Privacy Policy

Last modified: May 26, 2025

Introduction

1. Introduction

Welcome to BuildSavanna (“we,” “us,” or “our”). This Privacy Policy explains how we collect, use, share, and protect the personal and usage information you provide when you visit https://www.buildsavanna.com (our “Website”) or interact with our WhatsApp Business Platform (our “Services”).

BuildSavanna is a robust and scalable WhatsApp Business Platform designed to help businesses streamline customer communication, automate workflows, and gain actionable insights. We respect your privacy and are committed to handling your data with transparency and care.

By accessing or using our Website and Services, you consent to the practices described in this policy. If you do not agree with any part of this policy, please do not use our Website or Services. We may update this policy from time to time—see Section 10 (“Changes to This Policy”) for details on how we will notify you of material changes.

2. Information We Collect

We collect information in two primary ways: data you provide directly to us when you sign up or interact with our Services, and data we automatically gather as you use our Website and the BuildSavanna platform. We organize this information into the following categories:


2.1 Personal & Account Data

Registration Details: Your full name, company name, business email address, phone number, and role or position.
Authentication Credentials: Hashed passwords and any multi-factor authentication tokens you enable.
Profile & Preferences: Profile pictures, preferred language, time-zone settings, and other customization options you select.


2.2 Contact & Conversation Data

WhatsApp Identifiers: Phone numbers and WhatsApp Business API identifiers for you and your customers.
Messages & Media: Text, images, videos, documents, voice notes and other media you or your customers exchange through our chat interface.
Templates & Automation Rules: Any message templates, quick-reply buttons, or workflow rules you create within the platform.


2.3 Usage & Analytics Data

Platform Activity: Logs of chat sessions, chatbot interactions, broadcast campaigns, and API calls.
Performance Metrics: Delivery status, open and click-through rates, response times, and other engagement statistics.
System & Device Information: IP addresses, browser type/version, operating system, device identifiers, referring URLs, and timestamps.


2.4 Payment & Billing Data

Transaction Records: Amounts, currencies, transaction IDs, and statuses for payments processed via Paynow, EcoCash, OneMoney, etc.
Billing Information: Invoicing name and address, VAT or tax registration numbers, and any purchase order references you provide.


This information enables us to operate and improve BuildSavanna, secure your account, facilitate payments, power analytics, and deliver the automated workflows and chat features you depend on. If you have questions about any data we collect, please see Section 11 (“Contact Us”).

3. How We Use Your Data

We use the information we collect to operate, maintain, and improve BuildSavanna, to communicate with you, and to keep our platform secure and compliant. Specifically, we process your data for the following purposes:

  • Service Delivery & Operations
    We route and store your WhatsApp messages, power chatbots, execute broadcast campaigns, generate reports, and run all of the core platform features you rely on.

  • Account Management & Authentication
    We verify your identity when you sign in, manage your user roles and permissions (Admin, Manager, Agent, Client), and enforce access controls.

  • Customization & Personalization
    We remember your preferences (language, time zone, UI settings), tailor the layout and content of the dashboard, and surface relevant templates or workflows based on your usage patterns.

  • Customer Support & Communication
    We use your contact information and activity logs to respond to support requests, diagnose and fix issues, and notify you about important platform updates or maintenance windows.

  • Analytics & Product Improvement
    We analyze aggregated usage and performance metrics (delivery rates, response times, campaign engagement) to optimize our features, identify trends, and plan new functionality.

  • Billing & Payments
    We process transactions, generate and send invoices, reconcile payments via Paynow, EcoCash, OneMoney, and maintain accurate billing records.

  • Security & Fraud Prevention
    We monitor system logs and activity patterns to detect suspicious behavior, block unauthorized access attempts, and protect your account and data from misuse.

  • Compliance & Legal Obligations
    We retain and audit logs to satisfy GDPR, local data-privacy laws, and financial regulations (e.g., record-keeping for payments), and we cooperate with lawful requests from regulators or courts.

