Skip to content
RGS Tech Center
Legal

RGS Solution Privacy Policy

RGS Solution — WhatsApp Business CRM

Effective 1 May 2026 · last updated May 2026

This policy applies to RGS Solution, a WhatsApp Business CRM operated by RGS Tech Center (Pvt.) Ltd. ("RGS Tech Center", "we", "us"). RGS Solution lets a business manage customer conversations, run broadcast campaigns and automate messaging through the WhatsApp Cloud API provided by Meta Platforms, Inc.

It explains what we collect, how we use it, who we share it with, how long we keep it, and how data is deleted — including data obtained from Meta through the Embedded Signup flow and the WhatsApp Business API. This is the privacy policy submitted to Meta for app review; it is kept current at https://rgstech.center/connect-privacy-policy.

1. Controller and processor roles

For the account data of the people who sign in to RGS Solution (name, email, role, workspace) we are the data controller.

For the WhatsApp conversations, contacts, media and campaign data that flow through a customer’s connected WhatsApp Business Account, we act as a data processor on that customer’s behalf and on their instructions. That business is the controller of its own end-users’ data.

2. Information we collect

  • Account & business information: Business name, email address and phone number; the signed-in user’s name, role and encrypted login credentials; workspace settings.
  • Meta / WhatsApp onboarding data: Via Meta Embedded Signup: the WhatsApp Business Account (WABA) ID, the Phone Number ID and its display phone number, business verification status, and the access tokens needed to call the WhatsApp Cloud API on your behalf.
  • Messaging data: Messages sent and received through the WhatsApp Cloud API (text, media, templates, contacts, locations); delivery and read status and message metadata (timestamps, message IDs); message templates and their approval status; campaign recipient lists and delivery reports.
  • End-user (customer) data: The phone numbers of people who message your WhatsApp Business number, their WhatsApp profile names, and the conversation history and media exchanged with them.
  • Technical data: IP address, browser and device information, access logs, session and authentication tokens, and error diagnostics.

3. How we use the information

  • Provide the service: Deliver and receive WhatsApp messages, run the shared inbox, send campaigns, build and submit templates, and run automations.
  • Connect your account: Use Embedded Signup data and tokens to link your WABA to the WhatsApp Cloud API and keep that connection working.
  • Authenticate and secure: Verify identity, enforce role-based access, and protect the platform from abuse.
  • Support and improve: Answer your support requests, diagnose faults, and improve reliability. We do not use your end-users’ message content to train machine-learning models or to build advertising profiles.
  • Comply: Meet the Meta Platform Terms, the WhatsApp Business Messaging Policy, and applicable law.

4. Meta Platform data — our commitments

We use data obtained from Meta and the WhatsApp APIs only to provide RGS Solution to you. Specifically:

  • We do not sell or rent any data obtained from Meta or the WhatsApp APIs.
  • We do not use Meta Platform data for any purpose unrelated to operating the CRM you asked us to run.
  • We do not share Meta Platform data with third parties except the sub-processors listed below and where required by law.
  • Access tokens and API credentials are encrypted at rest and are never exposed to end users, written to logs, or placed in job queues or browser payloads.
  • We comply with the Meta Platform Terms, the Developer Policies and the WhatsApp Business Messaging Policy.

5. Legal bases

Where required, we rely on: performance of a contract (running the CRM for the business); the business customer’s instructions and their own legal basis for processing their end-users’ data; our legitimate interests in securing and improving the service; legal obligation; and consent where we ask for it.

6. Sharing and sub-processors

We do not sell personal data. We share it only with sub-processors, each for one bounded purpose, under a data-processing agreement:

  • Meta Platforms, Inc.: To send and receive the WhatsApp messages themselves through the WhatsApp Cloud API, under WhatsApp’s own terms.
  • Cloud hosting & database provider: Stores the application data and media. Data is isolated per workspace at the database level (row-level security).
  • Email provider: Sends transactional email such as alerts, invoices and one-time codes.
  • Payment provider: Processes subscription payments where card billing is enabled.

We tell customers before adding a sub-processor that would have access to workspace content.

7. Storage, security and location

  • Encryption: Passwords are hashed with bcrypt; API tokens and other secrets are encrypted at rest with AES-256-GCM.
  • Transport: All API and browser traffic uses HTTPS / TLS.
  • Access control: Role-based access with token-based authentication and session management; operator access is restricted and logged.
  • Isolation: Each workspace’s data is separated at the database level; one workspace cannot read another’s records. Media is stored in a private bucket under the workspace’s own prefix and served only through short-lived signed links.
  • Location: Application data is hosted with our cloud provider; where data is transferred across borders we rely on standard contractual clauses or an equivalent safeguard.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Data retention

  • Account and workspace data is kept while the account is active.
  • Message and conversation data is kept for as long as the CRM needs it and any retention rules you set, and is removed on account deletion.
  • For a lapsed free trial, conversation, campaign and template data is removed after the grace period stated in the product; the account record itself is retained briefly so the trial cannot simply be repeated.
  • Billing records are kept as long as tax law requires.
  • Technical logs are rotated out within 90 days unless held for an open security investigation.

9. Data deletion

You can delete or manage your data at any time:

  • Disconnect / Unlink WhatsApp: Disconnecting or unlinking your WhatsApp Business Account from RGS Solution revokes our Meta API access tokens, deregisters the phone number, and disconnects webhook routing. Existing CRM conversations, contact directories, custom templates, and media files remain safely stored and fully accessible in your workspace.
  • Request Workspace Data Deletion: A Tenant Administrator may submit a formal Data Deletion Request directly from Settings using account password and email OTP verification. An immediate security alert with a cryptographically signed cancellation link is emailed to all administrators, allowing the request to be cancelled at any time before execution. When executed by the platform Master Administrator, all workspace conversations, contacts, media files, campaigns, custom templates, and automations are permanently and irreversibly purged from our database and cloud storage.
  • Request without signing in: If you cannot access the account, email solution@rgstech.center from the registered address, or the business owner’s address, with "Data deletion request" in the subject. We verify the request and confirm completion by email.

Data deletion instructions and requests: solution@rgstech.center — or in writing to the address in section 12. This URL (https://rgstech.center/connect-privacy-policy#data-deletion) is the data-deletion contact provided to Meta.

10. Your rights

Depending on your jurisdiction you may request access to, correction of, deletion of, or a portable copy of your personal data, and you may object to or restrict certain processing or withdraw consent. For an end-user whose data a business processes through RGS Solution, that business is the first point of contact; we assist them in responding. Contact solution@rgstech.center to exercise a right; we respond within 30 days. You may also complain to your local data-protection authority.

11. Cookies and children

RGS Solution uses only essential authentication cookies and preference cookies (for example, to remember a collapsed sidebar). It uses no third-party advertising or tracking cookies.

RGS Solution is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children; if we learn that we have, we delete it.

12. Changes and contact

We may update this policy; changes are posted here with a new effective date and, for material changes, emailed to account owners before they take effect.

RGS Tech Center (Pvt.) Ltd. — privacy contact for RGS Solution: solution@rgstech.center. General: info@rgstech.center.

Questions about any of this?

Write to solution@rgstech.center and a person will answer.