Privacy Policy
How Osama Raed Jenana Technology Company collects, uses, shares and retains personal data — on this website, and in the WhatsApp conversation platform we operate for business customers.
Last updated:
1.Who we are
Osama Raed Jenana Technology Company is a technology company registered in Palestine under commercial registration number 39679, company number 563493311, with its registered office at Gaza – Al-Rimal Al-Shamali – near Palestine Stadium, Palestine.
We build custom software and we operate an AI-assisted WhatsApp conversation platform for businesses. This policy explains what we do with personal data in both capacities.
For questions about this policy, or to exercise any of the rights described below, contact us at the details in the final section.
2.Two roles: controller and processor
The distinction matters, because it decides who you should contact about your data.
We are the controller for data we decide the purposes of ourselves: visitors to this website, people who send us a message through the contact form, and the business customers who hold an account with us.
We are a processor for the conversation data that flows through the platform. When a customer messages a business that uses our platform, that business decides why the conversation happens and what is done with it; we process it on that business’s documented instructions. Requests about those conversations are normally answered by the business, though we act on any request sent directly to us — see "If you messaged a business" below.
3.Data we collect
We collect only what a stated purpose below actually needs. We do not buy personal data, and we do not build advertising profiles.
- Website enquiries
- Name, email address, subject and message text you type into the contact form, plus the time it was submitted.
- Server logs
- IP address, user agent, requested URL, response status and timestamp. Written by the web server for security and debugging, not linked to a profile.
- Business account data
- Contact name, business name, email, phone number, the Meta business assets you connect (WhatsApp Business Account ID, phone number ID, display name), and billing records.
- Conversation data
- The WhatsApp phone number and profile name of the person messaging the business, message content, any media or documents sent, delivery and read receipts, and message timestamps. Processed on behalf of the business.
- Order and catalogue data
- Where the business uses the platform for commerce: items selected, quantities, delivery address if the customer provides one, order status and payment status.
- AI processing data
- The message text and the conversation context sent to a language model provider to draft or suggest a reply, and the reply returned.
- Operational telemetry
- Error traces, queue and delivery metrics, and audit records of who in the business account viewed or sent what.
5.What we use it for
- Answering enquiries sent through the contact form, and the correspondence that follows.
- Creating and administering business accounts, and providing the platform they subscribed to.
- Delivering messages to and from WhatsApp through the Meta WhatsApp Business Platform.
- Generating or suggesting replies, classifying intent, and routing a conversation to a human when the model should not be deciding.
- Recording orders and payment status where the business uses the platform for commerce.
- Keeping the service secure and available: rate limiting, abuse prevention, backups and incident investigation.
- Billing, accounting and meeting our tax and commercial record-keeping obligations.
- Complying with the WhatsApp Business Messaging Policy and other platform rules that bind us as a Meta technology provider.
6.Our basis for processing
- Performance of a contract
- Account data, conversation data and order data — we cannot provide the platform a customer signed up for without processing them.
- Consent
- Messages you choose to send us through the contact form or WhatsApp. You can withdraw it at any time by asking us to delete the correspondence.
- Legitimate interests
- Server logs, security measures, abuse prevention and service improvement — balanced against your rights, and limited to what those purposes need.
- Legal obligation
- Invoices, accounting records and anything a competent authority lawfully requires us to keep or produce.
- Documented instructions
- For conversation data we act as a processor, on the instructions of the business customer who is the controller of it.
8.International transfers
Meta, the language model providers and the email delivery provider operate infrastructure outside Palestine, including in the United States and the European Union. Using the WhatsApp Business Platform necessarily means data crosses borders — there is no version of this service that keeps message delivery inside one country.
Where a provider offers contractual transfer safeguards, such as standard contractual clauses, we accept them. Where a provider offers a regional processing option that suits a customer’s requirements, we will configure it on request.
9.How long we keep it
Every category has an end date. Nothing is kept "just in case".
- Contact form messages
- 24 months from the last message in the thread, then deleted — unless the enquiry became a contract, in which case it is kept with the project record.
- Server logs
- 30 days, then rotated out. Retained longer only for a specific security incident under investigation.
- Conversation and order data
- For as long as the business customer’s account is active, or for the shorter period that customer configures. Deleted within 30 days of account termination or of a verified deletion request.
- AI request context
- Not stored separately from the conversation it belongs to. It is deleted when that conversation is deleted.
- Account and billing records
- Kept for the retention period that applicable tax and commercial law imposes on accounting records, counted from the end of the business relationship.
- Backups
- Encrypted backups roll on a 35-day cycle. Data deleted from the live system disappears from backups within that cycle at the latest; it is never restored back into the live system.
10.How we protect it
- All traffic to the website and the platform is served over TLS. Plain HTTP is redirected, never served.
- Webhooks from Meta are verified against Meta’s signature on the raw request body; an unsigned or mis-signed request is rejected before anything reads it.
- Internal services authenticate to each other with HMAC signatures, so no component acts on a request another component did not sign.
- Credentials and API keys live in server environment configuration, never in the codebase and never in the browser.
- Operator access is role-separated and least-privilege; who saw and sent what is recorded in an audit trail.
- Backups are encrypted at rest and their restore path is exercised, not assumed.
- No security is absolute. If a breach affects your personal data we will notify the affected customers and any authority we are required to inform, without undue delay, and tell you what we know rather than what sounds reassuring.
11.Your rights
Subject to the law that applies to you, you can ask us to do any of the following. We do not charge for it, and we answer within 30 days of verifying who you are.
- Access — get a copy of the personal data we hold about you, and know what we do with it.
- Rectification — have anything inaccurate corrected, and anything incomplete completed.
- Erasure — have your data deleted where we have no overriding legal reason to keep it. The steps are on the data deletion page.
- Restriction — have processing paused while a dispute about accuracy or lawfulness is resolved.
- Portability — receive the data you gave us in a structured, machine-readable format.
- Objection — object to processing we base on legitimate interests, and we stop unless we can show compelling grounds.
- Withdraw consent — at any time, without affecting processing already carried out lawfully before the withdrawal.
- Complain — to your local data protection authority, if one has jurisdiction over you.
12.If you messaged a business
If you sent a WhatsApp message to a business that runs on our platform, that business is the controller of your conversation. It decides what the conversation is for, how long it is kept, and who inside the business can read it.
The fastest route is therefore to ask that business directly. If you would rather not, or the business does not respond, write to info@osamajenana.com with the WhatsApp number you messaged from and the name of the business. We will forward the request within five business days and act on it as soon as the business instructs us — and where we are ourselves the controller of the data in question, we act on it directly.
You can also stop the messages at any time by replying with a stop or unsubscribe request in the conversation, or by blocking the number in WhatsApp. An opt-out is honoured on the first request, not the second.
13.Children
The platform is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child’s data has reached us, tell us and we will delete it.
14.Changes to this policy
When the platform’s behaviour changes — a new subprocessor, a different retention window — this policy changes on the same day, and the date at the top moves with it.
Material changes are notified to business customers by email at least 30 days before they take effect, so there is time to object or to leave.
15.Contact us
Privacy questions, rights requests and complaints all go to the same place:
Osama Raed Jenana Technology Company Gaza – Al-Rimal Al-Shamali – near Palestine Stadium, Palestine Email: info@osamajenana.com · Phone: +970 59 290 3278 Commercial registration 39679 · Company number 563493311
