Legal

Privacy Policy

Last updated: 10 July 2026 · Effective: 10 July 2026

Summary. SeedAPI is a communication platform that helps businesses send messages over WhatsApp and other channels. We process data to operate that service. We do not sell personal data, and we do not use the contents of your business messages for advertising. This policy explains what we collect, why, and the rights you have over it.

1. Who we are

SeedAPI ("SeedAPI", "we", "us") is a communication application programming interface (API) platform operated by SeedAPI. SeedAPI enables businesses ("Customers") to send and receive messages across channels including the WhatsApp Business Platform.

For the purposes of data-protection law, SeedAPI acts as a data controller for the account and profile information of our Customers, and as a data processor for the message content and end-user contact data that Customers send through our platform.

2. Scope of this policy

This policy applies to the SeedAPI website, dashboard, APIs, SDKs, plugins, and related services (together, the "Services"). It covers two groups of people: our Customers (the businesses who hold SeedAPI accounts) and the end users those Customers communicate with (for example, a store's shoppers who receive a WhatsApp order update).

3. Data we collect

3.1 Customer account data

  • Identity and contact details: name, business name, email address, phone number.
  • Account credentials and authentication data.
  • Billing information: billing address, tax identifiers, and payment method details (processed by our payment providers; we do not store full card numbers).
  • Business verification documents you provide for WhatsApp onboarding (e.g. certificate of incorporation, address proof).

3.2 End-user / message data (processed on the Customer's behalf)

  • Recipient phone numbers and contact identifiers.
  • Message content, templates, and media that Customers send or receive.
  • Delivery, read, and interaction status returned by the messaging channel.

3.3 Technical & usage data

  • Log data: IP address, device and browser information, timestamps, API request metadata.
  • Usage analytics about how the dashboard and APIs are used.
  • Cookies and similar technologies used to keep you signed in and to understand product usage. You can control cookies through your browser settings.

4. How we use data

We use data to: provide and operate the Services; route and deliver messages you send; authenticate accounts and prevent abuse or fraud; provide support; bill for usage; comply with legal obligations; and improve the reliability and performance of the platform. We do not sell personal data, and we do not use the contents of Customer business messages for our own advertising or to train advertising models.

5. WhatsApp & Meta Platform data

SeedAPI integrates with the WhatsApp Business Platform provided by Meta. When a Customer connects a WhatsApp Business Account through SeedAPI, we receive and process information from Meta necessary to operate that connection, such as the WhatsApp Business Account identifier, phone number identifiers, message templates, and delivery status.

Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, including any limited-use requirements. We use Meta-derived data only to provide and improve the messaging features the Customer has enabled, and not for unrelated purposes. Message delivery over WhatsApp is also subject to Meta's own privacy and data practices.

Where the EU/UK GDPR or similar data-protection laws apply, we rely on one or more of the following legal bases: performance of a contract (to provide the Services you request); legitimate interests (to secure, maintain, and improve the platform); consent (where required, for example certain cookies or marketing); and compliance with legal obligations.

7. Sharing & sub-processors

We share data only as needed to run the Services:

  • Messaging providers such as Meta (WhatsApp) and, in future, SMS and email providers, to deliver your messages.
  • Infrastructure and hosting providers that store and process data on our behalf under contract.
  • Payment processors for billing.
  • Professional advisers and authorities where required by law.

All sub-processors are bound by contractual obligations to protect data and to process it only on our instructions. A current list of sub-processors is available on request.

8. Data retention

We retain Customer account data for as long as the account is active and as needed to comply with legal, tax, and accounting obligations. Message content and end-user data processed on a Customer's behalf are retained according to the Customer's configuration and our operational needs, and are deleted or anonymised when no longer required. Customers may request deletion as described in Data Deletion.

9. Security

We use technical and organisational measures appropriate to the risk, including encryption of credentials and access tokens, tenant isolation, access controls, and monitoring. No system is perfectly secure, but we work to protect data against unauthorised access, alteration, and loss, and we maintain processes to respond to suspected incidents.

10. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing or withdraw consent. Customers can exercise many of these directly in the dashboard; otherwise, contact us using the details below. End users whose data was processed through a Customer's account should contact that Customer (the controller of that data) in the first instance; we will support the Customer in responding.

11. International transfers

We may process data in the countries where we and our service providers operate. Where data is transferred across borders, we take steps to ensure an appropriate level of protection consistent with applicable law, such as standard contractual clauses or equivalent safeguards.

12. Children

The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children. If you believe a child's data has been provided to us, contact us and we will take appropriate steps to delete it.

13. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify Customers. Continued use of the Services after an update constitutes acceptance of the revised policy.

14. Contact us

For privacy questions or to exercise your rights, contact our privacy team at privacy@seedapi.io, or write to SeedAPI, [registered address]. If you have a data-protection concern we have not resolved, you may have the right to complain to your local data-protection authority.