Softora Read Archive
Privacy Policy
This policy explains how Softora processes data from the WhatsApp Business account that its owner explicitly connects to the private, read-only archive.
Read-only by design: the production integration gives Codex no tool to send, edit or delete WhatsApp messages. It does not import group chats. Any controlled message used solely for Meta App Review is outside the production archive workflow.
1. Scope and data source
This policy applies only to the app named Softora Read Archive. The account owner starts the official WhatsApp Business Platform Coexistence flow through Meta and, where used, YCloud, and chooses whether to share available history.
Subject to Meta's availability and the owner's choice, the archive can receive:
- WhatsApp Business account and phone-number identifiers;
- contact phone numbers and profile names;
- one-to-one message content and message metadata;
- available one-to-one history shared during onboarding, currently limited by Meta to at most six months; and
- new inbound messages and message echoes after connection.
Group conversations are not synchronized by this integration.
2. Why the data is processed
The data is used only to maintain a private searchable archive and to give the account owner accurate context when the owner explicitly asks Codex to read, search or summarize a conversation. Softora does not use archived messages for advertising, cold outreach, sale of data, profiling of chat participants or training public AI models.
3. Legal grounds and control
The account owner explicitly authorizes the connection. Depending on the conversation and relationship, processing is based on performance of an agreement, compliance with legal obligations, or Softora's legitimate interest in securely organizing and retrieving its own business correspondence. Where consent is legally required, processing occurs only with that consent.
The archive is for the connected account owner's use. It is not a public inbox and is not made available to unrelated users.
4. Security and access
- Direct Meta webhooks require a valid Meta signature. If an approved provider routes Meta events directly to Softora and cannot share its app secret, a separate high-entropy provider callback address is required and can be rotated independently.
- YCloud webhook deliveries require a valid
YCloud-Signature, verified with HMAC-SHA256 over the exact request body and the provider-issued endpoint secret. - Message bodies, contact details and stored webhook payloads are encrypted at rest.
- Search uses keyed, non-plaintext indexes.
- Archive endpoints require a private access token and do not use browser caching.
- Access is limited to the account owner and infrastructure needed to operate the archive.
No internet-connected system can be guaranteed completely secure. Softora limits collection and access and responds to suspected security incidents.
5. Service providers and international transfers
Meta provides the WhatsApp Business Platform. When selected by the account owner, YCloud acts as the WhatsApp solution provider that receives and forwards the permitted one-to-one history and new-message events. YCloud's provider-side retention for synchronized conversation data is up to six months under its service terms.
Softora separately stores a private archive in encrypted form and uses contracted hosting, database and AI-assistant infrastructure only as needed to operate it. These providers process data under their own terms and applicable data-protection safeguards. Softora does not sell WhatsApp data or share it with data brokers.
If data is processed outside the European Economic Area, Softora uses available safeguards such as adequacy decisions or standard contractual clauses where required.
6. Retention
YCloud's provider-side copy of synchronized conversation data may be retained for up to six months. Softora's separate encrypted archive is retained only while the archive remains active and the data is needed for the owner's stated retrieval purpose, legal obligations or dispute handling. The need for retention is reviewed periodically. A verified deletion request is completed without undue delay and normally within 30 days, unless a legal obligation requires limited retention.
7. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection. You may also withdraw consent where consent is the basis for processing and complain to the Dutch Data Protection Authority.
For a request, email serve@softora.nl. To protect conversation data, Softora may ask for information needed to verify identity and locate the relevant conversation.
View deletion instructions8. Changes and contact
Material changes will be reflected on this page with a new effective date. Questions can be sent to serve@softora.nl.
Softora Read Archive is an independent Softora application and is not endorsed by or affiliated with WhatsApp or Meta.