This policy explains how Berkobot ("Berkobot," "we," "us") collects, uses, and protects information when businesses use our platform to connect with their own customers over WhatsApp and related channels, and when we act as a Meta Tech Provider to onboard and operate WhatsApp Business Accounts on their behalf.
Berkobot builds messaging, scheduling, and customer-management software for service businesses. We operate as a Meta Tech Provider, meaning we build software on top of the WhatsApp Business Platform and help businesses ("our clients," "business clients") connect their own WhatsApp Business Account to that software.
This policy is written for two audiences at once: the business clients who use Berkobot directly, and the end users — a business client's own customers or patients — who message that business over WhatsApp or use a booking page we host on the business's behalf. Section 3 explains which data we collect from each.
This policy covers:
If you are an end user messaging a business that uses Berkobot: that business is the controller of your personal data, and Berkobot acts as its processor — we handle your data under that business's instructions and for the purposes it sets, such as booking an appointment or receiving a document it sends you. Questions about how a specific business uses your information should go to that business first; this policy explains our role as their service provider.
| Category | Examples |
|---|---|
| Account & identity | Business name, contact name, email, phone, role, login credentials |
| WhatsApp platform identifiers | WhatsApp Business Account (WABA) ID, business phone number ID, Meta business portfolio ID, message template content you create |
| Access credentials | OAuth tokens issued by Meta authorizing us to send/receive messages on your WABA — stored encrypted, never visible to our staff in plaintext |
| Billing | Invoicing details, where applicable to your plan (payment card data itself is handled by our payment processor, not stored by us) |
| Category | Examples |
|---|---|
| Contact information | Phone number, name, as provided when messaging the business or booking an appointment |
| Message content & metadata | Messages exchanged with the business, delivery/read status, timestamps, template messages sent to you |
| Booking & scheduling data | Appointment times, service selected, reschedule/cancellation history |
| Documents | Files a business sends you (e.g. invoices, referrals) or that you send the business, where the business has enabled this feature |
| Payment references | Payment status and provider transaction reference for payments initiated through a business's payment link (we do not store full card numbers) |
We do not sell personal data, and we do not use end-user data collected on a business client's behalf for our own advertising or marketing purposes.
Where applicable law requires a stated legal basis, we rely on:
Some Berkobot business clients are healthcare providers. Where a business client uses Berkobot to send or receive health-related information (for example, appointment details, referrals, or test results), Berkobot processes that data strictly as a processor, under the business's instructions, and does not use it for any purpose other than delivering the service to that business.
We apply additional safeguards to this category of data specifically: encryption at rest and in transit, access limited to what's operationally necessary, audit logging of access to sensitive documents, and delivery via time-limited authenticated links rather than permanent message attachments where the business has enabled that option.
Depending on the business client's configuration, data may be processed in Israel or in other regions where our infrastructure providers operate. Where data is transferred internationally, we use providers that offer appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) and, for business clients with data residency requirements, offer region-specific hosting.
No system is perfectly secure. If you believe you've found a vulnerability, please contact us at the address in Section 15 before disclosing it publicly.
Subject to applicable law (including Israel's Privacy Protection Law and, where relevant, the GDPR), you may have the right to:
If your data is held by us on behalf of a business client (i.e. you're that business's customer or patient), we'll generally direct your request to that business, since they control how your data is used — but you're welcome to contact us directly and we'll help route it correctly.
Berkobot's platform is intended for use by businesses and their adult customers or patients. We do not knowingly collect personal data directly from children. Where a business client's own services involve minors (for example, a pediatric practice), that business is responsible for obtaining any necessary parental consent under applicable law; Berkobot processes that data solely as instructed by the business.
We'll update the "last updated" date at the top of this page when we make changes. For material changes, we'll notify business clients directly (e.g. by email) in addition to updating this page.
Questions about this policy, or requests relating to your data, can be sent to:
Berkobot
ברקובוט
2 Yanna, Netanya
Email: office@berkobot.com