AIPaths Connect

Privacy Policy

Last updated: 26 August 2026

This policy explains what AIPaths Connect collects when you connect your WhatsApp Business Account, why we collect it, and what you can do about it.

Who we are

AIPaths Connect is operated by AIPATHS LTD, a company registered in England and Wales. You can reach us about anything in this policy at platform@aipaths.academy.

What we collect

  • Account data: the email address and password hash of each user, and the business name of the workspace.
  • WhatsApp Business Account data: the account identifier, phone number identifiers, display names and quality ratings that Meta returns when you connect your account.
  • Access credentials: the business access token Meta issues for your account, always encrypted before it is stored.
  • Message data: the content, direction, timestamps and delivery status of the messages your agent sends and receives on the connected number.
  • Activity records: an audit log of security-relevant actions, such as connecting an account or changing your agent.

How we use it

We use this data to run the service you asked for: connecting your WhatsApp Business Account, generating replies with the agent you configured, sending and receiving messages on your behalf, and managing your message templates.

We do not sell your data, we do not use it for advertising, and we do not use the content of your conversations to train models.

AI processing

To generate replies, the content of a conversation is processed by a large language model provider acting as our processor under contract. That provider does not use your data to train its models and retains it only as long as needed to return a response.

You can disable the agent at any time, which stops all such processing for your account.

Platform Data from Meta

Data we obtain through the WhatsApp Business Platform is used only to provide the features you enabled, under the permissions you granted. We request only the two permissions the product needs: whatsapp_business_messaging and whatsapp_business_management.

You can revoke our access at any time from your Meta Business settings. When access is revoked we stop processing and delete the associated credentials.

How we protect it

  • All data is encrypted in transit using TLS 1.2 or higher.
  • Access tokens are encrypted at rest with AES-256-GCM, on top of full-disk encryption of the database.
  • Each workspace is isolated at the database level, so one customer cannot read another customer data.
  • Administrative access requires multi-factor authentication and is reviewed at least annually.
  • Security-relevant application logs are reviewed at least weekly.

How long we keep it

Account and configuration data is kept while your workspace is active. Message records are kept for as long as you need them to review your conversations, and are deleted with your workspace.

When you delete your workspace we delete your data within 30 days, except where we are required by law to keep a record.

Your rights

If you are in the United Kingdom or the European Economic Area you have the right to access, correct, export, restrict or delete your personal data, and to object to processing. Write to us and we will respond within one month.

Instructions to delete your data are on our data deletion page.

Changes to this policy

If we change this policy we will update the date at the top of this page and, for material changes, notify you by email before the change takes effect.