  • Marketing & Newsletters (Opt-In Only)
    If you choose to subscribe, we may send you product announcements, newsletters, or promotional offers. You can opt out of these communications at any time via unsubscribe links or by contacting us.


By using your data in these ways, we ensure BuildSavanna remains functional, secure, and continually improving—while giving you control and visibility over how your information is handled.

4. Data Sharing & Disclosure

We do not sell your personal data. We only share it in the limited circumstances described below:

  1. WhatsApp API Providers

    • We integrate with partners like 360dialog and Meta (WhatsApp Business API) to send and receive your messages.

    • These providers process message metadata (timestamps, delivery status) but do not use your data for their own marketing.

  2. Cloud Storage & Infrastructure

    • Media and documents you upload (images, videos, invoices) may be stored on AWS S3 or Google Cloud Storage.

    • We—and only we—control access to that storage; providers act as data processors under our instructions.

  3. Payment & Billing Processors

    • Transactions are handled via Paynow, EcoCash, OneMoney, and similar services.

    • We share only the payment details required to complete and reconcile your orders (amount, currency, transaction ID).

  4. Support & Email Services

    • To send you system notifications, invoices, or support replies, we may use email delivery services (e.g., SendGrid, Mailgun).

    • Only your name, email address, and relevant transaction identifiers are shared.

  5. Analytics & Monitoring

    • We may share anonymized, aggregated usage metrics (e.g., total message volume, average response times) with analytics platforms like Google Analytics to help us improve performance and feature set.

    • No personally identifiable information is disclosed in these reports.

  6. Legal Obligations

    • We will disclose your information if required by law (e.g., court order, subpoena) or to defend our rights, property, or safety—or that of our users or the public.

  7. Business Transfers

    • If BuildSavanna undergoes a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction—but only on the condition that the acquirer adheres to this Privacy Policy.

  8. With Your Consent

    • You may choose to connect BuildSavanna to third-party CRMs (Salesforce, HubSpot, Zoho) or analytics tools. In those cases, we share only the data fields you authorize.

In all cases, we require our partners to process your data in accordance with this policy and applicable data-protection laws. If you have questions about any specific sharing scenario, please see Section 11 (“Contact Us”).

5. Cookies & Tracking

To enhance your experience and help us understand how you use BuildSavanna, we employ “cookies” and similar tracking technologies:

  • What Are Cookies?
    Small data files placed on your device when you visit our Website. Cookies enable us to remember your preferences (such as language or time-zone), keep you logged in, and deliver a smoother, more personalized experience.

  • Types of Cookies We Use

    1. Essential Cookies

      • Required for core functionality: user authentication, session management, and security checks.

      • Cannot be disabled without impacting your ability to use the platform.

    2. Performance & Analytics Cookies

      • Collect anonymized usage data (pages visited, time on page, error messages) via tools like Google Analytics.

      • Help us measure feature adoption, identify bottlenecks, and continuously improve performance.

    3. Functional & Preference Cookies

      • Remember your display preferences (dark mode, dashboard layout), language settings, and other customizations.

      • Enable features such as “Remember me” on login.

    4. Marketing & Third-Party Cookies

      • If you opt in, we or our partners may use cookies to serve you targeted product announcements or offers.

      • Third-party providers (e.g., social-media widgets, embedded videos) may set their own cookies; their use is governed by their respective policies.

  • How to Manage or Disable Cookies

    • You can adjust your browser settings to block or delete cookies. Common instructions:

      • Chrome: Settings → Privacy and security → Cookies and other site data

      • Firefox: Preferences → Privacy & Security → Cookies and Site Data

      • Safari: Preferences → Privacy → Manage Website Data

    • Disabling non-essential cookies may limit certain features or prevent automatic sign-in.

  • Do-Not-Track Signals

    • Our Website does not currently honor browser “Do-Not-Track” signals, but performance and marketing cookies remain fully optional and under your control.

