Skip to content
Osama Jenana

Privacy Policy

How Osama Raed Jenana Technology Company collects, uses, shares and retains personal data — on this website, and in the WhatsApp conversation platform we operate for business customers.

Last updated:

1.Who we are

Osama Raed Jenana Technology Company is a technology company registered in Palestine under commercial registration number 39679, company number 563493311, with its registered office at Gaza – Al-Rimal Al-Shamali – near Palestine Stadium, Palestine.

We build custom software and we operate an AI-assisted WhatsApp conversation platform for businesses. This policy explains what we do with personal data in both capacities.

For questions about this policy, or to exercise any of the rights described below, contact us at the details in the final section.

2.Two roles: controller and processor

The distinction matters, because it decides who you should contact about your data.

We are the controller for data we decide the purposes of ourselves: visitors to this website, people who send us a message through the contact form, and the business customers who hold an account with us.

We are a processor for the conversation data that flows through the platform. When a customer messages a business that uses our platform, that business decides why the conversation happens and what is done with it; we process it on that business’s documented instructions. Requests about those conversations are normally answered by the business, though we act on any request sent directly to us — see "If you messaged a business" below.

3.Data we collect

We collect only what a stated purpose below actually needs. We do not buy personal data, and we do not build advertising profiles.

Website enquiries
Name, email address, subject and message text you type into the contact form, plus the time it was submitted.
Server logs
IP address, user agent, requested URL, response status and timestamp. Written by the web server for security and debugging, not linked to a profile.
Business account data
Contact name, business name, email, phone number, the Meta business assets you connect (WhatsApp Business Account ID, phone number ID, display name), and billing records.
Conversation data
The WhatsApp phone number and profile name of the person messaging the business, message content, any media or documents sent, delivery and read receipts, and message timestamps. Processed on behalf of the business.
Order and catalogue data
Where the business uses the platform for commerce: items selected, quantities, delivery address if the customer provides one, order status and payment status.
AI processing data
The message text and the conversation context sent to a language model provider to draft or suggest a reply, and the reply returned.
Operational telemetry
Error traces, queue and delivery metrics, and audit records of who in the business account viewed or sent what.

4.Cookies and local storage

This website sets no advertising or analytics cookies and runs no third-party trackers. Your theme and language choices are kept in your own browser’s local storage and never leave your device.

The platform application sets a session cookie that is strictly necessary to keep a signed-in operator signed in. It carries no tracking value and expires when the session ends.

5.What we use it for

  • Answering enquiries sent through the contact form, and the correspondence that follows.
  • Creating and administering business accounts, and providing the platform they subscribed to.
  • Delivering messages to and from WhatsApp through the Meta WhatsApp Business Platform.
  • Generating or suggesting replies, classifying intent, and routing a conversation to a human when the model should not be deciding.
  • Recording orders and payment status where the business uses the platform for commerce.
  • Keeping the service secure and available: rate limiting, abuse prevention, backups and incident investigation.
  • Billing, accounting and meeting our tax and commercial record-keeping obligations.
  • Complying with the WhatsApp Business Messaging Policy and other platform rules that bind us as a Meta technology provider.

7.Who we share data with

We do not sell personal data, we do not rent it, and we do not share it for anyone else’s advertising. The recipients below are the complete list, and each one receives only what its stated function requires.

Meta Platforms, Inc.
Unavoidable and central: WhatsApp messages are delivered through the Meta WhatsApp Business Platform (Cloud API) and business assets are managed through the Meta Graph API. Meta receives recipient phone numbers, message content and media, template submissions, and delivery status. Meta processes that data under its own terms and privacy policy, which we do not control. Nothing in the platform sends Meta anything beyond what delivering the message requires.
Language model providers
Message text and conversation context are sent to the model provider configured for the customer’s account, solely to generate or suggest a reply. We use providers under business terms that exclude our data from model training, and we retain no copy at the provider beyond the request wherever the provider offers that setting. Customers are told which provider their account uses.
Payment providers
Where a business collects payment through the platform, the payment provider receives the amount, reference and whatever the provider itself requires to process the transaction. Card details are entered on the provider’s own page and never reach our servers.
Email delivery provider
Transactional email — contact form notifications, account and billing notices — is delivered by a third-party email API, which receives the recipient address and the message body.
Hosting
The application and its database run on servers we administer ourselves at a commercial hosting provider. The provider supplies the infrastructure and has no functional access to application data.
Professional advisers and authorities
Accountants, auditors and legal advisers under confidentiality, and any competent authority where disclosure is lawfully required. We tell the affected customer unless we are legally prohibited from doing so.

