Privacy Policy
This privacy policy describes how Butterfly Foundation & Agency ("we", "us",
"our"), the operator of the BFA Notify platform at
notify.bfa.zone, collects, uses, stores, and protects
personal data. BFA Notify is a WhatsApp Business messaging platform
that lets businesses send messages to their own customers using the
official WhatsApp Cloud API provided by Meta Platforms, Inc.
1. Who we are
BFA Notify is owned and operated by Butterfly Foundation & Agency, a business based in Erbil, Kurdistan Region, Iraq. Contact details are listed at the bottom of this page and on our Contact page.
The WhatsApp Business Accounts and phone numbers used by this platform are held in the verified Meta business portfolio of Brivan ADV, a Butterfly Foundation & Agency company. Butterfly Foundation & Agency is the entity responsible for personal data processed through BFA Notify.
2. Who uses this platform
BFA Notify is a business-to-business (B2B) product. Two distinct audiences interact with it:
- Business customers — organizations (hospitals, clinics, banks, universities, schools, malls, restaurants, delivery companies, tourism operators, etc.) that sign up for an account on BFA Notify and use it to send WhatsApp messages to their own end-users.
- End-recipients — the people who receive WhatsApp messages sent through BFA Notify by a business customer. These people are the business customer's own contacts. BFA Notify acts as a data processor on behalf of the business customer when handling these messages.
3. What data we collect
3.1 From business customers (the account holder)
- Business name, admin name, work email address, and a password (stored hashed using bcrypt).
- WhatsApp Business Account credentials that the business customer provides to connect their own WhatsApp Cloud API number — namely: Phone Number ID, WhatsApp Business Account (WABA) ID, and a permanent access token. The access token is encrypted at rest using AES-256 with a per-installation encryption key.
- Team members added by the admin (name, email, role).
- Balance and billing events (top-ups, deductions, refunds).
- API keys generated by the business customer to integrate their own systems with our platform.
- Audit log entries — IP address, action type, target, and timestamp of important account activity (login, contact create/delete, template create/delete, settings changes, balance changes, etc.).
3.2 From end-recipients (the people receiving messages)
- Phone number (in E.164 international format).
- Display name (only if the business customer provides one).
- Custom fields the business customer chooses to attach to a contact (for example, a customer ID, order number, or appointment date).
- Message content sent through the platform — including the template name, language, variables filled in, and the resulting full text of the WhatsApp message.
- WhatsApp delivery status events received from Meta for each message we send (sent / delivered / read / failed) and any failure reason Meta reports.
- If an end-recipient replies via WhatsApp, Meta notifies our webhook. We record only the sender's phone number and the time of the reply, so that the business customer can see that a 24-hour customer service window is open for that contact. We do not read or store the content of replies.
3.3 What we do NOT collect
- We do not buy or sell personal data.
- We do not run advertising trackers or third-party analytics on this platform.
- We do not collect end-recipient data independently — we only process what the business customer uploads or what Meta sends us via the WhatsApp webhook for messages already routed through our system.
- We do not share data between business customers — each business's contacts, templates, messages, and balance are isolated by tenant ID.
4. How we use this data
We process the data described above for the following purposes:
- To deliver the service. Routing WhatsApp messages through Meta's Cloud API on behalf of the business customer, recording delivery status, and showing it back to the customer in their dashboard.
- Authentication. Letting the business customer's admin, manager, and staff sign in and use the platform.
- Billing. Deducting message costs from the customer's balance and providing a ledger of every charge and refund.
- Security and abuse prevention. Logging IP addresses and sensitive actions in the audit log so the customer can investigate suspicious activity; rate-limiting and blocking abusive behaviour.
- Customer support. Diagnosing problems reported by a business customer with their permission.
We do not use end-recipient phone numbers or message content for any purpose other than fulfilling the message-sending request from the business customer that uploaded them.
5. Lawful basis
For business customers, our lawful basis is the contract between us and them (the Terms of Service) and our legitimate interest in operating the platform securely.
For end-recipients, the lawful basis is consent obtained by the business customer (under WhatsApp Business policies, every recipient must have opted in to receive messages from that business before any message is sent through this platform). Butterfly Foundation & Agency is a data processor in this relationship — the business customer is the data controller and is responsible for collecting and recording that consent.
6. WhatsApp data & OTP messages
When a business customer sends a WhatsApp message through this platform, we transmit the recipient's phone number and the message body to Meta Platforms, Inc. via the WhatsApp Cloud API. Meta delivers the message and returns a delivery status. The phone number, message body, and status are stored in our database so that the business customer can see a record of the conversation and so we can correctly bill the message.
