Snapshot 36762
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Need help? Message us on WhatsAppWhatsApp us+1 279-243-3696Open chat Trust Trust & Compliance Notifyer by Whatsable is committed to data protection and GDPR-aligned practices. Our infrastructure is built on SOC 2 Type 2 and ISO 27001–certified providers. Security · Automazing LLC On this page Notifyer by Whatsable (operated by Automazing, LLC) processes business communications and customer data on behalf of our clients. We take that responsibility seriously and maintain security, privacy, and compliance practices appropriate for business buyers, procurement teams, and auditors. This page describes our operational security posture, infrastructure certifications, subprocessors, incident handling, and how to request security documentation. The Sub-processor list below is kept aligned with Annex 1 of our Data Processing Agreement. For data-subject rights and lawful-basis disclosures, see our Privacy Policy. For contractual terms, see our Terms of Service. Scope Whatsable acts as a data processor for customer message content and account data. Customers remain the data controller for end-user communications sent through the platform. Data deletion requests can be submitted via our data deletion form or by email. Our primary backend, including data storage, business logic, and API handling, is built on Xano, a platform that maintains SOC 2 Type 2 and ISO 27001 certifications and a documented GDPR compliance program. Infrastructure-level monitoring, access controls, and security operations for this layer are managed by Xano in accordance with their security program. Application frontends are hosted on Vercel: the marketing site (whatsable.app), the Notifyer console (notifyer.whatsable.app), and the chat UI (chat.notifyer-systems.com). Vercel is not used to process, store, or deliver WhatsApp messages. Additional Node.js/Hono application servers run on Railway Corporation in Amsterdam, Netherlands (EU). Customer Data is processed primarily in the United States (Xano) and in part in the EU (Railway). WhatsApp message delivery is handled through Meta's WhatsApp Business Platform (WhatsApp Cloud API), which operates under Meta's data processing terms for technology providers. Encryption in transit All client–server communication uses TLS. API credentials and tokens are transmitted over encrypted channels. Encryption at rest Encryption at rest is provided by sub-processor infrastructure (Xano and Railway), in line with those providers' security standards. Access control Least-privilege, role-based access to production systems. Unique credentials per staff member, no shared logins, and two-factor authentication (2FA) on all employee logins. Secure development We follow industry-standard practices for credential management, environment separation, and dependency hygiene in our application layer. SOC 2 Type II Our backend provider has completed a comprehensive SOC 2 Type II audit covering security, availability, and confidentiality controls. Summary documentation is available via the Xano Security Center. Full SOC 2 reports are available to enterprise customers upon request through our security contact. ISO 27001 Our backend infrastructure is covered under ISO 27001:2022 certification for information security management. Details and certificate references are published in the Xano Security Center. GDPR alignment We process personal data in accordance with applicable data protection law, including the GDPR where it applies. Lawful basis, data-subject rights, and collection disclosures are documented in our Privacy Policy. Data processing agreements are available on request at [email protected]. Meta technology provider As a WhatsApp Business Platform technology provider, we maintain data protection and security practices in accordance with Meta's requirements for partners integrating with the WhatsApp Cloud API. Customer provides general written authorization for the Sub-processors below, which is the same list as Annex 1 of our Data Processing Agreement. The transfer mechanism for each vendor is the mechanism named in that annex. Copies of the relevant Sub-processor SCCs are available on request. Sub-processor Purpose Location Transfer mechanism Xano, Inc. Primary application database and backend logic (api.insightssystem.com). Security Center United States (Woodland Hills, CA) Standard Contractual Clauses (DPA); SOC 2 Type II, ISO 27001 certified Railway Corporation Application server hosting (Node.js/Hono services) Amsterdam, Netherlands (EU) Primarily EU-hosted. Railway Corporation is a US entity, so limited administrative/support access may involve a restricted transfer, covered by SCCs in Railway's DPA. OpenAI, L.L.C. / OpenAI Ireland Ltd AI-generated chatbot responses, used only if Customer enables AI features United States / Ireland Standard Contractual Clauses and EU-U.S. Data Privacy Framework certification Meta Platforms, Inc. WhatsApp