Privacy Policy
This Privacy Policy explains what personal data Asas Labs Ltd collects, how we use it, and the choices you have. It covers our website, our software products, and the WhatsApp messaging platform we operate for business customers. Please read it carefully.
1. Who We Are
Asas Labs Ltd (Hebrew: אסאס לאבס בע״מ) — "Asas Labs," "we," "us," or "our" — is a private company incorporated in the State of Israel under company number 517341970.
Company No. 517341970
27 Al-Wurud, Tamra 3081100, Israel
Privacy contact: admin@asaslabsltd.com
All privacy questions, data subject requests, and deletion requests should be sent to admin@asaslabsltd.com.
2. Scope
This policy applies to:
- The website at asaslabsltd.com, including all of its pages;
- Our software products — ClinicaOS, Qampus, and QalamSign; and
- The WhatsApp messaging platform services we provide to business customers, through which businesses connect their own WhatsApp Business Account to our platform and send and receive messages via Meta's WhatsApp Business Platform (Cloud API).
Where a business customer has its own privacy policy governing its relationship with its own customers, that policy — not this one — describes how that business handles the personal data of the people it messages. See Section 4.
3. Data We Collect
3.1 From website visitors
This website does not host a contact form, an account system, or a login. If you contact us, you do so by email or telephone using the details published on the site, and we receive whatever you choose to put in that message — typically your name, email address, phone number, company name, and the content of your enquiry.
Like any website, asaslabsltd.com generates standard server and security logs at our hosting provider. These may include your IP address, approximate location derived from it, browser and device type, the pages requested, and the time of the request. We use these logs to keep the site available and to protect it from abuse.
3.2 From business customers
- Account data — the business name, its registration details, and the name, work email address, phone number, and role of the people who administer the account.
- Configuration and support data — settings you choose, the messages you send us through support channels, and diagnostic information about your use of the platform.
- Billing data — the details needed to invoice you and record payment for our service, including billing contact, billing address, tax identifiers, and the invoice and payment history. Card details are handled by our payment provider and are not stored on our systems.
3.3 From Meta and WhatsApp, when a business connects via Embedded Signup
Asas Labs is a Meta-verified WhatsApp Tech Provider. When a business connects its own WhatsApp Business Account to our platform through Meta's Embedded Signup flow, we receive and store:
- The WhatsApp Business Account (WABA) ID and the associated Meta Business Account identifiers;
- The phone numbers registered to that WhatsApp Business Account, together with their display names, quality ratings, and messaging limits;
- Access tokens issued by Meta that authorise our platform to call the WhatsApp Business Platform on the business's behalf;
- Message templates created, submitted, or approved for that account, and their approval status; and
- Message content and metadata for messages sent or received through the platform — the text, media, and attachments of the message, the sender and recipient phone numbers, timestamps, and delivery, read, and error statuses.
3.4 End users' data, processed on behalf of a business
When a person messages a business that uses our platform, or receives a message from that business, we process that person's WhatsApp phone number, WhatsApp profile name, and the content and metadata of the messages exchanged. We do this solely on the instructions of, and on behalf of, the business customer.
4. Our Role: Controller and Processor
Our role depends on the data:
- For our website, our direct business customers' account and billing data, and our own marketing and correspondence, Asas Labs is the controller (in Israeli terms, the owner and manager of the database).
- For WhatsApp messaging — the phone numbers and message content of the people a business communicates with — Asas Labs acts as a processor / service provider. The business customer is the controller. It decides who is messaged, what is said, on what legal basis, and for how long the data is kept. We act only on its documented instructions.
5. How We Use Data
We use personal data to:
- Provide the service — create and administer accounts, connect a business's WhatsApp Business Account, and operate our products;
- Deliver messages — transmit outbound messages to the WhatsApp Business Platform, receive inbound messages, and record delivery and read status;
- Troubleshoot and support — diagnose faults, respond to support requests, and investigate delivery failures;
- Secure the platform — detect and prevent fraud, abuse, spam, and unauthorised access, and maintain audit logs;
- Bill and account — invoice our business customers and keep the financial records the law requires; and
- Comply with the law — meet our legal, regulatory, tax, and contractual obligations, including Meta's platform requirements.
Where a product feature uses an AI model to help a business draft or handle its own messages, that processing happens at that business's request, on its own data, to produce its own output — it is not used to improve models for anyone else.
6. Data We Receive From Meta
Data we obtain from Meta — including WhatsApp Business Account identifiers, phone numbers, access tokens, templates, and message content — is used only to provide the platform service to the business that granted us access, and only for as long as that authorisation stands.
