Privacy Policy
Last updated: 11 October 2026 · Versión en español
Controller
RONIN 49, SOCIEDAD LIMITADA (Ronin 49, S.L.), tax ID B05630710, registered address LG. A Rocha, 114, 36400 O Porriño (Pontevedra), España. Privacy contact: contacto@roninfox.com.
This policy covers this website (ronin49.es) and Ronin 49's customer messaging platform, the service businesses use to handle their customers' WhatsApp conversations from a shared web inbox.
This website
- Email enquiries. If you write to us, we use your message and address to reply. Legal basis: your consent.
- Web analytics (only with your consent). If you accept analytics cookies we use Google Analytics 4 (Google Ireland Limited). Data is pseudonymised and may be transferred to the US under the EU-US Data Privacy Framework or standard contractual clauses. You can withdraw consent at any time from “Configurar cookies” in the footer.
Customer messaging platform for WhatsApp
With Ronin 49's customer messaging platform, a client business connects its own WhatsApp Business phone number through Meta's official Embedded Signup and, if it wishes, keeps using the WhatsApp Business app on its phone at the same time (Coexistence). Its authorised employees receive and reply to conversations from a multi-agent web inbox. We do not sell data, we do not use it for advertising and we do not share it with third parties except as described here.
Roles
- Client businesses and their employees (account, users, billing): Ronin 49 is the controller.
- Conversations with each business's end customers: the business is the controller and Ronin 49 acts as its processor (Article 28 GDPR) under our contract with it. If you messaged a business on WhatsApp, that business decides about your data; we help you exercise your rights with it.
Data we process
- WhatsApp messages and metadata: content of messages sent and received (text, images, audio, documents and shared locations), the contact's phone number and profile name, timestamps, message IDs and delivery/read statuses.
- Meta business identifiers: Business Portfolio ID, WhatsApp Business Account (WABA) ID, phone number ID and display name, message templates, and the access token Meta issues when the business authorises the connection.
- Agent data: name, email, role, company, conversation assignments and activity logs (logins, relevant actions and IP addresses) for security and audit.
- Client business data: legal name, contact and billing details.
We only request the Meta permissions the service needs: whatsapp_business_messaging (send and receive messages) and whatsapp_business_management (manage phone numbers, templates and webhook subscriptions) and, if Meta requires it for onboarding, business_management. We do not access personal Facebook profiles, friends, Pages or posts.
Purposes and legal bases
- Providing the service: connecting the number, displaying and delivering messages, assigning conversations, managing templates and keeping the history the business has contracted. Basis: performance of the contract with the client business (Art. 6(1)(b) GDPR) and, for conversations, its instructions as controller.
- Security, abuse prevention and audit. Basis: legitimate interest (Art. 6(1)(f) GDPR).
- Billing and legal obligations. Basis: legal obligation (Art. 6(1)(c) GDPR).
The client business must obtain its customers' opt-in before messaging them on WhatsApp and comply with the WhatsApp Business Messaging Policy. We use platform data only as described in this policy.
Recipients
- Meta Platforms Ireland Limited / WhatsApp Ireland Limited: messages travel through the WhatsApp Business Platform (Cloud API), operated by Meta under its own terms and privacy policy. Meta may process data outside the EEA with the safeguards set out in its terms.
- Infrastructure providers (hosting, databases, backups and transactional email) acting as sub-processors under data processing agreements. The current list is available to client businesses on request.
- Authorities and courts, only when required by law.
Security
- All traffic uses HTTPS; Meta webhooks are validated before being processed.
- Meta access tokens are encrypted at rest, never sent to the browser or written to logs, and used only by the integration service.
- Each business is isolated from the others: its agents only see its own numbers and conversations.
- Administrative access uses two-factor authentication and is audit-logged.
Retention
- Messages and history: while the business keeps the service, according to its retention settings.
- When a number is disconnected or the account is closed, the Meta token is revoked and deleted immediately and the history is deleted within 30 days, unless the business asks us to export it first or the law requires us to keep something.
- Technical and security logs (no message content): 90 days.
- Backups are overwritten in 30-day cycles.
- Billing data: as long as tax and commercial law require.
How to request deletion
Anyone who uses the platform, or whose data is in it, can ask us to delete it. The steps for each case (business, agent or end customer) are on our Data Deletion page. We respond within 30 days.
Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to contacto@roninfox.com. If your data is processed on behalf of a client business, we will forward your request to it and help it respond. You may also lodge a complaint with the Spanish Data Protection Agency (aepd.es).
Changes
If we make significant changes we will announce them on this page and email client businesses before they take effect.