Summary (Plain Language)
MegaSend is a B2B WhatsApp Business messaging platform operated by Weblix Global Technologies LLC. We collect the minimum personal data necessary to provide our service, never sell your data, and never use it for cross-context advertising.
We act as a Data Processor for our business customers (handling messages they send to their recipients) and as a Data Controller for our own users (account holders, billing contacts, website visitors).
You have rights over your personal data — access, correction, deletion, portability, objection, and more — depending on where you live. To exercise any right, email [email protected] and we will respond within the legally required timeframe.
This summary is for convenience only. The full policy below is the legally binding document.
Weblix Global Technologies LLC ("Weblix", "MegaSend", "we", "our", or "us") operates the MegaSend platform — a Software-as-a-Service product that integrates with the official WhatsApp Business Solution API offered by Meta Platforms, Inc., enabling our business customers to communicate with their own customers and contacts at scale.
This Privacy Policy describes how we collect, use, disclose, store, transfer, and protect Personal Data when you (a) visit our website or marketing pages; (b) register for, access, or use the MegaSend platform; (c) communicate with us via email, support channels, or social media; or (d) are a recipient of messages sent through our platform by one of our business customers.
We act in two distinct capacities depending on the relationship: (i) as a "Controller" (under the EU/UK GDPR) or "Business" (under the CCPA/CPRA) for Personal Data of our Customers, account administrators, billing contacts, prospects, and website visitors — meaning we determine the purposes and means of processing; and (ii) as a "Processor" (under the GDPR) or "Service Provider" (under the CCPA/CPRA) for Personal Data of our Customers' end users (message recipients, contact lists they upload, conversations they conduct), where our Customer is the Controller and we process such data only on documented instructions pursuant to a Data Processing Agreement.
By accessing, registering for, or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Policy, you must not use the Service. If you are using the Service on behalf of an organization, you represent that you have authority to bind that organization to this Policy.
Key Definitions
- "Personal Data" / "Personal Information" — any information relating to an identified or identifiable natural person, as defined under the GDPR, CCPA/CPRA, the Israeli Privacy Protection Law 5741-1981, and equivalent laws.
- "Processing" — any operation performed on Personal Data, including collection, recording, storage, access, use, disclosure, transmission, alignment, restriction, erasure, or destruction.
- "Controller" / "Business" — the entity that determines the purposes and means of Processing.
- "Processor" / "Service Provider" — the entity that Processes Personal Data on behalf of the Controller, under documented instructions.
- "Customer" — a business or individual who has registered for and uses the MegaSend platform (the account holder).
- "End User" / "Message Recipient" — a natural person whose phone number, name, or other identifier appears in a Customer's contact list and who exchanges WhatsApp messages with the Customer through our platform.
- "Service" — the MegaSend platform, including the website, dashboard, APIs, mobile interfaces, AI assistant features, campaigns, flows, and all related functionality.
- "Sub-processor" — a third party engaged by Weblix to Process Personal Data on our behalf in connection with delivering the Service.
Personal Data We Collect
We collect Personal Data in three ways: (a) information you provide directly to us; (b) information we collect automatically through your use of the Service; and (c) information we receive from third parties (such as Meta/WhatsApp, payment processors, and authentication providers).
