Privacy Policy
Last updated: 21 August 2026
This policy explains how Finest Solutions LLC (“we”, “us”) processes personal data in the Finest Solutions WhatsApp Connector (the “Connector”), the software that connects a client business’s WhatsApp Business account to the CRM portal we operate for them.
1. Who we are
Finest Solutions LLCSharjah Media City, Al Messaned 515000
United Arab Emirates
Licence no. 2221792.01
Email: contact@finest-solutions.com
2. What the Connector is, and our role
Finest Solutions builds and operates CRM portals for business clients. The Connector is the component that lets each client link their own WhatsApp Business account to their own portal, so their staff can send and receive WhatsApp messages from inside the portal they already use.
A client authorises this themselves through Meta’s Embedded Signup flow. We never take control of a client’s WhatsApp account without that authorisation, and a client can revoke it at any time from Meta Business Manager.
This distinction matters for your rights:
- The client business is the controller of the messages it exchanges with its own customers, and of the contact details it holds for them. It decides who to message and why.
- We are a processor acting on that client’s instructions when we transmit, receive and store those messages on their behalf.
- We are the controller only for the limited operational data described in section 4 — the connection records and logs we need to run the service.
If you were messaged by a business using one of our portals and want your data corrected or erased, the fastest route is to contact that business directly. You may also contact us at the address above and we will pass the request to them without delay, and act on it ourselves where we are able.
3. Data we process on behalf of client businesses
- Message content — the text and media of WhatsApp messages sent and received through the client’s connected number.
- Phone numbers of the client’s correspondents, and the WhatsApp profile name where WhatsApp supplies it.
- Message metadata — timestamps, direction, and delivery or read status.
This data is stored in the client’s own portal database, kept separate from every other client’s data, and is not combined across clients.
4. Data we process as controller
- Connection records — the client’s WhatsApp Business Account ID, phone number ID, display number and verified business name, plus an access token, which is encrypted at rest.
- Administrator identity — which portal administrator performed the connection, and when.
- Operational logs — records of delivery attempts, failures and webhook events, kept so the service can be supported and audited.
5. What we do not do
- We do not sell personal data.
- We do not use message content for advertising, profiling or automated decision-making.
- We do not use one client’s data for another client’s purposes.
- We do not use message content to train machine-learning models.
- We do not send marketing messages of our own to a client’s contacts.
6. Meta and WhatsApp
Messages are delivered over the WhatsApp Business Platform, provided by Meta Platforms, Inc. When a message is sent or received, the phone number and message content pass through Meta’s infrastructure so it can be delivered. Meta processes that data as an independent controller under its own terms — see the WhatsApp Privacy Policy.
The Connector requests only the permissions it needs to do this: whatsapp_business_management, to complete onboarding and read the connected account’s configuration, and whatsapp_business_messaging, to send and receive messages on the client’s behalf.
Some clients operate the connected number alongside the WhatsApp Business app on a phone (Meta’s “Coexistence” mode). Where that applies, messages sent from the phone and messages sent from the portal form a single conversation history.
7. Who else we share data with
- Meta, for message delivery, as described above.
- Hosting and database providers acting on our instructions under written terms, to run the portals and this service.
- Authorities, where we are legally required to disclose.
We do not share client data with other clients, and we do not share it with advertisers or data brokers.
8. International transfers
We are established in the United Arab Emirates, which is outside the European Economic Area and is not currently the subject of a European Commission adequacy decision. Where we process the personal data of people in the EEA, that data is therefore transferred outside the EEA to us. We rely on appropriate safeguards for those transfers, including the European Commission’s Standard Contractual Clauses, and we apply the protections in this policy regardless of where data is held.
Delivering a WhatsApp message additionally involves transferring data to Meta, which may process it outside the EEA under its own safeguards. A copy of the safeguards we rely on can be requested at contact@finest-solutions.com.
9. Retention
Connection records are kept for as long as the client’s WhatsApp account remains connected. When a client disconnects, we delete the stored access token and the connection record.
Message history is retained in the client’s portal for as long as that client requires it, under their retention policy, and is deleted when their portal is decommissioned or on their instruction.
Operational logs are kept for up to 12 months.
10. Your rights
Where the GDPR applies, you have the right to request access to your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, and to data portability.
To exercise these rights, contact contact@finest-solutions.com. We respond within one month. Where the data belongs to a client business as controller, we will forward your request to them and support them in answering it.
Instructions specific to deleting WhatsApp data held through the Connector are on our Data deletion page.
You also have the right to lodge a complaint with a data protection supervisory authority in the country where you live or work.
11. How you can stop receiving messages
If a business is contacting you on WhatsApp through one of our portals and you do not want to be contacted again, simply reply to the conversation and say so — for example, “STOP”. The request is honoured on the business’s side and no further messages will be sent to your number. You do not need to send an email or fill in a form.
You can also block the number in WhatsApp itself, which stops delivery regardless of what the sender does.
12. Security
Access tokens are encrypted at rest. Inbound webhook requests from Meta are verified by HMAC signature before being processed, so events that do not genuinely originate from Meta are rejected. Portal access requires an individual account with role-based permissions, passwords are stored only as salted hashes, and significant actions are recorded in an audit trail. Each client’s data is isolated from every other client’s.
13. Changes to this policy
We may update this policy as the service changes. The date at the top shows when it was last revised.
14. Contact
Questions about this policy, or about data we hold: contact@finest-solutions.com.
This document describes our current data processing practices. It is not legal advice and should be reviewed by a qualified adviser before being relied upon.