1. Who we are
Archus Lab is a customer relationship management service operated by {{LEGAL_ENTITY}} (registration number {{REGISTRATION_NO}}), a company registered in Singapore with its registered office at {{REGISTERED_ADDRESS_FULL}}. In this policy, "Archus Lab", "we", "us", and "our" mean that company.
This policy applies to archuslab.com and to the Archus Lab application (together, the "Service").
2. Controller and processor
Archus Lab handles personal data in two distinct roles, and your rights differ depending on which applies.
| Role | Whose data | What it means |
|---|---|---|
| Controller | Our own customers — the businesses that subscribe to Archus Lab, and their staff users | We decide why and how this data is processed: account creation, billing, support, security, and product communication. |
| Processor | Our customers' contacts — the people a business messages through its own WhatsApp Business Account | The business is the controller. We process this data only on that business's documented instructions, to operate the Service on its behalf. |
If you were messaged by a business using Archus Lab and want your data corrected or deleted, contact that business first — it decides what happens to its customer records. If you cannot reach them, write to privacy@archuslab.com and we will pass the request on and help where the law requires us to.
3. Data we collect
3.1 Account data (we are the controller)
- Name, work email address, and telephone number of the people who register and use a workspace.
- Business name, billing address, tax identifiers, and payment records. Card details are handled by our payment processor; we do not store full card numbers.
- Authentication data: password hashes, session tokens, and multi-factor settings.
- Support correspondence you send us.
3.2 Customer data (we are the processor)
- Contact records a business creates or imports: name, WhatsApp phone number, email address, tags, custom fields, and consent records including opt-in source and date.
- Message content and metadata exchanged between that business and its contacts through the WhatsApp Business Platform, including media the parties send.
- Conversation state: assignment, internal notes, resolution status, and opt-out status.
3.3 Technical data
- IP address, browser type and version, operating system, and timestamps of requests to the Service.
- Application and audit logs recording administrative actions inside a workspace.
- Error and diagnostic reports.
4. WhatsApp Business Platform data
Archus Lab connects to the WhatsApp Business Platform to operate a business's own WhatsApp Business Account ("WABA"). We describe this separately because it is the part of the Service that most affects the people our customers message.
4.1 What connecting does
A business connects its WABA through Meta's Embedded Signup, inside its own Meta login. Archus Lab never receives or asks for Meta account passwords. The WABA, the business phone number, and the Meta billing relationship remain owned by that business in its own Meta Business Manager.
4.2 What we access, and why
| Permission | What we access | Why |
|---|---|---|
whatsapp_business_management |
The connected WABA's identifiers, registered phone numbers, display name, quality rating, and message templates | To show account status in settings and to let the business create, submit, edit, and delete its own message templates from our editor |
whatsapp_business_messaging |
Inbound and outbound messages on the connected number, and their delivery and read status | To deliver agents' replies, send approved templates to contacts who opted in, and display incoming customer messages in the shared inbox |
We request no other WhatsApp permissions. We do not access a WABA that has not been connected to us by an authorised administrator of the business that owns it.
4.3 Consent and opt-out
Businesses using Archus Lab must obtain opt-in before sending template messages, and must honour opt-outs. Archus Lab records the opt-in source and date against each contact, recognises opt-out keywords in inbound messages, and blocks template sends to opted-out contacts at the point of sending. Our Acceptable Use Policy sets out what is and is not permitted, and we suspend accounts that breach it.
4.4 Meta's own processing
Messages sent through the WhatsApp Business Platform are also processed by Meta Platforms, Inc. and its affiliates as part of delivering them. That processing is governed by Meta's and WhatsApp's own terms and privacy policies, which we do not control.
5. How we use data
- To provide the Service: deliver and display messages, maintain contact records, run the template editor, and keep workspaces available.
- To secure it: authenticate users, detect abuse and fraud, rate-limit, and investigate incidents.
- To support you: answer tickets and diagnose faults.
- To bill: issue invoices, take payment, and meet tax and accounting obligations.
- To improve the product: using aggregated and de-identified usage statistics. We do not read customer message content to build features, train models, or market to anyone.
- To meet legal obligations: respond to lawful requests and enforce our terms.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
6. Legal bases
Where the GDPR or UK GDPR applies to our processing as a controller, we rely on:
- Contract — to provide the Service to a subscriber and to bill for it.
