Privacy policy
Last updated 5 September 2026
This policy explains what personal data VUUN LTD ("we") collects, why, how long it is kept and what your rights are. It covers this website, the Vuun Connector service and the data we handle for our customers on the WhatsApp Business Platform.
1. Who we are
VUUN LTD is a company registered in England & Wales under company number 13160975, with its registered office at 128 City Road, London EC1V 2NX, United Kingdom. We are the data controller for the personal data described in section 4 and a data processor for the data described in section 3. You can reach us at [email protected].
The law that applies to us is the UK General Data Protection Regulation and the Data Protection Act 2018. Where we process personal data of people in the European Economic Area on behalf of a customer established there, the EU General Data Protection Regulation applies as well.
2. This website
This website sets no cookies and runs no analytics or advertising scripts. If you choose the dark or light theme, that single preference is kept in your browser's local storage and is never sent to us. Our hosting provider keeps ordinary web-server access logs, which include your IP address and the pages requested, for up to 30 days, on the basis of our legitimate interest in keeping the site secure and available.
If you e-mail us, we keep the correspondence for as long as we need it to answer you and to keep a record of what was agreed.
3. Data we process for our customers
Our customers are businesses that connect their own WhatsApp Business account and phone number to the service and use it to send notifications to, and receive messages from, their own customers. For that data the business is the data controller and we are its data processor. We process it only on the business's instructions, under a data processing agreement that every customer accepts at signup as an annex to the terms of service.
The data we handle in that role, and why:
- Account and phone number details from the customer's WhatsApp Business account, such as the account id, the phone number, its display name, status, quality rating and messaging limits, and the message templates registered on it. Used to link the account to the customer's workspace and to show the customer the state of their number and templates.
- Messages the customer sends: the recipient's phone number, the template used and its variables, and the delivery and read status Meta reports. Used to deliver the notification and to show the customer whether it arrived. One-time verification codes are the exception: their content is never written to the database or to a log, and is held only for the seconds needed to send them.
- Messages the customer receives: the sender's phone number, the message content, any attached media and the time. Stored when received, so that no message is lost, and delivered to the customer's own system, where their team replies and acts.
- The record of delivery: what was sent to the customer's system, when, and how it answered. Used to retry, to replay on the customer's request and to settle what was delivered.
Each customer's data is kept separate and is visible only to that customer, enforced in the database itself and not only in application code. We do not sell, share or use this data for our own purposes, for advertising, or for anything other than providing the service described here.
If you are a customer of one of our customers — you messaged a business on WhatsApp and that business uses our service — the business is the controller of your data. Direct requests about your data to that business; its own privacy notice applies. If you write to us instead, we will pass your request on to the business and help it respond.
4. Data we process as a controller
- Account data: the name, e-mail address and password (stored only as a hash) of each person who signs up or is invited to a workspace, or the identity a Google or Microsoft sign-in provides instead of a password, the workspace's name, country and industry, and the roles of its members. Basis: performance of the contract with the customer.
- Billing data: billing address, VAT or tax number, and the invoices we issue. Payment card details are collected and held by Stripe, not by us. Basis: contract, and our legal obligation to keep accounting records.
- Service records: the audit log of a workspace, including every access by our staff, which the customer can see; API keys, stored only as a hash; and the technical logs of the service, from which phone numbers, message content, one-time codes and secrets are redacted at the source, and the error reports our monitoring collects. Basis: contract and our legitimate interest in running a secure service.
- Product usage inside the service: which screens and features of the panel are used, to improve onboarding. Kept in the European Union. Basis: legitimate interest; it is never used for advertising.
- Correspondence: support and sales e-mail. Basis: contract and legitimate interest.
5. Who else processes the data
Meta operates the WhatsApp Business Platform that carries every message sent and received through the service. Our customers contract with Meta directly for it; Meta is a recipient of the data under that agreement, and Meta's own terms and privacy policy govern what it does with messages on WhatsApp, which operates globally.
For the data we handle on our customers' behalf (section 3) we use these sub-processors. Customers are told of a change to this list in advance, as the data processing agreement provides.
| Sub-processor | Purpose | Location |
|---|---|---|
| Our hosting provider | Runs the service and stores its database, backups, media and secrets, and the monitoring that runs with it | A single region in the United Kingdom or the European Union, named in the data processing agreement |
For the data we control ourselves (section 4) we use these processors:
| Processor | Purpose | Location and transfer basis |
|---|---|---|
| Stripe | Subscription billing, payment cards, invoices and tax | European Union and United States; transfers under the UK international data transfer addendum |
| Postmark | Transactional e-mail: verification links, invitations, alerts and invoices | United States; transfers under the UK international data transfer addendum |
| PostHog | Product usage analytics inside the panel | European Union; UK adequacy regulations |
| Sentry | Error reporting for the service | United States; transfers under the UK international data transfer addendum |
6. Where data is stored and how it is protected
The service runs in a single hosting region in the United Kingdom or the European Union; the region is named in the data processing agreement. Messages themselves travel over WhatsApp, which is global by nature.
- All traffic is encrypted in transit; the database and backups are encrypted at rest.
- Access tokens for customers' WhatsApp accounts are kept in a secrets vault, never in the database.
- Each customer's data is isolated by row-level security in the database.
- One-time codes are never written to the database or to a log. Phone numbers, message content, template variables and secrets are redacted from the service's application logs.
- Our staff can open a customer's workspace only for support, every access is written to the customer's own audit log, and the customer can switch that access off.
7. How long data is kept
| Data | Kept for |
|---|---|
| Sent and received messages, their status history and delivery attempts | The customer's plan window: 7, 30 or 90 days, or as agreed for Enterprise. Then deleted automatically |
| Webhook deliveries we could not complete (the dead-letter queue) | 30, 90 or 180 days by plan, independent of the message window, so a customer can replay them |
| Sandbox (test) data | 7 days |
| The raw notifications Meta sends us | 30 days, and up to 60 days counting backups |
| Encrypted backups | 30 days |
| Account, workspace and configuration | For the life of the account, and 30 days after it is closed |
| The workspace's audit log | 2 years; anonymised when the workspace is deleted |
| Invoices and accounting records | 6 years, as UK law requires |
When a customer closes their workspace, an export of its data is available for 30 days and the data is then permanently deleted, along with stored media and the references to the customer's tokens; the customer's WhatsApp account and number are untouched and remain theirs. The steps are on the data deletion page.
8. Your rights
You have the right to ask for access to the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form. Write to [email protected]; we answer within one month. Where we act as a processor we will pass the request to the customer that controls the data and help it respond.
You may also complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk, or to the supervisory authority of the EEA country you live in.
9. If something goes wrong
If we become aware of a personal data breach we notify the Information Commissioner's Office within 72 hours where the law requires it, and we notify affected customers without undue delay with what happened, what data was involved and what we are doing.
10. Changes
When this policy changes the date at the top changes with it, and customers are told by e-mail of any change that affects how their data is processed.