Last updated: August 2026
Privacy Policy
What we do with personal information, why, and what you can ask us to do about it. Written for the Protection of Personal Information Act and the GDPR.
1. Who we are and what this policy covers
Relay66 is a business messaging platform operated by Relay66 (Pty) Ltd, a company registered in the Republic of South Africa. We connect businesses to the WhatsApp Business Platform, giving them an API to send messages, signed webhooks to receive them, and a management portal (the Hub) to run the channel day to day.
This policy explains what personal information we handle, why, who we share it with and what rights you have. It applies to our website, the Hub, our APIs and the support we provide. It is written to meet the Protection of Personal Information Act 4 of 2013 (POPIA) and, where it applies, the EU General Data Protection Regulation (GDPR).
Relay66 is offered to businesses. It is not intended for personal or household use.
- Registered name
- Relay66 (Pty) Ltd
- Registration number
- 2026/552149/07
- Registered address
- Cape Town, Western Cape, South Africa
- Information Officer
- Dane Killian
2. Our two roles: responsible party and operator
This distinction decides who you should approach about your information, so it is worth being precise about it.
Where we are the responsible party (controller)
For information about our own customers and the people who work for them - account holders, Hub users, billing contacts, people who email us - we decide why and how the information is processed. We answer for it directly.
Where we are the operator (processor)
For the conversations that flow through the platform - the messages a business sends and receives, and the phone numbers and profile names of the people on the other end - we act on behalf of our customer. The business you messaged decides what to send, to whom and why. We process that information only to deliver the service, under section 20 and 21 of POPIA, and we do not use it for our own purposes.
In practice: if you are a consumer who messaged a business on WhatsApp, that business is the responsible party for your information. See section 4.
3. Personal information we process
Account and user information
- Name, email address, mobile number and profile image of people who sign in to the Hub
- Authentication identifiers, sign-in timestamps and the permissions assigned to each user
- Organisation name and logo
Billing information
- Billing contact details, country, currency, tax and VAT registration numbers
- Subscriptions, quotes, invoices and payment records
Message information processed for our customers
- Sender and recipient WhatsApp numbers and the display names WhatsApp provides
- Message content, including text, media attachments, locations, contact cards and interactive replies
- Delivery metadata: timestamps, delivery and read status, provider identifiers and error codes
- Records of webhook deliveries we made to our customer’s systems, including the request and response bodies, which we keep so delivery problems can be diagnosed
- Message templates and their revision history
Technical and operational information
- Server logs, application traces and performance metrics, used to keep the platform running
- Usage statistics. These are aggregated at channel and account level - message counts, delivery outcomes, media types, error categories. They do not contain phone numbers, names or message content.
We do not maintain a separate contact or CRM database about the people our customers message. Their details exist only as part of the message records described above.
4. If you messaged a business on WhatsApp
You may have reached this page because a business you contacted uses Relay66. We are the infrastructure that carried your message. We did not decide to contact you, we do not market to you, and we do not build a profile of you.
Approach the business you messaged first. They hold the relationship with you, they chose what to send, and they are the responsible party for your information. They can act on your request without involving us.
If you cannot reach them, or you want your information removed from our systems specifically, email [email protected]. We will identify the relevant business, act on their authorisation as their operator, and confirm the outcome to you. Full instructions are on our data deletion page.
We cannot delete anything held by Meta on WhatsApp’s own systems, or the copy of the conversation on your own phone. Those are governed by WhatsApp’s privacy policy and controlled by you.
5. Why we process information, and our lawful basis
POPIA requires processing to be justified under section 11, and the GDPR under Article 6. Our grounds are:
- Performance of a contract. Creating and running accounts, connecting channels, transmitting messages, storing media, delivering webhooks, issuing invoices and providing support.
- Legitimate interests. Keeping the platform secure and available, investigating abuse and fraud, diagnosing delivery failures, and understanding aggregate usage so we can improve the service. We balance these against your interests and rights.
