Tefa AI

TEFA AI WhatsApp Business Automation Platform

Privacy Policy

Last Updated: August 2025

TEFA AI, operated by a legal entity with NIT 901652038, is a WhatsApp Business API automation platform that enables companies to manage customer conversations through AI-powered chatbots and automated messaging. This Privacy Policy explains how we collect, use, store, and protect information when you use our platform, including through the WhatsApp Business API.

By using TEFA AI, you agree to the practices described in this policy. If you do not agree, please discontinue use of our platform.

1. Information We Collect

1.1 Information from Business Clients

When businesses register and use our platform, we collect:

  • Business name, legal entity, and NIT or tax identification number
  • Contact information: email address, phone number, and name of account administrators
  • WhatsApp Business Account (WABA) credentials and configuration data
  • Meta Business Manager ID and associated application identifiers

1.2 Information from End Users (via WhatsApp)

When end users interact with a business through our platform via WhatsApp, we may process:

  • WhatsApp phone number and display name
  • Message content: text, images, documents, audio, and other media shared in conversations
  • Conversation history and interaction timestamps
  • Message delivery and read status

1.3 Automatically Collected Data

  • API usage logs and request metadata
  • Webhook event data received from Meta's WhatsApp Business Platform
  • Error logs and diagnostic information for platform stability

2. How We Use the Information

We use collected information for the following purposes:

  • Platform operation: To provide, maintain, and improve our WhatsApp automation services.
  • Message processing: To route, deliver, and store messages between businesses and their customers via the WhatsApp Business API.
  • Chatbot functionality: To process conversation content and generate automated responses based on configured workflows.
  • Account management: To manage business client accounts, billing, and technical support.
  • Compliance and security:To detect fraud, abuse, or violations of our terms of service and Meta's policies.
  • Analytics: To generate anonymized usage statistics that help us improve platform performance.
  • Legal obligations: To comply with applicable laws and respond to lawful requests from authorities.

We do not sell, rent, or trade personal data to third parties for advertising or marketing purposes.

3. Legal Basis for Processing

We process personal data based on the following legal grounds:

  • Contractual necessity: Processing required to fulfill our service agreement with business clients.
  • Legitimate interests:To operate, maintain, and improve the platform in ways that do not override users' privacy rights.
  • Legal compliance: Where required by applicable law in Colombia, the United States, or other jurisdictions where we operate.
  • Consent: For processing not covered by the above, we obtain explicit consent from the relevant party.

4. WhatsApp Business API and Meta

TEFA AI operates as a technology provider using the WhatsApp Business API, hosted by Meta Platforms, Inc. As a result, message data transmitted through our platform also passes through Meta's infrastructure. Meta's own privacy policy governs how Meta processes this data. We encourage users to review Meta's Privacy Policy.

Our platform connects client WhatsApp Business Accounts to our servers via API integrations authorized by the business client. We act as a data processor on behalf of our business clients, who are the data controllers for conversations with their end customers.

5. Data Sharing and Third Parties

We share data only in the following circumstances:

  • With Meta:Message routing through the WhatsApp Business API requires transmitting data to Meta's servers.
  • With cloud infrastructure providers: We use AWS (Amazon Web Services) for hosting and data storage. These providers are bound by confidentiality obligations.
  • With business clients: We provide business clients access to conversation data generated through their own WhatsApp channels.
  • For legal reasons: If required by law, court order, or governmental authority.
  • Business transfers: In the event of a merger, acquisition, or asset sale, data may be transferred subject to equivalent privacy protections.

6. Data Retention

We retain business client data for the duration of the service agreement and for up to 12 months after account termination, unless a longer retention period is required by law. Conversation data (messages) is retained for the period configured by each business client, with a default of 90 days. Clients may request earlier deletion.

After the retention period, data is securely deleted or anonymized from our systems.

7. Data Security

We implement industry-standard security measures to protect your data, including:

  • Encryption in transit using TLS/HTTPS for all API communications
  • Encryption at rest for stored data on our cloud infrastructure
  • Role-based access controls limiting who can access data internally
  • Regular security audits and vulnerability assessments
  • Secure token management for API credentials

Despite these measures, no system is 100% secure. We will notify affected clients promptly in the event of a confirmed data breach.

8. User Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure: Request deletion of your personal data, subject to legal retention requirements.
  • Portability: Request your data in a structured, machine-readable format.
  • Objection: Object to certain types of processing, including processing based on legitimate interests.
  • Withdrawal of consent: Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, please contact us at privacy@tefa.ai. We will respond within 15 business days.

9. Cookies and Tracking

Our web platform (tefa.ai) may use cookies and similar technologies for authentication, session management, and analytics. We do not use cookies for cross-site advertising tracking. You may configure your browser to reject cookies, though some features of the platform may not function correctly as a result.

10. International Data Transfers

TEFA AI operates in Colombia and the United States. Data may be processed and stored in servers located in the United States (AWS infrastructure). When transferring data internationally, we ensure adequate safeguards are in place in accordance with applicable data protection laws, including Colombia's Law 1581 of 2012 (Habeas Data).

11. Children's Privacy

Our platform is intended for business use only and is not directed at children under the age of 13. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected such data, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will notify business clients via email or through the platform. The date of the most recent revision is indicated at the top of this document. Continued use of our platform after changes constitutes acceptance of the updated policy.

13. Contact Information

For questions, requests, or complaints regarding this Privacy Policy, please contact us:

This Privacy Policy was prepared in accordance with Colombia's Law 1581 of 2012 on personal data protection, and is intended to comply with Meta's requirements for WhatsApp Business Platform access.