Privacy policy
Inventtify Connect is a platform that lets businesses serve their customers on WhatsApp, Instagram and Messenger from a single inbox, and connect their own systems (online store, ERP, CRM, AI agents) to those channels through an API. This policy explains what data we process, why, and how you can exercise your rights, in accordance with Colombian Law 1581 of 2012 and Decree 1377 of 2013. The Spanish version prevails in case of discrepancy.
1. Controller
Inventtify ("Inventtify", "we"), based in Medellín, Colombia.
- Privacy contactcontacto@inventtify.com
- Websiteconnect.inventtify.app
2. Our role depending on the data
- Data about the businesses that use Connect (account, users, settings): Inventtify is the controller.
- Data about the people who message those businesses on WhatsApp, Instagram or Messenger: the business is the controller and Inventtify acts as a processor, processing that data only on the business's behalf and following its instructions. If you messaged a business and want to exercise your rights, you can contact that business or us; we will forward your request to the business where appropriate.
3. Data we process
About businesses
- Business name, panel users and contact details.
- Connected channel data: WhatsApp phone number and its ID, WhatsApp Business Account, Instagram professional account, Facebook Page, and the access tokens Meta issues when they are connected.
- Connect API credentials (we only store a hashed fingerprint of the key, never the key itself) and the URL where the business wants to receive events.
- Message templates created from the panel.
About people who message businesses
- Channel identifier: phone number (WhatsApp), Instagram or Messenger scoped ID, and the public profile name or username.
- Content of messages sent and received (text, and links or references to images, audio, documents and other attachments), their date, and their delivery and read status.
- Organization data added by the business: contact name, tags and conversation status.
Technical
- Operational and security logs (for example, IP address and time of API requests) to run the service and prevent abuse.
4. How we use it
- To receive and display customer messages in the business's inbox, and to send the replies and notifications the business decides to send.
- To deliver those messages and events to the systems the business itself connects (its store, ERP, CRM or AI agent).
- To create and manage message templates on behalf of the business.
- To operate, secure and support the platform, and to comply with legal obligations.
We do not sell personal data, we do not use it for advertising, and we do not use conversation content to train artificial intelligence models.
5. Data we receive from Meta platforms
When a business connects its WhatsApp, Instagram or Messenger, Meta provides the data needed to operate those channels (messages, identifiers, delivery statuses and the business's access tokens). We use it solely to provide the service to that business, in accordance with the Meta Platform Terms and WhatsApp Business policies. We do not combine it with other businesses' data or share it with third parties beyond what this policy describes. A business can disconnect a channel at any time; when it does, we delete its access token.
7. Retention
- Conversations and contacts: while the business's account is active, or until the business or the data subject requests deletion.
- Channel access tokens: until the business disconnects the channel.
- When an account is cancelled we delete its data within 30 days; backups are overwritten within up to 30 additional days.
8. Security
We use encrypted connections (HTTPS) for all communications, verify the signature of every notification we receive from Meta, sign the events we send to businesses' systems, store API keys only as hashed fingerprints, and restrict data access to staff who need it to operate the service.
9. Your rights
As a data subject you can access, update, correct and delete your data, request proof of authorization, revoke it, be informed about how your data is used, and file complaints with Colombia's Superintendency of Industry and Commerce (SIC). Write to contacto@inventtify.com.
- Inquiries: answered within 10 business days.
- Claims (correction, update or deletion): answered within 15 business days.
10. How to request deletion of your data
- Email contacto@inventtify.com with the subject "Delete my data – Inventtify Connect".
- Include the WhatsApp number or Instagram/Facebook username you messaged from, and the business name if you know it.
- We will confirm receipt and delete your contacts and messages within 15 business days, informing the relevant business.
Businesses can also disconnect their channels or request account closure by writing to the same address.
11. Changes to this policy
If we change it, we will publish the new version on this page with its date and notify businesses by email before it takes effect. Connect is a tool for businesses and is not directed at people under 18.