Messago / Privacy Policy
Legal
Privacy Policy
What Messago collects, why we hold it, and who it reaches. Written for the business users who run the platform and the customers who message them.
Effective date · 9 August 2026 · Last updated · 9 August 2026
In short
We do not sell personal data. We do not use end-customer message content, or any customer data held in Messago, to train our own models or anyone else’s. Message content leaves Messago only where the transport requires it, or where the business customer has told us to send it.
1 · Who we are
Messago is a WhatsApp Business Platform for teams, built on Meta’s official WhatsApp Business API. It is operated by Xylm.
- Legal entity: Xylm Technologies Private Limited
- Registered address: M-12A, Shiv Smruti Complex, Ghod Dod Road, Surat – 395002, Gujarat, India
- Contact for privacy questions: messago@xylm.ai
2 · Scope
This policy covers two groups of people.
Business users — people who hold an account on the Messago platform and use it to run a WhatsApp number on behalf of their organisation.
End customers — people who message a business that uses Messago. You do not have a Messago account; your messages reach the business through us.
3 · Controller and processor
End-customer conversation data
The business customer is the controller. Messago is the processor and acts on that business’s documented instructions.
Business-user account data
Messago is the controller for the account records of the people who use the platform: name, email, role and organisation membership.
In practice this means an end customer’s request about their conversation goes to the business they messaged. We will help that business carry it out, and we will act ourselves where the request reaches us directly.
4 · What we collect
Information business users give us
- Name, work email, password credential, role and organisation membership.
- Content created in the platform: message templates, saved replies, flows, forms, keyword rules and campaign lists.
- Campaign recipient lists uploaded as CSV, including the phone numbers and merge values in them.
- API keys for a third-party AI provider, if you choose to connect one. These are stored encrypted and are used only to send requests on your behalf.
Information collected automatically
- Log data: IP address, browser and device information, pages and actions within the product, and timestamps.
- Delivery state reported back by WhatsApp: sent, delivered, read or failed.
- Diagnostic records of API calls made by your flows, including the endpoint called and whether it succeeded.
End-customer data received through the WhatsApp Business API
- Phone number in E.164 format, WhatsApp profile name, and any contact name the business adds.
- Inbound and outbound message content, including text, images, video and documents.
- Chatbot session data: answers captured by prompt steps, and fields mapped from external API responses.
- WhatsApp Flows form submissions.
5 · How we use it
- To deliver the service and keep accounts working.
- To route, store and display conversations against the right contact, so history survives a change of staff.
- To run the automations a business has configured: keyword rules, flows, forms, AI answering and campaigns.
- To produce analytics for the business about its own volumes, agents and campaigns.
- To keep the platform secure and prevent abuse, spam and fraud.
- To meet legal obligations and to establish or defend legal claims.
We do not sell personal data. We do not use end-customer message content, business content, or any other customer data held in Messago to train AI models — neither our own nor a third party’s.
6 · Who we share it with
- Meta / WhatsApp — the messaging transport. Every message sent or received passes through Meta’s WhatsApp Business Platform and is handled under Meta’s own terms.
- The AI provider the business selects — OpenAI, Anthropic or Google AI. If a business enables AI answering, message content is sent to that provider using the business’s own API key. No provider is contacted unless a business connects one.
- Endpoints the business configures itself — API call steps, webhook steps, flow-completion webhooks and Custom Actions. Messago transmits to these on the business’s instruction and does not control what happens at the other end.
- Infrastructure subprocessors — hosting, storage, email and error monitoring.
- Disclosure required by law — where we are legally compelled, or to protect rights and safety.
7 · Security
- Data is encrypted in transit and at rest.
- Third-party AI provider keys are stored encrypted and are never displayed back in full.
- Access inside a business is governed by role-based permissions, per resource and per action; restricted pages and buttons are not rendered for users who lack the permission.
- Internal access is limited to staff who need it to run the service, and is logged.
No system is perfectly secure. We do not claim otherwise, and we will notify affected customers of a breach in line with our obligations.
8 · Your rights
Subject to the law that applies to you, you may ask for access to your data, correction of it, deletion of it, a portable copy of it, and you may object to processing or withdraw a consent you gave earlier.
If you messaged a business using Messago
Contact that business first. They are the controller of your conversation and they decide what happens to it. If you cannot reach them, or you would rather come to us, use the data deletion instructions and we will act as processor for that business.
Business users can exercise most rights inside the product, and can write to messago@xylm.ai for the rest. We acknowledge requests within 7 business days and verify identity before acting.
9 · Contact
Questions about this policy, or about data we hold:
messago@xylm.aiWe update this policy when the product or our processing changes. The effective and last-updated dates at the top of this page always reflect the current version.
