Privacy Policy
Last updated: August 21, 2026
1. Who We Are
This Privacy Policy is provided by Plada, Corp., a company incorporated in the United States.
- Website: https://plada.ai
- Contact: support@plada.ai
Plada is a multi-tenant SaaS platform designed for service businesses — including schools, clinics, gyms, and agencies. Plada enables each business to:
- Connect their WhatsApp Business Account (WABA) via Meta Embedded Signup
- Send and receive WhatsApp messages with their customers
- Connect their business email inbox (Google Gmail or Microsoft Outlook) via OAuth to sync emails and extract structured business data
- Use AI-powered automated replies (powered by Anthropic Claude) grounded in the business's own data
- Build custom workflows and applications on the Plada platform
Plada is a server-to-server application. After a business connects its WABA, all Meta Graph API calls are made backend-to-backend on behalf of that business.
2. Scope of This Policy
This Privacy Policy applies to all users of the Plada platform, including:
- Business users — owners, operators, and employees who configure and manage their accounts on Plada.
- End users / consumers — individuals who interact with businesses through applications or messaging channels (including WhatsApp) powered by Plada.
It covers information collected through the Plada web application, APIs, and any integrations with third-party platforms such as Meta's WhatsApp Business Platform.
By using Plada, you agree to the practices described in this Privacy Policy.
Plada does not direct its services to individuals located in the European Economic Area. If we offer them there in the future, we will designate a representative in accordance with Article 27 of the GDPR and identify them in this policy.
3. Information We Collect
3a. Information You Provide
We may collect information you voluntarily provide, including:
- Name, email address, and phone number
- Account credentials and authentication information
- Business information (business name, role, services offered)
- Messages, forms, files, images, or other content you submit
- Payment-related information (processed by third-party providers)
- Communications with Plada support
3b. Information Collected Automatically
When you use our Services, we may automatically collect:
- Device information (device type, OS version, browser type)
- Log data (IP address, timestamps, usage events)
- Approximate location (derived from IP address; no precise GPS unless explicitly enabled)
- Performance and diagnostic data
3c. WhatsApp Business Platform Data
When a business connects its WhatsApp Business Account to Plada through Meta Embedded Signup, Plada receives and processes the following categories of data from Meta's WhatsApp Business Platform:
- Message content — text messages, media (images, documents, audio, video), message templates, and interactive replies
- Customer phone numbers and display names — as provided via WhatsApp conversations
- Message delivery and read statuses — sent, delivered, read, and failed status events
- WABA identifiers and phone number metadata — WhatsApp Business Account IDs, phone number IDs, display phone numbers, and quality ratings
- Webhook event data — real-time event notifications delivered by Meta to Plada's servers
This data is received via the Meta Graph API and WhatsApp Cloud API webhooks, and is processed solely to provide the messaging and automation features described in this policy.
3d. Information Processed by AI Features
If you use Plada's AI-powered features, Plada may process:
- Text, files, images, or data you submit for analysis or automated responses
- WhatsApp message content (with business authorization) to generate AI-powered replies
- Email content (with business authorization) to extract structured business data such as opportunities, inquiries, and tickets
- Business or workflow data associated with your account
AI processing is performed only to provide the requested functionality. See Section 5 for details on how AI data is handled.
3e. Email Integration Data (Google Gmail and Microsoft Outlook)
When a business connects an email inbox to Plada via Google OAuth (Gmail) or Microsoft OAuth (Outlook), Plada syncs and processes messages from that mailbox solely for the purpose of providing the email-integration features the business has activated (such as inbox indexing, search, and AI-powered extraction of business data).
Google OAuth scopes Plada may request:
https://www.googleapis.com/auth/gmail.readonly— read messages, threads, labels, and metadata so Plada can sync your inbox and run extraction.https://www.googleapis.com/auth/gmail.modify— apply Plada-managed labels (e.g. "Plada: processed") and mark messages as read after Plada processes them. Plada does not delete, move to trash, or send messages under this scope.https://www.googleapis.com/auth/gmail.send— only requested if your business explicitly enables outbound automated replies. Plada never sends bulk or unsolicited email.
