Privacy Policy
Last updated 4 October 2026
1. Who we are
O Technologies, trading as Oasis Technologies ("Oasistech", "we", "us"), of Dar es Salaam, Tanzania, operates Oasistech Connect at connect.oasistech.co.tz (the "Platform"). The Platform lets businesses (our "Clients") connect their WhatsApp Business accounts through Meta's WhatsApp Business Platform (Cloud API) and use them to message their customers and manage message templates.
Questions about this policy: info@oasistech.co.tz.
2. Our role
- Client account data (the names, email addresses and logins of people who use the Platform): we are the data controller.
- WhatsApp messaging data (the messages and contact details of a Client's customers): the Client decides why and how it messages its customers and is the controller. We act as the Client's processor and service provider, and process this data only to provide the Platform to that Client.
- Meta. Messages are carried by the WhatsApp Business Platform, which is operated by Meta Platforms, Inc. and its affiliates ("Meta") under Meta's own terms and privacy policy.
3. Information we collect
3.1 Client account information
Business name, user names, email addresses, passwords (stored only as one-way hashes), login sessions, IP addresses and timestamps.
3.2 WhatsApp Business account information
When a Client connects WhatsApp through Meta's Embedded Signup (using Facebook Login for Business), Meta shares with us: the WhatsApp Business Account ID, the phone number ID, display phone number, verified business name and quality rating, the Facebook user ID of the person who completed the signup, and an access token that lets us act on the Client's WhatsApp account. Access tokens are encrypted before they are stored.
3.3 WhatsApp messaging data
For messages sent or received through the Platform: the customer's phone number (WhatsApp ID) and WhatsApp profile name; the text of messages and captions; a short description of media, location, contact and reaction messages; delivery and read status; timestamps; and error codes returned by WhatsApp. We do not download or store photos, videos, voice notes or documents that customers send.
3.4 Message templates
Template names, text, sample values, category, language and Meta's review status.
3.5 Technical logs
Raw event notifications (webhooks) received from Meta and records of failed requests to Meta's API, used for security and troubleshooting. These logs never contain access tokens.
4. How we use information
- To provide the Platform: connecting WhatsApp Business accounts, sending messages and templates when a Client's user asks us to, showing conversations and delivery status, and managing templates.
- To keep the Platform secure: verifying that notifications really come from Meta, preventing abuse, and investigating errors.
- To communicate with Clients about their account and the service.
- To meet legal obligations and Meta's platform requirements.
We do not sell personal data, use WhatsApp messaging data for advertising or profiling, use it to train artificial intelligence models, or share it with anyone except as described in section 6.
5. Legal basis and customer consent
We process data to perform our contract with Clients, for our legitimate interest in running a secure service, to comply with the law, and with consent where the law requires it, in line with Tanzania's Personal Data Protection Act, 2022. Each Client is responsible for having a lawful basis to message its customers, including the opt-in permission that WhatsApp's Business Messaging Policy requires before a business starts a conversation.
6. Who we share information with
- Meta (WhatsApp). Every message sent or received through the Platform passes through Meta's WhatsApp Business Platform.
- Our hosting provider, which runs the servers the Platform uses, under confidentiality and security obligations.
- Authorities, when we are legally required to.
- A successor, if our business is merged or sold, with notice to Clients.
A Client's data is never visible to other Clients.
7. International transfers
Meta processes WhatsApp messages on its own infrastructure, which may be outside Tanzania. Where data leaves Tanzania we rely on the safeguards the Personal Data Protection Act requires.
8. How long we keep information
- Messages, contacts and templates: while the Client's account is active. When a Client closes its account we delete this data within 30 days.
- Access tokens: deleted when a WhatsApp connection is removed or a deletion request is completed.
- Raw webhook notifications: deleted automatically after 30 days.
- API error logs: deleted automatically after 90 days.
- Deletion records: we keep a confirmation code and a one-way hash of the Facebook user ID, so we can show that a deletion happened.
9. Security
All traffic uses HTTPS. Access tokens are encrypted at rest with AES-256. Every request from Meta is checked against Meta's signature before we accept it. Each Client's data is kept separate in our database, and only authorised O Technologies staff can access the Platform's systems.
10. Your rights
You may ask to access, correct or delete your personal data, or object to how we use it, by writing to info@oasistech.co.tz. If you are a customer who received WhatsApp messages from one of our Clients, please contact that business first; we will help it respond. You can also block a business inside WhatsApp at any time. You have the right to complain to Tanzania's Personal Data Protection Commission.
11. Deleting your data
See our data deletion instructions. If you connected WhatsApp with Facebook and then remove Oasistech from your Facebook settings, Meta tells us automatically and we delete the connection and the data held through it.
12. Children
The Platform is for businesses and is not intended for anyone under 18.
13. Changes
We will update the date at the top of this page when this policy changes, and we will email Clients about significant changes.
14. Contact
O Technologies (Oasis Technologies), Dar es Salaam, Tanzania. Email: info@oasistech.co.tz.