Summary. SeedAPI is a communication platform that helps businesses send messages over WhatsApp and other channels. We process data to operate that service. We do not sell personal data, and we do not use the contents of your business messages for advertising. This policy explains what we collect, why, and the rights you have over it.
SeedAPI ("SeedAPI", "we", "us") is a communication application programming interface (API) platform operated by SeedAPI. SeedAPI enables businesses ("Customers") to send and receive messages across channels including the WhatsApp Business Platform.
For the purposes of data-protection law, SeedAPI acts as a data controller for the account and profile information of our Customers, and as a data processor for the message content and end-user contact data that Customers send through our platform.
This policy applies to the SeedAPI website, dashboard, APIs, SDKs, plugins, and related services (together, the "Services"). It covers two groups of people: our Customers (the businesses who hold SeedAPI accounts) and the end users those Customers communicate with (for example, a store's shoppers who receive a WhatsApp order update).
We use data to: provide and operate the Services; route and deliver messages you send; authenticate accounts and prevent abuse or fraud; provide support; bill for usage; comply with legal obligations; and improve the reliability and performance of the platform. We do not sell personal data, and we do not use the contents of Customer business messages for our own advertising or to train advertising models.
SeedAPI integrates with the WhatsApp Business Platform provided by Meta. When a Customer connects a WhatsApp Business Account through SeedAPI, we receive and process information from Meta necessary to operate that connection, such as the WhatsApp Business Account identifier, phone number identifiers, message templates, and delivery status.
Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, including any limited-use requirements. We use Meta-derived data only to provide and improve the messaging features the Customer has enabled, and not for unrelated purposes. Message delivery over WhatsApp is also subject to Meta's own privacy and data practices.
Where the EU/UK GDPR or similar data-protection laws apply, we rely on one or more of the following legal bases: performance of a contract (to provide the Services you request); legitimate interests (to secure, maintain, and improve the platform); consent (where required, for example certain cookies or marketing); and compliance with legal obligations.
We share data only as needed to run the Services:
All sub-processors are bound by contractual obligations to protect data and to process it only on our instructions. A current list of sub-processors is available on request.
We retain Customer account data for as long as the account is active and as needed to comply with legal, tax, and accounting obligations. Message content and end-user data processed on a Customer's behalf are retained according to the Customer's configuration and our operational needs, and are deleted or anonymised when no longer required. Customers may request deletion as described in Data Deletion.
We use technical and organisational measures appropriate to the risk, including encryption of credentials and access tokens, tenant isolation, access controls, and monitoring. No system is perfectly secure, but we work to protect data against unauthorised access, alteration, and loss, and we maintain processes to respond to suspected incidents.
Depending on your jurisdiction, you may have rights to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing or withdraw consent. Customers can exercise many of these directly in the dashboard; otherwise, contact us using the details below. End users whose data was processed through a Customer's account should contact that Customer (the controller of that data) in the first instance; we will support the Customer in responding.
We may process data in the countries where we and our service providers operate. Where data is transferred across borders, we take steps to ensure an appropriate level of protection consistent with applicable law, such as standard contractual clauses or equivalent safeguards.
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children. If you believe a child's data has been provided to us, contact us and we will take appropriate steps to delete it.
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify Customers. Continued use of the Services after an update constitutes acceptance of the revised policy.
For privacy questions or to exercise your rights, contact our privacy team at privacy@seedapi.io, or write to SeedAPI, [registered address]. If you have a data-protection concern we have not resolved, you may have the right to complain to your local data-protection authority.