Microsoft Graph permissions Plada may request:
Mail.Read— read messages, folders, and metadata from the connected Outlook mailbox.User.Read,offline_access,openid,email,profile— basic identity and refresh-token capabilities required by the OAuth flow itself.
Email data Plada accesses and stores:
- Message headers (From, To, Cc, Subject, Date, message-id, thread-id)
- Message body (plain text and, when present, HTML)
- Attachment metadata (filename, MIME type, size) and, where the business activates attachment ingestion, attachment bytes
- Labels / folders applied to the message in Gmail or Outlook
- OAuth tokens (access and refresh) for the connected account, stored encrypted with AES-256-GCM at the application layer
Where the data is stored:
- Headers, body plain text, and labels are stored in Amazon DynamoDB in the AWS us-east-1 region.
- Full HTML bodies and attachment bytes are stored in Amazon S3 in the AWS us-east-1 region, under a per-tenant, per-account key prefix.
- All data at rest is encrypted (SSE-S3 for object storage, SSE for DynamoDB). OAuth tokens carry an additional layer of application-level AES-256-GCM encryption.
- All data in transit is protected by TLS 1.2 or higher.
Retention and deletion:
- Synced emails are retained while the connection is active.
- When you disconnect an email account (or revoke access from Google's or Microsoft's account-management page), Plada automatically and immediately deletes every synced message, every stored HTML body, and every stored attachment associated with that account from DynamoDB and S3.
- Encrypted OAuth tokens are invalidated and removed at the same time.
- You can also request deletion at any time at support@plada.ai — see Section 9.
3f. Google Sheets and Drive Integration
When a business connects Google Sheets or Google Drive to Plada via Google OAuth, Plada reads and writes the spreadsheets the business connects, solely to keep the business's collection and catalog data in sync with the documents Plada generates (such as a generated linesheet). Plada accesses only the spreadsheets the business explicitly connects — it does not browse, list, or access other files in the user's Google Drive.
Google OAuth scopes Plada may request:
https://www.googleapis.com/auth/spreadsheets— read and write the spreadsheets the business connects, so Plada can read the business's existing collection spreadsheets and write updates back, keeping them in two-way sync with the Plada-generated linesheet. The non-sensitivedrive.filescope is insufficient because it only covers files the app itself created and cannot read the business's pre-existing spreadsheets.https://www.googleapis.com/auth/drive.file— create and manage only the files Plada itself creates in the user's Drive (e.g. the generated linesheet). Does not grant access to other Drive files.openid,email— basic identity required by the OAuth flow.
Sheets/Drive data Plada accesses and stores:
- Cell values and structure (sheets, rows, columns) of the spreadsheets the business connects
- File and spreadsheet identifiers for the connected documents
- OAuth tokens (access and refresh) for the connected account, stored encrypted with AES-256-GCM at the application layer
This data is stored in Amazon DynamoDB in the AWS us-east-1 region, encrypted at rest, with TLS 1.2+ in transit — the same controls described for email data above.
Retention and deletion:
- Synced spreadsheet data is retained while the connection is active.
- When you disconnect the account (or revoke access at myaccount.google.com/permissions), Plada deletes the synced spreadsheet data and invalidates the stored OAuth tokens.
- Use of data from these scopes adheres to the Google API Services User Data Policy (Limited Use) — see Section 14.
3g. Cookies and Local Storage
Plada does not use advertising, tracking or profiling cookies, and does not share browsing data with advertising networks. In your browser we store your language preference, your theme preference and your answer to the cookie notice, so the site looks the way you left it and so we do not ask you twice; you can clear them from your browser settings. Our network provider generates technical logs of requests, including the IP address, for security and aggregate traffic measurement; those logs are not used to identify you or for advertising, and are retained for 90 days.
3g-bis. Website Analytics
On plada.ai we use Google Analytics 4, provided by Google, to understand how the website is used — which pages are visited, from which country and on what kind of device — so we can improve it. These analytics cookies are NOT set when you arrive. They are blocked by default and are only enabled after you accept them in the cookie notice; if you reject, or if your browser sends a Global Privacy Control or Do Not Track signal, no analytics cookie is written and no data is sent. Advertising and personalisation signals remain disabled at all times: this data is never used for advertising and is never combined with advertising audiences. Google processes an approximate location derived from your IP address without storing the full address. We keep this data for a maximum of 14 months. You can change your answer at any time from the Cookies link in the site footer, or by clearing your browser's site data; withdrawing consent stops any further collection.
