1. Platform Overview & Data Roles
FastDesk Inc. (βFastDeskβ, βweβ, βourβ, or βusβ) operates a high-performance multi-tenant Software-as-a-Service (SaaS) infrastructure designed for integrating, processing, and routing data between Meta WhatsApp Cloud API (WhatsApp Business Accounts / WABA), customer enterprise software, and artificial intelligence models.
To ensure legal transparency under global privacy frameworks including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA/CPRA), and Meta Platform Terms:
- Business Tenants (Data Controllers): Independent businesses (e.g., Business A, Business B, Business C) that deploy FastDesk to connect their Meta WhatsApp Business Accounts (WABA) act as the primary Data Controllers for end-user communications.
- FastDesk Platform (Data Processor / Service Provider): FastDesk acts as a Data Processor, ingesting webhooks via our central endpoint, resolving business tenant boundaries, and executing automated workflows strictly in accordance with tenant instructions.
- Meta Platforms, Inc. (Channel Provider): End-user messages originalize on Meta's WhatsApp network and transit through Meta Cloud API servers (`graph.facebook.com`).
2. Data We Collect and Process
FastDesk processes categories of data strictly required to execute real-time WhatsApp message routing, tenant authorization, AI analysis, and CRM sync.
| Data Category | Specific Data Elements | Primary Purpose |
|---|---|---|
| WhatsApp End-User Data | Phone number, WhatsApp Display Name (`profile.name`), WhatsApp Message ID (`wamid`), message content (text, audio, media, documents), timestamps, delivery statuses (`sent`, `delivered`, `read`), reaction events. | Routing messages, rendering conversation logs, feeding AI responses, and updating CRM ticket records. |
| Business Tenant Credentials | Meta Business Manager ID, WABA ID, Phone Number ID, encrypted System User Access Tokens (`WHATSAPP_ACCESS_TOKEN`), Webhook Verification Tokens (`hub.verify_token`). | Authenticating outbound Graph API requests and verifying inbound Meta webhook challenges. |
| Technical & Telemetry Data | IP addresses, HTTP headers (`X-Hub-Signature-256`), request payload size, API execution latency, webhook event type, error diagnostic logs. | Webhook security verification, rate limiting, system debugging, and fraud prevention. |
| Tenant Admin Data | Business contact email, tenant account settings, API keys, webhook subscription preferences. | Managing SaaS subscription accounts, access control, and sending operational notifications. |
3. Multi-Tenant Architecture & Data Flow
Our processing pipeline maps explicitly to our operational business model. Below is the step-by-step breakdown of how user data transits through FastDesk:
- Ingestion via FastDesk Webhook: When a WhatsApp user messages Business A, Business B, or Business C, Meta Cloud API dispatches an encrypted HTTP POST webhook to FastDesk's centralized endpoint (`https://api.fastdesk.in/webhook/whatsapp`).
- Tenant Resolver Isolation: Upon receipt, the FastDesk Tenant Resolver inspects the incoming payload's Meta `phone_number_id` and WABA metadata. It deterministically resolves the exact business tenant context to ensure complete data separation between Business A, Business B, and Business C.
- CRM Synchronization: Resolved customer interactions (contact numbers, conversation history, delivery receipts) are dispatched to the tenant's designated Customer Relationship Management (CRM) system (e.g., Salesforce, HubSpot, or custom enterprise DBs).
- AI & Automation Engine Processing: Where enabled by the business tenant, message content is routed to AI engines (natural language processing, intent models, automated customer support agents) to generate real-time automated responses or assist human agents.
- Business Tools & Meta API Dispatch: Formulated replies or triggered workflow actions are sent back through Meta's WhatsApp Cloud API endpoint to reach the end-user's WhatsApp client.
4. How We Use User Data
FastDesk uses collected data exclusively to operate, maintain, and provide the multi-tenant SaaS messaging services described in this policy. Specific use cases include:
- Executing Real-Time Messaging: Transporting incoming WhatsApp messages to business dashboards, CRMs, and connected business tools.
- Automated AI Processing: Providing context to tenant-configured AI assistants to generate relevant customer support answers.
