This Data Protection Policy describes the technical and organizational measures TipSep implements to protect personal data processed through our WhatsApp Business messaging platform. It supplements our Privacy Policy and applies to all customers, authorized users, and data subjects whose information is handled through the Services.
Our commitment to data protection
TipSep is committed to protecting the confidentiality, integrity, and availability of personal data. We design our platform with security in mind and continuously evaluate our practices against industry standards and regulatory requirements.
We process data in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable, and require our subprocessors to maintain equivalent standards.
Security measures
الأمن السيبراني
We implement layered security controls to safeguard data throughout its lifecycle:
- Encryption in transit: all data transmitted between your browser, our servers, and third-party APIs is protected using TLS 1.2 or higher.
- Encryption at rest: sensitive data stored in our databases and file systems is encrypted using industry-standard algorithms.
- Network security: firewalls, intrusion detection, and DDoS mitigation protect our infrastructure.
- Vulnerability management: regular security assessments, patching, and penetration testing.
- Secure development: code reviews, dependency scanning, and security testing in our development lifecycle.
- تدريب الموظفين على ممارسات حماية البيانات والأمن السيبراني.
Access controls and authentication
Access to production systems and customer data is restricted on a need-to-know basis:
Employees and contractors with data access are bound by confidentiality obligations and receive security awareness training.
نُعالج البيانات الشخصية فقط وفق تعليماتكم الموثقة ولهذه الشروط والسياسات المنشورة.
- Role-based access control limits employee access to data required for their job function.
- Multi-factor authentication is required for administrative and production system access.
- Access requests and privilege changes are logged and reviewed periodically.
- Customer Accounts are protected by password requirements and optional two-factor authentication.
Data processing roles
Depending on the context, TipSep acts as a data controller or data processor:
When acting as a processor, we process personal data only according to your documented instructions, this policy, our Terms, and applicable data processing agreements.
- Data controller: for Account registration data, billing information, and platform usage data related to our direct relationship with you.
- Data processor: for message content, contact lists, and end-recipient data that you upload or transmit through the platform on behalf of your organization.
- مزودو الدفع والفوترة.
- مزودو خدمات الدعم والمراقبة التقنية.
Subprocessors and third parties
We engage carefully vetted subprocessors to support hosting, payment processing, messaging delivery, and operational functions. A current list of subprocessors is available upon request at support@tipsep.com.
Meta Platforms, Inc. processes message data as an independent controller or processor under its own terms when messages are delivered through WhatsApp.
- All subprocessors are bound by written agreements requiring appropriate security and confidentiality measures.
- We conduct due diligence before engaging subprocessors and review their compliance periodically.
- Material changes to subprocessors will be communicated to customers with reasonable notice where required by law or contract.
Data retention and deletion
We retain data according to the schedules described in our Privacy Policy and your Plan configuration. Upon Account termination or a verified deletion request, we delete or anonymize personal data within a reasonable timeframe, except where retention is required by law.
Deletion requests should be sent to support@tipsep.com with sufficient information to identify the data subject and the Account concerned.
- Backup copies may persist for a limited period before being overwritten in the normal course of operations.
- Customers may export their data prior to Account closure through available platform tools or by contacting support.
- توثيق الخرق والإجراءات التصحيحية المتخذة.
Incident response and breach notification
We maintain an incident response plan to detect, contain, and remediate security events. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify affected customers and relevant supervisory authorities within the timeframes required by applicable law.
Notifications will describe the nature of the breach, likely consequences, and measures taken or proposed to address it. We cooperate with customers and authorities during investigations.
If you suspect a security incident involving your Account, contact us immediately at support@tipsep.com or +212 5 22 00 00 00.
- جمع ومعالجة بيانات شخصية لأغراض مشروعة وبموافبة قانونية مناسبة.
- عدم إرسال بيانات حساسة (صحية، مالية) عبر المنصة دون تشفير إضافي أو ضمانات مناسبة.
- إخطارنا فوراً بأي طلب من أصحاب البيانات أو سلطة رقابية يتعلق ببيانات مُعالَجة عبر حسابكم.
- الحفاظ على أمن بيانات الدخول وعدم السماح بالوصول غير المصرح به.
Your rights and contact
Data subjects may exercise their rights as described in our Privacy Policy, including access, rectification, erasure, restriction, portability, and objection. Customers acting as data controllers are responsible for responding to end-recipient requests regarding data processed through their Account.
For data protection inquiries, to request a copy of our Data Processing Agreement, or to contact our data protection representative, reach TipSep at support@tipsep.com, +212 5 22 00 00 00, +212 6 72 91 31 11, or Casablanca, Maroc. We respond to verified requests within the timeframe required by applicable law.
- البريد الإلكتروني: support@tipsep.com
- الهاتف: +212 5 22 00 00 00
- واتساب: +212 6 72 91 31 11
- العنوان: Casablanca, Maroc