1. Account & Identity Data
- Full name, business name, job title
- Email address, telephone number, WhatsApp Business phone number
- Authentication credentials (hashed passwords, API keys, OAuth access and refresh tokens, multi-factor authentication tokens)
- Account preferences, language, time zone
- Profile picture or company logo (if uploaded)
2. Billing & Financial Data
- Billing name and address
- VAT/Tax ID, business registration number
- Subscription tier, plan history, invoices, payment history
- Last four digits of payment card and card brand (full card numbers are never stored on our servers — they are tokenized and held by Stripe, our PCI-DSS Level 1 certified payment processor)
- Bank transfer reference details (where applicable)
3. Customer Content (Processed on Behalf of Customers)
- Contact lists uploaded by Customers (recipient phone numbers, names, custom attributes, tags, segmentation data)
- Message content, templates, media files (images, video, audio, documents) sent or received via WhatsApp
- Campaign configurations, automated flows, AI assistant instructions and responses
- Conversation history, message status (sent/delivered/read), timestamps
- Webhook payloads and integration data
4. Technical & Usage Data (Collected Automatically)
- IP address, approximate geolocation derived from IP
- Browser type and version, operating system, device identifiers, screen resolution
- Pages visited, features used, click events, session duration, referrer URL
- Diagnostic logs, error reports, performance metrics
- Cookies and similar tracking technologies (see the Cookies section)
- Login times, session tokens, IP addresses of API calls
5. Support & Communications Data
- Records of correspondence with our support, sales, or compliance teams
- Chat transcripts, screenshots, voluntary feedback, survey responses
- Information you provide when reporting bugs or abuse
6. Marketing Data (Where Lawful)
- Email engagement metrics (opens, clicks) for our own newsletters
- Webinar attendance, downloaded resources, demo requests
- UTM parameters and marketing attribution data
We do not knowingly collect Special Categories of Personal Data (under GDPR Article 9) or Sensitive Personal Information (under the CCPA/CPRA) — such as racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning a person's sex life or sexual orientation — and we instruct Customers not to upload, transmit, or process such data through the Service unless they have a valid legal basis and have notified us in advance to enter a supplementary agreement.
We do not knowingly collect Personal Data from individuals under 16 years of age (or the higher minimum age applicable in your jurisdiction). See the Children's Privacy section.
Legal Bases for Processing (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we process your Personal Data only when one or more of the following legal bases (Article 6) is satisfied:
- Performance of a contract (Art. 6(1)(b)) — when Processing is necessary to provide the Service you signed up for, including account creation, authentication, message delivery, billing, and customer support.
- Consent (Art. 6(1)(a)) — for non-essential cookies, marketing communications, and any other Processing that is not strictly necessary. You may withdraw consent at any time without affecting prior Processing.
- Legitimate interests (Art. 6(1)(f)) — for service improvement, security, fraud and abuse prevention, internal analytics, network and information security, direct B2B marketing to existing customers, and exercising or defending legal claims. We balance our interests against your rights and freedoms.
- Compliance with a legal obligation (Art. 6(1)(c)) — for tax records, anti-money-laundering checks, sanctions screening, lawful disclosures to authorities, retention of accounting records, and responses to valid legal process.
- Vital interests (Art. 6(1)(d)) — in rare emergencies where Processing is necessary to protect the life or safety of a natural person.
- Public interest or official authority (Art. 6(1)(e)) — only where specifically required by applicable law.
Where Processing is based on consent, you may withdraw it at any time by emailing [email protected] or by using in-product controls. Withdrawal does not affect the lawfulness of Processing carried out before the withdrawal.
How We Use Personal Data
We use Personal Data for the purposes listed below. The specific legal basis for each purpose is indicated in brackets.
- Provide, operate, maintain, and secure the Service; create and authenticate accounts; provision API access; deliver messages through the WhatsApp Business Platform [Contract / Legitimate Interests].
- Process subscriptions, payments, invoices, refunds, taxes, and chargebacks; collect overdue amounts; comply with accounting and tax laws [Contract / Legal Obligation].
- Respond to support requests, troubleshoot issues, communicate service-related notices (security alerts, downtime, policy changes) [Contract / Legitimate Interests].
- Analyze how the Service is used in aggregate, improve features, develop new functionality, and conduct A/B testing [Legitimate Interests / Consent where required].
- Detect, investigate, and prevent fraud, abuse, spam, malware, account takeovers, denial-of-service attacks, and violations of our Terms of Use [Legitimate Interests / Legal Obligation].
- Comply with applicable laws, regulations, court orders, lawful requests from public authorities, sanctions screening, anti-money-laundering, and Meta's WhatsApp Business Solution Terms [Legal Obligation].
- Send marketing communications (only with consent or to existing customers under the soft opt-in rule, where applicable); measure campaign effectiveness [Consent / Legitimate Interests].
- Provide AI-powered features (assistant, suggested replies, automated flows) — see the AI Processing section [Contract / Legitimate Interests].
- Establish, exercise, or defend legal claims; enforce our Terms; protect our rights, property, and the safety of others [Legitimate Interests / Legal Obligation].