One-time passcodes (OTP) sent through Authentication templates are treated like any other message body — they are stored in our database so that audit and delivery records remain complete. OTP codes are not inspected or used by Butterfly Foundation & Agency for any purpose, and they are not sold, shared, or used to enrich any other profile.
7. Retention
- Account data (business customer accounts and team members): kept while the account is active. Closing an account suspends access; the underlying data is retained until deletion is requested — see Section 9.
- Contacts uploaded by the business customer: kept while the business customer keeps them in their contact list; deleted when the customer deletes them, or when their account is deleted.
- Message records (template name, body, phone number, status, timestamps): retained for billing, audit and dispute resolution for as long as the account exists, and deleted when the account is deleted.
- Audit log entries: retained for the life of the account so that the customer's own admin can review historic activity.
- Deletion is carried out on request, and removes the account's contacts, message records, templates, team members, audit entries and stored WhatsApp credentials. See our Data Deletion page for how to ask.
8. Storage and security
- Data is stored on servers operated under our control, with database access restricted to a small number of authorized personnel.
- Passwords are hashed using bcrypt.
- WhatsApp access tokens are encrypted at rest using AES-256 with a per-installation encryption key.
- All connections to the platform are encrypted in transit using TLS (HTTPS).
- Each business customer's data is logically isolated by tenant ID — one business cannot see another's contacts, messages, templates, team members, or balance.
- We log all sensitive actions (login, settings changes, template changes, balance changes) in an audit trail visible to the admin of the business customer.
9. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Delete your data — see our Data Deletion page for instructions.
- Restrict or object to certain processing.
- Withdraw consent at any time for processing based on consent.
- Export your data in a portable format on request.
To exercise any of these rights, contact us at the email address listed at the bottom of this page. We respond within 30 days.
10. Third parties we use
We share data only with third parties strictly necessary to deliver the service:
- Meta Platforms, Inc. — to deliver WhatsApp messages through the official WhatsApp Cloud API. Phone numbers and message content are transmitted to Meta. See WhatsApp's Privacy Policy.
- Hetzner Online GmbH (Germany) — our infrastructure provider. Hosts the application server and database on which the platform runs. No data is shared beyond what is needed to host the service.
- Google LLC (United States) — machine translation. When a business customer uses the built-in translation helper to produce a message template in another language, the template text is sent to the Google Translate API. Contact data and message logs are never sent to this service.
- Hostinger (Lithuania) — outgoing email. Delivers account verification and administrative notification emails. These contain account holders' names, email addresses and message template names. Recipient phone numbers and message content are never sent by email.
- Payment providers — PayPal, FIB (First Iraqi Bank) and Heleket, used to process balance top-ups. They receive only the payment amount, currency and an internal order reference. No contact data, phone numbers or message content are shared with them.
- Google Fonts — web fonts are loaded from Google's font CDN when you view our pages, which makes your browser's IP address visible to Google. No account or message data is transmitted.
We do not sell or rent personal data to any third party.
11. Children
BFA Notify is intended for business use. We do not knowingly collect data about anyone under 16. If a business customer uploads contact details for a recipient under 16 (for example, a parent's number stored on a school account), it is the business customer's responsibility to have lawful consent. If we discover we hold data about a child without a lawful basis, we delete it.
12. International transfers
Butterfly Foundation & Agency is based in Iraq, but the platform's data is processed outside Iraq:
- Our application server and database are hosted in Germany by Hetzner Online GmbH. This is where contacts, message logs and account records are stored.
- Message content and recipient phone numbers are transmitted to Meta Platforms, Inc. to deliver WhatsApp messages, in line with Meta's published data handling.
- Template text sent through the translation helper is processed by Google LLC in the United States.
- Account and administrative emails are delivered via Hostinger in Lithuania.
We do not transfer personal data to any recipient other than those listed in Section 10.
13. Changes to this policy
We may update this policy from time to time. When we do, we update the "Last updated" date at the top of this page and, if the changes are material, we notify the admin email on each affected account at least 14 days before the changes take effect.
14. Contact
If you have any question about this privacy policy or about the personal data we hold, contact us:
Butterfly Foundation & Agency
Sultan Muzaffar Street, Alassadi Mall, Ground floor 18th
Erbil, Kurdistan 44001
Iraq
Email: notify@bfa.zone
Phone: +964 750 222 6141
Website: https://notify.bfa.zone