X
X
WhatsApp

Privacy Policy for Atarix Meta Gateway

Privacy Policy for Atarix Meta Gateway

# Privacy Policy — Atarix Meta Gateway

**Effective Date:** April 24, 2026  
**Last Updated:** April 24, 2026  
**Company:** Atarix Ltd.  
**Website:** [https://www.atarix.co.il/](https://www.atarix.co.il/)  
**Contact Email:** [email protected]  

---

## 1. Introduction

Welcome to the Atarix Meta Gateway (the "Service," "Platform," or "we/us/our"). The Atarix Meta Gateway is a multi-tenant API integration platform operated by **Atarix Ltd.**, an Israeli technology company. This platform connects businesses ("Tenants" or "Clients") to Meta's APIs — specifically the **WhatsApp Business Platform** and the **Facebook Graph API** — for the purpose of business messaging, page management, and lead generation.

This Privacy Policy explains how we collect, use, store, share, and protect data when you interact with the Atarix Meta Gateway, whether you are:
- A **Tenant** (a business that connects its Meta assets through our platform)
- An **End User** (a person who sends messages to, receives messages from, submits lead forms to, or interacts with a Tenant's Facebook Page or WhatsApp number through our platform)
- A **Visitor** to our website at [https://www.atarix.co.il/](https://www.atarix.co.il/)

This policy is designed to comply with **Meta's Platform Terms**, **Meta's Developer Policies**, the **Israeli Privacy Protection Law, 5741-1981**, and applicable international data protection regulations including the **EU General Data Protection Regulation (GDPR)** where applicable.

---

## 2. Data Controller & Data Processor Roles

- **Atarix Ltd.** acts as a **Data Processor** on behalf of each Tenant. We process data as instructed by the Tenant and in accordance with this policy and our service agreements.
- Each **Tenant** (the business using the Atarix Meta Gateway) acts as the **Data Controller** for data related to their own end users, customers, and Facebook/WhatsApp interactions.
- For data relating to Tenant account management (Tenant contact details, billing, API keys), **Atarix Ltd.** acts as the Data Controller.

---

## 3. Information We Collect

### 3.1 Tenant Information (Collected Directly)

When a business registers as a Tenant on the Atarix Meta Gateway, we collect:

| Data Type | Examples | Purpose |
|-----------|----------|---------|
| **Business identity** | Company name, business registration number | Tenant account creation and identification |
| **Contact details** | Admin name, email address, phone number | Account management, support, notifications |
| **API credentials** | API keys (stored as SHA-256 hashes) | Authentication and authorization |
| **Meta asset identifiers** | WhatsApp Business Account ID (WABA ID), Phone Number IDs, Facebook Page IDs | Routing messages, webhooks, and API calls to the correct Tenant |
| **Meta access tokens** | Business Integration System User (BISU) tokens, Page Access Tokens | Making API calls to Meta on the Tenant's behalf |

### 3.2 WhatsApp Messaging Data (Processed on Behalf of Tenants)

When messages are sent or received through a Tenant's WhatsApp Business number via our platform, we process:

| Data Type | Examples | Purpose |
|-----------|----------|---------|
| **Message content** | Text messages, media URLs, template message parameters | Routing messages between the Tenant and Meta's WhatsApp Cloud API |
| **Message metadata** | Message IDs, timestamps, delivery/read status | Status tracking, deduplication, audit logging |
| **Sender/recipient identifiers** | Phone numbers (`wa_id`), Business-Scoped User IDs (`bsuid`) | Message routing and delivery |
| **Template data** | Template names, categories, approval status, language codes | Template management on behalf of Tenants |

### 3.3 Facebook Page Data (Processed on Behalf of Tenants)

When Tenants connect their Facebook Pages, we process:

| Data Type | Examples | Purpose |
|-----------|----------|---------|
| **Page metadata** | Page ID, Page name | Identifying the connected asset |
| **Post content** | Text, images, links published via the Gateway | Publishing posts to the Tenant's Page on their behalf |
| **Engagement data** | Post engagement metrics (likes, comments, shares) | Providing engagement data to Tenants via API |
| **Lead Ads submissions** | Lead form fields (name, email, phone number, custom fields) submitted by end users | Ingesting and routing lead data to the Tenant's internal systems |

