Skip to content

Security & compliance

Your customers' conversations, handled like they're ours.

NudgeDesk sits on top of your real business relationships, the DMs that turn into sales. We're direct on the boring, important details: who we are to Meta, where the encryption stands, what we store, and the laws we're built to satisfy. No hand-waving.

Standing

Official Meta Tech Provider

A direct, accountable relationship with Meta, not a reseller passing along someone else's access.

01 · Standing

A Tech Provider, not a reseller.

The distinction matters for your safety. We onboard your business directly onto the official WhatsApp Business Platform and Instagram through Meta's own Embedded Signup. You own your WhatsApp Business Account, on your own number.

Direct onboarding

No BSP middleman between you and Meta. You keep ownership of your account and number.

Official APIs only

Built on the WhatsApp Cloud API and Instagram Platform. No unofficial automation that puts your account at risk.

No new number

Your existing WhatsApp business number and Instagram account, no Facebook Page required.

Accountable to Meta

We pass Meta App Review and Business Verification, and operate under Meta's platform policies.

02 · Encryption & infrastructure

Encrypted in transit. Certified where it lands.

We'd rather explain exactly how this works than wave an "encrypted" badge at you.

In transit

WhatsApp's end-to-end encryption

Every WhatsApp message travels over WhatsApp's end-to-end encryption. It's decrypted at the official Cloud API endpoint, the point where your business itself receives the message, so NudgeDesk can read and answer it on your behalf, exactly as your own staff would. Nothing is intercepted in flight.

At rest

SOC 2 Type II & ISO 27001 infrastructure

Messages ride Meta's WhatsApp Cloud API, which is certified SOC 2 Type II and ISO 27001. The AI itself runs on a bound cloud provider under a data-processing agreement with zero data retention. Your conversations are processed to generate a reply and not retained by the model provider.

03 · Our own audit

NudgeDesk's SOC 2: in progress.

The infrastructure underneath us is certified today. Our own SOC 2 Type II examination is underway. We're building and documenting the controls now. We'd rather tell you it's in progress than claim a report we don't hold yet. When the attestation completes, it'll be listed here with its date.

Status

SOC 2 Type II: in progress

Controls being implemented. No completed report is being claimed.

04 · Data handling

What we store, in plain words.

No legalese wall. Here's what lives in NudgeDesk, how long, and how you get it out.

What we store
Your customers' messages, the AI's replies, lead details you capture (name, number, what they asked), and the settings and catalog you connect. Enough to run your lead desk, nothing collected for its own sake.
How long we keep it
For as long as your account is active, so returning customers aren't strangers. Delete a conversation or a lead any time, and it's gone. Close your account and we erase your data on a defined schedule.
What we never do
We never train shared or public AI models on your customer conversations. Your data is used to run your workspace, not to improve a model that other businesses touch.
Leaving is easy
Disconnect Instagram or WhatsApp in one click and the automation stops immediately. Export your data and request full erasure whenever you want. No hostage-taking, no export fees.

05 · Regulatory

Built for India's DPDP and Europe's GDPR.

Because "India-first, global in framing" has to be true in the plumbing, not just the pitch. The same consent, access and erasure machinery satisfies both regimes: region-aware, handled under the hood.

India

DPDP Act compliant

Consent capture, purpose limitation, data-principal rights (access, correction, erasure) and breach handling built to India's Digital Personal Data Protection Act.

European Union

GDPR-ready

Lawful-basis consent flows, right-to-erasure, data-processing agreements and EU-appropriate handling for tenants and their customers in Europe.

06 · Consent & opt-out

Every contact opts in. Any contact can stop.

WhatsApp's rules, and the law, require it, and it's the right way to treat the people who message you. We record consent with a timestamp and honour opt-outs instantly.

Timestamped consent

Every opt-in is logged with when and how it was given, mandatory under WhatsApp policy since 2026, and provable if you're ever asked.

STOP means stop

A customer replies STOP (or any clear opt-out) and outbound messaging to them halts immediately, automatically, and stays halted.

AI disclosure on

Automated replies disclose they're automated by default. Customers know when they're talking to the desk, and you can hand off to a human any time.

No unsolicited blasts

Marketing templates go only to opted-in contacts, within Meta's per-user limits. We won't help you spam. It gets accounts banned.

07 · Architecture

Every business, walled off from every other.

Per-tenant isolation isn't a feature we bolted on. It's the first architectural decision we made. Each business runs on its own WhatsApp Business Account and its own isolated data boundary. One tenant's data can't leak into another's, and one tenant's problem, even a Meta-level ban, never cascades to anyone else on the platform.

  • One WhatsApp Business Account per client, never pooled.
  • Isolated data boundaries, no cross-tenant reads, ever.
  • A per-tenant kill-switch to pause automation instantly.
  • Conservative rate limits, so no account endangers another.

Questions before you connect your account?

Bring them to the demo. We'll walk through exactly how your data flows, on your own catalog, fifteen minutes, no slides.