Security & compliance
Your customers' conversations, handled like they're ours.
NudgeDesk sits on top of your real business relationships, the DMs that turn into sales. We're direct on the boring, important details: who we are to Meta, where the encryption stands, what we store, and the laws we're built to satisfy. No hand-waving.
Standing
Official Meta Tech Provider
A direct, accountable relationship with Meta, not a reseller passing along someone else's access.
01 · Standing
A Tech Provider, not a reseller.
The distinction matters for your safety. We onboard your business directly onto the official WhatsApp Business Platform and Instagram through Meta's own Embedded Signup. You own your WhatsApp Business Account, on your own number.
Direct onboarding
No BSP middleman between you and Meta. You keep ownership of your account and number.
Official APIs only
Built on the WhatsApp Cloud API and Instagram Platform. No unofficial automation that puts your account at risk.
No new number
Your existing WhatsApp business number and Instagram account, no Facebook Page required.
Accountable to Meta
We pass Meta App Review and Business Verification, and operate under Meta's platform policies.
02 · Encryption & infrastructure
Encrypted in transit. Certified where it lands.
We'd rather explain exactly how this works than wave an "encrypted" badge at you.
In transit
WhatsApp's end-to-end encryption
Every WhatsApp message travels over WhatsApp's end-to-end encryption. It's decrypted at the official Cloud API endpoint, the point where your business itself receives the message, so NudgeDesk can read and answer it on your behalf, exactly as your own staff would. Nothing is intercepted in flight.
At rest
SOC 2 Type II & ISO 27001 infrastructure
Messages ride Meta's WhatsApp Cloud API, which is certified SOC 2 Type II and ISO 27001. The AI itself runs on a bound cloud provider under a data-processing agreement with zero data retention. Your conversations are processed to generate a reply and not retained by the model provider.
03 · Our own audit
NudgeDesk's SOC 2: in progress.
The infrastructure underneath us is certified today. Our own SOC 2 Type II examination is underway. We're building and documenting the controls now. We'd rather tell you it's in progress than claim a report we don't hold yet. When the attestation completes, it'll be listed here with its date.
Status
SOC 2 Type II: in progress
Controls being implemented. No completed report is being claimed.
04 · Data handling
What we store, in plain words.
No legalese wall. Here's what lives in NudgeDesk, how long, and how you get it out.
- What we store
- Your customers' messages, the AI's replies, lead details you capture (name, number, what they asked), and the settings and catalog you connect. Enough to run your lead desk, nothing collected for its own sake.
- How long we keep it
- For as long as your account is active, so returning customers aren't strangers. Delete a conversation or a lead any time, and it's gone. Close your account and we erase your data on a defined schedule.
- What we never do
- We never train shared or public AI models on your customer conversations. Your data is used to run your workspace, not to improve a model that other businesses touch.
- Leaving is easy
- Disconnect Instagram or WhatsApp in one click and the automation stops immediately. Export your data and request full erasure whenever you want. No hostage-taking, no export fees.
05 · Regulatory
Built for India's DPDP and Europe's GDPR.
Because "India-first, global in framing" has to be true in the plumbing, not just the pitch. The same consent, access and erasure machinery satisfies both regimes: region-aware, handled under the hood.
India
DPDP Act compliant
Consent capture, purpose limitation, data-principal rights (access, correction, erasure) and breach handling built to India's Digital Personal Data Protection Act.
European Union
GDPR-ready
Lawful-basis consent flows, right-to-erasure, data-processing agreements and EU-appropriate handling for tenants and their customers in Europe.
06 · Consent & opt-out
Every contact opts in. Any contact can stop.
WhatsApp's rules, and the law, require it, and it's the right way to treat the people who message you. We record consent with a timestamp and honour opt-outs instantly.
Timestamped consent
Every opt-in is logged with when and how it was given, mandatory under WhatsApp policy since 2026, and provable if you're ever asked.
STOP means stop
A customer replies STOP (or any clear opt-out) and outbound messaging to them halts immediately, automatically, and stays halted.
AI disclosure on
Automated replies disclose they're automated by default. Customers know when they're talking to the desk, and you can hand off to a human any time.
No unsolicited blasts
Marketing templates go only to opted-in contacts, within Meta's per-user limits. We won't help you spam. It gets accounts banned.
07 · Architecture
Every business, walled off from every other.
Per-tenant isolation isn't a feature we bolted on. It's the first architectural decision we made. Each business runs on its own WhatsApp Business Account and its own isolated data boundary. One tenant's data can't leak into another's, and one tenant's problem, even a Meta-level ban, never cascades to anyone else on the platform.
- One WhatsApp Business Account per client, never pooled.
- Isolated data boundaries, no cross-tenant reads, ever.
- A per-tenant kill-switch to pause automation instantly.
- Conservative rate limits, so no account endangers another.
Questions before you connect your account?
Bring them to the demo. We'll walk through exactly how your data flows, on your own catalog, fifteen minutes, no slides.