Privacy policy

Last updated : 5 September 2026

This policy describes how TEERAL ("TEERAL", "we") collects, uses and protects personal data through its WhatsApp Business messaging platform for businesses. TEERAL is a service operated by JOKKALE, a sole proprietorship registered with the Dakar RCCM under number SN DKR 2026 A 23030, NINEA 013156288, with its registered office at Mermoz Pyrotechnique, Dakar, Senegal, acting as data controller in compliance with Law No. 2008-12 of 25 January 2008 on the protection of personal data, under the supervision of Senegal's Personal Data Protection Commission (CDP). We do not sell your personal data.

1. Two distinct roles

TEERAL processes personal data in two roles that should be distinguished:

  • As a data controller, for the data of our business customers and their agents (account creation, billing, support) and for operating the platform.
  • As a data processor, for the data our customers process through the platform about their own contacts (numbers, messages, conversation information). The customer remains the controller of this data; TEERAL processes it solely on their instructions.

2. Data we collect

Phone numbers are masked in our technical logs and no access token appears in them.

  • Account data: name, email address, password (hashed), role, associated business.
  • WhatsApp connection data: WhatsApp Business Account (WABA) identifiers, connected business number, quality indicators and messaging tiers provided by Meta.
  • Conversation data (on behalf of the customer): contact numbers, message content, timestamps, delivery statuses, consents (opt-in/opt-out).
  • Technical data: access logs, IP address, usage data needed for security and proper operation of the service.
  • Mobile app data: a device-specific push notification token, a device label (model and operating system), language, and a per-device session identifier. Every signed-in device is listed under the account's "Devices" and can be signed out remotely.
  • Address book (mobile app, only at the agent's request): the name and number of the contacts the agent explicitly selects during an import. The address book is never transferred in bulk or read in the background, and no marketing consent is inferred from an import.
  • Microphone: voice notes and WhatsApp calls, only while recording or on a call. Calls are recorded only if the customer enables that feature; informing the other party is the customer's responsibility.
  • Photos and camera: only the images, videos and documents the agent chooses to attach to a conversation or to share to TEERAL from another app.
  • Sign in with Apple or Google: the technical identifier provided by Apple or Google, the email address (where applicable the relay address provided by Apple) and the name transmitted, used only to link the sign-in to an existing TEERAL account. The app does not create accounts.

3. The mobile app

The TEERAL mobile app (iOS and Android) is reserved for agents of customers who are already registered; it does not allow account creation. Each phone permission (contacts, microphone, camera, photos, notifications) is requested only when the agent uses the corresponding feature, and can be withdrawn at any time in the phone settings: that feature then stops working, the rest of the app does not.

Notifications: message content does not appear in notifications by default; the customer can enable it for their business. The customer can also hide contact names in notifications and on the call screen. On iPhone, an incoming call rings the phone through a call (VoIP) notification that contains only the call identifier and the contact's display name, never a phone number.

Data kept on the phone: session credentials in the system's secure storage (Keychain on iOS, Keystore on Android), a local outbox holding messages and files awaiting sending for at most twenty-four hours, and a cache of recent conversations. Signing out erases the session credentials; uninstalling erases everything.

Sign in with Apple can be revoked from the phone's Apple settings: the app then closes the related session. Deletion of server-side data follows the rules in the "Your rights" section and the closure of the customer's business account.

4. Purposes and legal bases

  • Provide and secure the service (performance of the contract).
  • Route WhatsApp messages between our customers and their contacts (performance of the contract).
  • Comply with the obligations imposed by Meta and by law (legal obligation and legitimate interest).
  • Bill, prevent fraud and improve the service (legitimate interest).
  • Send transactional communications (performance of the contract) and, where applicable, marketing with your consent.

