Privacy Policy
1. Introduction
Tenashi (“Tenashi”, “we”, “us”, or “our”) provides a shared WhatsApp workspace for teams — a shared inbox, a lightweight CRM, and a support desk built around the messaging channels your customers already use. This Privacy Policy explains what personal data we process, why we process it, who we share it with, and the rights you have. It applies to our marketing website, our web application, and the related services we provide (together, the “Service”).
Our role depends on the data in question. For information about your account and the people who administer or use your workspace — for example, the name and email of a team member who signs in — we act as a data controller and decide how that data is processed. For the WhatsApp conversation data inside a customer’s workspace — the messages, contacts, group metadata, and media that flow through a connected WhatsApp number — we act as a data processor, processing that data on behalf of and under the instructions of the customer, who is the controller of it. Where we are a processor, our handling of that data is governed by our agreement with the customer, including our Data Processing Addendum.
2. Data we collect
- Account data. When you create an account or set up a workspace, we collect your name, email address, password credentials, workspace name, team member details, roles, and the settings and preferences you configure.
- WhatsApp conversation data. When you connect a WhatsApp number to a workspace, we process the data that flows through it so your team can view and reply from a shared inbox. This includes message content, the phone numbers and profile names of contacts you communicate with, group metadata (such as group names, participants, and roles), delivery and read receipts, reactions, edits, message revocations, and media such as images, documents, audio, and video. We process this data on your behalf as a processor.
- Usage and diagnostic data. To operate and secure the Service, we collect logs and technical information such as IP address, browser and device details, timestamps, feature usage, error and performance diagnostics, and audit records of significant actions.
- Billing data. When you subscribe to a paid plan, our payment provider collects and processes the information needed to take payment, such as billing contact details and card or bank information. We do not store full payment card numbers on our own systems; we receive limited billing metadata (such as plan, invoice, and the last four digits of a card) to manage your subscription.
3. How we use data
We use personal data to:
- operate the shared inbox, CRM, and support desk;
- sync and display your WhatsApp message history and contacts;
- send and deliver messages on your behalf, including receipts and notifications;
- provide customer support and respond to your requests;
- secure the Service — detecting, preventing, and investigating abuse, fraud, and technical problems;
- manage billing, subscriptions, and invoices; and
- comply with our legal obligations.
We do not sell personal data, and we do not use the content of your WhatsApp conversations to train third-party artificial intelligence models.
4. Legal bases for processing
Where the EU or UK General Data Protection Regulation (GDPR) applies, we rely on the following legal bases under Article 6:
- Performance of a contract — to provide the Service to you under our terms, manage your account, and take payment.
- Legitimate interests — to secure, maintain, and improve the Service, prevent abuse, and communicate with you about your account, provided those interests are not overridden by your rights.
- Consent — where we ask for it, for example for certain non-essential communications; you may withdraw consent at any time.
- Legal obligation — to comply with applicable laws, tax and accounting requirements, and lawful requests from authorities.
For WhatsApp conversation data processed on a customer’s behalf, the customer, as controller, is responsible for establishing the legal basis for that processing.
5. Sharing and sub-processors
We do not sell personal data. We share data only with service providers who help us run the Service, and only as needed for them to perform their function. Our key sub-processors are:
- Amazon Web Services (AWS) — cloud hosting, storage, and infrastructure on which the Service runs.
- Our payment processor — to handle subscription billing and process payments securely.
- Our email provider — to send transactional email such as sign-in, verification, and account notifications.
We enter into data-processing terms with our sub-processors, and each is bound to protect personal data. We may also disclose data where required by law or to protect our rights, users, or the public. A Data Processing Addendum (DPA) is available for customers who require one — contact us at the address below to request it.
6. International transfers
The Service runs on AWS infrastructure, and personal data may be processed in the regions where that infrastructure is located. Where personal data is transferred across borders — for example from the European Economic Area or the United Kingdom to another country — we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs) and equivalent mechanisms, to ensure your data receives an adequate level of protection.
7. Security
We take the security of personal data seriously. Data is encrypted in transit using industry standard protocols, access to production systems is restricted on a need-to-know basis and protected by authentication and access controls, and we maintain logging and monitoring to detect and respond to issues. Our infrastructure runs on AWS, whose data centres are independently audited and hold SOC 2 and ISO 27001 certifications. These certifications belong to AWS as our infrastructure provider; they describe the security of the underlying platform rather than an independent audit of Tenashi itself. No method of transmission or storage is completely secure, but we work to protect your data using appropriate technical and organisational measures.
8. Retention and deletion
We retain personal data for as long as your workspace is active and as needed to provide the Service. When an account is closed, we delete or anonymise the associated personal data — including WhatsApp conversation data — within a reasonable period, unless we are required to retain it to meet a legal, tax, accounting, or regulatory obligation, or to resolve disputes and enforce our agreements. Where we act as a processor, we delete or return conversation data in line with the customer’s instructions and our Data Processing Addendum.
9. Your rights
Depending on where you live, and subject to applicable law, you have the following rights over your personal data under the GDPR and similar laws:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — ask us to delete your data in certain circumstances.
- Portability — receive your data in a portable, machine-readable format.
- Restriction — ask us to limit how we process your data.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — where we rely on consent, withdraw it at any time.
- Complain — lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, contact us at the address below. Where we act as a processor for WhatsApp conversation data in a customer’s workspace, we act on the customer’s instructions; if you are a contact or end user of one of our customers, please direct your request to that customer, and we will support them in responding to your data-subject request.
10. Cookies
We use essential cookies and similar technologies that are necessary to run the Service — for example, to keep you signed in and to maintain your session securely. We keep tracking to a minimum and do not use the Service to build advertising profiles about you. You can control cookies through your browser settings, though disabling essential cookies may affect how the Service works.
11. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the Service, our practices, or legal requirements. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you through the Service or by email. Your continued use of the Service after an update takes effect constitutes acceptance of the revised policy.
13. Contact
If you have questions about this policy or wish to exercise your rights, contact us at hello@usetenashi.com.