Wesend Privacy Policy
Last Updated: July 2026
Contents
- Who this policy applies to
- Roles and processing positions
- Data we collect
- How we use data & AI Processing
- Lawful bases
- Sharing & Service Providers
- Security Measures & Data Breaches
- International transfers
- Retention & User Data Deletion
- Your rights
- Cookies Policy
- Children
- Contact
- Changes to this Privacy Policy
1. Who this policy applies to
This Privacy Policy explains how WESEND LTD (“Wesend”, “we”, “us”, “our”) collects, uses, and protects personal data when we act as a controller, including, but not limited to, on and through the wesend.chat website, our sales and support channels, signup and billing flows, and when administering customer accounts.
By using our Services, you acknowledge that you have read this Privacy Policy.
2. Roles and processing positions
Depending on the processing activity, our role may differ:
- Controller: Where Wesend determines the purposes and means of processing (e.g., managing your billing, account creation, and website analytics), we act as the Data Controller.
- Processor / Service Provider: Where a customer uses Wesend to collect, store, or send messages involving their own contacts or end users via Connected Platforms (such as Meta/Instagram), Wesend acts strictly as a Processor or Service Provider on that customer’s behalf. In such cases, the customer acts as the Controller and is responsible for obtaining any necessary consents from their end users.
3. Data we collect
- Identity and account data: name, email address, username, password hash or login token, organisation name, role, and team information.
- Billing and commercial data: plan, invoices, tax IDs, country, billing contact details, and subscription status.
- Usage and device data: IP address, browser and device data, activity logs, error logs, and approximate location derived from IP.
- Connected-platform and Platform Data: integration metadata, page/account IDs, permission states, and "Platform Data" received from Meta Products and APIs (including Instagram Direct Messages, comments, and public profile information) processed in the Service.
4. How we use data & AI Processing
We use your data to provide and administer the Service, authenticate users, process transactions, secure our systems, and communicate with you about your account.
AI Processing, Automated Responses, and Meta Platform Terms:
Where our Service utilizes Artificial Intelligence (AI) features to process Customer Content or Meta Platform Data, such processing is strictly automated to generate real-time, reactive responses configured by the customer. We do not use automated decision-making that produces legal or similarly significant effects on individuals.
Strictly in compliance with Meta's Platform Terms: Platform Data is used solely to provide the requested service. We do not use Meta Platform Data or Customer Content to train, fine-tune, or improve our own AI models or those of any third party.
5. Lawful bases
For UK / EU / EEA data subjects, our lawful bases under the GDPR include:
- Performance of a contract: To provide the Service and manage your account.
- Legitimate interests: For running and improving the Service, securing our systems, and preventing abuse.
- Compliance with legal obligations: For tax, billing, and regulatory requirements.
- Consent: Where required for cookies or direct marketing (which can be withdrawn at any time).
6. Sharing & Service Providers
We do not sell your personal data. We may share personal data only in the following circumstances:
- Service Providers & Subprocessors: With hosting providers (e.g., OVH) and AI service providers (such as OpenAI and other providers we may use from time to time) that process data on our behalf. These providers are bound by strict data processing agreements and are prohibited from using Platform Data for their own purposes.
- Connected Platforms: With platforms like Meta/Instagram, to the extent required to provide the Service.
- Legal Requests: If required by a court order, law enforcement, or to defend against legal claims, we may disclose necessary data, adhering to data minimization principles.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, user data may be transferred to the acquiring entity under the same privacy commitments.
7. Security Measures & Data Breaches
We implement robust technical and organizational measures to protect personal data, including encryption in transit (HTTPS/TLS), encryption at rest for sensitive data, and strict access controls. We continuously monitor for vulnerabilities. In the event of a data breach that poses a risk to your rights, we will notify you and the relevant supervisory authorities in accordance with applicable laws.
8. International transfers
Wesend may process personal data in the UK, EEA, US, and other locations where Wesend or its service providers operate. Where personal data is transferred internationally, we utilize recognized transfer safeguards such as adequacy regulations, Standard Contractual Clauses (SCCs), or the UK Addendum.
9. Retention & User Data Deletion
We retain personal data only for as long as reasonably necessary to fulfill the purposes outlined in this policy, comply with legal obligations, and resolve disputes.
User Data Deletion: Users have the right to request the complete deletion of their account and associated data. You can delete your data, manage your Connected Platforms, or revoke our access to Meta/Instagram via your account dashboard or by strictly following the data deletion instructions provided at: https://www.wesend.chat/user-data-deletion.html.
10. Your rights
Depending on your jurisdiction (e.g., GDPR, CCPA), you have the right to access, correct, delete, restrict, port, object to certain processing, or withdraw consent regarding your personal data. If Wesend acts as a Processor for a customer’s end-user data, we will direct your request to the relevant customer (the Controller).
11. Cookies Policy
Our Website uses cookies and similar tracking technologies to ensure core functionality, analyze website traffic, and improve user experience. Where required by law, we obtain your consent before placing non-essential cookies. We do not use cookies to track personally identifiable information for unaffiliated third-party advertising. You can manage your cookie preferences through your browser settings.
12. Children
The Service is intended for business use. We do not knowingly collect personal data from children under 18 (or under the age required by applicable law in your jurisdiction, such as 16 under GDPR). If we become aware of such collection, we will take steps to delete the information immediately.
13. Contact and complaints
For privacy questions, access requests, or to exercise your rights, please contact us at: [email protected]
WESEND LTD
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, legal obligations, or business practices. The updated version will be published on this page together with the revised "Last Updated" date. Where required by applicable law, we will provide additional notice of material changes.