Skip to main content

Data Privacy & Security | Developer Documentation

Understand where WhatsApp message content is handled and stored

ChatArchitect does not store customer message texts or attachments. When you connect WhatsApp to a CRM, help desk or another supported tool, review that tool's message history and storage settings. Its handling of conversation records is separate from ChatArchitect's.

Check each part of the connection

Service or systemWhat to check
ChatArchitectCustomer message texts and attachments are not stored by ChatArchitect. For a question about another data type, such as account details, templates or delivery records, identify that type when asking support.
Meta and WhatsAppMeta operates the WhatsApp messaging infrastructure. Its processing and retention rules are described in the Cloud API data privacy and security reference.
Your CRM, help desk or other connected toolCheck which message texts and attachments the tool saves, who can view them, its retention settings and the scope of its deletion controls.
Your own copiesInclude any downloaded attachments, exported conversations, screenshots and copies created by your team's other systems.

Find a conversation or attachment

  1. Open the conversation in the tool your team used to send or receive the message. Confirm the customer, connected business number and date.
  2. Check the tool's history and attachment controls. Ask its administrator about the retention settings if an older record or file is missing.
  3. If you exported or downloaded a copy, check the location where your team saved it. Treat those copies as part of your own record-handling process.

A delivery status and the content of a message answer different questions. A status does not establish that a particular CRM retained the text or attachment. For a delivery problem, use the sending guide and provide the number, time with time zone, message ID if available, and exact status to support.

Set retention and handle deletion in the systems that keep copies

Have the administrator of each connected system confirm the intended retention period, staff access and available deletion procedure. If you remove a conversation, check whether the action also covers its attachments and whether separate exports or backup copies remain under that system's rules. Deleting a record in one tool does not establish that copies in other systems were deleted.

Use the business access guide for access to the correct Meta portfolio and WhatsApp account. Conversation visibility in a CRM is controlled by that CRM's access settings.

Interpret Meta's security information within its scope

Meta describes an encrypted WhatsApp connection between the user and Cloud API. Cloud API decrypts incoming messages on behalf of the business and forwards them to the business; outbound messages are encrypted for delivery to the user. Review Meta's reference for the details of that part of the message flow.

Meta's Cloud API documentation describes Meta's service. Its retention periods, storage locations and certifications do not define the settings of your CRM or certify the entire connected workflow. Confirm any storage-location or deletion requirement with the provider of the system to which it applies.

For the current ChatArchitect service, selection of Meta's storage country is not offered, and Meta No Storage is not used. Review those guides if a requirement names either Meta feature.

If you need an explanation of ChatArchitect's handling of a specific data type, send support the name of the data type and your requirement. Keep passwords, App key/Secret values and unrelated conversation content out of the initial request.