Skip to content
WeHub
FeaturesChannelsPricingIntegrationsSecurityDevelopers
מעבר לעבריתSign inStart a trial
  • Features
  • Channels
  • Pricing
  • Integrations
  • Security
  • Developers
  • About
  • Contact
  • מעבר לעברית
Sign inStart a trial

Privacy Policy

Version 1 · updated September 2, 2026

On this page

1. Two kinds of data, two roles2. What data is collected3. How data is collected4. Purposes and legal bases5. Sharing with sub-processors6. Artificial intelligence7. International transfers8. Retention and deletion9. Security10. Rights and how to exercise them11. Security incidents12. Children13. Privacy officer and contact details14. Policy updates

Other documents

Terms of ServiceAccessibility statementCookie policyData Processing Agreement (DPA)Acceptable Use Policy (AUP)Data deletionService Level Agreement (SLA)

WeHub Privacy Policy

Last updated: 2 September 2026

WeHub is a customer-communication platform for businesses, operated by [full registered company name] ("WebPower", "we"), company number [ח.פ.], of [address], Israel. This policy explains what personal data the Service collects, why, who it is shared with, how long it is kept, and what rights are available to the people it concerns.

It is written to meet the Israeli Protection of Privacy Law, 5741-1981 and Amendment No. 13 to it, the Protection of Privacy Regulations (Data Security), 5777-2017, and, for users and End Customers in the European Union and the European Economic Area, the GDPR.

1. Two kinds of data, two roles

There is an important distinction, because our legal role differs in each case:

| The data | Controller | WeHub's role | |---|---|---| | Data about our business customers and their users (account details, billing, usage, sign-in logs) | WeHub | Controller | | Conversation content and End Customer details arriving through the connected channels | The business customer | Processor only, acting on the business's instructions |

In other words: someone who contacted a business over WhatsApp, Instagram, Messenger, email or phone and wants to exercise a right regarding that conversation should first contact that business. We will assist the business in handling the request and will forward requests that reach us. See Section 10 and the Data Deletion Instructions.

2. What data is collected

2.1 Account and user details

Name, email address, phone number, profile picture, language and time zone, a gender field (used solely to phrase interface text correctly when addressing agents), role and permissions in each business, display name per business, department assignment and telephony extension.

2.2 Authentication and security data

Password hash, two-factor authentication data (encrypted TOTP secret, SMS phone number, hashed recovery codes), session records (token hash, IP address, browser type, device identifier, sign-in times), mobile devices (model, app version, push tokens, basic health signals such as battery and power-saving state, used to diagnose notification failures).

2.3 Conversation data of a business's End Customers

Message content in both directions; sender identifiers (E.164 phone number, Messenger PSID, Instagram IGSID, email address); name and profile picture as provided by the channel; delivery metadata (sent, delivered, read, errors); assignment, labels, status, close reasons and agents' internal notes; contact fields defined by the business; marketing consent state (opt-in/opt-out) per channel; customer satisfaction (CSAT) responses.

2.4 Media

Images, videos, documents and voice messages sent by End Customers or agents, and files uploaded by the business (logo, brand assets). Media is stored on Cloudflare R2 under a key that includes the business identifier and is never exposed at a public URL: access goes through our server, which validates permission and returns a short-lived signed link.

2.5 Call logs, recordings and transcripts

Call metadata (numbers, direction, duration, outcome, extension), and recordings and transcripts where the business has enabled them. Enabling recording and notifying the caller are the business's responsibility, under the Israeli Wiretapping Law, 5739-1979 and privacy law.

2.6 Usage and measurement data

Message and conversation counts per channel, response times, WhatsApp conversations by Meta billing category, AI token consumption, peak seats, storage volume, API calls and webhook deliveries. This data is used for billing, plan limits, reporting and capacity planning.

2.7 Billing data

Legal name, company or VAT number, address, billing email, currency, payment terms, invoices and payments. We do not store full card numbers: payment is processed on the payment provider's secure page, and we retain an encrypted token, card brand, last four digits and expiry.

2.8 System and audit logs

An audit log of sensitive actions (sign-in, permission changes, channel connect and disconnect, export, plan changes, support sessions) recording actor, action, target, IP address and time. In technical system logs we redact tokens and secrets, mask phone numbers, and never write message bodies.

2.9 Cookies and local storage

Full detail in the Cookie and Local Storage Policy. In short: cookies strictly necessary for session management and business selection, plus display preferences (theme and language). There are no advertising cookies.