  • More Information

    • For details on how third parties use cookies and how to opt out of third-party analytics, please visit the respective providers’ websites (e.g., google.com/policies/technologies/cookies).

By using BuildSavanna, you consent to our use of cookies as described above. If you have questions or wish to opt out of specific tracking, please contact us at privacy@buildsavanna.com.

6. Data Security

We take the security of your information seriously and employ a variety of administrative, technical, and physical safeguards to protect it against unauthorized access, disclosure, alteration, and destruction:

  • Encryption

    • In Transit: All data exchanged between your browser or app and our servers is encrypted using TLS/HTTPS.

    • At Rest: Sensitive fields (passwords, tokens, payment references) are encrypted or hashed in our databases.

  • Access Controls

    • Role-Based Permissions: We enforce the principle of least privilege—Admins, Managers, Agents, and Clients see only the data they need.

    • Multi-Factor Authentication: Optional MFA adds a second layer of identity verification for account logins.

  • Network & Infrastructure Security

    • Firewalls & IDS/IPS: We use firewalls and intrusion-detection/prevention systems to block malicious traffic.

    • Secure Configuration: All servers and services follow hardened, industry-standard configurations.

  • Secure Development Practices

    • Code Reviews & Testing: New code is peer-reviewed and undergoes automated vulnerability scans before deployment.

    • Dependency Management: We monitor and patch third-party libraries for known security vulnerabilities.

  • Monitoring & Audit Logging

    • We log all critical events (logins, configuration changes, payment actions) and continuously monitor for suspicious activity, enabling rapid detection and response.

  • Data Backups & Disaster Recovery

    • We perform regular, encrypted backups and maintain a tested disaster-recovery plan to ensure business continuity.

  • Incident Response

    • We maintain a formal incident-response process: upon detection of a breach or security event, we contain the issue, notify affected users, and take remedial actions in line with applicable laws.

  • Employee Training & Policies

    • All team members undergo regular security awareness training and are bound by confidentiality agreements and internal data-handling policies.

By combining these measures, we strive to keep your data safe, maintain the integrity of our platform, and ensure compliance with GDPR, local privacy regulations, and industry best practices.

7. Your Rights & Choices

Depending on where you live, you may have the following rights with respect to your personal data. To exercise any of these rights, please contact us at privacy@buildsavanna.com—we aim to respond within 30 days.

  1. Right of Access
    You can request a copy of the personal information we hold about you and details on how we process it.

  2. Right to Rectification
    If your data is incomplete or inaccurate, you can ask us to correct or update it.

  3. Right to Erasure (“Right to be Forgotten”)
    You may request that we delete your personal data, subject to any legal retention requirements (for example, accounting or compliance obligations).

  4. Right to Restrict Processing
    You can ask us to suspend processing of your data where you contest its accuracy, object to processing, or during the period of an erasure request.

  5. Right to Data Portability
    You may request a machine-readable copy of the data you provided to us, and to have that data transmitted to another controller where technically feasible.

  6. Right to Object
    You can object to our processing of your data for direct-marketing purposes, or on grounds relating to your particular situation—unless we have overriding legitimate grounds to continue.

  7. Right to Withdraw Consent
    When we rely on your consent to process data (e.g., for marketing emails), you can withdraw it at any time. Withdrawal will not affect processing carried out before you withdrew consent.

  8. Opting Out of Marketing Communications
    You may unsubscribe from our newsletters and promotional emails by clicking the “Unsubscribe” link in any email or by contacting us directly.

  9. Cookie & Tracking Preferences
    You can manage or disable cookies at any time via your browser settings (see Section 5 for details). Disabling non-essential cookies may limit certain features.

  10. Filing a Complaint
    If you believe we have violated your data-protection rights, you have the right to lodge a complaint with your local data-protection authority.


We’ll honor all valid requests in accordance with applicable laws and our internal policies. For any questions or to submit a request, email privacy@buildsavanna.com.

