What Room
Privacy Policy
Who we are
What Room is run by White Room (M) Sdn Bhd ("White Room", "we"), registration number 1509000-P, 169, Lebuh Victoria, 10300 George Town, Penang, Malaysia. White Room is a software agency in Malaysia that builds apps for its clients.
What Room connects the WhatsApp numbers of White Room's clients to the apps we build for them, so those apps can send and receive WhatsApp messages. It is only for existing White Room clients, by invitation. This policy explains how we handle data in What Room. It doesn't cover the clients' own apps, which have their own privacy notices.
Questions: hello@whiteroom.work.
Our role
We process WhatsApp data on behalf of, and at the direction of, each client. The client decides which messages its app sends and to whom. We never use WhatsApp data for our own purposes or for advertising. We don't sell it, build profiles of the people in it, or share it except as this policy describes.
Some data is ours to look after: the accounts of people who sign in to the What Room portal, described below.
What we process and why
About each client's WhatsApp connection
- The identifiers of the client's Meta business portfolio, WhatsApp accounts and phone number, the number itself and its business name, so we can send and receive messages for the right number.
- The access Meta grants us when the client connects through Meta's Embedded Signup. We keep it encrypted and use it only to provide What Room to that client.
- The client's message templates and their approval status at Meta, so its app sends only templates Meta has approved.
About messages
- Message metadata: message IDs, delivery statuses, timestamps, template names and the end user's WhatsApp number. We use it to send messages, report delivery to the client's app, apply WhatsApp's 24-hour customer service window and investigate problems.
- Messages a client's app sends pass through us to Meta. We keep a record of each send attempt, without the message content.
- For clients whose incoming messages come through us, we keep the message content, reduced to what the client's app needs and encrypted, until shortly after the app confirms it has received it (see How long we keep data).
- Photos customers send: when a client's app needs one, we download it from Meta and keep an encrypted copy for the app to fetch, for a limited time (see How long we keep data). Only the client's own app can fetch it.
- For clients whose own app can't show messages typed on the business phone, the portal shows the client a read-only conversation thread, so the whole conversation stays visible to the business. Sign-in codes are never shown in it.
About people who sign in to the portal
The portal is for White Room staff and invited client staff. We keep each person's name, email address, password (as a secure hash) and two-factor authentication settings, and for each signed-in session the IP address and browser details, to keep accounts secure.
What we don't collect
- When a number is connected, Meta requires a one-time request for the business phone's contacts and chat history. Our clients decline to share their history, and we don't import or keep contacts or chat history: anything Meta sends from them is discarded.
- Our logs never contain message text, phone numbers, sign-in codes or access tokens.
- This website sets no cookies, runs no analytics and loads nothing from other sites.
Sign-in codes
Some client apps send sign-in codes by WhatsApp. Our gateway does not store or log sign-in codes. The client apps keep short-lived verification records for login.
Because the client's number also works in the WhatsApp Business app, every message sent from it, sign-in codes included, also appears on the client's business phone. The client accepts this in writing when it connects.
Messages delivered straight to a client's app
A client's connection can be set up so that Meta delivers its incoming messages, delivery updates and messages typed on the business phone straight to the client's own app, without passing through What Room. For those connections we never receive that data, with one exception: when the client's app asks for a photo a customer sent, we fetch it from Meta and keep an encrypted copy for the app to download. The client's app handles everything else under the client's own privacy notice. Messages the app sends still go through What Room, and we still receive account and template updates from Meta.
How long we keep data
- Incoming message content held for a client's app: deleted 72 hours after the app confirms receipt, and after 7 days at most if it never does.
- Photos customers send, held for a client's app: 7 days from the message, or 24 hours from the app's request for connections whose messages go straight to the client's app.
- The portal conversation thread: 30 days.
- Message metadata: 90 days.
- Connection data and the access Meta granted us: kept while the client is connected. When the client disconnects, we delete the access at once and the rest of the connection's data within 30 days.
- Portal sessions end after 7 days without use. Session records are kept for 30 days after the session ends, and portal accounts until 30 days after the person's access ends.
- Encrypted database backups: kept for up to 30 days. Data deleted from the live system stays in backups until they expire.
Who processes data for us, and where
- DigitalOcean hosts What Room, its database and backups, in Singapore (DigitalOcean's SGP1 region).
- Netlify hosts this website. To serve its pages, Netlify receives each visitor's IP address and browser details, under its own privacy policy, and may process them outside Malaysia. The website holds no WhatsApp data.
- Our alerts go to an internal team chat channel that only White Room staff can read. An alert carries only its name, a connection ID and a count: never message content or personal data.
White Room works from Malaysia. Meta runs WhatsApp and processes messages under its own terms, which each client accepts when it connects.
How we protect data
- The access Meta grants us and the message content we store are encrypted in our database, with the encryption keys kept outside it. Client apps never hold the client's Meta access: they use a separate key from us.
- Each client's data is kept separate from every other client's, and encrypted data can only be read back for the client it belongs to.
- All traffic to What Room uses HTTPS.
- The portal is invitation-only. White Room staff must use two-factor authentication, and each client's users see only their own client's data.
- Logs are limited to a fixed list of technical fields.
Your rights and requests
You can ask us for access to, correction of, or deletion of personal data we hold about you. If you received WhatsApp messages from a business that uses What Room, that business decides how your data is used, so you can also ask it directly. Email us at hello@whiteroom.work.
We disclose data to a public authority only when the law requires it. We check that each request is lawful, challenge requests that aren't, disclose no more than the request needs, and keep a record of every request.
Deleting data
How to ask
Email hello@whiteroom.work with the subject "Data deletion request".
- Clients: send it from the client owner's or a client admin's email address, and name the WhatsApp number.
- End users: include your WhatsApp number with its country code, and the name of the business that messaged you.
We may ask you to confirm the request before we delete anything.
What we delete
- For a client: its connection data, the access Meta granted us, the keys we issued to its app, its message metadata and stored message content, its templates as we hold them, its portal conversation thread and its staff's portal accounts.
- For an end user: the message metadata, stored message content and conversation thread entries linked to your number for that business. We tell the business about your request, so it can handle the data in its own app.
How long it takes
We complete deletion within 30 days and confirm by email. Copies in encrypted backups expire within a further 30 days.
What stays elsewhere
- The client's WhatsApp Business app: messages stay on the business phone, as they do in any WhatsApp chat.
- The client's own app: what the app stores is the client's to delete. Ask the business directly.
- Meta: WhatsApp messages are also processed by Meta under its own terms and privacy policy. We can't delete data Meta holds.
A client can also end What Room's access at any time by disconnecting its number in the WhatsApp Business app.
Malaysian data protection law
Malaysia's Personal Data Protection Act 2010 applies to the personal data we handle. For WhatsApp data, each client decides why and how the data is processed, and we process it on the client's behalf. For portal accounts, White Room decides. Either way, you can ask us for access to or correction of your personal data at hello@whiteroom.work. What Room's personal data is stored outside Malaysia, in Singapore; this website's visitor details are handled by Netlify, as described above.
Changes and contact
When we change this policy, we update this page and the date at the top. Questions or requests: hello@whiteroom.work, 169, Lebuh Victoria, 10300 George Town, Penang, Malaysia.