8.International transfers

Meta, the language model providers and the email delivery provider operate infrastructure outside Palestine, including in the United States and the European Union. Using the WhatsApp Business Platform necessarily means data crosses borders — there is no version of this service that keeps message delivery inside one country.

Where a provider offers contractual transfer safeguards, such as standard contractual clauses, we accept them. Where a provider offers a regional processing option that suits a customer’s requirements, we will configure it on request.

9.How long we keep it

Every category has an end date. Nothing is kept "just in case".

Contact form messages
24 months from the last message in the thread, then deleted — unless the enquiry became a contract, in which case it is kept with the project record.
Server logs
30 days, then rotated out. Retained longer only for a specific security incident under investigation.
Conversation and order data
For as long as the business customer’s account is active, or for the shorter period that customer configures. Deleted within 30 days of account termination or of a verified deletion request.
AI request context
Not stored separately from the conversation it belongs to. It is deleted when that conversation is deleted.
Account and billing records
Kept for the retention period that applicable tax and commercial law imposes on accounting records, counted from the end of the business relationship.
Backups
Encrypted backups roll on a 35-day cycle. Data deleted from the live system disappears from backups within that cycle at the latest; it is never restored back into the live system.

10.How we protect it

  • All traffic to the website and the platform is served over TLS. Plain HTTP is redirected, never served.
  • Webhooks from Meta are verified against Meta’s signature on the raw request body; an unsigned or mis-signed request is rejected before anything reads it.
  • Internal services authenticate to each other with HMAC signatures, so no component acts on a request another component did not sign.
  • Credentials and API keys live in server environment configuration, never in the codebase and never in the browser.
  • Operator access is role-separated and least-privilege; who saw and sent what is recorded in an audit trail.
  • Backups are encrypted at rest and their restore path is exercised, not assumed.
  • No security is absolute. If a breach affects your personal data we will notify the affected customers and any authority we are required to inform, without undue delay, and tell you what we know rather than what sounds reassuring.

11.Your rights

Subject to the law that applies to you, you can ask us to do any of the following. We do not charge for it, and we answer within 30 days of verifying who you are.

  • Access — get a copy of the personal data we hold about you, and know what we do with it.
  • Rectification — have anything inaccurate corrected, and anything incomplete completed.
  • Erasure — have your data deleted where we have no overriding legal reason to keep it. The steps are on the data deletion page.
  • Restriction — have processing paused while a dispute about accuracy or lawfulness is resolved.
  • Portability — receive the data you gave us in a structured, machine-readable format.
  • Objection — object to processing we base on legitimate interests, and we stop unless we can show compelling grounds.
  • Withdraw consent — at any time, without affecting processing already carried out lawfully before the withdrawal.
  • Complain — to your local data protection authority, if one has jurisdiction over you.

12.If you messaged a business

If you sent a WhatsApp message to a business that runs on our platform, that business is the controller of your conversation. It decides what the conversation is for, how long it is kept, and who inside the business can read it.

The fastest route is therefore to ask that business directly. If you would rather not, or the business does not respond, write to info@osamajenana.com with the WhatsApp number you messaged from and the name of the business. We will forward the request within five business days and act on it as soon as the business instructs us — and where we are ourselves the controller of the data in question, we act on it directly.

You can also stop the messages at any time by replying with a stop or unsubscribe request in the conversation, or by blocking the number in WhatsApp. An opt-out is honoured on the first request, not the second.

13.Children

The platform is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child’s data has reached us, tell us and we will delete it.

14.Changes to this policy

When the platform’s behaviour changes — a new subprocessor, a different retention window — this policy changes on the same day, and the date at the top moves with it.

Material changes are notified to business customers by email at least 30 days before they take effect, so there is time to object or to leave.

15.Contact us

Privacy questions, rights requests and complaints all go to the same place:

Osama Raed Jenana Technology Company Gaza – Al-Rimal Al-Shamali – near Palestine Stadium, Palestine Email: info@osamajenana.com · Phone: +970 59 290 3278 Commercial registration 39679 · Company number 563493311