Relay66[email protected]

1. Who we are and what this policy covers

Relay66 is a business messaging platform operated by Relay66 (Pty) Ltd, a company registered in the Republic of South Africa. We connect businesses to the WhatsApp Business Platform, giving them an API to send messages, signed webhooks to receive them, and a management portal (the Hub) to run the channel day to day.

This policy explains what personal information we handle, why, who we share it with and what rights you have. It applies to our website, the Hub, our APIs and the support we provide. It is written to meet the Protection of Personal Information Act 4 of 2013 (POPIA) and, where it applies, the EU General Data Protection Regulation (GDPR).

Relay66 is offered to businesses. It is not intended for personal or household use.

Registered name
Relay66 (Pty) Ltd
Registration number
2026/552149/07
Registered address
Cape Town, Western Cape, South Africa
Information Officer
Dane Killian

2. Our two roles: responsible party and operator

This distinction decides who you should approach about your information, so it is worth being precise about it.

Where we are the responsible party (controller)

For information about our own customers and the people who work for them - account holders, Hub users, billing contacts, people who email us - we decide why and how the information is processed. We answer for it directly.

Where we are the operator (processor)

For the conversations that flow through the platform - the messages a business sends and receives, and the phone numbers and profile names of the people on the other end - we act on behalf of our customer. The business you messaged decides what to send, to whom and why. We process that information only to deliver the service, under section 20 and 21 of POPIA, and we do not use it for our own purposes.

In practice: if you are a consumer who messaged a business on WhatsApp, that business is the responsible party for your information. See section 4.

3. Personal information we process

Account and user information

  • Name, email address, mobile number and profile image of people who sign in to the Hub
  • Authentication identifiers, sign-in timestamps and the permissions assigned to each user
  • Organisation name and logo

Billing information

  • Billing contact details, country, currency, tax and VAT registration numbers
  • Subscriptions, quotes, invoices and payment records

Message information processed for our customers

  • Sender and recipient WhatsApp numbers and the display names WhatsApp provides
  • Message content, including text, media attachments, locations, contact cards and interactive replies
  • Delivery metadata: timestamps, delivery and read status, provider identifiers and error codes
  • Records of webhook deliveries we made to our customer’s systems, including the request and response bodies, which we keep so delivery problems can be diagnosed
  • Message templates and their revision history

Technical and operational information

  • Server logs, application traces and performance metrics, used to keep the platform running
  • Usage statistics. These are aggregated at channel and account level - message counts, delivery outcomes, media types, error categories. They do not contain phone numbers, names or message content.

We do not maintain a separate contact or CRM database about the people our customers message. Their details exist only as part of the message records described above.

4. If you messaged a business on WhatsApp

You may have reached this page because a business you contacted uses Relay66. We are the infrastructure that carried your message. We did not decide to contact you, we do not market to you, and we do not build a profile of you.

Approach the business you messaged first. They hold the relationship with you, they chose what to send, and they are the responsible party for your information. They can act on your request without involving us.

If you cannot reach them, or you want your information removed from our systems specifically, email [email protected]. We will identify the relevant business, act on their authorisation as their operator, and confirm the outcome to you. Full instructions are on our data deletion page.

We cannot delete anything held by Meta on WhatsApp’s own systems, or the copy of the conversation on your own phone. Those are governed by WhatsApp’s privacy policy and controlled by you.

5. Why we process information, and our lawful basis

POPIA requires processing to be justified under section 11, and the GDPR under Article 6. Our grounds are:

  • Performance of a contract. Creating and running accounts, connecting channels, transmitting messages, storing media, delivering webhooks, issuing invoices and providing support.
  • Legitimate interests. Keeping the platform secure and available, investigating abuse and fraud, diagnosing delivery failures, and understanding aggregate usage so we can improve the service. We balance these against your interests and rights.
  • Legal obligation. Retaining accounting and tax records, and responding to lawful requests from authorities.
  • Consent. Where we ask for it, such as optional product updates. You can withdraw consent at any time.

Where we act as operator, our customer is responsible for establishing a lawful basis for the messages they send, including the opt-in that Meta’s WhatsApp Business Messaging Policy requires and the consent that section 69 of POPIA requires for electronic direct marketing.

6. Who we share information with

We do not sell personal information and we do not share it for advertising. We rely on the following providers to run the service. Each processes information only as needed to perform its function.

  • Meta Platforms Ireland Limited - the WhatsApp Business Platform, which carries every message to and from its recipient. Meta is an independent controller of the information it holds under its own terms.
  • DigitalOcean - cloud hosting, managed databases and media storage, in Frankfurt, Germany.
  • Cloudflare - domain name resolution and TLS certificate issuance for our public endpoints.
  • Mailtrap - delivery of transactional email such as notifications and account messages.
  • OneUptime - collection of system telemetry and error traces so we can monitor availability. This is service-level data, not end-user profiles.
  • Google Ireland Limited - Google Analytics, which counts page views on this marketing website. Loaded only if you allow analytics cookies, and never on the Hub. See Cookies below.