3h. Sensitive Data
Plada may process sensitive data — health data or biometric data, for example — when the customer business uploads it to the platform. That processing is carried out on behalf of and under the instruction of that business, which is responsible for obtaining the data subject's explicit authorisation and for informing them that they are not obliged to authorise its processing. Plada neither requires nor induces the upload of sensitive data: the business can operate the platform without it.
3i. Sources of the Data
We receive personal data from: you directly, when you create an account, fill in a form or write to us; your browser and device, automatically, when you use the service; the business that operates the account, when you interact with it through a channel powered by Plada; and the platforms the business connects — specifically Meta for WhatsApp, Google for Gmail, Sheets and Drive, and Microsoft for Outlook.
4. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Plada platform
- Authenticate users and manage accounts
- Deliver and receive WhatsApp messages on behalf of connected businesses
- Sync emails from connected Gmail or Outlook inboxes and extract structured business data (such as opportunities, leads, inquiries) for the connecting business
- Power AI-driven automated replies and workflow features
- Process transactions and subscriptions
- Communicate with you (service updates, support responses)
- Monitor security, prevent fraud, and enforce our policies
- Comply with legal obligations
Plada does not sell personal data.
Legal Basis for Processing
We process your data on the basis of: performance of the contract between us, in order to provide, authenticate and bill the service; our legitimate interest, for security, fraud prevention and product improvement; your consent, for commercial communications and for the integrations you explicitly connect; and compliance with legal obligations, where the law requires us to retain or hand over information. In Colombia, the basis is the data subject's prior, express and informed authorisation under the terms of Law 1581 of 2012.
5. AI and Automated Processing
Plada uses artificial intelligence — specifically Anthropic's Claude models — to help businesses automate WhatsApp replies, generate content, and analyze data at the direction of each business.
- No model training: WhatsApp Business Platform Data and user data are not used to train, fine-tune, or improve any AI or machine learning models — including Anthropic Claude or any other model.
- Inference only: Data is sent to Anthropic's API solely for real-time inference (generating a response).
- Provider retention: The AI model providers we use apply their own retention policies, published in their documentation, and the version in force at any given time governs. As of the date of this policy, inputs and outputs are deleted automatically within thirty (30) days of receipt or generation, unless a different arrangement is in place with the provider, unless retention is necessary to enforce their usage policies, or unless the law requires it. If an interaction is flagged by their automated safety systems, it may be retained for up to two (2) years. In no case is it used to train models.
- Business-controlled: AI features are activated and configured by the business. Each business is responsible for reviewing and approving AI-generated responses.
- No sale or sharing for AI: Platform Data processed through AI features is not sold, licensed, or shared with any third party for their own purposes.
No Automated Decisions with Legal Effects
Plada's AI features prepare, classify and draft, but they do not take decisions that produce legal effects or that significantly affect a person. Any response or action with an effect on a third party requires review and approval by a person at the business that operates the account.
6. Data Sharing and Service Providers
Plada shares data only with the third-party service providers listed below, and only to the extent necessary to operate the platform. All processors are bound by data processing agreements and confidentiality obligations.
| Provider | Purpose | Country |
|---|---|---|
| Google LLC | Website analytics (Google Analytics 4), only with your prior consent | United States |
| Amazon Web Services (AWS) | Cloud hosting, database (DynamoDB), file storage (S3) | United States (us-east-1) |
| Anthropic, PBC | Claude AI model inference for automated responses | United States |
| Stripe, Inc. | Payment processing | United States |
Meta Platforms, Inc. is the upstream source of WhatsApp Business Platform Data. Meta is not a processor of Plada's data; rather, Plada processes data received from Meta's platform on behalf of connected businesses.
Google LLC and Microsoft Corporation are the upstream sources of Gmail and Outlook email data, respectively. Neither Google nor Microsoft is a processor of Plada's data; Plada processes email data received from their APIs on behalf of the business that authorized the connection via OAuth.