- Legal obligation. Retaining accounting and tax records, and responding to lawful requests from authorities.
- Consent. Where we ask for it, such as optional product updates. You can withdraw consent at any time.
Where we act as operator, our customer is responsible for establishing a lawful basis for the messages they send, including the opt-in that Meta’s WhatsApp Business Messaging Policy requires and the consent that section 69 of POPIA requires for electronic direct marketing.
7. Cross-border processing
Our production systems run in Frankfurt, Germany. Databases, message records and media are stored in the European Union, not in South Africa. If you are a South African customer, your information leaves the Republic.
Section 72 of POPIA permits this where the receiving jurisdiction has a law providing a substantially similar level of protection, or where the recipient is bound by binding corporate rules or contract to similar standards. Germany is subject to the GDPR, which meets that test, and our hosting provider is contractually bound to protect the information it holds for us.
Message traffic also reaches Meta, which operates globally and transfers information under its own terms and safeguards.
8. How long we keep information
We keep personal information only for as long as it is needed for the purpose it was collected for, and then dispose of it. Rather than fix a single period, we apply these criteria:
- Message and media records are kept for the period configured on the channel by the customer who owns it, so that conversations, delivery status and attachments remain available for as long as that business needs them, and no longer.
- Webhook and provider delivery records are kept only as long as they are useful for diagnosing delivery problems, with failed attempts kept longer than successful ones.
- Account and user records are kept while the account is open, and removed after closure once the recovery period described in our data deletion instructions has passed.
- Aggregate usage statistics are kept while the account is open and removed when it is deleted.
- Invoices, payment records and accounting data are kept for the periods required by South African company and tax legislation. These survive deletion of the account, because we are obliged to keep them.
Customers can configure retention on their channels in the Hub, within the limits of their plan.
9. How we protect information
Section 19 of POPIA requires appropriate technical and organisational measures. The measures we apply include:
- Encryption of all traffic in transit, on our public endpoints and between our services and the database
- Encryption of data at rest, covering the database volumes that hold your information, the backups taken from them, and the object storage where media is kept
- Authentication through a dedicated identity provider, with multi-factor authentication available to accounts that enable it
- Scoped API credentials, so an integration only receives the permissions it needs
- Separation of the platform into distinct databases by function, so that messaging, billing and identity data are not held together
- Signed webhooks, so our customers can verify that a delivery genuinely came from us
- Monitoring and alerting on the availability of the platform
No platform is perfectly secure, and we do not claim otherwise. If a security compromise affects personal information, we will notify the Information Regulator (South Africa) and affected people as section 22 of POPIA requires.
10. Your rights
Under POPIA you may:
- Ask whether we hold information about you, and ask for a copy
- Ask us to correct or complete information that is wrong
- Ask us to delete or destroy information we no longer have grounds to keep
- Object to processing based on legitimate interests, on reasonable grounds
- Withdraw consent where we relied on it
- Complain to the Information Regulator (South Africa)
If the GDPR applies to you, you additionally have rights to restriction of processing and to data portability, and you may complain to your local supervisory authority.
To exercise any of these, email [email protected]. We will ask for enough information to confirm who you are before we act, and will respond without undue delay. Where the request concerns a message conversation, we will refer it to the business that holds the relationship with you, or act on their instruction.
The Regulator can be reached at inforegulator.org.za or [email protected].
12. Changes to this policy
We will update this policy as the platform changes. The date at the top of the page reflects the current version. Where a change materially affects how we handle personal information, we will tell affected customers before it takes effect.
13. Contact us
Privacy questions, requests and complaints go to our Information Officer at [email protected]. For anything else, email [email protected].
- Registered name
- Relay66 (Pty) Ltd
- Registration number
- 2026/552149/07
- Registered address
- Cape Town, Western Cape, South Africa
- Information Officer
- Dane Killian