Our identity and access management runs on Keycloak, which we host ourselves on our own infrastructure rather than through a third party.

We may also disclose information where the law requires it, to establish or defend legal claims, or to a purchaser as part of a merger or sale of the business, in which case we will tell affected customers.

7. Cross-border processing

Our production systems run in Frankfurt, Germany. Databases, message records and media are stored in the European Union, not in South Africa. If you are a South African customer, your information leaves the Republic.

Section 72 of POPIA permits this where the receiving jurisdiction has a law providing a substantially similar level of protection, or where the recipient is bound by binding corporate rules or contract to similar standards. Germany is subject to the GDPR, which meets that test, and our hosting provider is contractually bound to protect the information it holds for us.

Message traffic also reaches Meta, which operates globally and transfers information under its own terms and safeguards.

8. How long we keep information

We keep personal information only for as long as it is needed for the purpose it was collected for, and then dispose of it. Rather than fix a single period, we apply these criteria:

  • Message and media records are kept for the period configured on the channel by the customer who owns it, so that conversations, delivery status and attachments remain available for as long as that business needs them, and no longer.
  • Webhook and provider delivery records are kept only as long as they are useful for diagnosing delivery problems, with failed attempts kept longer than successful ones.
  • Account and user records are kept while the account is open, and removed after closure once the recovery period described in our data deletion instructions has passed.
  • Aggregate usage statistics are kept while the account is open and removed when it is deleted.
  • Invoices, payment records and accounting data are kept for the periods required by South African company and tax legislation. These survive deletion of the account, because we are obliged to keep them.

Customers can configure retention on their channels in the Hub, within the limits of their plan.

9. How we protect information

Section 19 of POPIA requires appropriate technical and organisational measures. The measures we apply include:

  • Encryption of all traffic in transit, on our public endpoints and between our services and the database
  • Encryption of data at rest, covering the database volumes that hold your information, the backups taken from them, and the object storage where media is kept
  • Authentication through a dedicated identity provider, with multi-factor authentication available to accounts that enable it
  • Scoped API credentials, so an integration only receives the permissions it needs
  • Separation of the platform into distinct databases by function, so that messaging, billing and identity data are not held together
  • Signed webhooks, so our customers can verify that a delivery genuinely came from us
  • Monitoring and alerting on the availability of the platform

No platform is perfectly secure, and we do not claim otherwise. If a security compromise affects personal information, we will notify the Information Regulator (South Africa) and affected people as section 22 of POPIA requires.

10. Your rights

Under POPIA you may:

  • Ask whether we hold information about you, and ask for a copy
  • Ask us to correct or complete information that is wrong
  • Ask us to delete or destroy information we no longer have grounds to keep
  • Object to processing based on legitimate interests, on reasonable grounds
  • Withdraw consent where we relied on it
  • Complain to the Information Regulator (South Africa)

If the GDPR applies to you, you additionally have rights to restriction of processing and to data portability, and you may complain to your local supervisory authority.

To exercise any of these, email [email protected]. We will ask for enough information to confirm who you are before we act, and will respond without undue delay. Where the request concerns a message conversation, we will refer it to the business that holds the relationship with you, or act on their instruction.

The Regulator can be reached at inforegulator.org.za or [email protected].

11. Cookies

This website sets no cookies until you allow them. We run no advertising pixels and no cross-site trackers at all.

If you allow it, we load Google Analytics to count page views and see which pages people actually find useful. It stores a randomly generated identifier in your browser and reports to Google. Nothing is requested from Google before you agree, and if you decline, the analytics code is never loaded.

You can change your mind whenever you like through the Cookie preferences link in the footer. Withdrawing permission deletes the analytics cookies and stops the code loading again.

Your answer is kept in your browser’s own storage so we do not have to ask on every visit. It is the one thing we store without asking first, and it never leaves your device.

The Hub sets strictly necessary cookies to keep you signed in and to protect the session. These are required for it to work and cannot be switched off while you are using it.

12. Changes to this policy

We will update this policy as the platform changes. The date at the top of the page reflects the current version. Where a change materially affects how we handle personal information, we will tell affected customers before it takes effect.

13. Contact us

Privacy questions, requests and complaints go to our Information Officer at [email protected]. For anything else, email [email protected].

Registered name
Relay66 (Pty) Ltd
Registration number
2026/552149/07
Registered address
Cape Town, Western Cape, South Africa
Information Officer
Dane Killian