3. How data is collected

  • Directly from you: registration, inviting team members, settings, support requests.
  • From connected channels: messages and events delivered by webhooks from Meta, Twilio, Voicenter and SendGrid.
  • Automatically from use: logs, metrics, device data.
  • From payment providers: transaction status, approval or decline, last four digits.

4. Purposes and legal bases

| Purpose | Legal basis (GDPR) | Note under Israeli law | |---|---|---| | Providing the Service, managing accounts and tenants | Performance of a contract (Art. 6(1)(b)) | Informed consent at registration | | Processing conversation content on behalf of a business | Contract with the business; for End Customers, the business is the Controller | We act as processor on the business's instructions | | Information security, fraud prevention, isolation between businesses | Legitimate interests (Art. 6(1)(f)) | Security duty under the Data Security Regulations | | Billing, invoicing and accounting records | Contract + legal obligation (Art. 6(1)(c)) | Retention duties under tax law | | Improving the Service, aggregate usage analysis | Legitimate interests | Aggregate, non-identifying analysis | | Service and operational notices (incidents, billing, security) | Performance of a contract | Not promotional messaging | | WeHub marketing to business customers | Consent, or legitimate interest in an existing customer | Under s.30A of the Communications Law, with opt-out in every message | | AI features for drafting suggestions, summaries, transcription and knowledge agents | Contract, where enabled by the business | See Section 6 |

What we do not do: we do not sell personal data; we do not use customers' conversation content for advertising; and we do not train general-purpose AI models on it.

5. Sharing with sub-processors

The Service relies on providers that process data on our behalf, each limited to what its function requires, under processing agreements and confidentiality and security obligations:

| Provider | Function | Data categories | Main processing location | |---|---|---|---| | Meta Platforms (WhatsApp Cloud API, Instagram, Messenger) | Messaging channels | Message content, sender identifiers, delivery metadata | US / global | | Twilio | Telephony and numbers | Phone numbers, call metadata, recordings where enabled | US / Europe | | Voicenter | Telephony, extensions, voice agent | Phone numbers, CDRs, voice streams | Israel | | SendGrid (Twilio) | Inbound and outbound email | Addresses, subject, body, attachments | US / Europe | | Cloudflare R2 | Media and file storage | Images, video, documents, audio, invoice PDFs | [to be completed: bucket region] | | Anthropic (Claude) | Drafting suggestions, summaries, knowledge-base agent | Conversation excerpts sent for the task | US | | OpenAI | Complementary AI features, where enabled | As above | US | | ElevenLabs | Speech synthesis for the voice agent, where enabled | Text to be spoken, audio segments | US | | HYP (Yaad Sarig) | Card processing | Payment details submitted directly to the provider, token, status | Israel | | iCount | Invoice and receipt issuance | Billing details, invoice lines | Israel | | Stripe (optional) | Processing for customers outside Israel | Payment details, status | US / Europe | | Google Firebase (FCM) | Push notifications to the mobile app | Device token, notification title, business and conversation identifiers | US / global | | Hosting provider [to be completed: provider and region] | Running the servers and database | All Service data | [to be completed] |

The binding sub-processor list, including updates, is in the annex to the Data Processing Agreement. On AI: content is sent to the provider only for the requested task, under an agreement that prohibits use for model training, and is deleted at the provider under its retention policy. A business may disable AI features in its desk settings.

We will also disclose data where required by court order or binding law, to protect our rights, or in a merger or transfer of business, with prior notice and subject to the continued application of this policy.

6. Artificial intelligence

  • AI features operate only where a business enables and configures them: drafting suggestions for agents, conversation summaries, transcription, an AI agent that answers only from a knowledge base the business supplied, and a voice agent.
  • What is sent to the provider: the conversation excerpt or document needed for the task. Billing data and passwords are never sent.
  • Each business has a separate daily cost cap and usage measurement.
  • AI output is not an automated decision with legal effect: it is presented to a human agent, and in AI-agent mode escalation to a human remains available.

7. International transfers

Some of the providers listed above process data outside Israel and outside the European Economic Area. Such transfers rely on one of: an adequacy decision, EU Standard Contractual Clauses (SCCs) together with supplementary measures, or explicit consent where appropriate. Israel is recognised by the European Commission as providing an adequate level of protection [for counsel: verify the status and scope of that decision at the time of publication]. A copy of the safeguards is available on request at [[email protected]].