8. Data Retention

We retain your personal and usage data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law.

  • Account & Profile Data
    We keep your registration details, profile settings, and authentication credentials for the duration of your active account. After you close your account, we will permanently delete or anonymize most of this information within 90 days—except where required to retain certain records for legal or compliance reasons (see “Billing & Transaction Records” below).

  • Chat & Conversation Logs
    By default, we store message history and media for up to 12 months so you can review past customer interactions and analytics. You may request shorter retention or export and delete your chat data through your account settings or by contacting us.

  • Analytics & Performance Metrics
    Aggregated and anonymized usage statistics (delivery rates, open/click-through rates, response times) are retained for up to 24 months to help us improve our features and monitor system health. These records are not linked to individual user identities once aggregated.

  • Billing & Transaction Records
    To satisfy financial regulations and tax laws, we retain invoices, payment confirmations, and related billing data for a minimum of seven (7) years. This includes transaction amounts, dates, payment methods, and any required accounting references.

  • Audit & Security Logs
    We keep security logs, access records, and system events (login attempts, configuration changes) for up to 24 months to support incident response, fraud detection, and compliance audits.

  • Document Uploads
    Files you upload (e.g., contracts, receipts, ID documents) are stored for as long as needed to complete the associated workflow or transaction, and then for a maximum of 90 days thereafter—unless you request deletion sooner or legal requirements dictate otherwise.

  • Deletion & Archiving
    When data reaches the end of its retention period, we either delete it permanently or anonymize it in a way that it can no longer be linked to you. If you wish to request earlier deletion of any personal data, please contact us at privacy@buildsavanna.com.

By enforcing these retention schedules, we balance your need for continuity and auditability with our commitment to data minimization and your privacy rights.

9. Children’s Privacy

Our services are intended for use by businesses and professionals, not by children under the age of 16. We do not knowingly collect or solicit personal information from anyone under 16.

  • No Accounts for Minors:
    You must be at least 16 years old (or the minimum age required in your jurisdiction) to register for a BuildSavanna account.

  • No Intentional Collection:
    We do not knowingly require or solicit children’s personal data in any of our forms, chatbots, or sign-up processes.

  • Parental Requests:
    If you believe that we may have collected personal information from a child under 16 in error, please contact us immediately at privacy@buildsavanna.com. We will promptly delete any such data upon verification.

  • Proxy Use by Businesses:
    If a parent or guardian uses our platform on behalf of a minor customer (for example, to send appointment reminders via WhatsApp), the parent or guardian remains responsible for obtaining any necessary consents and ensuring compliance with applicable laws.

By strictly limiting our services to users over 16, we help safeguard children’s privacy and comply with global data-protection regulations.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, new features, legal requirements, or feedback from our users. When we make changes, we will:

  • Post the Revised Date:
    We will update the “Last updated” date at the top of this page so you can see when the policy was last modified.

  • Highlight Material Changes:
    For significant updates—such as new data-sharing practices or changes in your rights—we will either (a) post a notice on our Website homepage or (b) send you an email notification, depending on the scope of the change and the contact information we have on file.

  • Provide Access to Prior Versions:
    We will maintain an archive of previous versions of this policy, which you can request by contacting us (see Section 11).

  • Obtain Consent When Required:
    If a material change requires your explicit consent under applicable law, we will prompt you to review and accept the updated policy before continuing to use certain features.

  • Your Continued Use:
    By continuing to access or use BuildSavanna after the policy’s “Last updated” date, you agree to the revised terms. If you do not agree, you must stop using our services and may request deletion of your account and data (see Section 7).

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to us:

  • Privacy & Data Requests:
    Email support@buildsavanna.com and include “Privacy Request” in the subject line. We aim to respond within 30 days.

  • General Inquiries & Support:
    Email info@buildsavanna.com for any other questions about our services.

Thank you for trusting BuildSavanna. We’re here to help and will do our best to address your concerns promptly.