- Legitimate interests — to secure the Service, prevent abuse, and improve the product, balanced against your rights.
- Legal obligation — accounting, tax, and lawful requests.
- Consent — where we ask for it, such as optional product emails. You can withdraw it at any time.
Where Singapore data protection law applies, we process personal data on the bases that law provides, including consent and the legitimate interests of the business we act for. Where we act as a processor, the controller is responsible for establishing its own basis, including opt-in for messaging.
7. Sharing and sub-processors
We share personal data only with:
- Sub-processors that run parts of the Service under written contract, listed below.
- The business you are a contact of, where we act as its processor.
- Professional advisers — auditors and lawyers, under confidentiality.
- Authorities, where we are legally required to disclose. We notify the affected customer unless prohibited by law.
- A successor entity in a merger or acquisition, subject to this policy.
| Sub-processor | Purpose | Location |
|---|---|---|
| Meta Platforms, Inc. | WhatsApp Business Platform message delivery | United States and global |
| Supabase (on AWS) | Application hosting and database | Singapore (ap-southeast-1) |
| Stripe | Subscription billing and payments | Singapore |
| Twilio SendGrid | Transactional and support email | United States |
We give workspace administrators advance notice before adding a sub-processor that processes customer data. To be told directly, subscribe by writing to privacy@archuslab.com.
8. International transfers
Personal data may be transferred outside Singapore — in particular to Meta in the United States, which is inherent to delivering WhatsApp messages. Where such a transfer occurs we rely on appropriate safeguards, including Standard Contractual Clauses or an equivalent mechanism recognised in the exporting jurisdiction, and we satisfy ourselves that the recipient provides a comparable standard of protection.
9. Retention
| Data | Kept for |
|---|---|
| Account and workspace records | The life of the subscription, then 30 days |
| Message content and contact records | The retention window the workspace sets, and in any case no longer than 30 days after termination |
| Billing and tax records | As required by law in Singapore, typically 7 years |
| Security and audit logs | 90 days |
| Backups | Rolling 35 days, after which deleted data ages out |
See Data deletion for how to ask us to delete data sooner.
10. Security
- TLS 1.2 or higher for all traffic in transit; encryption at rest for stored message content and contact records.
- Role-based access control inside each workspace, and least-privilege access for our own staff. Administrative actions are written to an audit log.
- Logical separation of every workspace's data.
- Multi-factor authentication available on Archus Lab accounts, and required for our staff.
- Encrypted, access-controlled backups, restore-tested on a regular schedule.
- Incident response: we notify affected customers without undue delay, and regulators within the period the applicable law requires.
No system is perfectly secure. If you believe you have found a vulnerability, please write to security@archuslab.com — we will acknowledge and will not pursue good-faith research.
11. Your rights
Subject to the law that applies to you, you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Correct data that is inaccurate or incomplete.
- Delete data, where we have no overriding obligation to keep it.
- Restrict or object to processing, including profiling.
- Receive your data in a portable, machine-readable format.
- Withdraw consent, without affecting processing already carried out.
- Complain to your data protection authority.
Write to privacy@archuslab.com. We respond within 30 days, and will verify your identity before acting. There is no charge for a reasonable request. If your data reached us because a business using Archus Lab holds you as a contact, see section 2 — we will route the request to that business.
12. Cookies and web fonts
This website sets no advertising or analytics cookies. It loads web
fonts from Google Fonts, which means your browser makes a request to
fonts.googleapis.com and fonts.gstatic.com, and your IP
address is processed by Google in order to serve those files.
The application sets a strictly necessary cookie to keep you signed in and to protect against cross-site request forgery. It cannot function without it, and it is not used for tracking.
13. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 18. Where a customer is a school or tuition centre, its contacts are ordinarily parents or guardians; that customer is responsible for its own basis for holding any data concerning a minor. If you believe a child's data has reached us, write to privacy@archuslab.com and we will delete it.
14. Changes
We will update this policy as the Service changes. The effective date at the top always reflects the current version. For material changes we give notice by email to workspace administrators, or in the application, at least 30 days before they take effect.
15. Contact us
Privacy enquiries and data subject requests
privacy@archuslab.com
Postal
{{LEGAL_ENTITY}}
{{REGISTERED_ADDRESS_FULL}}
{{PHONE}}
Our data protection contact is the Data Protection Officer, privacy@archuslab.com, reachable at the address above.