Overview & Service Roles (Controller vs. Processor)
Bluetick CRM is a multi-tenant business software platform enabling organizations to manage WhatsApp customer relationships, chat in real time with end customers, route conversations to team members, run compliant template notifications, and manage sales deals.
Roles Under Applicable Data Protection Laws (GDPR & CCPA):
The Business (Our Customer)
Data Controller
The company subscribing to Bluetick CRM is the Data Controller of customer phone numbers, message content, customer identities, and opt-in consents.
Bluetick CRM
Data Processor / Service Provider
Bluetick CRM operates solely as a Data Processor, ingesting, displaying, storing, and transmitting customer communication strictly in accordance with our customer’s instructions.
Information We Collect and Process
Depending on how you interact with Bluetick CRM and which integrations you activate, we collect and store the following categories of data:
A. End-User WhatsApp Customer Data
- Contact Identifiers: WhatsApp phone numbers (in E.164 MSISDN format), profile display names, and profile pictures provided through WhatsApp.
- Message Records & Media: Text messages, inbound audio/voice notes, video files, images, PDF documents, location coordinates, interactive button selections, and list menu clicks.
- Delivery Metadata: Unique WhatsApp message IDs (`wamid`), delivery status timestamps (sent, delivered, read, failed), and error codes.
- CRM Enrichment: Custom contact fields, organizational tags, deal stages, conversation resolution notes, and agent assignments added by your team.
B. Workspace Account & Agent Credentials
- Account Information: Agent name, business email address, cryptographically hashed passwords, and assigned role permissions (Owner, Admin, Manager, Agent).
- Authentication & Presence: JWT access tokens, session device identifiers, user IP addresses, login audit logs, and agent online presence heartbeats.
C. WhatsApp Business Account (WABA) Integration Details
- Meta Configuration: WhatsApp Business Account (WABA) ID, Phone Number ID, App ID, System User Access Tokens, and Meta Webhook verification secrets.
- Approved Templates: WhatsApp message template names, language codes, approval statuses, and variable body structures.
How We Use WhatsApp Data
All customer personal data processed through Bluetick CRM is used strictly to provide, maintain, and optimize CRM operations:
Receiving inbound messages via Meta webhooks and transmitting outbound replies or transactional templates in real time.
Assigning conversations to available human agents, managing open/closed conversation states, and preventing duplicate responses.
Linking WhatsApp chat threads with pipeline stages, deal values, and expected close dates for sales tracking.
Broadcasting new message alerts, desktop notifications, and unread badges via Server-Sent Events (SSE).
WhatsApp Cloud API & Meta Platforms Processing
Bluetick CRM integrates with the WhatsApp Business Cloud API operated by Meta Platforms, Inc. (and Meta Platforms Ireland Ltd. for European users).
Understanding Encryption in WhatsApp Business Cloud API
In consumer WhatsApp, messages are end-to-end encrypted directly between user devices. When messaging a WhatsApp Business Account (WABA) powered by the Cloud API, messages travel encrypted from the user’s phone to Meta’s Cloud API servers, where they are decrypted to allow the business solution (Bluetick CRM) to ingest and display them for customer service agents.
Meta processes this data in accordance with the WhatsApp Business Terms of Service and Meta Commercial Terms.
Customer Opt-In Consent & The STOP Opt-Out Policy
Meta’s WhatsApp Business Messaging Policy strictly forbids sending unsolicited commercial messages (spam). Bluetick CRM enforces compliance guidelines for all workspaces:
Prior Verifiable Opt-In Required
Businesses must obtain clear, affirmative consent (opt-in) from recipients before initiating WhatsApp template messages or broadcast campaigns. This can be gathered via website sign-up forms, transactional checkout checkboxes, SMS/email confirmations, or direct user-initiated WhatsApp chats.
Automated Keyword Opt-Out Handling (STOP Policy)
End customers have the unequivocal right to withdraw consent at any time. When an end user sends any of the recognized opt-out keywords:
The contact will be automatically marked as unsubscribed, and future broadcast template messaging will be halted immediately.
Third-Party Sharing, Subprocessors & AI Disclosures
We hold a strict policy regarding third-party disclosures:
Our Absolute Guarantee: We Never Sell Your Data
Bluetick CRM has never sold, rented, leased, or disclosed customer personal information or contact phone numbers to any third-party marketing brokers, data aggregators, or advertising networks, and will never do so.
Authorized Technical Subprocessors:
Meta Platforms, Inc.
Routing and transmission of WhatsApp messages
Cloud Database & Storage Providers
PostgreSQL storage, Redis caching & encrypted media assets
Optional AI Copilot Inference (If Activated)
Ephemeral draft suggestion processing (Never used to train foundation models)
Data Retention & Deletion Rights
We retain personal data only for as long as necessary to provide the workspace services and comply with legal or auditing obligations:
Active Workspaces
Chat records, contact phone numbers, notes, and deal pipelines remain stored while the workspace is active, enabling continuous customer conversation history.
Workspace Termination
Upon subscription cancellation or account closure request, all workspace data, associated customer profiles, message archives, and API credentials will be permanently purged within thirty (30) days.
End-User Right to Erasure ("Right to be Forgotten")
Individual WhatsApp end users can request deletion of their contact profile and conversation logs by contacting the business directly or submitting a verified request to our privacy team.
Data Security & Technical Safeguards
We implement rigorous technical and organizational security controls designed to protect information from accidental loss, unauthorized access, destruction, or disclosure:
All HTTP and WebSocket connections utilize Transport Layer Security (TLS 1.3). All database volumes and backups are encrypted at rest using industry-standard AES-256 encryption.
Strict multi-tenant isolation ensures data from one workspace can never be queried or accessed by another tenant. Granular role permissions restrict agent capabilities.
Inbound Meta webhooks are cryptographically authenticated using HMAC-SHA256 signatures with secret verification tokens to block spoofed payloads.
JWT access tokens have short lifespans and system user credentials can be revoked immediately from the workspace settings panel.
Your Rights (GDPR, CCPA/CPRA & International)
Under applicable data privacy laws, workspace users and WhatsApp end-customers have defined statutory rights:
- Right of Access: Request an export of personal data and conversation logs held in your workspace.
- Right to Rectification: Update inaccurate contact records, names, or phone numbers.
- Right to Erasure: Delete specific contact records, message logs, or entire workspaces.
- Right to Restrict Processing: Request suspension of automated campaigns or message processing.
- Non-Discrimination: We will never discriminate against any user for exercising their privacy rights.
Contact Information & Data Protection Officer
If you have questions about this Privacy Policy, your WhatsApp data, or wish to submit a data subject request, please reach out to our team:
© 2026 Bluetick CRM. All rights reserved.