Privacy Policy

1. Who We Are

Asas Labs Ltd (Hebrew: אסאס לאבס בע״מ) — "Asas Labs," "we," "us," or "our" — is a private company incorporated in the State of Israel under company number 517341970.

Asas Labs Ltd
Company No. 517341970
27 Al-Wurud, Tamra 3081100, Israel
Privacy contact: admin@asaslabsltd.com

All privacy questions, data subject requests, and deletion requests should be sent to admin@asaslabsltd.com.

2. Scope

This policy applies to:

Where a business customer has its own privacy policy governing its relationship with its own customers, that policy — not this one — describes how that business handles the personal data of the people it messages. See Section 4.

3. Data We Collect

3.1 From website visitors

This website does not host a contact form, an account system, or a login. If you contact us, you do so by email or telephone using the details published on the site, and we receive whatever you choose to put in that message — typically your name, email address, phone number, company name, and the content of your enquiry.

Like any website, asaslabsltd.com generates standard server and security logs at our hosting provider. These may include your IP address, approximate location derived from it, browser and device type, the pages requested, and the time of the request. We use these logs to keep the site available and to protect it from abuse.

3.2 From business customers

3.3 From Meta and WhatsApp, when a business connects via Embedded Signup

Asas Labs is a Meta-verified WhatsApp Tech Provider. When a business connects its own WhatsApp Business Account to our platform through Meta's Embedded Signup flow, we receive and store:

3.4 End users' data, processed on behalf of a business

When a person messages a business that uses our platform, or receives a message from that business, we process that person's WhatsApp phone number, WhatsApp profile name, and the content and metadata of the messages exchanged. We do this solely on the instructions of, and on behalf of, the business customer.

4. Our Role: Controller and Processor

Our role depends on the data:

5. How We Use Data

We use personal data to:

Where a product feature uses an AI model to help a business draft or handle its own messages, that processing happens at that business's request, on its own data, to produce its own output — it is not used to improve models for anyone else.

6. Data We Receive From Meta

Data we obtain from Meta — including WhatsApp Business Account identifiers, phone numbers, access tokens, templates, and message content — is used only to provide the platform service to the business that granted us access, and only for as long as that authorisation stands.

We handle that data in accordance with the Meta Platform Terms, the WhatsApp Business Terms of Service, and the WhatsApp Business Messaging Policy. Specifically:

7. Sharing and Subprocessors

We share personal data only in these circumstances:

8. International Transfers

Meta operates the WhatsApp Business Platform globally, and some of our infrastructure providers operate outside the State of Israel, including in the European Union and the United States. Where personal data is transferred across borders, we rely on the legal safeguards available to us, including contractual protections such as standard contractual clauses and, in the case of the European Economic Area, the European Commission's adequacy decision for Israel.

9. Retention

When a business disconnects from the platform, or asks us to delete its data, we delete or irreversibly anonymise the data within 30 days, except for records the law requires us to keep. Backups are purged on their normal rotation cycle.

10. Security

We take reasonable technical and organisational measures to protect personal data, including:

No internet service can be guaranteed perfectly secure. If a security incident affects your personal data and the law requires us to notify you, we will do so without undue delay.

11. Your Rights

Under the Israeli Protection of Privacy Law, 5741-1981, as amended — including Amendment 13 — you have the right to:

If you are in the European Economic Area or the United Kingdom, the GDPR (or UK GDPR) also gives you rights of access, rectification, erasure, restriction of processing, data portability, and objection, and the right to lodge a complaint with your local supervisory authority.

To exercise any of these rights, email admin@asaslabsltd.com. We may need to verify your identity before we act, and we will respond within the time the applicable law allows. Where we hold your data as a processor on behalf of a business customer, we will pass your request to that business and act on its instructions — see Section 4.

12. Data Deletion

Step-by-step instructions for requesting deletion of your data — for end users, for business customers, and for anyone who connected through Facebook Login for Business — are on a dedicated page:

Data Deletion Instructions →

13. Children

Our services are business-to-business tools and are not directed at anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, email admin@asaslabsltd.com and we will delete it.

14. Changes to This Policy

We may update this Privacy Policy as our services and legal obligations change. When we do, we will revise the "Last updated" date at the top of this page. If a change materially affects how we handle personal data, we will give business customers advance notice by email or through the platform. Continued use of our services after a change takes effect means you accept the updated policy.

15. Contact

For any question about this policy, about the data we hold, or to exercise your rights:

Asas Labs Ltd (אסאס לאבס בע״מ)
Company No. 517341970
27 Al-Wurud, Tamra 3081100, Israel
Email: admin@asaslabsltd.com
Phone: +972 54-500-5453

This Privacy Policy is governed by the laws of the State of Israel.