We do not sell your Personal Data, do not share your Personal Data for cross-context behavioral advertising, and do not use your Personal Data to train third-party AI models without your explicit instruction.
We will not Process your Personal Data for materially different, unrelated, or incompatible purposes without providing notice and, where required, obtaining your consent.
Automated Decision-Making and Profiling
We do not make decisions that produce legal or similarly significant effects on you based solely on automated processing (within the meaning of GDPR Article 22).
We use limited automated systems for: (i) abuse, fraud, and spam detection (which may temporarily restrict an account pending human review); (ii) AI-generated message suggestions or chatbot replies (always subject to human override by the Customer); (iii) deliverability optimization. Where any automated decision could significantly affect a person's rights, a human reviewer is involved before the decision becomes final.
You have the right to obtain human intervention, express your point of view, and contest a decision. Contact [email protected] to exercise this right.
How We Share Personal Data
We share Personal Data only as described below. We never sell Personal Data and never share it for cross-context behavioral advertising.
Categories of Recipients
- Vetted Sub-processors that provide infrastructure, payment processing, communication delivery, analytics, and security services on our behalf, under written data processing agreements containing the safeguards required by Article 28 GDPR.
- Meta Platforms, Inc. and its affiliates — to deliver messages through the WhatsApp Business Solution API (you must also accept Meta's terms; Meta is a separate Controller for the underlying WhatsApp service).
- Our Customers, when you are an End User receiving messages through our platform — your message content and contact details are visible to the Customer who initiated the conversation. The Customer is the Controller of that data.
- Professional advisors (accountants, auditors, lawyers, insurers) under duties of confidentiality, where strictly necessary.
- Law enforcement, regulatory authorities, courts, or other government bodies — only when we have a good-faith belief that disclosure is required by applicable law or compelled by valid legal process, and only the minimum data necessary.
- Successors in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets — subject to confidentiality and continuity of this Policy or notice to you.
- Other parties with your explicit consent or at your direction.
Current Sub-processors
We maintain an up-to-date list of Sub-processors. As of the effective date of this Policy, our material Sub-processors include:
- Meta Platforms, Inc. — WhatsApp Business Solution API, message delivery — USA / Ireland
- Stripe, Inc. — payment processing, billing — USA / Ireland
- Cloudflare, Inc. — content delivery network, DDoS protection, Turnstile CAPTCHA — global edge network
- Amazon Web Services, Inc. — cloud infrastructure, storage, compute — region-selectable (we use EU and US regions)
- Redis Ltd. — managed in-memory cache — EU / USA
- OpenAI, L.L.C. and/or Anthropic, PBC — large language model inference for AI assistant features (configurable; data is not used for model training under our enterprise agreements)
- Twilio Inc. (SendGrid) — transactional email delivery — USA
- Functional Software, Inc. (Sentry) — error monitoring and crash reporting — USA / EU
- Google LLC — analytics (only with consent), Google Workspace for internal email — USA / EU
We update the Sub-processor list when we engage a new Sub-processor or replace an existing one. Customers on plans that include a Data Processing Agreement may subscribe to receive prior notice of changes and may object to material changes.
International Data Transfers
Weblix is incorporated in the United States (Wyoming) and operates internationally. Your Personal Data may be transferred to, stored in, and Processed in countries other than the country in which you reside, including the United States, the European Economic Area, the United Kingdom, and Israel.
Where we transfer Personal Data from the EEA, the United Kingdom, or Switzerland to a country that has not received an adequacy decision from the European Commission (or the UK Government / Swiss Federal Data Protection and Information Commissioner, as applicable), we rely on one or more of the following safeguards:
- European Commission Standard Contractual Clauses (SCCs) (Decision 2021/914), with the UK International Data Transfer Addendum where applicable;
- EU–US Data Privacy Framework, UK Extension to the EU–US DPF, and Swiss–US DPF (where the recipient is self-certified and the framework remains in force);
- Adequacy decisions, including the Israeli adequacy decision for transfers from the EEA to Israel and reciprocal arrangements;
- Transfer Impact Assessments and supplementary technical, organizational, and contractual measures (such as encryption in transit and at rest, pseudonymization, and access controls) where required following the Schrems II ruling.
