Privacy Policy
Arino One provides business-to-business (B2B) services to companies worldwide. We are established in the European Union with an EU-based team, and we apply GDPR-grade data protection to every instance regardless of where the customer is located. This Policy does not apply to consumer users.
This Privacy Policy explains how Arino One Tech Experts Limited ("Arino One," "we," "our," or "us") collects, uses, shares, and safeguards personal data when providing services, including our WhatsApp Business API solutions, analytics services, and website functionality.
1Controller Information
Landscape House, Brownsbarn, Baldonnell, Co. Dublin, D22 P3K7, Ireland
Company Registration Number: 789699
Sales: hello@arino.one
Support: hello@arino.one
Partnerships: hello@arino.one
Security: hello@arino.one
Legal & Privacy: legal@arino.one
Data Protection Officer: dpo@arino.one
Tel: +44 7860 089353 (WhatsApp)
We act as a Data Controller under GDPR where applicable. When processing Personal Data on behalf of our business customers, we act as a Data Processor under the terms of our Data Processing Agreement (see our Terms of Service, Section 9).
2Data We Collect
We may collect the following categories of information:
- WhatsApp Business Data — Phone numbers, message content, metadata (timestamps, delivery status), and identifiers necessary for communication.
- Client Analytics Data — Usage metrics, engagement reports, and aggregated insights to support business decision-making.
- Website & Tracking Data — Cookies, device identifiers, IP addresses, and browsing behaviour via Google Analytics and Meta Pixel. See Section 3 for cookie details.
- Business Contact Information — Names, emails, and phone numbers provided voluntarily for support, partnerships, or sales inquiries.
- Authentication Data — Phone numbers and encrypted authentication credentials (including TOTP secrets) used to verify user identity when accessing the Platform.
3Cookies & Tracking Technologies
Our website uses cookies and similar tracking technologies. When you first visit, a cookie consent banner allows you to choose your preferences.
- Strictly Necessary Cookies — Required for site functionality, authentication, and security. These cannot be disabled.
- Analytics Cookies — Google Analytics, used to understand site usage, visitor behaviour, and improve our services. Data is anonymised where possible.
- Marketing Cookies — Meta Pixel, used for remarketing and measuring the effectiveness of advertising campaigns on Meta platforms.
You can manage your cookie preferences at any time using the cookie settings available on our website, or by adjusting your browser settings. Withdrawing consent for analytics or marketing cookies will not affect the functionality of our platform.
4Purpose of Processing
We process data for the following purposes:
- Delivering and managing WhatsApp Business Platform services in compliance with Meta's Developer Platform Terms
- Providing analytics to clients
- Improving, monitoring, and securing our platform
- Meeting legal obligations, including data retention and security requirements
- Marketing and remarketing through cookies, where lawful consent has been obtained
- Authenticating users and maintaining platform security
5Legal Basis (GDPR)
Processing is based on:
- Contractual necessity: To deliver WhatsApp and analytics services
- Legitimate interests: Platform improvement, security, analytics
- Consent: Cookies, marketing communications
- Legal obligations: Record-keeping, compliance with Meta policies, Irish Revenue requirements
6Sharing & Authorised Sub-Processors
We do not sell personal data.
Data may be disclosed to the following authorised sub-processors and service providers, each bound by data processing agreements:
- Meta Platforms Ireland Limited — WhatsApp Business Platform infrastructure, message routing, and delivery
- Infobip Ltd. — Messaging infrastructure and message routing services
- Stripe, Inc. — Payment processing and billing data management
- SMSAdvert — SMS fallback messaging services
- Google LLC — Google Analytics for website analytics (anonymised data)
- Meta Platforms, Inc. — Meta Pixel for advertising measurement
- Legal and regulatory authorities where required by law
We will notify customers of any changes to sub-processors with at least 30 days' notice, providing an opportunity to object. A full list of current sub-processors is available upon request to legal@arino.one.
7Data Retention
We retain data according to the following schedule, aligned with our Terms of Service (Section 9):
- Message Data: Retained for 12 months following the date of the message, then securely deleted or anonymised
- Account Data: Retained for the duration of the Agreement and 30 days following termination
- Analytics & Aggregated Data: Anonymised and aggregated analytics data may be retained indefinitely for platform improvement
- Financial & Billing Records: Retained for a minimum of 7 years per Irish Revenue requirements
- Consent Records: Retained for a minimum of 3 years following the last relevant consent event
- Authentication Data: Retained for the duration of the account and securely deleted within 30 days of account termination
8Data Security
We implement industry-standard administrative, technical, and physical safeguards, including encryption in transit and at rest, role-based access controls, data-flow logging, and periodic penetration testing in line with Meta Platform Terms and GDPR Article 32. A summary of testing outcomes is available to enterprise customers under NDA.
9Your Rights Under GDPR
Under GDPR, you have the right to:
- Access and obtain a copy of your personal data (Article 15)
- Rectify inaccurate or incomplete information (Article 16)
- Request erasure of your personal data (Article 17)
- Restrict or object to processing (Articles 18 & 21)
- Port your data in a machine-readable format (Article 20)
- Withdraw consent at any time (where applicable)
- Lodge a complaint with a supervisory authority
You also have the right to lodge a complaint with the Irish Data Protection Commission (DPC), 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland. Website: www.dataprotection.ie
10Data Deletion & Erasure Requests
Arino One provides a dedicated self-service erasure flow for the GDPR right to erasure (Article 17) and for Meta's data-deletion requirements. The form is the canonical way to request deletion:
Accessibility fallback. If you cannot use the form, email our Data Protection Officer at dpo@arino.one with the words "Data Deletion" in the subject line and we will process the request manually.
11International Data Transfers
Where data is transferred outside the European Economic Area, appropriate safeguards such as Standard Contractual Clauses (SCCs) under Article 46(2)(c) GDPR are implemented. Details of applicable transfer mechanisms are available upon written request to legal@arino.one.
12Children's Privacy
Our services are not directed to individuals under 16. We do not knowingly process children's personal data.
13Updates to this Policy
We may update this Privacy Policy from time to time. Material changes will be notified by updating the "last updated" date and, where appropriate, direct communication.
Questions about your data? Contact our Data Protection Officer at dpo@arino.one.