We may also share information:
- With third-party integrations a business explicitly connects
- If required by law, subpoena, or legal process
- To protect the rights, safety, and security of Plada and its users
- In connection with a business transaction (merger, acquisition, or asset sale)
7. Payments
Payments are processed by Stripe, Inc. Plada does not store full payment card numbers or CVVs on its servers.
Payment data is handled in accordance with Stripe's privacy policy and PCI DSS requirements.
8. Data Retention
We retain data according to the following schedule:
| Data Category | Retention Period |
|---|---|
| Active account data | Retained while the account is active |
| WhatsApp message history | Up to 12 months by default, configurable to less by the business, or until the business requests deletion — whichever comes first |
| Synced email content (Gmail / Outlook) | Retained while the email account is connected; deleted automatically and immediately upon disconnect, OAuth revocation, or user request |
| Synced spreadsheet data (Google Sheets / Drive) | Retained while the account is connected; deleted upon disconnect, OAuth revocation, or user request |
| OAuth tokens (Google, Microsoft) | Encrypted at rest; invalidated and removed upon disconnect |
| Deleted account data | Permanently removed within 90 days of account deletion |
| AI provider inputs and outputs | The AI model providers we use apply their own retention policies, published in their documentation, and the version in force at any given time governs. As of the date of this policy, inputs and outputs are deleted automatically within thirty (30) days of receipt or generation, unless a different arrangement is in place with the provider, unless retention is necessary to enforce their usage policies, or unless the law requires it. If an interaction is flagged by their automated safety systems, it may be retained for up to two (2) years. In no case is it used to train models. |
| Diagnostic logs | 90 days |
Data may be retained beyond these periods only when required by law, regulation, or an active legal proceeding.
9. Data Deletion and User Rights
Requesting Deletion
You may request deletion of your data through any of these methods:
- Email: Send a request to support@plada.ai
- WhatsApp data-deletion endpoint: https://api.plada.ai/whatsapp/data-deletion
- Disconnect an email account: from the Plada dashboard → Connected Accounts → click Disconnect on the Gmail or Outlook card. Disconnection triggers immediate deletion of all synced messages, HTML bodies, and attachments associated with that account from Plada's storage.
- Revoke at the source: you can also revoke Plada's OAuth access directly at myaccount.google.com/permissions (Google) or myaccount.microsoft.com (Microsoft). Revocation leads to the same purge on Plada's side.
General deletion requests are processed within 30 days. Email-account disconnect/revocation triggers deletion immediately. You will receive a confirmation once your data has been removed.
Your Rights
Depending on your location and applicable law (including GDPR and CCPA), you may have the right to:
- Access the personal data we hold about you
- Correct or update inaccurate information
- Request deletion of your personal data
- Object to or restrict certain processing
- Data portability — export your data in a structured format
- Opt out of the sale of personal information (Plada does not sell personal data)
- Not be discriminated against for exercising any of these rights. We will not deny you the service, charge you a different price, or give you a different level of quality because you exercised a privacy right.
- Lodge a complaint with the data protection authority that applies to you. In Colombia, the Superintendencia de Industria y Comercio. In the European Economic Area, the supervisory authority of your country of residence. In California, the State Attorney General or the California Privacy Protection Agency.
To exercise any of these rights, contact us at support@plada.ai.
Deadlines
Answering you and emptying our systems are two different clocks. This is which is which:
| Clock | What it is | Deadline |
|---|---|---|
| Answer | Replying to someone who requests access, correction or deletion | 15 business days in Colombia. 30 calendar days elsewhere |
| Consult | Requesting information only, without a complaint | 10 business days in Colombia |
| Empty | Purging the systems after an account is terminated | 90 days |
| Disconnect | Deletion on disconnecting email or Sheets | Immediate |
10. Security
We implement industry-standard safeguards to protect your information, including:
- Encryption in transit (TLS) and at rest (AES-256)
- Role-based access controls and principle of least privilege
- Continuous monitoring and logging of access to sensitive data
- Secure cloud infrastructure hosted on AWS
No system is 100% secure, but we continuously evaluate and improve our protections.
