Sendryx is a WhatsApp Business messaging platform based in the United Kingdom. We provide messaging automation services to businesses using the Meta WhatsApp Business API. Contact: hello@sendryx.cloud
We collect and process the following categories of data: • Business client data: company name, contact email, WhatsApp Business Account details, API credentials • End-recipient data: WhatsApp phone numbers, message delivery status, opt-in consent records • Usage data: message logs, campaign send history, delivery receipts • Technical data: IP addresses, browser type, access timestamps for security and debugging purposes
We use collected data to: • Deliver WhatsApp messaging services to our business clients • Maintain opt-in consent records on behalf of business clients • Process message delivery and track campaign performance • Ensure platform security and prevent abuse • Comply with Meta's WhatsApp Business API terms and applicable law
We process personal data under the following legal bases under UK GDPR: • Contract performance: processing necessary to deliver the services you have contracted with us • Legitimate interests: platform security, fraud prevention, and service improvement • Legal obligation: compliance with applicable laws and Meta platform policies • Consent: where you have provided explicit consent for specific processing activities
If you have received a WhatsApp message sent via Sendryx on behalf of one of our business clients, your phone number and message interaction data is processed on behalf of that business. The business client is the data controller for your data; Sendryx acts as a data processor. To exercise your rights regarding data held by a business client, please contact them directly. To opt out of receiving messages, reply STOP to any message.
We do not sell personal data. We share data only with: • Meta Platforms Inc. — as required to deliver WhatsApp Business API services • Supabase Inc. — cloud database infrastructure for message and campaign data storage • Cloudflare Inc. — message routing infrastructure All third-party processors are bound by data processing agreements and operate in compliance with UK GDPR.
Message logs and campaign data are retained for 12 months from the date of send, after which they are automatically deleted. Business client account data is retained for the duration of the contract and deleted within 30 days of contract termination upon written request. Opt-in consent records are retained for as long as the consent remains valid or until a data deletion request is received.
Under UK GDPR, you have the right to: • Access the personal data we hold about you • Rectify inaccurate data • Request deletion of your data • Restrict or object to processing • Data portability • Withdraw consent at any time To exercise any of these rights, contact us at hello@sendryx.cloud. We will respond within 30 days.
To request deletion of your data, email hello@sendryx.cloud with the subject line "Data Deletion Request" and include your name, company name (if applicable) and the email address or phone number associated with your account. We will action deletion requests within 30 days and confirm completion in writing.
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, and regular security reviews. However, no system is completely secure and we cannot guarantee absolute security.
We may update this privacy policy from time to time. We will notify business clients of material changes by email. The current version will always be available at sendryx.cloud/privacy.
For privacy-related enquiries contact: hello@sendryx.cloud If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Sendryx, UK · hello@sendryx.cloud