8. Retention and deletion

| Data type | Retention | |---|---| | Conversation content, media, contacts | For as long as the business is an active customer, plus 30 days after termination (export window), then deleted within [90 days] including backups | | Call recordings and transcripts | As configured by the business, default [to be completed], and no longer than the term plus 30 days | | Closed user account | Deleted or anonymised within [30 days], excluding audit records | | Deleted tenant | 30-day soft delete, then full deletion | | Invoices and accounting records | 7 years, per Israeli law | | Audit logs | [24 months], without message content | | Technical system logs | [90 days] | | Inbound webhook records | [30 days] | | Meta deletion requests | The record is retained as proof of handling, without content |

Early deletion of an individual contact is performed by the business's administrators and removes that contact's conversations, messages, media and identities; only an audit record without content remains.

9. Security

  • Encryption in transit (TLS) and encryption at rest for secrets and credentials using AES-256-GCM, cryptographically bound to the business identifier and field, so that ciphertext from one business cannot be decrypted in the context of another.
  • Isolation between businesses as a governing principle: every business table carries a business identifier, and all data access passes through a layer that injects that filter. Automated tests fail the build if code bypasses that layer.
  • Permissions by role and visibility scope, enforced on the server on every request, including in real-time streams, notifications and media access.
  • Two-factor authentication (TOTP or SMS), the option to enforce it business-wide, IP allow-listing on suitable plans, session and device management with remote sign-out.
  • Passwords stored hashed (bcrypt); session tokens stored hashed only.
  • Media with no public URL; access only through short-lived signed links.
  • Rate limits, webhook signature verification, and an audit log of sensitive actions.
  • WeHub staff access to a business's data is limited to a documented, time-limited support session that is read-only by default and clearly indicated in the interface.
  • Security reviews and isolation tests are run before releases.

No system is entirely immune. In the event of a security incident we will act under Section 11.

10. Rights and how to exercise them

10.1 For users of the Service (our customers' staff)

You have the right to access your data, correct inaccurate data, request deletion, restrict processing, object to processing, receive your data in a portable format, and lodge a complaint with a supervisory authority. Some of these can be exercised directly in the profile and security screens.

10.2 For people who contacted a business that uses WeHub

The conversation content belongs to the business you contacted. Please contact that business directly. A request that reaches us will be forwarded to the relevant business within [5 business days], and we will assist it in performing the deletion or correction. See the Data Deletion Instructions.

10.3 How to contact us

Write to [[email protected]] with enough identifying detail to locate the record. We will respond within 30 days; in complex cases we will notify you of an extension. There is no charge, except for repetitive or excessive requests.

10.4 Complaints

  • In Israel: the Privacy Protection Authority at the Ministry of Justice.
  • In the EU: the supervisory authority in your country of residence.
  • We would welcome the chance to resolve the matter directly first.

11. Security incidents

We maintain procedures for detecting and responding to security incidents. Where an incident presents a risk to personal data, we will notify the affected customer without undue delay and no later than 72 hours after becoming aware of it, provide the information it needs as Controller, and report to the authorities as required by law.

12. Children

The Service is intended for business use and is not directed at children. We do not knowingly collect data about children under [16]. A minor may contact a business through a connected channel; responsibility for handling that, including parental consent where required, rests with the business as Controller. If you believe data about a child was collected unlawfully, contact us and we will act to delete it.

13. Privacy officer and contact details

  • Privacy officer: [privacy officer name]
  • Email: [[email protected]]
  • Phone: [phone]
  • Postal address: [address]
  • EU representative under GDPR Article 27: [to be completed if required]

14. Policy updates

We will update this policy from time to time. A material change will be announced in-product and by email to account administrators at least 30 days in advance, and the version number and date at the top of the document will change accordingly. Previous versions are retained and available on request.

---

> Note: draft pending review by a licensed Israeli attorney (לתשומת-לב: טיוטה לבדיקת עורך-דין). This document is a working draft and not legal advice. Complete the bracketed placeholders, verify the sub-processor list and the actual retention periods, and have the text approved by counsel before publication.

WeHub

Customer communication for businesses

Product

  • Features
  • Channels
  • Integrations
  • Pricing

Company

  • About
  • Security
  • Developers
  • Contact

Legal

  • Terms of service
  • Privacy policy
  • Accessibility statement
  • Cookie policy
  • Data deletion

Contact

  • [email protected]
  • [email protected]
  • Create an account
  • Sign in to your account
© 2026 WeHub. All rights reserved.מעבר לעברית