This prototype is limited to a designated test group. It is not intended for real customer, shop, or prospect conversations.
Who is responsible
Cauza Labs operates this supervised WhatsApp shared-inbox prototype. Privacy questions and deletion requests may be sent to support@cauzalabs.com.
What the prototype processes
When a designated participant sends a message to the test business number, Meta and WhatsApp transport the message and related delivery information to the prototype's authenticated webhook. The received data may include message content, WhatsApp identifiers, timestamps, message or event identifiers, and delivery status.
Ignored, unsupported, or unadmitted messages may still be transported by Meta and received at the webhook boundary. Ignoring a message is not the same as never processing it.
How the data is used
The prototype uses test data to authenticate and normalize provider events, detect duplicates, admit an eligible event into the shared inbox, display a conversation to designated operators, exercise AI and human ownership, and test controlled replies and handoffs.
Webhook authentication establishes that the received bytes match the configured signature. It does not establish that message content is true, admit it into the application, or authorize an ownership change or reply.
AI and human participation
The prototype may use an AI assistant for disclosed initial intake and routing. Designated human operators may claim and handle conversations. The interface and customer-visible messages are intended to distinguish AI participation from human participation. Internal notes and mentions are not intended for the WhatsApp participant.
Service categories
The prototype relies on messaging transport supplied by Meta and WhatsApp, temporary secure request forwarding during controlled development tests, and limited operational monitoring. These services may process technical and message data necessary to provide their function under their own terms and policies.
Retention
- Raw webhook bodies are kept only in request-scoped process memory and are not intentionally written to ordinary logs or durable storage.
- Admitted test conversations are retained only for the active development round, for no more than 30 days.
- Redacted operational receipts are retained for no more than 14 days.
- Other evidence derived from live tests is deleted within seven days after the corresponding test round is reviewed.
- Synthetic fixtures that contain no participant data may be retained for regression testing.
Transport providers may retain delivery, security, or operational information according to their own systems and policies. Cauza Labs cannot directly erase copies controlled solely by Meta, WhatsApp, a participant's device, or another provider.
Operational safeguards
Operational receipts use a limited field allowlist and exclude message bodies, names, phone numbers, access tokens, signatures, full request headers, and private endpoints. The prototype does not enable public-site analytics or external log export under this development policy.
Your choices
Designated participants may ask what prototype data Cauza Labs controls, request correction, or request deletion by following the data-deletion instructions. Some requests may depend on identity verification or on a provider's separate controls.
Changes
This policy may be updated as the prototype changes. Material changes will be reflected on this page with a revised effective date. This policy describes current approved prototype behavior and is not a representation of general production availability or legal certification.