Privacy policy
This policy describes how Iterpax handles personal data when you use iterpax.com, the agency operations software, and the Meta WhatsApp Cloud API integration. It is a product notice, not legal advice. Questions: info@iterpax.com.
Who is responsible
The controller is Iterpax, reachable at info@iterpax.com. We operate from Valencia (Spain) and Buenos Aires (Argentina).
Each customer agency has its own Iterpax instance. That agency’s operational data (bookings, passengers, suppliers, communication channels) is stored in that instance, not in a shared database across customers.
Website and sales contact
On iterpax.com we may process name, email, phone and the message you send (forms, WhatsApp or email) to answer enquiries, book demos and send resources you requested.
If site analytics are enabled, technical browsing data may be recorded (pages viewed, traffic source, measurement identifiers).
Iterpax software (agencies)
The software processes, on behalf of each agency, the information that agency loads or generates: customers, passengers, bookings, suppliers, invoicing, notifications and system users.
Iterpax provides the platform. The agency decides what data to load and for which business purposes (quoting, operating the service, invoicing, notifying passengers or suppliers).
WhatsApp Cloud API (Meta)
If an agency connects its WhatsApp Business account to Iterpax (Embedded Signup or phone number ID + token), Iterpax uses Meta’s Cloud API to send business notifications with approved templates, such as notices to passengers or suppliers.
That agency’s instance may store, among other data:
- Meta identifiers: WABA, phone number ID and, if applicable, business ID.
- Graph access token, stored as a channel secret (not shown in full in the UI).
- WhatsApp template names and the variable mapping the agency configures in Iterpax.
- Recipients and content of notifications the agency triggers (for example a passenger or supplier phone number).
- Meta webhook events (delivery, read or others Meta sends), to the extent the instance receives them.
Why we use that data
Only so that agency can send and manage its WhatsApp Business notifications from Iterpax, and keep the channel connected (validate the number, list templates, store the sent message id).
Iterpax does not use the agency’s WhatsApp account for Iterpax’s own marketing and does not sell that data. Meta processes data under its own policies when the message travels on WhatsApp.
Retention
Commercial website data is kept as long as needed for the enquiry or the commercial relationship.
Instance data (including the WhatsApp channel) is kept while the agency maintains the service and the connected channel, or for as long as that agency requires for its operations. Disconnecting the channel stops Iterpax from using the token to send.
Processors
We may use infrastructure providers (hosting, email, analytics) to run the site and the software. WhatsApp Cloud messaging is provided by Meta. Each agency may also configure other senders (email, etc.) on its instance.
How to request deletion
If your data sits in an agency that uses Iterpax, the primary request is to that agency: they load and operate the file.
If you are an Iterpax customer (the agency) and want us to delete or disconnect platform data, including the WhatsApp Business connection, email info@iterpax.com with the instance or company name and what you want removed.
You can also disconnect the WhatsApp Cloud channel in Iterpax (communication channels) to stop using the linked token and number.
Full data deletion instructions: https://iterpax.com/eliminar-datos
Your rights
You may request access, correction or deletion of data Iterpax processes as controller (website and the contract with the agency) by writing to info@iterpax.com. Depending on your country, you may also contact the relevant data protection authority.
Changes
If we update this policy, we will publish the change date on this page. Continued use of the site or software after that date means you have seen the current version.
