Privacy Policy
Last updated: 12 August 2026
Fizmoh is software that businesses use to talk to their customers on WhatsApp. That gives us two quite different relationships with personal data, and this policy keeps them apart because your rights depend on which one you are in.
Two roles, plainly stated
- When you use Fizmoh — you signed up, you have an account, we bill you. We decide what we collect and why, so we are the controller of that data.
- When a business uses Fizmoh to talk to you — they chose to message you, they hold your details, they decide what to do with them. They are the controller; we are their processor, and we act on their instructions. If you want your data corrected or deleted, ask them first. We will help them do it, and we will act ourselves if they do not.
What we collect about businesses that use Fizmoh
- The name, email address and phone number given at sign-up, and for each colleague added afterwards.
- What was done in the product and when — enough to answer “who changed this”, to bill accurately, and to investigate an abuse report.
- Payment records for the subscription. Card details are entered on the payment gateway’s own pages and never reach our servers.
- Technical logs: IP address, browser, timestamps. Kept for security and kept briefly.
What we hold on a business’s behalf
Whatever they put in: their customers’ names and phone numbers, the WhatsApp conversations, orders, payments, files sent in a chat, and notes their staff write. We do not sell it, mine it, or use it to train anything. We access it only to keep the service running, to fix a fault we have been asked to fix, or where the law requires it.
Who else sees it
- Meta Platforms — messages go through the WhatsApp Business Platform, so Meta processes them to deliver them. Their handling is governed by their own terms.
- The payment gateway — card details and the amount, so a payment can be taken. We receive the result, not the card.
- Our hosting provider — the servers this runs on, located in the region stated in your agreement.
- An AI provider, only where a business has switched AI replies on, and only the conversation being replied to. Not used to train their models.
Nobody else. No advertisers, no data brokers, no analytics companies.
How long we keep it
- Account and billing records: while you are a customer, and for seven years afterwards where tax law requires it.
- A workspace’s own data: while the workspace exists. When it is closed, thirty days to export, then deletion.
- Technical logs: ninety days.
What you can ask for
A copy of your data, a correction, deletion, or a restriction on what we do with it. Write to privacy@fizmoh.cloud. We answer within thirty days. If you are a customer of a business using Fizmoh, see Data Deletion, which explains how to reach both of us.
Security
Credentials — WhatsApp tokens, gateway keys — are encrypted at rest. Each workspace’s data is separated at the database layer, so one business’s query cannot return another’s rows. Traffic is encrypted in transit. No system is perfect; if one of ours fails in a way that affects you, we will tell you what happened and what we did.
Changes
If this policy changes in a way that affects you, we will say so in the product before it takes effect rather than quietly changing the date at the top.