We handle that data in accordance with the Meta Platform Terms, the WhatsApp Business Terms of Service, and the WhatsApp Business Messaging Policy. Specifically:
- We do not sell, license, or transfer Meta platform data to any third party, other than the subprocessors listed in Section 7 that are necessary to run the service;
- We do not use it for advertising, ad targeting, or building profiles for advertising purposes;
- We do not use it to train AI or machine learning models;
- We do not use it to make eligibility decisions about people, such as credit, insurance, housing, or employment decisions; and
- We keep access tokens encrypted and revoke them when a business disconnects.
7. Sharing and Subprocessors
We share personal data only in these circumstances:
- Meta Platforms — message content and recipient phone numbers are transmitted to the WhatsApp Business Platform (Cloud API) in order to deliver messages, and inbound messages reach us the same way. Meta's handling of that data is governed by its own terms and policies.
- Hosting and infrastructure subprocessors — we use reputable cloud hosting providers to run the platform, store data, and protect the service from attack. They act on our instructions under written agreements that require them to protect the data and prohibit them from using it for their own purposes.
- Payment providers — we use a payment provider to collect fees for our own service and to issue invoices. They receive billing details, not message content.
- Professional advisers — accountants and lawyers, under a duty of confidentiality, where necessary.
- Legal and regulatory authorities — where we are required to disclose data by law, court order, or a binding request from a competent authority, or where disclosure is necessary to establish or defend legal claims.
- Successors — in connection with a merger, acquisition, or sale of assets, subject to this policy continuing to apply.
8. International Transfers
Meta operates the WhatsApp Business Platform globally, and some of our infrastructure providers operate outside the State of Israel, including in the European Union and the United States. Where personal data is transferred across borders, we rely on the legal safeguards available to us, including contractual protections such as standard contractual clauses and, in the case of the European Economic Area, the European Commission's adequacy decision for Israel.
9. Retention
- Website correspondence — kept for up to 24 months from our last contact with you, unless a longer period is needed for a live matter or required by law.
- Business customer account data — kept for as long as the account is active, and then for as long as needed to close out the relationship.
- WhatsApp message content and metadata — retained according to the business customer's own configuration and instructions. The business decides the retention period for its conversations; we apply it.
- Access tokens — revoked and deleted when a business disconnects its WhatsApp Business Account or when Meta invalidates them.
- Billing and accounting records — kept for seven (7) years, as required by Israeli tax and bookkeeping law.
When a business disconnects from the platform, or asks us to delete its data, we delete or irreversibly anonymise the data within 30 days, except for records the law requires us to keep. Backups are purged on their normal rotation cycle.
10. Security
We take reasonable technical and organisational measures to protect personal data, including:
- Encryption in transit — all traffic to our services and to Meta's APIs is carried over TLS;
- Encrypted credentials — access tokens and API keys are stored encrypted at rest and are never exposed in our interfaces or logs;
- Access controls — role-based access, least privilege, and separation between customer environments, so one business cannot see another's data;
- Audit logging — administrative and access events are logged; and
- Operational practice — patching, dependency updates, and review of access rights.
No internet service can be guaranteed perfectly secure. If a security incident affects your personal data and the law requires us to notify you, we will do so without undue delay.
11. Your Rights
Under the Israeli Protection of Privacy Law, 5741-1981, as amended — including Amendment 13 — you have the right to:
- Access the information held about you in our databases;
- Correct information that is inaccurate, incomplete, or out of date;
- Delete information, subject to the exceptions the law allows;
- Object to processing, and to withdraw consent where processing rests on consent; and
- Complain to the Israeli Privacy Protection Authority (PPA).
If you are in the European Economic Area or the United Kingdom, the GDPR (or UK GDPR) also gives you rights of access, rectification, erasure, restriction of processing, data portability, and objection, and the right to lodge a complaint with your local supervisory authority.
To exercise any of these rights, email admin@asaslabsltd.com. We may need to verify your identity before we act, and we will respond within the time the applicable law allows. Where we hold your data as a processor on behalf of a business customer, we will pass your request to that business and act on its instructions — see Section 4.
12. Data Deletion
Step-by-step instructions for requesting deletion of your data — for end users, for business customers, and for anyone who connected through Facebook Login for Business — are on a dedicated page:
13. Children
Our services are business-to-business tools and are not directed at anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, email admin@asaslabsltd.com and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy as our services and legal obligations change. When we do, we will revise the "Last updated" date at the top of this page. If a change materially affects how we handle personal data, we will give business customers advance notice by email or through the platform. Continued use of our services after a change takes effect means you accept the updated policy.
15. Contact
For any question about this policy, about the data we hold, or to exercise your rights:
Company No. 517341970
27 Al-Wurud, Tamra 3081100, Israel
Email: admin@asaslabsltd.com
Phone: +972 54-500-5453
This Privacy Policy is governed by the laws of the State of Israel.