01What we build on
We build exclusively on Meta’s official WhatsApp Business platform. We do not use unofficial libraries and we do not automate a personal WhatsApp number, because that breaks Meta’s terms and can get your number banned.
The websites and the panel run on infrastructure we administer, and all traffic between the browser and our servers goes encrypted over HTTPS.
02What data our systems touch
A WhatsApp bot and the panel behind it work with the minimum data a booking or an answer needs:
- The phone number the customer writes from and the name they give
- The conversation with the bot, so a person can take over when needed
- The booking: the service, the time, and who it is with
- Your business catalog: services, prices, hours, address
What we do not hold: card or bank account details, your customers’ passwords, medical records or other clinical data. For clinics, dental and veterinary practices, the panel keeps bookings and conversations, not medical history. Your medical software stays where it is.
03Who has access
Every client has their own account in the panel and sees only their own business data. There is no shared screen where several companies’ customers show up together.
On our side, technical access is limited to the two of us, for building and maintenance. There are no account managers, subcontractors, or outsourced support team going through your data.
04What the bot never does
- It never asks for card details, national ID numbers, passwords, or codes received by SMS
- It does not process payments or hold money
- It does not act inside your other systems unless we explicitly build that integration
- It does not invent an answer when it does not know: it hands the conversation to a person
- It does not answer medical questions, not even partially
05GDPR, briefly
For your customers’ data, you are the data controller and we are the processor: we process the data to run the system we built for you, not for purposes of our own. We do not sell or lend data to third parties.
The details of what we collect through our own site are in the privacy policy, and your obligations as a business messaging customers on WhatsApp are explained in our GDPR guide.
If you need a signed data processing agreement, a specific retention period, or deletion of the data when we stop working together, we agree those in writing at the start of the project. Those belong in a contract, not on a marketing page.
06Updates and incidents
We host and maintain the systems we build, so updates and fixes are our job, not yours. You have no server to manage and no updates to run.
If you notice something odd, you write directly to us, the people who built the system, not to a support form. If a problem affects your data, we tell you what happened and what we did about it, without dancing around it.
07What we do not promise
We are two people, not a vendor with a dedicated security department. In practice, that means:
- We hold no ISO 27001, SOC 2, or similar certification, and we do not claim to
- We do not sell uptime guarantees we cannot back with measurements
- If you have formal security requirements from a large client or an audit, tell us in the first conversation: either we can meet them, or we tell you honestly that we are not the right fit
Nemvio · contact@nemvio.co · Version of August 20, 2026. The latest version is always on legal.nemvio.co.
Other documents