- Specific derogations under Article 49 GDPR (such as your explicit consent, performance of a contract at your request) — used only in limited cases.
You may request a copy of the relevant transfer mechanism (with commercially sensitive terms redacted) by emailing [email protected].
Data Retention
We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, regulatory, or reporting obligations. The retention periods below apply unless a longer or shorter period is required by law or agreed in your contract.
- Account profile and authentication data — for the duration of your account plus up to 36 months after closure (for legal claims, audit, and reactivation), then deleted or fully anonymized.
- WhatsApp message content and conversation history — retained for the period configured by the Customer (default 30 days for media, longer for text where required by Customer settings or applicable law). Customers may request immediate deletion at any time.
- Invoices, tax records, and payment history — retained for 7 years (or the longer period required under applicable tax, accounting, or anti-money-laundering laws).
- System logs, security logs, and audit trails — up to 24 months, then aggregated or deleted; longer where needed for security investigations or legal claims.
- Support correspondence — up to 36 months from last contact.
- Marketing consent records — for the duration of consent plus 24 months after withdrawal (to demonstrate compliance with consent rules).
- Encrypted backups — overwritten on a rolling cycle of up to 90 days.
After expiration of the applicable retention period, we delete or irreversibly anonymize Personal Data. Anonymized data may be retained indefinitely for analytics and product improvement.
Security Measures
We implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, or disclosure. Our measures include:
- Encryption in transit (TLS 1.2+) for all communications between clients, servers, and Sub-processors
- Encryption at rest (AES-256) for databases, file storage, and backups
- Strict role-based access controls, principle of least privilege, and audit logging
- Mandatory multi-factor authentication for staff with access to production systems
- Network segmentation, firewalls, intrusion detection, and continuous vulnerability scanning
- Regular penetration testing by independent security firms
- Secure software development lifecycle, code review, and automated dependency scanning
- Background checks and confidentiality obligations for all employees and contractors with access to Personal Data
- Documented incident response and business continuity plans
- Regular employee privacy and security training
- Compliance with the Israeli Privacy Protection Regulations (Data Security) 5777-2017 at the security level appropriate to our database
While we apply industry-standard safeguards, no method of transmission or storage is 100% secure. We cannot guarantee absolute security and you use the Service at your own risk to the extent permitted by law.
You are responsible for keeping your password and API keys confidential, enabling multi-factor authentication, and notifying us immediately of any suspected unauthorized access at [email protected].
Data Breach Notification
If we become aware of a Personal Data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will:
- Notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Article 33 GDPR);
- Notify affected data subjects without undue delay where the breach is likely to result in a high risk (Article 34 GDPR);
- Notify the Israeli Privacy Protection Authority and affected individuals as required under the Israeli Privacy Protection Regulations (Data Security) 5777-2017;
- Notify Customers (where they are the Controller) without undue delay so they can fulfill their own notification obligations;
- Provide reasonable assistance to Customers and authorities in investigation and mitigation;
- Notify affected California residents in accordance with Cal. Civ. Code § 1798.82 and equivalent US state laws.
Your Privacy Rights
Subject to applicable law, you have the rights described below. Some rights are not absolute — we may decline a request where an exemption applies (for example, where compliance would adversely affect the rights of others, or where we are required by law to retain the data).
- Right of access — obtain confirmation of whether we Process your Personal Data and a copy of that data, plus information about the Processing.
- Right to rectification — have inaccurate Personal Data corrected and incomplete data completed.
- Right to erasure ("right to be forgotten") — have your Personal Data deleted in defined circumstances.
- Right to restriction of Processing — limit how we use your Personal Data while a dispute is resolved.
- Right to data portability — receive your Personal Data in a structured, commonly used, machine-readable format and transmit it to another controller, where Processing is based on consent or contract and carried out by automated means.
- Right to object — object to Processing based on legitimate interests, including profiling, and to direct marketing at any time.
- Right to withdraw consent — at any time, where Processing is based on consent.
- Right not to be subject to a decision based solely on automated Processing, including profiling, that produces legal or similarly significant effects (Article 22 GDPR).
- Right to lodge a complaint with a supervisory authority (see the Supervisory Authorities section).