Cloud API message transport (required for core Service) United States Meta's own GDPR terms for the WhatsApp Business Platform; Data Privacy Framework certified Stripe, Inc. Billing and payment processing United States Standard Contractual Clauses; Stripe's own DPA Functional Software, Inc. (Sentry) Technical error monitoring and application logs. Confirmed: message content, phone numbers, and contact data never reach Sentry, by design. United States Standard Contractual Clauses and EU-U.S. Data Privacy Framework certification; self-serve DPA available The following vendors are also used to operate the Notifyer console, marketing site, and product analytics. They are disclosed here so security questionnaires can see who hosts the frontend and who processes pseudonymous usage data. They are not in Annex 1 of the signed DPA today; they should be added there so the two documents stay aligned. Vendor Purpose Location Transfer mechanism Vercel, Inc. Frontend hosting for whatsable.app (marketing site), notifyer.whatsable.app (Notifyer console), and chat.notifyer-systems.com (chat UI). Vercel does not process, store, or deliver WhatsApp message content, phone numbers, or CRM Customer Data. United States (global edge network) Standard Contractual Clauses; Vercel DPA PostHog, Inc. Product analytics and session insights on the marketing site and Notifyer console. Processes pseudonymous usage data (page views, feature usage, and similar events). WhatsApp message content, phone numbers, and contact records are not sent to PostHog as Customer Data. European Union (PostHog EU Cloud) Primarily EU-hosted. PostHog, Inc. is a US entity; transfers are covered by Standard Contractual Clauses in PostHog's DPA. Sub-processor updates We will notify customers of any intended addition or replacement at least 14 days in advance via email or the Notifyer console, and customers may object on reasonable data-protection grounds within that period, as set out in Section 7 of our DPA. For a signed DPA or Annex 1 copy, contact [email protected]. Customer-configured integrations Customers may connect third-party automation or CRM platforms (e.g. Make, Zapier, n8n, monday.com, Pipedrive, Attio). Data shared with those platforms is governed by the customer's configuration and each platform's own terms. They are not Whatsable Sub-processors under Annex 1. Detection & monitoring. Infrastructure-level threat monitoring, logging, and vulnerability management for our backend are handled by Xano as part of their certified security program. We monitor application-level errors and availability for the Notifyer service, including through Functional Software, Inc. (Sentry) for technical error monitoring and logs. Sentry does not receive message content, phone numbers, or contact data. Sentry logs are retained for 90 days. Triage & containment. Suspected security incidents are escalated to our internal team for assessment. We take steps to contain impact, preserve evidence, and determine scope. Notification. We will notify Customer without undue delay, and in any event within 72 hours of becoming aware of a Personal Data breach affecting Customer Data, providing the information reasonably available at the time, as set out in Section 13 of our DPA. Remediation & review. After resolution, we document root cause, corrective actions, and preventive measures. Material incidents are reviewed to improve our controls and response procedures. Report a concern If you believe you have discovered a security vulnerability or incident affecting Notifyer by Whatsable, please report it promptly to [email protected]. Include sufficient detail for us to reproduce and investigate the issue. Customer Data is processed primarily in the United States (Xano, Woodland Hills, CA) and in part in the European Union (Railway, hosted in Amsterdam). Message content transits through Meta's WhatsApp Cloud API for delivery. We can provide further detail in security questionnaires on request. Message content and conversation history are retained for the duration of the subscription term, then deleted or returned within 30 days of termination unless a longer period is required by law. Primary database backups use a rolling 30-day retention window. Technical error logs in Sentry are retained for 90 days and contain no message content or phone numbers by design. For account or data deletion, use our data deletion request form or email [email protected]. SOC 2Type II infrastructure ISO 27001Certified backend GDPRAligned processing TLSEncrypted in transit Get in touch Security questionnaires & DPA requests For SOC 2 summaries, subprocessors lists, data processing agreements, or responses to vendor security assessments, our team will respond as promptly as possible. CompanyAutomazing, LLC Address18585 Coastal Highway, Rehoboth Beach, DE 19971, US Phone+1 (801) 895-4223 WhatsApp+1 279-243-3696 [email protected] Message on WhatsAppSend us an email Start Free Trial