11. International Data Transfers
Plada's infrastructure is primarily hosted in AWS us-east-1 (United States). If you are located outside the United States, your data will be transferred to and processed in the United States.
Where required by applicable law (such as the GDPR), Plada relies on Standard Contractual Clauses (SCCs) or other legally recognized transfer mechanisms to ensure an adequate level of protection for personal data transferred internationally.
For data subjects in Colombia, the transfer of data to the United States relies on the declaration of an adequate level of protection in Circular Externa 005 of 2017 of the Superintendencia de Industria y Comercio. Where a provider is located in a country without that declaration, we will first adopt one of the safeguards set out in Article 26 of Law 1581 of 2012.
12. Children's Privacy
Plada is not directed at children under the age of 13, and we do not knowingly collect personal data from children under 13, in compliance with the Children's Online Privacy Protection Act (COPPA).
If we learn that we have collected personal data from a child under 13, we will promptly delete that information. If you believe a child has provided us with personal data, please contact us at support@plada.ai.
That covers minors as end users of the platform. Separately, customer businesses may process minors' data on the platform under their own responsibility as controllers. Where a business processes the data of anyone under 18 in Colombia, it must hold the prior authorisation of the minor's legal representative and must have heard the minor's own view according to their maturity, under Article 7 of Law 1581 of 2012 read together with Constitutional Court Judgment C-748 of 2011. Plada does not verify that authorisation.
13. Meta Platform Terms Compliance
Plada accesses and processes WhatsApp Business Platform Data in accordance with Meta's Platform Terms and Developer Policies, including the following commitments:
- Platform Data received from Meta is used solely to provide and improve the Plada service for connected businesses.
- Platform Data is not sold, licensed, or shared with any third party except the data processors listed in Section 6.
- Platform Data is not used to train AI models or for any purpose unrelated to the services requested by the business.
- Plada provides mechanisms for data deletion as described in Section 9, including an automated data-deletion callback endpoint.
- Plada implements appropriate technical and organizational security measures to protect Platform Data as described in Section 10.
14. Google API Services User Data Policy
Plada's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Plada uses data accessed through Gmail API scopes only to provide and improve the email-integration features the connecting business has activated (inbox sync, indexing, AI-powered extraction, label management, and — when explicitly enabled by the business — outbound automated replies).
- Plada uses data accessed through the Google Sheets and Drive scopes (
spreadsheets,drive.file) only to provide the spreadsheet-sync features the business has activated — reading the spreadsheets the business connects and writing updates back to keep them in sync with Plada-generated documents. - Plada does not transfer Google user data to any third party except as necessary to provide or improve user-facing features (Anthropic for inference of business-content-only prompts; AWS as the underlying hosting provider — see Section 6), or as required by law.
- Plada does not use Google user data to serve advertisements of any kind.
- Plada does not allow humans to read Google user data unless (a) we have obtained the user's affirmative agreement for specific messages, (b) it is necessary for security purposes (such as investigating abuse), (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and is used for internal operations in accordance with applicable privacy laws.
- Plada does not use Google user data to develop, improve, or train generalized AI and/or machine learning models. Email content sent to Anthropic's Claude API for per-tenant business-data extraction is processed for that single inference request only and is not retained by Anthropic for model training (Anthropic's API does not train on its API customers' data).
15. Microsoft Graph Compliance
Plada's use of Microsoft Graph APIs (including Outlook mail data) adheres to the Microsoft APIs Terms of Use and the Microsoft Services Agreement. The same Limited-Use principles outlined in Section 14 for Google data apply equally to data Plada receives from Microsoft Graph: business-purpose only, no advertising use, no model training, no third-party transfer except to the processors listed in Section 6 or as required by law, and immediate deletion on disconnect or token revocation.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Plada application or website.
Continued use of Plada after updates constitutes acceptance of the revised policy. We encourage you to review this page periodically.
17. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, contact us at:
Company: Plada, Corp.
Email: support@plada.ai
Website: https://plada.ai
Data Deletion Endpoint: https://api.plada.ai/whatsapp/data-deletion