How to Exercise Your Rights
Email [email protected] from the email address associated with your account or use the in-product privacy controls. We will respond within one month of receiving a verifiable request (extendable by two further months for complex requests, as permitted by Article 12 GDPR). Service is provided free of charge unless requests are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or refuse to act.
To protect your data, we will verify your identity before responding. We may ask for information that allows us to confirm you are the person you claim to be. If you submit a request through an authorized agent, we will require written authorization and may verify the identity of the underlying consumer.
If we deny your request, you may appeal by replying to our denial email. Where applicable state law (such as Virginia, Colorado, Connecticut) provides an appeal process, we will follow that process and inform you of the outcome within the statutory timeframe.
Notice for Residents of the EEA, the UK, and Switzerland
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the GDPR, the UK GDPR / Data Protection Act 2018, or the Swiss Federal Act on Data Protection (revFADP) applies to our Processing of your Personal Data. The Controller-related rights described above apply to you in full.
For Personal Data Processed in our capacity as Controller, the Controller is Weblix Global Technologies LLC, contactable at [email protected].
Pursuant to Article 27 GDPR, our designated representative within the European Union is being appointed and contact details will be published below upon completion. Until then, EEA users may contact us directly at [email protected].
Pursuant to Article 27 UK GDPR, our designated representative in the United Kingdom is being appointed and contact details will be published below upon completion. Until then, UK users may contact us directly at [email protected].
While we are not strictly required to appoint a Data Protection Officer under Article 37 GDPR, we have designated a Privacy Lead who oversees our privacy program and can be reached at [email protected].
You have the right to lodge a complaint with the supervisory authority of the EU/EEA Member State of your habitual residence, place of work, or place of the alleged infringement; with the UK Information Commissioner's Office (ico.org.uk); or with the Swiss Federal Data Protection and Information Commissioner (edoeb.admin.ch). We would, however, appreciate the opportunity to address your concerns directly first.
Notice for California Residents (CCPA / CPRA)
This section supplements the rest of this Policy and applies solely to California residents ("consumers"). It is provided pursuant to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, the "CCPA"). Capitalized terms have the meanings given in the CCPA.
Categories of Personal Information We Collect
In the preceding 12 months we have collected the following categories of Personal Information:
- Identifiers — name, postal address, email, phone number, account name, IP address, unique personal and online identifiers.
- Customer records (Cal. Civ. Code § 1798.80(e)) — billing address, payment information.
- Commercial information — products or services purchased, subscription tier, purchase history.
- Internet or other electronic network activity — browsing history on our Service, interactions with our website, advertisement-interaction information.
- Geolocation data — approximate location derived from IP address.
- Professional or employment-related information — job title, company name.
- Inferences drawn from the above to create a profile reflecting preferences and product usage.
- Audio, electronic, visual, or similar information — support call recordings (where lawful and disclosed), screenshots you submit.
- Sensitive Personal Information — account credentials (username + password). We use Sensitive Personal Information only for the purposes permitted by Cal. Civ. Code § 1798.121(a) (such as providing the Service you requested) and do not use it to infer characteristics about you.
Sources of collection: directly from you, from your device, from third-party authentication providers, payment processors, Meta/WhatsApp, and analytics tools.
Business purposes: providing the Service, security, fraud prevention, billing, support, compliance with law, internal research, and short-term transient use such as debugging. We do not use Personal Information for any purpose materially different without notice.
Disclosure of Personal Information
We disclose the categories listed above to the categories of recipients identified in the Sharing section (Sub-processors, Meta, Customers, professional advisors, authorities, successors). We do not knowingly disclose the Personal Information of California residents under 16 without consent.
No Sale or Sharing of Personal Information
We do NOT sell Personal Information for monetary or other valuable consideration, and we do NOT share Personal Information for cross-context behavioral advertising as those terms are defined under the CCPA. We have not done so in the preceding 12 months.
Your California Rights
- Right to know — request the categories of Personal Information collected, sources, business or commercial purposes, categories of third parties to whom it is disclosed, and the specific pieces collected about you.
- Right to delete — request deletion of Personal Information collected from you, subject to permitted exceptions.
- Right to correct — request correction of inaccurate Personal Information.
- Right to opt out — of any sale or sharing for cross-context behavioral advertising (we do not engage in either).
