Kode PunditKode Pundit

Privacy Policy

Last updated: 19 August 2026

Kode Pundit provides WhatsApp Business messaging infrastructure that lets businesses communicate with their customers over the WhatsApp Business Platform. This policy explains what information we process, why, and the choices available to you.

1. Who we are

Kode Pundit (“Kode Pundit”, “we”, “us”) operates a platform that connects businesses to the WhatsApp Business Platform (provided by Meta) so they can send and receive messages with their own customers. We act as a service provider / processor on behalf of the businesses that use our platform; those businesses are the controllers of their customer data.

2. Information we process

  • Business account data — the WhatsApp Business Account and phone number identifiers, display names, and access tokens a business authorizes us to use on their behalf.
  • Message content and metadata — the WhatsApp messages (text, media, templates) exchanged between a business and its customers, including timestamps and delivery/read status.
  • Contact information — the phone numbers and profile names of the end customers a business messages.
  • Operational data — logs, usage counts, and error diagnostics needed to run the service reliably and securely.

We do not use message content for advertising, and we do not sell personal information.

3. How we use information

  • To deliver messages to and from WhatsApp on behalf of the business.
  • To maintain message state, delivery status, and conversation history for the business.
  • To secure the service, prevent abuse, and troubleshoot problems.
  • To meet legal, tax, and regulatory obligations.

4. Sharing

We share information only as needed to provide the service:

  • Meta Platforms — message delivery flows through the WhatsApp Business Platform (Cloud API), subject to Meta’s own terms and policies.
  • Infrastructure subprocessors — cloud hosting and storage providers that run our database and media storage under contract.
  • Legal — where required by law or to protect rights, safety, and the integrity of the service.

5. Data isolation & security

Each business’s data is isolated at the data layer and access-controlled. Access tokens and other secrets are stored encrypted (AES-256-GCM) and are never exposed to other tenants or logged in plaintext. Access to production systems is restricted and audited.

6. Retention

We retain message and contact data for as long as the business’s account is active and as needed to provide the service, then delete or anonymize it in line with the business’s instructions and our legal obligations.

7. Your rights & choices

If you are an end customer, requests to access, correct, or delete your data are directed to the business you were messaging with, since they control that data. We assist those businesses in fulfilling such requests. See our Data Deletion instructions.

8. International transfers

Data may be processed in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.

9. Changes

We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above.

10. Contact

Questions about this policy or your data can be sent to kodepundit@gmail.com.