1. Who we are and what this policy covers
Unwire Growth is operated by Unwire Growth LLC, a Wyoming limited liability company registered with the Wyoming Secretary of State under filing number 2026-002058685, at 30 N Gould St #31848, Sheridan, WY 82801, United States. For privacy matters contact privacy@unwiregrowth.com.
This policy covers three groups of people:
- Website visitors — anyone browsing https://unwiregrowth.com, including people who use the contact form;
- Customers — the businesses (and the people at those businesses) that buy our service, and prospective customers we talk to;
- End Users — the people who send WhatsApp messages to a number on which we operate an assistant for a customer.
We write this policy to meet the requirements of the EU and UK General Data Protection Regulation and comparable laws elsewhere. Where a specific law gives you more rights than this policy describes, that law applies.
2. Our role: controller or processor
The distinction matters because it decides who is responsible for what.
- For website visitors and customers we are the controller: we decide what data we collect and why, and this policy is our notice to you.
- For End User conversation data our customer is the controller and we are their processor. The business you messaged decides why your messages are processed; we process them on that business’s instructions to run its assistant, under a data-processing agreement. Their privacy notice governs; section 11 explains how we help.
3. The data we collect
3.1 Website visitors
- Server logs. Our hosting provider records IP address, request time, requested URL, referrer and user-agent for security and to keep the site running. Logs are kept for a short period (see section 8).
- Contact form. Name, business name, email address, WhatsApp number (optional), sector, plan interest, your message, and the IP address the form was sent from (used for spam prevention).
- Call requests. When you ask for a setup call on our booking page: the same contact details, the time you chose, and your browser’s time zone, so that we confirm the right time.
- Cookies. This website does not set analytics or advertising cookies. See our Cookie Policy.
3.2 Customers and prospective customers
- Account and contact data: names, roles, email addresses, phone and WhatsApp numbers of the people we deal with; business name, address, registration and tax details.
- Billing data: invoices, payment history and the last four digits and expiry of your card. Full card details are held by our PCI DSS-compliant payment processor, not by us.
- Materials you give us to build the assistant: price lists, catalogues, policies, documents, past conversations (which may contain End User data), tone guidance and integration credentials.
- Meta assets: identifiers and access tokens for the Meta Business account, WhatsApp Business Account and phone number we operate for you.
- Correspondence with us by email, WhatsApp or on calls, including notes from kickoff and review calls. We do not record calls without telling you.
3.3 End Users
- Message content sent to and from the assistant, including text, and where the customer’s brief allows it, images, documents and voice notes you send;
- Metadata: your WhatsApp phone number, WhatsApp profile name, timestamps, delivery and read status;
- Details you choose to give in the conversation, such as a delivery address, an appointment preference or an order reference;
- Data returned by the customer’s integrations (for example an order status from their store) when the assistant looks it up for you.
We do not receive payment card details from End Users: payment links go to the customer’s own payment provider.
4. How we use it and why
| Purpose | Data | Legal basis (where GDPR applies) |
|---|---|---|
| Replying to enquiries and arranging a setup call | Contact form and correspondence | Legitimate interests (responding to you); steps before a contract |
| Providing the service: building, connecting, running and supporting the assistant | Customer account data, Materials, Meta assets, conversation data (as processor) | Performance of our contract with the customer |
| Billing, accounting and tax | Billing data | Contract; legal obligation |
| Quality assurance: reviewing samples of conversations and flagged misses to improve a customer’s assistant | Conversation data (as processor, on the customer’s instruction) | Customer’s instructions under the contract |
| Security, abuse and spam prevention | Server logs, IP addresses, form metadata | Legitimate interests (keeping the service safe) |
| Service emails: invoices, cancellations, notices of changes | Customer contact data | Contract; legal obligation |
| Occasional product news to customers (never to End Users) | Customer contact data | Legitimate interests, with an unsubscribe link in every email; consent where required |
| Establishing, exercising or defending legal claims | Whatever is relevant | Legitimate interests; legal obligation |
We do not sell personal data, we do not share it with data brokers, and we do not use End User conversations for advertising, profiling across businesses or training general-purpose AI models.
5. AI processing
The assistant generates replies using large language models operated by third-party providers, currently OpenAI, Anthropic and Google. To generate a reply, the relevant part of the conversation and the customer’s knowledge base are sent to the provider through its business API. Our agreements with these providers prohibit them from using the data to train their models and require them to delete it after processing or within a short retention period for abuse monitoring (typically 30 days or less).
The assistant does not make decisions with legal or similarly significant effects about End Users. It answers questions, books slots, sends links and hands conversations to people; commercial decisions (accepting an order, granting a refund, giving professional advice) are made by the customer’s staff.
