YakkoYakko
PrivacyTermsData deletion

Privacy Policy

Effective date: 6 July 2026

This Privacy Policy explains what personal data Yakko collects when you use the Yakko WhatsApp Business Platform, why we collect it, how we protect it, and the choices you have. It applies to our website, the application at yakko.chat, and every service we provide through them.

1. Who we are

Yakko (“Yakko”, “we”, “us”) is the operator of yakko.chat, a software platform built on the official WhatsApp Business Platform provided by Meta. Our customers are businesses that connect their own WhatsApp Business Accounts to Yakko in order to manage conversations, message templates, contacts and campaigns with their end customers.

For most of the data described in this policy, our business customer is the data controller and Yakko acts as a processor on its behalf. For account and billing data of the people who sign up to Yakko directly, we act as the controller. You can reach our privacy team at [email protected].

2. Data we collect

Account data

When you create a Yakko account or are invited to a workspace, we collect your name, email address, password (stored only as a salted hash), workspace role, and preferences such as language and theme. We also record sign-in events for security purposes.

WhatsApp Business data received via Meta APIs

When a customer connects a WhatsApp Business Account through Meta’s Embedded Signup or coexistence flows, we receive and store the data needed to operate the connection: WhatsApp Business Account (WABA) identifiers, business phone number identifiers and display details, message template names, contents and review statuses, quality and messaging-limit signals, and the access tokens Meta issues for the connection. Access tokens are always stored encrypted (see Section 8).

Message content and media

To provide the shared team inbox, we process the messages exchanged between the customer’s WhatsApp number and its contacts: message text, delivery and read status, and media attachments (images, video, audio and documents), together with the contact’s phone number, profile name and any attributes the customer records about the contact. This content belongs to our customer; we process it solely to deliver the service to that customer’s workspace.

Usage and billing records

We keep records of how the platform is used — for example message and conversation counts, template submissions, feature usage, API logs and diagnostic events — and the billing information needed to charge for subscriptions, such as plan, invoices and payment status. Card details are handled by our payment provider and never touch our servers.

3. How we use your data

We use the data described above to:

  • provide, operate and secure the messaging dashboard, team inbox, template builder, contact management, analytics and billing;
  • route messages between our customers and their contacts through the official WhatsApp Business Platform;
  • send service communications such as onboarding steps, template review outcomes, security alerts and invoices;
  • measure aggregate product usage so we can improve reliability and plan capacity; and
  • comply with legal obligations, including tax and accounting law.

We do not sell personal data, and we do not use customer message content for advertising or to build advertising profiles.

4. Meta Platform data commitments

Yakko is built on Meta’s APIs, and we make the following commitments regarding data received through them:

  • Data received via Meta APIs is used only to provide the Yakko service to the business that authorized the access. It is never repurposed for other customers, resold, or used for our own marketing.
  • Access tokens issued by Meta are encrypted at rest with AES-256-GCM and are decrypted only at the moment an API call is made on the authorizing customer’s behalf.
  • We do not sell any data obtained through Meta’s platform.
  • We process this data in accordance with the Meta Platform Terms and the WhatsApp Business Terms of Service, including their requirements on data use, security and deletion. If a customer revokes our access through Meta, we stop processing and delete the associated platform data as described in our Data Deletion Instructions.

5. AI processing

Some Yakko features use artificial intelligence — for example drafting replies, summarising conversations or powering an AI agent a customer chooses to enable. When these features are used, relevant message content is sent to an AI inference provider strictly to generate the requested output for the connected workspace. AI features operate only for the benefit of the workspace whose data is processed; we do not use one customer’s message content to train models or to serve any other customer.

6. Retention

We retain personal data for as long as the workspace account is active and the data is needed to provide the service. When a workspace is deleted, or when a verified deletion request is received, we delete the associated conversations, contacts, media, templates and encrypted Meta tokens within 30 days. Limited records — such as invoices and audit logs — may be retained longer where a law requires it, and backup copies are purged on a rolling schedule shortly after primary deletion. See our Data Deletion Instructions for the exact steps.

7. Subprocessors

We share personal data only with service providers that help us run the platform, each bound by a data-processing agreement and instructed to process data solely on our behalf. The categories are:

  • Hosting and infrastructure — the cloud servers and databases that run the application;
  • Object storage — encrypted storage for media attachments and exports;
  • Payments — subscription billing and invoicing;
  • AI inference — model providers used for the AI features described in Section 5.

We do not share personal data with third-party advertising networks. A current list of subprocessors is available on request from [email protected].

8. Security

All traffic to and within the platform is encrypted in transit with TLS. Credentials and Meta access tokens are encrypted at rest using AES-256-GCM, and media is stored in access-controlled object storage. Access to production systems is restricted to authorized personnel under role-based access control, and administrative actions are audit logged. We review our security practices regularly and will notify affected customers and authorities of a personal data breach where the law requires it.

9. Your rights

Depending on where you live, you may have rights to access, export, correct or delete personal data we hold about you:

  • Access — ask us to confirm what personal data we process about you and receive a copy;
  • Export — receive your data in a structured, machine-readable format;
  • Correction — have inaccurate data corrected, either in-app or by contacting us;
  • Deletion — have your data erased, as described in our Data Deletion Instructions.

To exercise any of these rights, email [email protected] from the email address associated with your account. If you are an end customer of a business that uses Yakko, we will refer your request to that business and assist it in responding, as it controls the data.

10. International transfers

Our infrastructure and subprocessors may store or process data in countries other than your own. Where data is transferred across borders, we rely on appropriate safeguards such as data-processing agreements incorporating standard contractual clauses or an equivalent lawful transfer mechanism, and we require the same level of protection described in this policy wherever the data is processed.

11. Changes to this policy

We may update this policy as the product or the law evolves. We will post the revised version at this URL with a new effective date and, for material changes, notify workspace owners by email or in-app notice before the change takes effect.

12. Contact

For any privacy question, request or complaint, contact our privacy team at [email protected]. For general product support, use [email protected].

This document is provided by Yakko; consult your counsel for jurisdiction-specific requirements.

Questions about these documents? Write to [email protected] (privacy) or [email protected] (support).

Yakko — operator of yakko.chat · Back to home