Privacy Policy
Last updated: October 1, 2026
Thank you for using Wazend (the “Service”), available at wazend.net and in the portal portal.wazend.net. This Privacy Policy explains what personal data we collect, how we use it, who we share it with and how you can exercise your rights.
The Service is operated by:
By using the Service you agree to the handling of your information as described in this Policy. If you do not agree with it, do not use the Service.
Wazend is an API that connects WhatsApp with your applications and is not affiliated with WhatsApp or Meta: when you link a number, its use is also governed by WhatsApp's policies.
For the terms of use of the Service, see our Terms of Service.
1. Information We Collect
We only collect the data we need to provide the Service.
1.1 Account data
- Name, surname and company if you provide it
- Email address and, if you give it, phone number
- Encrypted password, or your account identifier if you sign in with Google or GitHub
- Security settings such as two-factor authentication
- Notification preferences
1.2 Billing data
Payments are processed by Stripe. We receive the customer identifier, the plan you contract and the subscription status; we do not store full card details.
- Plan and instances contracted
- Invoices, credits and transactions
- Tax details you give us for the invoice
1.3 WhatsApp and file data
To provide the Service we process data from the instances you connect:
- The linked number and the session status, including the QR code and its expiry
- The messages and files your instances send and receive, which pass through our infrastructure so they can be delivered
- The events we send to your server through webhooks
- The files you upload to the portal, with their name, type and size
1.4 AI assistant
If you use the portal assistant, we store the conversation thread and any files you attach, and the content is sent to our model provider (OpenRouter) to generate the response.
1.5 Technical and usage data
- IP address, browser, device and operating system
- API request logs, usage per instance and errors
- Audit records of actions taken in the account
1.6 Cookies and similar technologies
We use cookies and local storage to keep your session and remember preferences. On the public website we store the language and the theme (light or dark); in the portal, your account session. We also use analytics, advertising and anti-automation tools:
- Google Tag and Google Ads
- Meta Pixel and the Meta Conversions API
- Microsoft Clarity
- Cloudflare Turnstile, to tell people apart from bots
You can block or delete cookies in your browser; some portal features may stop working.
2. Legal Basis for Processing
We process your data because it is necessary to perform our contract with you, because we have a legitimate interest in keeping the Service secure and improving it, because you consented in specific cases (for example, marketing communications or non-essential analytics) and because the law requires it in others (billing and requests from authorities).
3. How We Use Your Information
- Provide the Service: create and maintain your instances, send and receive messages and deliver webhooks
- Manage your account, access and security, including two-factor authentication
- Bill your plans and manage credits and subscriptions
- Answer your support requests
- Enforce usage limits and prevent abuse and fraud
- Send you important service notices and, if you allow it, marketing communications
- Analyse usage in aggregate to improve the product
- Comply with legal obligations
4. Who We Share Information With
We do not sell or rent your personal data. We share it only with providers that help us run the Service, under contract:
- Stripe, for payments and subscriptions
- Hosting and infrastructure providers that run Wazend and the WhatsApp instances
- S3-compatible object storage for the files you upload
- An email provider for transactional messages
- OpenRouter, for the AI assistant features
- Google, Meta and Microsoft, for analytics, advertising and anti-automation
- Authorities, when there is a legal obligation or a valid order
- A buyer, in the event of a merger or sale of assets, with prior notice
Messages you send through WhatsApp are delivered through WhatsApp's infrastructure, under its own policies.
5. AI Agents and API Access
You can connect AI assistants (Claude Code, Cursor, Codex and others) to the Service through the MCP server or by giving them an API key. This section explains what that access involves.
5.1 How access is authorised
API keys are created in the portal, shown only once, and you can revoke them whenever you want; once revoked, access ends on the next request. If you connect an assistant over MCP, the authorisation is limited to the tool or scope you approve.
5.2 What a connected assistant can do
Authorisation is account-wide: with a valid API key, an assistant can call Wazend tools on your behalf, including:
- Send and read messages from your instances
- Look up sessions, contacts and groups
- Manage files and webhook events
- Run the automations you have configured
5.3 What is shared with the assistant provider
When an assistant requests data, that data leaves Wazend for the provider that operates the assistant, which handles it under its own privacy policy. Only connect assistants you trust, because outside Wazend we do not control how they process it.
5.4 What we record
We log the calls made by connected assistants — which tool, with which parameters and with which credential — as API usage, to operate the Service, enforce limits, detect abuse and provide support.
5.5 Model training
We do not use the content that passes through our API or the MCP server to train machine-learning models.
5.6 Ending an assistant's access
You can delete an API key from the portal at any time; that invalidates access immediately. Deleting your account revokes every authorisation and associated key.
6. WhatsApp and Third-Party Services
Wazend is not affiliated with WhatsApp or Meta. When you link a number, its use is also governed by WhatsApp's policies and your account terms. We process message content only to deliver it and for the technical maintenance of the Service; we do not use it for advertising or sell it.
7. Data Security
We apply technical and organisational measures to protect your information: encryption in transit, credentials and keys stored securely, restricted access and backups. No system is infallible; if a breach affects your data, we will notify you as required by applicable law.
8. Data Retention
We keep your data while your account is active and for the periods needed to meet legal and tax obligations. If you delete your account, we delete or anonymise your personal data within 30 days, except what the law requires us to keep, such as invoices.
9. Your Rights
Depending on where you live, you can exercise the following rights over your personal data:
- Access: know what data we process and get a copy
- Rectification: correct inaccurate or incomplete data
- Erasure: ask us to delete your data when it is no longer needed
- Restriction and objection: ask us to stop processing your data in certain cases
- Portability: receive your data in a structured, commonly used format
- Withdraw consent: where processing is based on your consent
Write to the contact address telling us which right you want to exercise: we reply within 30 days and may ask you to verify your identity. You can also complain to the data protection authority in your country.
10. Children
The Service is intended for companies and professionals and is not directed at anyone under 18. We do not knowingly collect data from children; if we learn we have, we will delete it.
11. International Transfers
Our servers and providers may be in countries other than yours, including the United States. When we transfer personal data outside your region we apply the safeguards required by applicable law, such as standard contractual clauses.
12. Changes to This Policy
We may update this Privacy Policy. If the change is material, we will tell you by email or in the portal before it takes effect, and we will update the date at the top of the page.
13. Contact
If you have questions about this Privacy Policy or how we handle your data, write to us at:
This document is published in Spanish, English, Portuguese and German. In the event of any discrepancy between versions, the Spanish version prevails.