- Right to limit — the use and disclosure of Sensitive Personal Information to the purposes specified in Cal. Civ. Code § 1798.121(a). Because we already restrict our use to those purposes, this right is effectively honored by default.
- Right of non-discrimination — we will not deny goods or services, charge different prices, or provide a different level of quality because you exercised your rights.
To exercise these rights, email [email protected], or submit a request through your account settings. We will verify your identity using account credentials and recent account activity. Authorized agents must submit written authorization signed by the consumer; we may also require the consumer to verify their own identity.
California Shine the Light (Cal. Civ. Code § 1798.83) — California residents may request information once per calendar year about Personal Information disclosed to third parties for those parties' direct marketing purposes. We do not disclose Personal Information for third-party direct marketing.
We do not knowingly sell or share the Personal Information of California consumers under the age of 16.
Notice for Other US State Residents
If you reside in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, Delaware, New Jersey, New Hampshire, Minnesota, Maryland, or another US state with a comprehensive consumer privacy law, you may have rights similar to those described above, including:
- The right to know / access Personal Data we Process about you
- The right to correct inaccurate Personal Data
- The right to delete Personal Data
- The right to obtain a copy in a portable format
- The right to opt out of sale, targeted advertising, or profiling that produces legal or similarly significant effects (we do not engage in any of these)
- The right to appeal a denial of any of the above
To exercise these rights, email [email protected]. We will respond within the timeframe required by your state's law (typically 45 days, extendable once by another 45 days). To appeal a denial, reply to our denial email; we will respond to appeals within the statutory timeframe and, where applicable, inform you how to contact your state Attorney General.
Notice for Residents of the State of Israel
If you reside in Israel, the Israeli Privacy Protection Law 5741-1981, the Privacy Protection Regulations (Data Security) 5777-2017, and Amendment No. 13 to the Privacy Protection Law (in force from 14 August 2025) apply to our Processing of your Personal Data.
Where required, the database holding our user Personal Data is registered with the Israeli Privacy Protection Authority (Registrar of Databases). The registration number will be displayed here once issued. We Process Personal Data in compliance with the security level applicable to our database under the Data Security Regulations.
Your Rights Under Israeli Law
- Right of inspection (Section 13) — you may request inspection of Personal Data held about you in the database.
- Right of correction (Section 14) — you may request correction or deletion of Personal Data that is inaccurate, incomplete, unclear, or outdated.
- Right to object to direct mailing — you may request removal from any direct marketing list at any time.
- Additional rights under Amendment 13 — including expanded rights of access, transparency, and the right to lodge a complaint with the Privacy Protection Authority.
Personal Data may be transferred outside Israel under the Privacy Protection Regulations (Transfer of Data Abroad) 5761-2001. We rely on permitted transfer mechanisms, including transfers to countries with adequate data protection (such as the EEA), transfers to countries that comply with the principles of the Privacy Protection Law, and transfers based on your consent or contractual necessity.
To exercise any right, email [email protected]. We will respond within 30 days. If we refuse a request, we will explain why and inform you of your right to appeal to the Magistrates' Court within 30 days.
You may lodge a complaint with the Israeli Privacy Protection Authority (PPA) at gov.il/he/departments/the_privacy_protection_authority.
Notice for Message Recipients (End Users)
If you receive a WhatsApp message sent through MegaSend, the Customer who sent it (a business that uses our platform) is the Controller of your Personal Data. We Process your data only on that Customer's instructions.
We may Process your name, phone number, profile picture, message content, message status (delivered/read), and conversation metadata to deliver messages on the Customer's behalf.
To exercise privacy rights over data Processed in this context (access, correction, deletion, objection), you should first contact the Customer who sent you the message. If you cannot identify or reach them, contact us at [email protected] and we will assist in routing your request or, where lawful, act directly.
To stop receiving messages, reply STOP (or the equivalent in your local WhatsApp interface), block the sender on WhatsApp, or contact the Customer directly. We require Customers to honor opt-out requests promptly under Meta's WhatsApp Business Solution Terms and applicable law.
AI-Powered Features
MegaSend offers AI-powered features such as an AI assistant, suggested replies, automated flow generation, and intelligent message routing. These features may use third-party large language model providers (such as OpenAI or Anthropic) as Sub-processors.
