Official Privacy Policy

Privacy Policy

We are committed to protecting your personal data and being transparent about how we collect and use it.

Effective: September 1, 2025 Last Updated: September 4, 2026 Global Application

Overview

EasyManage ("we", "our", "us") operates a business management platform that integrates AI assistance, WhatsApp Business API messaging, email communication, and a REST API for mobile and third-party integrations.

This Privacy Policy explains what personal data we collect, why we collect it, how it is stored and protected, and your rights as a user or end-customer interacting with businesses that use our platform.

This policy applies to all users of the platform — company owners, employees, clients, suppliers, and individuals who interact via WhatsApp or API channels.

Data We Collect

CategoryExamplesPurpose
IdentityFull name, profile photo, national ID (optional)Account creation, employee cards
ContactEmail address, phone numberLogin, WhatsApp verification, notifications
Usage DataLogin timestamps, IP address, device info, session tokensSecurity, audit trails, 2FA
MessagingChat messages, file attachments, conversation historyInternal messaging, AI chat, WhatsApp routing
WhatsAppPhone number, messages sent/received, session tokensWhatsApp Business integration
AI InteractionsChat prompts, uploaded files, AI responses, audioAI assistant functionality
Business DataCompany name, subscription, invoices, production recordsPlatform service delivery
API TokensSanctum tokens, API keysMobile app & third-party access

WhatsApp Business API Integration

Our platform integrates with the WhatsApp Business API (via Meta/Facebook) to allow businesses to communicate with their customers and employees through WhatsApp.

What We Process via WhatsApp

  • Incoming and outgoing WhatsApp messages (text, audio, images, documents)
  • Sender phone numbers and WhatsApp profile names
  • Routing decisions based on your configured workflow
  • Session state and conversation history per user
  • Verification tokens exchanged during webhook handshake

How It Works

Each company configures its own WhatsApp Phone Number, Access Token, and Webhook on Meta's Developer Console. Incoming messages are routed to our webhook endpoint (/api/v1/whatsapp/webhook?company=...) using signature verification (App Secret). Messages may be processed by our AI assistant if the user is routed to the AI agent node.

WhatsApp conversation data is stored per company and is subject to Meta's own WhatsApp Privacy Policy and the Meta Platform Terms.

Data Retention for WhatsApp

WhatsApp messages are retained for as long as the company account is active or until explicitly deleted by a company administrator. Debug webhook logs are temporary and can be cleared from the admin panel at any time.

AI Assistant

Our platform includes an AI-powered assistant (powered by Google Gemini models and optionally OpenAI TTS) available via the web dashboard, mobile API, and WhatsApp channel.

What the AI Processes

  • Text messages and prompts you send to the assistant
  • Images, documents, and voice files you upload
  • Chat history for context continuity within a session
  • Generated audio responses (when TTS is enabled)
  • Business-specific context (company name, user role, etc.)

Third-Party AI Providers

Your prompts may be transmitted to Google's Gemini API or OpenAI's API for processing. These providers have their own privacy policies that govern data handling:

We use API-based access to these services. We do not sell your prompts or AI interactions. Sensitive business data sent to the AI is subject to the data processing agreements of the respective providers.

AI Logs

AI interaction logs are available to company administrators for debugging. These logs can be viewed and cleared from the AI Settings panel at any time.

Email Communication

We use email for the following purposes within the platform:

  • Transactional emails: Account registration, password resets, subscription confirmations, and invoices.
  • Internal messaging notifications: When a user receives an internal message or conversation invite.
  • Mail Client module: If your company uses our integrated mail client, emails sent and received are processed through your configured IMAP/SMTP server. We do not store the content of those emails on our servers beyond your session.
  • Email Content templates: Reusable email templates created by company administrators are stored and associated with the company account.
We do not send marketing emails without your explicit consent. All transactional emails include an unsubscribe option where legally required.

REST API & Mobile Access

Our platform exposes a REST API (/api/v1/...) secured via Laravel Sanctum tokens for mobile applications and authorized third-party integrations.

API Data Handling

  • API tokens are issued per user and scoped to their permissions
  • All API requests are authenticated and logged for security auditing
  • Tokens can be revoked at any time from the Security Settings page
  • API access must be explicitly granted by a company administrator

Public Endpoints

A small number of endpoints are publicly accessible without authentication (e.g., scanner device configuration by token, WhatsApp webhook). These are designed with minimal data exposure and are protected by other security mechanisms (signed tokens, HMAC signatures).

If you suspect an API token has been compromised, revoke it immediately from your Security Settings dashboard.

Security Measures

We implement industry-standard security measures to protect your personal data:

  • Encryption at rest: Sensitive credentials (WhatsApp access tokens, app secrets, API keys) are encrypted before storage.
  • HTTPS/TLS: All data in transit is encrypted using SSL/TLS.
  • Two-Factor Authentication (2FA): Supported via TOTP for all user accounts.
  • Device session management: Users can view and revoke active sessions from any device.
  • Webhook signature verification: All incoming WhatsApp webhook payloads are verified using HMAC-SHA256.
  • Role-based access control: All features are permission-gated based on user roles and group assignments.

Cookies & Session Data

We use the following cookies and browser storage mechanisms:

CookieTypePurpose
laravel_sessionEssentialMaintains your authenticated session
XSRF-TOKENEssentialCSRF protection for all form submissions
localePreferenceStores your chosen language (En/Fr/Ar)
darkmodePreferenceStores your UI theme preference
remember_*Functional"Remember me" login persistence

We do not use advertising or tracking cookies.

Third-Party Services

Our platform integrates with the following third-party services. Each is subject to its own privacy policy:

ServicePurposeData Shared
Meta / WhatsApp Business APIWhatsApp messagingPhone numbers, messages, webhook payloads
Google Gemini APIAI text generationUser prompts, uploaded files
OpenAI APIText-to-speech (TTS)AI-generated text for voice conversion
PayPal / StripePayment processingTransaction amounts, billing info (handled by provider)
Google Fonts / CDNUI assetsBrowser IP (standard CDN request)

Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right of Rectification: Correct inaccurate or incomplete data from your profile settings.
  • Right of Erasure: Request deletion of your account and associated personal data.
  • Right to Restrict Processing: Ask us to limit how we use your data.
  • Right to Data Portability: Receive your data in a portable, machine-readable format.
  • Right to Object: Object to certain types of processing, including automated decision-making.
  • WhatsApp Data Reset: Company administrators can reset WhatsApp session data for individual users from the user management panel.
To exercise any of these rights, contact your company administrator or reach out to us directly at the contact details below.

Data Retention

We retain personal data for as long as necessary to provide the service and comply with legal obligations:

  • Account data: Retained while the account is active. Deleted within 30 days of account closure request.
  • WhatsApp messages: Retained as long as the company account is active unless deleted by the administrator.
  • AI chat history: Retained per session. Administrators can clear AI logs at any time.
  • Webhook debug logs: Temporary — cleared on demand or automatically after 30 days.
  • Payment records: Retained for 7 years as required by financial regulations.
  • Security & audit logs: Retained for 90 days.

Contact & Data Controller

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

We will respond to all legitimate requests within 30 days. For complex requests, we may need up to 90 days, in which case we will notify you of the extension.

This Privacy Policy may be updated periodically. Material changes will be communicated via email or a notice within the platform dashboard.