Skip to content

Privacy Notice

This notice explains how AvisaFlow handles information for its website, appointment platform, billing, and official WhatsApp integration.

Last updated: August 7, 2026

AvisaFlow does not sell personal information. Businesses retain ownership and control of their WhatsApp Business Account, number, templates, and customer relationships.

1. Controller and contact

AvisaFlow is responsible for personal information collected through www.avisaflow.com and the AvisaFlow platform. Contact us at hola@avisaflow.com for privacy questions or rights requests.

2. Our role and the business customer's role

AvisaFlow acts as controller for account, subscription, security, support, and website data. For information a business enters about its clients, the business is normally the controller and AvisaFlow acts as its processor or service provider. Businesses are responsible for providing notices and obtaining any consent required by law.

3. Information we process

  • Identity and account data, including name, email, business name, role, and account dates.
  • Contact and locale data, including phone number, country, time zone, and business address.
  • Subscription and tax data, including plan, invoices, tax identifiers, and billing status.
  • Appointment and customer data entered by a business, including contact details, bookings, notes, payments, files, and communications.
  • Technical and security data, including IP address, browser, device, session, audit logs, and error records.
  • Support communications and information voluntarily supplied to resolve a request.
  • Meta and WhatsApp identifiers, configuration, message metadata, and encrypted credentials described below.

Payment card details are collected and processed by Stripe. AvisaFlow does not store full card numbers, card verification codes, or full payment credentials.

4. Sources of information

We receive information from account holders, authorized team members, end customers who use a booking page, Stripe, Meta and WhatsApp, support interactions, and the devices used to access the service. We process only information relevant to providing, securing, and improving AvisaFlow or complying with legal obligations.

5. Purposes of processing

  • Create, authenticate, and administer accounts and business workspaces.
  • Operate appointment, customer, payment, document, reporting, and staff features.
  • Process subscriptions and provide billing records through Stripe.
  • Connect a business to the official WhatsApp Cloud API through Meta Embedded Signup.
  • Send approved templates and receive delivery, read, failure, and inbound webhook events.
  • Provide support, service notices, fraud prevention, security, and audit capabilities.
  • Comply with tax, accounting, contractual, regulatory, and legal obligations.
  • Send optional product news or promotions when permitted, with an opt-out option.

6. Legal basis and consent

Depending on the jurisdiction and context, processing relies on performance of a contract, consent, legitimate interests such as security and service improvement, and compliance with legal duties. A business must obtain valid permission before sending WhatsApp messages and must honor requests to stop or limit communications.

7. Meta and WhatsApp Cloud API

AvisaFlow uses Meta Embedded Signup and the official WhatsApp Cloud API. During setup, Meta may provide a WhatsApp Business Account ID, Phone Number ID, display number, verified name, quality rating, and an authorization code. AvisaFlow exchanges the code server-side and stores the resulting access token encrypted. The six-digit two-step verification PIN is used during registration and is not stored.

AvisaFlow processes approved template requests, message identifiers, delivery status, error information, and webhook metadata needed for messaging operations. Webhook signatures are verified before events are accepted. Meta separately processes data under its own terms and privacy policies and bills applicable messaging charges to the business's WhatsApp Business Account.

8. Providers and international transfers

We use service providers only for defined operational purposes, including:

  • Vercel for hosting, application delivery, and related infrastructure.
  • Supabase for database, authentication, and storage services.
  • Stripe for subscription payments, billing, and fraud prevention.
  • Meta and WhatsApp for account onboarding, templates, message delivery, and messaging events.
  • Email and support providers for transactional notices and customer assistance.
  • Professional advisers and authorities when legally required.

These providers may process data outside your country. We use contractual, technical, and organizational safeguards appropriate to the service and applicable law.

9. Retention and deletion

We retain information while an account is active and for a reasonable period afterward when needed for tax, accounting, fraud prevention, security, backups, disputes, or legal claims. When retention is no longer required, information is deleted or irreversibly anonymized. Detailed request instructions are available on our Data deletion page.

10. Security

Measures include TLS in transit, encryption at rest where supported, AES-256-GCM encryption for stored Meta access tokens, role-based access controls, tenant isolation, signed webhook verification, audit logs, backups, and provider review. No system can guarantee absolute security. We notify affected users and authorities when required.

11. Privacy rights

Depending on applicable law, you may request access, correction, deletion, restriction, objection, consent withdrawal, or portability. Email hola@avisaflow.com with enough information to identify the account and request. We may verify identity and authority before responding. Exercising a right does not affect processing already lawfully completed.

12. Sensitive data and children

AvisaFlow is not directed to children under 18. Businesses should not place unnecessary sensitive information in reminders or WhatsApp templates. Medical, financial, government identifier, and similar data should be processed only with a valid legal basis and suitable safeguards. Contact us if information about a child was submitted without authorization.

13. Cookies and similar technologies

We use cookies needed for authentication, session security, and preferences. Optional analytics may be used to understand service performance. Browser controls can restrict cookies, but blocking required cookies may prevent account features from working.

14. Changes and contact

We may update this notice when the service, law, or our providers change. Material changes will be communicated when required. Questions, complaints, and rights requests may be sent to hola@avisaflow.com.