- Meta Webhook Verification: Handling Meta Graph API verification challenges (`hub.challenge` and `hub.verify_token`) to establish valid webhook subscriptions.
- Security & Integrity: Validating `X-Hub-Signature-256` HMAC signatures on every incoming POST payload to prevent unauthorized spoofing.
- Analytics & Performance Monitoring: Aggregating non-identifying telemetry metrics (message delivery rates, server response times) to maintain system availability.
5. Data Disclosure & Third-Party Services
FastDesk dispatches data to trusted third-party service providers only when strictly necessary to fulfill our service commitments to business tenants:
- Meta Platforms, Inc. (WhatsApp Cloud API): All outbound messages and WABA status queries pass through Meta infrastructure. Use of WhatsApp is governed by Meta's WhatsApp Business Terms and WhatsApp Developer Policies.
- AI Model Providers: If a tenant configures AI automation (e.g., OpenAI, Anthropic, Google Cloud Vertex AI), relevant conversation prompts are transmitted to the provider via secure APIs solely for generation. FastDesk configures zero-retention / non-training parameters wherever supported.
- Tenant-Selected CRM & Helpdesk Integrations: Data is shared with external CRM and ERP tools selected and authorized explicitly by each business tenant.
- Cloud Hosting Infrastructure: Cloud infrastructure providers hosting FastDesk servers (e.g., AWS, Vercel, GCP) process encrypted data solely under strict data processing addendums (DPAs).
- Legal Compliance & Protection: We may disclose data if required by law, subpoena, or court order, or to defend against legal claims or security breaches.
6. Meta Cloud API Compliance & Webhook Security
FastDesk is specifically architected to comply with Meta Developer Standards for WhatsApp Business Cloud API App Review:
- Meta Webhook Challenge Handling: Our backend implements full compliant logic for `GET` verification requests, validating `hub.verify_token` against secure tenant configuration and returning `hub.challenge` with `HTTP 200 OK`.
- HMAC SHA-256 Signature Verification: Every incoming `POST` payload is verified against Meta's payload signature (`X-Hub-Signature-256`) using the tenant's Meta App Secret before processing.
- Token Protection Guarantee: Meta WhatsApp Access Tokens (`WHATSAPP_ACCESS_TOKEN`) are stored using AES-256 encryption at rest and environment secret isolation.
7. Multi-Tenant Data Isolation & Security Safeguards
Because FastDesk serves multiple independent business tenants (Business A, Business B, Business C), security and isolation are paramount:
- Schema & Logical Tenant Isolation: Data associated with Business A is strictly isolated from Business B and Business C at database, memory, and cache levels via tenant-keyed schemas and lookup keys.
- Encryption in Transit: All HTTP traffic into FastDesk (webhooks) and out of FastDesk (CRM/AI APIs) is encrypted using TLS 1.3/1.2 protocols.
- Encryption at Rest: Database records, WABA access tokens, and persistent message logs are encrypted using industry-standard AES-256 algorithms.
8. Data Retention & Deletion Mechanisms
We retain personal data only for as long as necessary to fulfill the operational purposes set forth by business tenants:
- Webhook Event Logs: Raw webhook diagnostic logs are automatically purged after 30 days.
- Tenant Account Termination: Upon termination of a business tenant's subscription, all associated WhatsApp tokens, CRM maps, and conversation logs are permanently deleted within 30 days.
- Right to be Forgotten (Deletion Requests): End-users wishing to delete their data stored in FastDesk can submit erasure requests directly to the relevant Business Tenant (Data Controller) or by contacting our Data Protection Officer.
9. End-User Data Rights & Tenant Responsibilities
Depending on geographical jurisdiction, end-users communicating with Business Tenants via WhatsApp possess rights regarding their personal data, including the right to access, rectify, port, or request erasure of their personal information.
10. Contact Information & Data Protection Officer
If you have questions, concerns, or requests regarding this Privacy Policy or FastDesk's data governance practices, please reach out to our privacy team:
FastDesk Privacy & Data Governance Office
π§ Data Protection Officer: dpo@fastdesk.in
βοΈ General Privacy Inquiries: privacy@fastdesk.in
π Webhook Verification & API Endpoint: https://api.fastdesk.in/webhook/whatsapp