### 3.4 Technical & Operational Data

| Data Type | Examples | Purpose |
|-----------|----------|---------|
| **API request logs** | Request IDs, endpoints called, response codes, timestamps | Troubleshooting, monitoring, audit trails |
| **Webhook delivery logs** | Webhook event types, delivery status, retry counts | Ensuring reliable event delivery |
| **Error logs** | API error codes, failure reasons | Debugging and system health |

### 3.5 Data We Do NOT Collect

- We do **not** collect data from End Users directly — all End User data flows through Meta's APIs and is processed on behalf of the Tenant.
- We do **not** use cookies, tracking pixels, or analytics trackers on the Meta Gateway API itself (it is an API-only service with no end-user-facing UI).
- We do **not** collect financial or payment information from End Users. Payment methods for WhatsApp Business Accounts are handled directly by Meta during the Embedded Signup process.

---

## 4. How We Use Your Information

We use the collected data **strictly** to provide the Atarix Meta Gateway service. Specifically:

### 4.1 For Tenants

- **WhatsApp Embedded Signup:** Facilitating the secure connection of Tenant WhatsApp Business Accounts and phone numbers via Meta's Embedded Signup flow.
- **Message routing:** Sending and receiving WhatsApp messages on the Tenant's behalf via Meta's WhatsApp Cloud API.
- **Template management:** Creating, updating, deleting, and tracking the approval status of WhatsApp message templates.
- **Facebook Page publishing:** Publishing posts (text, images, links) to the Tenant's connected Facebook Pages.
- **Lead Ads ingestion:** Receiving lead form submissions from Facebook Lead Ads via webhooks and routing them to the Tenant's internal systems (CRM, Podium, etc.).
- **Event subscriptions:** Delivering real-time events (incoming messages, message status updates, new leads) to Tenant-registered webhook endpoints.
- **Monitoring & support:** Diagnosing API errors, monitoring system health, and providing technical support.
- **Audit logging:** Maintaining audit trails of all operations for security and compliance purposes.

### 4.2 For End Users

We process End User data (message content, phone numbers, lead form submissions) **only** as a Data Processor acting on behalf of the Tenant. We do not independently use, analyze, profile, or monetize End User data.

### 4.3 What We Do NOT Do With Your Data

- ❌ We do **not** sell, rent, lease, or trade your data or your customers' data to any third party.
- ❌ We do **not** use your data for advertising or marketing purposes.
- ❌ We do **not** use your data to train machine learning models or AI systems.
- ❌ We do **not** share data between Tenants. Each Tenant's data is completely isolated.
- ❌ We do **not** contact End Users directly for any purpose.

---

## 5. Legal Basis for Processing

We process personal data based on the following legal grounds:

| Legal Basis | Applies To |
|-------------|-----------|
| **Contractual necessity** | Processing Tenant data to fulfill our service agreement |
| **Legitimate interest** | Operational logging, security monitoring, fraud prevention |
| **Consent** | End Users consent to share data when they message a Tenant's WhatsApp number or submit a lead form (consent is given to the Tenant, not to Atarix) |
| **Legal obligation** | Retention of records as required by Israeli law |

---

## 6. Data Sharing & Disclosure

### 6.1 Sharing With Tenants

Data generated by a Tenant's connected Meta assets (WhatsApp messages, lead submissions, page engagement) is routed **exclusively** to that specific Tenant. No other Tenant can access or view this data.

### 6.2 Sharing With Meta (Facebook/WhatsApp)

When Tenants use the Gateway to send messages or publish posts, we transmit the necessary data to Meta's APIs (WhatsApp Cloud API, Facebook Graph API) as required to complete the requested action. This is inherent to the service.

### 6.3 Infrastructure Providers

We use the following third-party infrastructure providers to host and operate the Gateway:

| Provider | Service | Data Processed | Location |
|----------|---------|----------------|----------|
| **Amazon Web Services (AWS)** | Compute (ECS/Fargate), Database (RDS PostgreSQL), Queue (SQS), Key Management (KMS), Secret Management (Secrets Manager), Caching (ElastiCache) | All platform data | AWS eu-west-1 (Ireland) or as agreed with Tenant |

AWS acts as a sub-processor and is subject to their own data processing agreements and SOC 2 / ISO 27001 certifications.

### 6.4 Legal Requirements

We may disclose information if required to do so by:
- Israeli law or court order
- A valid request by Israeli or international public authorities (e.g., law enforcement)
- To protect the rights, property, or safety of Atarix Ltd., our Tenants, or others

### 6.5 Business Transfers

In the event of a merger, acquisition, or sale of all or a portion of our assets, Tenant data may be transferred to the acquiring entity. We will notify affected Tenants before any such transfer.