5. Processors and recipients

To provide the service, we rely on processors that process data on our behalf under contractual confidentiality and security commitments:

  • Meta Platforms Ireland Ltd. — WhatsApp Business API (Cloud API): message routing, statuses, WhatsApp Business account management.
  • Resend — sending transactional emails (account verification, password reset).
  • Hostinger — hosting the platform's servers and database.
  • Mistral AI (France) — classifying incoming messages and drafting suggested replies, only when the customer has enabled the AI Agent. Phone numbers are stripped from the content before transmission, and no suggestion is sent without human validation.
  • Google Ireland Ltd. — audience measurement on the marketing site (Google Analytics) and advertising campaign measurement, only after your consent. No Google tool is loaded inside the application once you are signed in.
  • Microsoft Ireland Operations Ltd. — usage analysis on the marketing site (Microsoft Clarity): anonymous session replay and heatmaps, only after your consent. Input fields are masked and no recording takes place inside the application once you are signed in.
  • Apple Inc. — push notifications and call notifications on iPhone (APNs), Sign in with Apple. Apple receives only the device token and the notification content described above.
  • Google LLC — call notifications on Android (Firebase Cloud Messaging) and Sign in with Google. Firebase receives only the device token and the call identifier.
  • Expo (650 Industries, Inc.) — relays the mobile app's ordinary push notifications to Apple and Google.
  • Cloudflare, Inc. — protection and routing of website and app traffic, storage of media files exchanged in conversations and of call recordings.
  • Wave Mobile Money — collection of subscription payments in CFA francs. Payment data is processed by Wave; TEERAL keeps only the transaction reference and status.

6. Transfers outside Senegal

Some processors (notably Meta, Apple, Google, Expo, Cloudflare, Resend, Mistral AI and Microsoft) process data outside Senegal. These transfers are covered by appropriate safeguards (contractual commitments, security measures) in accordance with applicable regulations.

7. Retention period

Data is kept for as long as necessary for the purposes described, then deleted or anonymised. Conversation data processed on behalf of a customer is kept according to that customer's instructions and deleted at the end of the contractual relationship, subject to legal retention obligations.

Push notification tokens are deleted when the device signs out, when the agent or an administrator revokes the device, or as soon as Apple or Google report that they are no longer valid.

Call recordings are kept for the period set by the customer (ninety days by default), then deleted. Contacts imported from an address book follow the same rules as the customer's other contacts.

8. Security

We implement appropriate technical and organisational measures: encryption of exchanges, per-customer data isolation (strict separation by tenant identifier), access control, masking of numbers in logs, and protection of access tokens that never leave our servers.

9. Your rights

You have the right to access, rectify, erase, object to and restrict the processing of your data. To exercise them, contact us at [email protected]. Anyone can unsubscribe from a customer's messages at any time by replying "STOP" on WhatsApp; the objection is then final.

10. WhatsApp and Meta compliance

Use of WhatsApp is subject to Meta's policies (WhatsApp Business Messaging Policy and Business Terms). Our customers undertake to contact only people who have given prior consent (opt-in) and to honour unsubscribe requests (opt-out). TEERAL enforces these rules strictly to protect the reputation and availability of numbers.

11. Cookies and analytics

Cookies strictly necessary for the service to operate (authentication, security, language preference) are set without prior consent: the service cannot work without them.

On the marketing site only, and only if you accept, we use Google Analytics to measure traffic and the effectiveness of our advertising campaigns, and Microsoft Clarity to understand how our pages are actually used (navigation paths and clicked areas). None of these scripts is loaded until you have accepted. You can change your mind at any time through the "Cookies" link in the footer.

Inside the application, once signed in, we measure usage with Plausible, hosted on our own infrastructure. Plausible sets no cookies and builds no visitor identifier. Page addresses sent to it are reduced to their route pattern: we send "/inbox", never the identifier of the open conversation.

No end-customer data, no phone number and no message content is sent to any analytics tool.

12. Changes

We may update this policy. The last-updated date appears at the top of the document; significant changes will be notified to you.

13. Contact and complaints

For any question or request about your data, write to us at [email protected]. You may also refer the matter to Senegal's Personal Data Protection Commission (CDP).

In case of discrepancy between language versions, the French version prevails.

Back to home