Under our enterprise agreements with AI Sub-processors, your prompts, messages, and outputs are NOT used to train, fine-tune, or improve their public AI models.
Outputs from AI features are suggestions only and are subject to human review and approval before being sent to End Users (unless the Customer explicitly enables fully automated reply mode). The Customer remains responsible for the content of all messages sent.
AI outputs may be inaccurate, incomplete, or unsuitable for some contexts. Do not rely on AI features for medical, legal, financial, safety-critical, or other regulated advice without independent human verification.
You may request that AI features be disabled for your account or that specific data not be used in AI Processing by emailing [email protected].
Cookies and Similar Technologies
We use cookies, local storage, session storage, and similar tracking technologies. The categories we use are:
- Strictly necessary — required to deliver core functionality (authentication, session management, security, load balancing, language preference). These cannot be disabled and do not require consent.
- Functional / preference — remember your settings, layout, and choices to improve usability. Used only with consent where required by law.
- Analytics / performance — help us understand how the Service is used so we can improve it. Used only with consent where required by ePrivacy or local law; disabled by default in EEA/UK until consent is given.
- Advertising / targeting — we do NOT use advertising or cross-context behavioral tracking cookies.
You can control cookies through our consent banner (where shown), through your browser settings, or through opt-out tools. Blocking strictly necessary cookies may break the Service.
We respect Global Privacy Control (GPC) signals where applicable. Because most modern browsers no longer support a meaningful Do Not Track signal in a standardized way, we do not act on legacy DNT headers but we do respect GPC.
A detailed list of cookies, their purposes, providers, and lifetimes is available in our Cookie Notice / consent banner.
Marketing Communications
We send marketing emails only where (a) you have given consent (in jurisdictions requiring opt-in, including the EEA, UK, and parts of the US and APAC), or (b) you are an existing customer or have requested information from us, where the soft opt-in / existing-business-relationship rule applies.
Every marketing email contains an unsubscribe link. You may also email [email protected] to opt out. We will process opt-out requests within 10 business days (and immediately for one-click unsubscribes). Transactional and service-related emails (security alerts, billing notices, policy changes) are not marketing and may continue regardless of opt-out.
Children's Privacy
The Service is intended for businesses and adults. It is not directed to children. We do not knowingly collect Personal Data from children.
United States — In compliance with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect Personal Data from children under 13. If you believe we have inadvertently collected such data, contact us at [email protected] and we will delete it.
EEA / UK — Our Service is not directed to children under 16 (or the lower age set by your Member State, where applicable, but not below 13). We do not knowingly process the data of such children without parental consent.
Israel — Our Service is not directed to minors under 18. Minors may use the Service only with the consent of a parent or legal guardian.
If you are a parent or guardian and believe your child has provided Personal Data to us, contact [email protected] and we will promptly delete it.
Third-Party Sites and Services
The Service may contain links to third-party websites, apps, or services (including Meta/WhatsApp, Stripe, integration partners, and informational links). We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing them with Personal Data.
Do Not Track and Global Privacy Control
We honor Global Privacy Control (GPC) signals as a valid opt-out of sale or sharing under applicable US state laws. Because there is no industry standard for legacy Do Not Track signals, we do not respond to those signals.
Changes to This Privacy Policy
We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. The "Last Updated" date at the top of this Policy shows when it was most recently revised.
If we make material changes, we will provide reasonable notice — for example, by email to your account address, by a prominent notice in the Service, or by other means required by law — at least 30 days before the changes take effect, unless an earlier effective date is required by law.
Prior versions of this Policy are archived and available upon request at [email protected].
How to Contact Us
For privacy questions, requests, or complaints, contact us using the details below. We will respond within the timeframe required by applicable law.
Weblix Global Technologies LLC
30 N Gould St, Ste 44467, Sheridan, WY 82801, United States
General privacy inquiries: [email protected]
EU Article 27 Representative: To be appointed — contact [email protected] in the interim
UK Article 27 Representative: To be appointed — contact [email protected] in the interim
Israeli Privacy Protection Authority: gov.il/he/departments/the_privacy_protection_authority