---

## 7. Data Security

We implement industry-standard security measures to protect data against unauthorized access, alteration, disclosure, or destruction:

### 7.1 Encryption

| Layer | Method |
|-------|--------|
| **Data in transit** | TLS 1.2+ (HTTPS) for all API communication |
| **Data at rest** | AES-256 encryption on all database storage (AWS RDS) |
| **Access tokens** | Encrypted using AWS KMS envelope encryption before storage. Never stored in plaintext. |
| **API keys** | Stored as SHA-256 hashes. Original key shown only once at creation. |
| **Secrets** | Stored in AWS Secrets Manager with automatic rotation support |

### 7.2 Access Control

- Multi-tenant data isolation via PostgreSQL **Row-Level Security (RLS)** — every database query is automatically scoped by `tenant_id`
- API authentication via scoped API keys with granular permissions
- System User access restricted to authorized operations only
- All administrative access logged in audit trails

### 7.3 Webhook Security

- All incoming Meta webhooks are verified via **HMAC-SHA256 signature verification** using the App Secret
- All outgoing webhooks to Tenant systems are signed with a shared secret for verification
- Webhook payloads are processed asynchronously to prevent data loss

### 7.4 Infrastructure Security

- VPC network isolation on AWS
- Security groups restricting database access to application layer only
- No direct public internet access to database or cache instances
- Regular security patching and updates
- CloudWatch monitoring and alerting for anomalous activity

---

## 8. Data Retention

| Data Type | Retention Period | Rationale |
|-----------|-----------------|-----------|
| **Tenant account data** | Duration of service agreement + 12 months | Contractual and legal requirements |
| **Meta access tokens** | Until revoked, expired, or Tenant disconnects | Required for ongoing API access |
| **Message content (WhatsApp)** | 30 days after processing | Operational troubleshooting; Tenants receive data in real-time via webhooks |
| **Message metadata & status** | 90 days | Delivery tracking and audit |
| **Lead Ads data** | 30 days after delivery to Tenant | Operational backup; Tenants receive data in real-time |
| **API request logs** | 90 days | Monitoring and troubleshooting |
| **Audit logs** | 24 months | Security and compliance |
| **Webhook delivery logs** | 30 days | Delivery verification and retry tracking |

After the retention period, data is permanently deleted from all systems including backups within 30 days.

Tenants may request shorter retention periods in their service agreement. We accommodate custom retention policies.

---

## 9. Data Subject Rights

### 9.1 For Tenants

As a Tenant, you have the right to:
- **Access** all data associated with your account via the Gateway API
- **Export** your data at any time via the API
- **Delete** your account and all associated data (see Section 10)
- **Restrict** processing by suspending your account
- **Object** to specific processing activities by contacting us

### 9.2 For End Users

End Users who interact with a Tenant's WhatsApp number or Facebook Page should direct data access, correction, and deletion requests to the **Tenant** (the business they are interacting with), as the Tenant is the Data Controller.

If an End User contacts Atarix directly, we will:
1. Identify the relevant Tenant
2. Forward the request to the Tenant
3. Assist the Tenant in fulfilling the request in accordance with applicable law

### 9.3 How to Exercise Your Rights

Contact us at:
- **Email:** [email protected]
- **Website:** [https://www.atarix.co.il/](https://www.atarix.co.il/)
- **Mail:** Atarix Ltd., האורנים 18, קריית ביאליק, Israel

We will respond to all requests within 30 days.

---

## 10. User Data Deletion

### 10.1 Tenant-Initiated Deletion

Tenants can request complete deletion of their data by:

1. **Via API:** Call `DELETE /v1/tenants/{tenant_id}` with admin authentication
2. **Via Email:** Send a request to **[email protected]** with the subject line: **"Data Deletion Request — Meta Gateway"**
3. **Via the Atarix Dashboard:** Navigate to Settings → Data Management → Request Deletion *(when available)*

Upon receiving a valid deletion request, we will:
- Revoke all Meta API tokens associated with the Tenant
- Delete all stored messages, leads, and webhook data
- Delete all encrypted credentials
- Remove the Tenant record and all associated metadata
- Complete the deletion within **30 days**
- Send confirmation to the Tenant's registered email

### 10.2 End User Data Deletion

End Users who wish to delete their data should:

1. **Contact the Tenant (business) directly** — the Tenant is the Data Controller and is responsible for honoring data deletion requests
2. If the Tenant instructs us to delete specific End User data, we will do so within **14 days**
3. Alternatively, End Users can **remove the app from their Facebook account:**
   - Go to Facebook **Settings & Privacy → Settings → Business Integrations**
   - Find the **Atarix Meta Gateway** app → Click **"Remove"**
   - This revokes the app's access to the user's data

### 10.3 Meta Deauthorize Callback

When a user removes the Atarix Meta Gateway app from their Facebook account, Meta sends a deauthorization callback to our endpoint. Upon receiving this callback, we:
- Log the deauthorization event
- Revoke any tokens associated with the user
- Notify the relevant Tenant

### 10.4 Meta Data Deletion Request

When Meta receives a data deletion request from a user, Meta forwards the request to our registered data deletion endpoint. Upon receiving this request, we:
- Identify all data associated with the requesting user across all Tenants
- Delete or anonymize the data within **30 days**
- Return a confirmation URL and status code to Meta per their requirements

---

## 11. International Data Transfers

Atarix Ltd. is based in **Israel**, which has been recognized by the European Commission as providing an adequate level of data protection (Adequacy Decision 2011/61/EU).

Data may be processed in AWS data centers located in the **EU (Ireland, eu-west-1)** or other regions as specified in the Tenant's service agreement. All transfers are protected by:
- AWS Data Processing Addendum (DPA)
- Standard Contractual Clauses (SCCs) where required
- Encryption in transit and at rest

---

## 12. Children's Privacy

The Atarix Meta Gateway is a B2B service designed for business use. We do not knowingly collect or process data from children under the age of 16. If we become aware that we have inadvertently collected data from a child, we will delete it promptly.

---

## 13. Third-Party Links & Services

The Atarix Meta Gateway integrates with Meta's platforms (Facebook, WhatsApp). These platforms have their own privacy policies:
- **Meta (Facebook) Privacy Policy:** [https://www.facebook.com/privacy/policy/](https://www.facebook.com/privacy/policy/)
- **WhatsApp Privacy Policy:** [https://www.whatsapp.com/legal/privacy-policy](https://www.whatsapp.com/legal/privacy-policy)

We are not responsible for the privacy practices of Meta or any other third-party service.

---

## 14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Meta's platform policies. When we make material changes:
- We will update the **"Last Updated"** date at the top of this page
- We will notify Tenants via email at their registered email address
- We will post the updated policy at [https://www.atarix.co.il/privacy-policy/meta-gateway](https://www.atarix.co.il/privacy-policy/meta-gateway)

Continued use of the Service after changes are posted constitutes acceptance of the updated policy.

---

## 15. Contact Us

For any questions, concerns, or requests related to this Privacy Policy or our data practices:

**Atarix Ltd.**  
**Email:** [email protected]  
**Website:** [https://www.atarix.co.il/](https://www.atarix.co.il/)  
**Privacy Policy URL:** [https://www.atarix.co.il/privacy-policy/meta-gateway](https://www.atarix.co.il/privacy-policy/meta-gateway)

For urgent privacy matters, please include **"URGENT — Privacy"** in your email subject line.

---

## 16. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the **State of Israel**, without regard to its conflict of law principles. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts of Tel Aviv-Jaffa, Israel.

---

*This Privacy Policy was last reviewed on April 24, 2026.*

האתרים והמערכות שלנו

quotes

אתריקס פיתחו עבורנו מערכת לניהול חדרים במכללה ברמה גבוהה. ניהול וליווי של כל העוסקים במלאכה בצורה מצויינת. תודה רבה ממכללת אורט הרמלין.

אדווה אבן ימין קטלןאורט הרמלין נתניה

quotes

החלפנו מערכות כיוון שהיינו במקום פחות נגיש ומתקדם, כאן באקטיבטק הכל מאוד נגיש, ברור ומבחר האפשרויות רב ועצום למגוון החוגים הן בגבייה לחוגים והן בגבייה להסעות ומכירת כרטיסים וכל מה שנרצה.

לימור קבוצת הכדורסל עירוני נהריה

quotes

צוות אתריקס המונה גרפיקאים, מנהלי תוכן, מנהלי פרסום דגיטלי ומתכנתים, מייצרים תהודה אדירה לפעילות המרכזים הקהליתיים ברשת וחשיפה חסרת תקדים בהקפה לפעילות החברה.

החברה למתנסים