Members of our team may read conversation logs to check quality, fix errors and improve the assistant for that customer, on the customer’s instructions and under confidentiality obligations. We minimise this access and log it.
6. Who we share data with
We share personal data only with the following categories of recipient, and only as needed:
- Meta Platforms, Inc. and its affiliates — messages are delivered through the WhatsApp Business Platform. Meta processes them under its own terms and its Business Data Processing Terms.
- AI model providers (section 5) — to generate replies.
- Hosting and infrastructure providers — the servers, databases and storage on which the assistant and its logs run, located in the United States.
- Payment processor — to take payments from customers. It handles card details directly.
- Email and communications providers — to send and receive email and to deliver contact-form messages to us.
- Integrations the customer chooses (their store, calendar, sheet or CRM) — the assistant sends and receives only what the brief requires.
- Professional advisers (accountants, lawyers, insurers) under confidentiality, and authorities where the law requires.
- A successor if our business is sold or merged, on the same terms as this policy, with notice to customers.
A current list of our sub-processors for End User data is available to customers on request at privacy@unwiregrowth.com, and we give customers 30 days’ notice before adding a new one.
7. International transfers
Some of the providers above process data outside the country where you or the customer are located, including in the United States. Where data protected by EU, UK or similar law is transferred to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant), the EU-US Data Privacy Framework where the recipient is certified, or other lawful mechanisms, together with additional safeguards such as encryption in transit and at rest.
8. How long we keep data
| Data | Retention |
|---|---|
| Contact-form enquiries and pre-sales correspondence | 24 months from last contact, then deleted, unless you become a customer |
| Customer account data and correspondence | Duration of the contract plus 6 years (for contractual and legal claims) |
| Billing records | As long as tax and accounting law requires (typically 7 to 10 years) |
| End User conversation data and assistant logs | Duration of the customer’s subscription, or a shorter period the customer specifies; exported to the customer on request and deleted from our systems within 30 days after the contract ends |
| Materials and assistant configuration | Duration of the contract; deleted within 30 days after it ends |
| Server and security logs | 90 days |
| Backups | Rolling backups are overwritten within 35 days; deleted data leaves backups on that cycle |
9. Security
We protect personal data with measures appropriate to the risk, including: encryption in transit (TLS) and at rest; access to production systems limited to named staff with multi-factor authentication and the least privilege needed; secrets and API tokens stored in a secrets manager, never in code; logging of administrative access; separation of each customer’s knowledge base and logs; regular dependency updates; and contractual security obligations on our providers. No system is perfectly secure; if we become aware of a personal-data breach affecting you or a customer we notify the customer without undue delay and, where the law requires, the relevant authority and affected individuals.
10. Your rights
Depending on where you are, you may have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- have data erased, where there is no overriding reason to keep it;
- restrict or object to processing, including to direct marketing at any time;
- receive data you gave us in a portable format;
- withdraw consent where processing is based on consent, without affecting earlier processing;
- complain to a supervisory authority — for the EU, the authority in your country of residence; for the UK, the Information Commissioner’s Office.
To exercise any of these, email privacy@unwiregrowth.com. We reply within one month (extendable by two further months for complex requests, with notice) and may need to verify your identity first. We do not charge for requests unless they are manifestly unfounded or excessive.
11. If you messaged one of our customers
If you sent a WhatsApp message to a business and an assistant we operate replied, that business is responsible for your data and its privacy notice applies. The quickest way to exercise your rights is to contact that business directly; the assistant will tell you how if you ask, and will hand you to a person on request. You may also contact us at privacy@unwiregrowth.com; we will pass your request to the business and help them respond within the legal deadlines. We never use your messages for anything other than running that business’s assistant.
12. Cookies and analytics
This website sets no analytics, advertising or tracking cookies. Our Cookie Policy lists exactly what is and is not stored on your device. If we introduce analytics in future we will update that policy and, where the law requires, ask for your consent first.
13. Children
Our service is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16 through this website. Assistants we operate for customers reply to whoever messages the business; customers whose services are aimed at minors must tell us so that appropriate handling can be configured.
14. Changes to this policy
We may update this policy as our service or the law changes. The effective date at the top shows the current version. For material changes affecting customers we give at least 30 days’ notice by email; for changes affecting how we process End User data on customers’ behalf we follow the notice terms of the data-processing agreement.
15. Contact
Privacy questions and requests: privacy@unwiregrowth.com.
Postal address: Unwire Growth LLC, 30 N Gould St #31848, Sheridan, WY 82801, United States.
If we appoint a data protection officer or a representative in the EU or UK, their details will be listed here.