnia
PlatformHow it worksPrivacySign inCreate account

Privacy Policy

Last updated: 18 September 2026 · Leer en español

This policy explains how HiperXomnia ("we", "us") handles personal data when a business (our "client") uses our platform to operate its own WhatsApp Business Account, and when that client's customers ("end users") exchange messages with them.

We access WhatsApp Business API data to provide messaging services on behalf of our clients. We act as a Meta Tech Provider and as a data processor for our clients: they decide which messages are sent and to whom; we operate the infrastructure that delivers them.

1. Who is responsible for your data

For the business account data and the message content, the client business that connected its WhatsApp Business Account is the data controller. HiperXomnia is the processor and only acts on that client's documented instructions. For the account we keep about the client itself (their email, password hash, workspace), HiperXomnia is the controller.

2. Data we collect

  • Client account data. Business name, email address and an authentication record managed by Firebase Authentication. We never store passwords in readable form.
  • WhatsApp Business Platform data. When a client completes Meta's Embedded Signup we receive the identifiers of their business portfolio, their WhatsApp Business Account (WABA) and their phone number, the phone number's display name, quality rating and messaging limits, and an access token that authorizes us to act on their behalf.
  • Message templates. The templates the client creates, their content, category, language and the approval status Meta returns.
  • Messages. Messages sent by the client to their end users and replies received from those end users, including text content, message identifiers, timestamps and delivery statuses.
  • End-user contact data. The end user's WhatsApp phone number, the profile name WhatsApp provides, and the opt-in record the client keeps for them: when consent was granted, through which channel, and the evidence reference the client stores.
  • Technical logs. Server logs required to run and secure the service: timestamps, request identifiers and errors.

3. How we use the data

  • To connect and maintain the client's WhatsApp Business Account.
  • To create and manage message templates, phone numbers and webhook subscriptions on the client's behalf (whatsapp_business_management).
  • To send and receive messages on the client's behalf, after the end user has opted in (whatsapp_business_messaging).
  • To show the client their conversations, delivery statuses and account health.
  • To keep the service secure, prevent abuse and comply with legal obligations.

We do not sell personal data. We do not use message content for advertising, and we do not use it to train machine-learning models.

4. Opt-in and opt-out

Business-initiated messages are only sent to end users with an active opt-in recorded in the platform. Our system blocks a template send when no valid consent exists. An end user can withdraw consent at any time by replying STOP (or an equivalent word) to the business, or by asking the business directly; the platform records the opt-out and stops further business-initiated messages to that number.

5. Who we share data with

  • Meta Platforms, Inc., as the operator of the WhatsApp Business Platform, under its own terms and privacy policy.
  • Google Cloud / Firebase, our hosting, authentication and database provider, acting as a sub-processor.
  • Competent authorities, when we are legally required to do so.

6. Storage and security

Data is stored on Google Cloud infrastructure. Access tokens are encrypted at rest with AES-256-GCM and are never exposed to the browser or to third parties. All traffic runs over HTTPS. Every webhook delivery from Meta is verified against its X-Hub-Signature-256 signature before it is processed. Access to production data is restricted to authorized personnel.

7. Retention

We retain connection data and messages while the client's account is active. When a client disconnects their WhatsApp Business Account from the console, the stored access token is destroyed immediately and, at the client's choice, all contacts and messages are erased at the same time. Otherwise, data is deleted within 30 days of a deletion request or of account closure, except where law requires longer retention.

8. Your rights

End users can exercise their rights of access, rectification, deletion and objection through the business they are talking to, who is the controller of that conversation. Clients can exercise the same rights over their own account data by writing to us. See our Data Deletion Instructions for the exact procedure and timelines.

9. International transfers

Our infrastructure and Meta's may process data outside your country of residence. Transfers are covered by the safeguards offered by our providers, including the European Commission's Standard Contractual Clauses where applicable.

10. Children

The service is intended for businesses and is not directed at people under 18 years of age.

11. Changes

If we change this policy we will update the date at the top of this page and, for material changes, notify clients through the contact details on their account.

12. Contact

Privacy questions and data requests: hyperommnia@gmail.com.

© 2026 HiperXomnia. Built on the WhatsApp Business Platform.

Privacy PolicyTerms of ServiceData Deletion InstructionsContact