This Privacy Policy explains how the coordinator CRM service provided by Gepgo collects, uses, stores and protects personal data. By using our service or our WhatsApp integration you accept this policy.
1. Who we are
Gepgo is a CRM solution that lets clinics and businesses manage customer communication and workflow. To provide messaging through the WhatsApp Business Platform (Meta) we act as a Tech Provider and manage, on their behalf, the WhatsApp Business Accounts (WABA) that our clients (businesses) authorise us to access.
2. Data we collect
- Account information: name, email, phone, business/clinic name, user roles.
- WhatsApp data: the WhatsApp Business Account (WABA) ID connected via Embedded Signup, the phone number ID and display number; incoming and outgoing message content, sender profile name and phone number, message timestamps and status information.
- Customer/lead data: contact records created from conversations (name, phone, notes, status).
- Technical data: usage logs, device/session information, error logs.
3. WhatsApp / Meta integration
Our clients grant us access to their WhatsApp Business assets through Meta's Embedded Signup flow. With that authorisation we use the following Meta permissions:
| Permission | Purpose |
|---|---|
| whatsapp_business_management | Access the client's WABA and phone numbers, subscribe to webhooks, manage templates. |
| whatsapp_business_messaging | Send and receive WhatsApp messages on behalf of the client's number. |
Processing of data transmitted over WhatsApp is also subject to Meta's own policies.
4. How we use data
- To display incoming WhatsApp messages in the CRM and assign them to the relevant department or lead.
- To let the business's staff reply to customers through the CRM.
- To provide, improve and secure the service and to meet legal obligations.
We do not sell data for advertising or transfer it to third parties for marketing.
5. Data sharing
- Meta Platforms: to deliver messages via the WhatsApp Cloud API.
- Google Firebase / Google Cloud: for hosting, database and server functions (our infrastructure provider).
- Legal authorities: where legally required.
6. Retention
We keep data only for as long as it is needed to provide the service, or for the periods required by law. When a business ends the service or requests it, the relevant data is deleted within a reasonable time.
7. Data deletion requests
You may request deletion of your data:
- Email: support.gepgo@gmail.com
- Automated data deletion endpoint:
https://europe-west1-izlemeta-bceb7.cloudfunctions.net/whatsappDataDeletion
8. Your rights (KVKK / GDPR)
Under applicable law you have the right to access, correct and delete your data, and to restrict or object to its processing. Contact us to exercise these rights.
9. Security
We take reasonable technical and administrative measures to protect data against unauthorised access (access control, encrypted transport, credentials stored server-side). No method is 100% secure.
10. Changes
We may update this policy from time to time. The current version is always published on this page.