Last updated: January 27, 2026
The General Data Protection Regulation (GDPR) is the toughest privacy and security law in the world. Though it was drafted and passed by the European Union (EU), it imposes obligations onto organizations anywhere, so long as they target or collect data related to people in the EU. At SalesWhiz, we embrace these standards globally, treating all user data with the same level of care and respect required by European law.
To help you understand this document, here are some key terms defined by the GDPR:
Any information relating to an identified or identifiable natural person (Data Subject), such as a name, email address, IP address, or phone number.
Any operation performed on personal data, such as collection, recording, organization, storage, adaptation, retrieval, use, disclosure, or erasure.
The entity that determines the purposes and means of the processing of personal data.
The entity that processes personal data on behalf of the controller.
Compliance is not just a checkbox for us; it is a fundamental part of our engineering culture. We operate under the following core principles:
We don’t bolt on privacy features at the end. All our systems are architected with data minimization and security as foundational elements. Default settings are always the most privacy-friendly.
We only collect the data we absolutely need to provide our services. If we don’t need it, we don’t ask for it, and we certainly don’t store it.
No hidden processing. We clearly document every third-party sub-processor we use and explain exactly how your data flows through our system.
We utilize enterprise-grade encryption for data in transit and at rest, along with rigorous access conduct and regular security audits.
Our Data Protection Officer (DPO) oversees all processing activities, ensuring ongoing compliance through regular impact assessments (DPIAs).
Understanding the distinction between our roles is critical for B2B compliance:
SalesWhiz as Data Controller
For your account data (admin name, billing info, login logs), SalesWhiz is the Controller. We decide how to manage your subscription and support your usage of our platform.
SalesWhiz as Data Processor
For the data of your end-users (chat logs, customer phone numbers, orders) flowing through our system, YOU are the Controller, and we are the Processor. We process this data strictly on your behalf.
We process the following categories of personal data depending on your interaction with our services:
Name, email address, password, phone number, and company details provided during registration.
Content of messages sent via our platform (WhatsApp/Telegram), including text, images, and metadata.
Information about your customers that you upload or that is collected through chat interactions (e.g., phone numbers, orders).
IP addresses, browser type, device information, and interaction logs with our user interface.
Under GDPR, we must have a valid lawful basis for processing your personal data. We rely on the following lawful bases:
| Lawful Basis | Description |
|---|---|
| Consent | You have given clear consent for us to process your personal data for a specific purpose. Example: Marketing communications, optional analytics, newsletter subscriptions |
| Contract | Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract. Example: Account creation, service delivery, billing, customer support |
| Legal Obligation | Processing is necessary for compliance with a legal obligation to which we are subject. Example: Tax records, fraud prevention, responding to legal requests |
| Legitimate Interests | Processing is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights. Example: Service improvements, security measures, internal analytics |
As a data subject, you have the following rights under GDPR. We are committed to honoring these rights in a timely manner.
As a global service, we may transfer your personal data to countries outside the European Economic Area (EEA). When we do so, we ensure that appropriate safeguards are in place to protect your data:
We may transfer data to countries that the European Commission has determined provide an adequate level of data protection.
For transfers to countries without adequacy decisions, we use the European Commission's Standard Contractual Clauses to ensure appropriate safeguards.
Where necessary, we implement additional technical and organizational measures to enhance protection, such as encryption and pseudonymization.
You can request a copy of the safeguards we use for international transfers by contacting our Data Protection Officer.
We employ a defense-in-depth strategy to secure your data. Our security posture includes, but is not limited to:
Data in transit is encrypted via TLS 1.3+. Sensitive data at rest (database fields, backups) uses AES-256 encryption managed via secure key management systems.
We follow the Principle of Least Privilege (PoLP). Employees access production data only when absolutely necessary (e.g., support ticket debugging) and all access is logged and audited.
Identifiers in database exports or non-production environments are hashed or tokenized to prevent direct identification of individuals.
We perform automated dependence scanning, static code analysis (SAST), and regular third-party penetration testing.
We maintain a tested Incident Response Team (IRT) available 24/7/365 to triage potential breaches.
All staff undergo GDPR and cybersecurity awareness training during onboarding and annually thereafter.
We conduct rigorous risk assessments of all sub-processors. We do not integrate third-party tools that do not meet our security baseline.
In the unlikely event of a personal data breach, we have strict protocols in place:
If your account data is compromised, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, provided it poses a risk to your rights and freedoms.
If we detect a breach affecting the data you process through our platform, we will notify you (the Controller) without undue delay after becoming aware of the breach, so you can fulfill your own notification obligations.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Our retention periods are determined based on:
To exercise any of your GDPR rights, you can:
Many actions (like data export and account deletion) can be performed directly in your SalesWhiz dashboard under Settings → Privacy.
Send an email to [email protected] with your request. Please include sufficient information to verify your identity.
For complex matters or complaints, contact our Data Protection Officer at [email protected].
Note: We will respond to your request within 30 days. In complex cases, we may extend this period by an additional 60 days, in which case we will inform you of the extension and the reasons for it within the initial 30-day period.
If you believe that we have not complied with your data protection rights, you have the right to lodge a complaint with a supervisory authority. You may do so in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.
However, we encourage you to contact us first so we can address your concerns. We are committed to resolving any issues related to your personal data promptly and fairly.
If you have any questions about this GDPR Compliance page, our data protection practices, or wish to exercise your rights, please contact: