Summary. Trioxen ("we", "us") provides a WhatsApp Business Platform, Messenger and Instagram messaging solution for businesses. We collect only the information needed to run the service, we never sell personal data, we process our customers' conversation data strictly on their instructions, and you can access, correct, export or delete your data at any time by emailing privacy@trioxen.app.
1. Who we are and what this policy covers
This Privacy Policy explains how Trioxen collects, uses, stores, shares and protects personal information when you:
- visit our website at https://trioxen.app (the "Website");
- create an account and use the Trioxen web application, mobile application, APIs and related services (together, the "Platform"); or
- communicate with a business that uses Trioxen through WhatsApp, Facebook Messenger, Instagram or a website form (you are then an "End User").
Trioxen is a product of Trioxen Limited, a company incorporated in Bangladesh under the Companies Act 1994 (Registration No. C-203066/2025), with its registered office at 175 North Avenue, Gulshan-2, Dhaka 1212, Bangladesh. We are a solution provider built on the WhatsApp Business Platform (Cloud API) and the Messenger and Instagram Messaging APIs offered by Meta Platforms, Inc. and its affiliates ("Meta"). We are not affiliated with, endorsed by or a subsidiary of Meta.
This policy is written in plain English on purpose. If anything is unclear, ask us and we will explain.
2. Our role: controller and processor
Understanding our role helps you know who to contact about your data.
| When | Our role | What it means |
|---|---|---|
| You visit the Website, book a demo, or create and manage a Trioxen account (a "Customer") | Data controller | We decide how and why your account, billing and contact information is used, as described in this policy. |
| You are an End User messaging a business that uses Trioxen | Data processor on behalf of that business | The business you are talking to is the controller of your conversation data. We process it only on that business's instructions and under our contract with them. Please also read that business's own privacy notice. You can contact us and we will forward your request to the business or act on it where the law allows. |
3. Information we collect
3.1 Information you give us directly
- Account and contact details: name, business name, email address, phone number, job title, password (stored hashed), profile photo and preferred language.
- Business verification details: trade licence, tax identification number (TIN), business address and website, and Facebook Business Manager / WhatsApp Business Account identifiers, used to connect your channels and complete Meta's business verification.
- Billing information: billing address, VAT/BIN number, invoices and payment records. Card and mobile-wallet details are collected and stored by our payment processors, not by us.
- Demo and support requests: what you type into our forms, emails, chats or support tickets, including attachments.
- Content you upload to the Platform: contact lists, message templates, chatbot flows, product catalogues, media files, notes, tags and custom fields.
3.2 Information processed when messages flow through the Platform
When an End User messages a Customer's connected channel, we receive from Meta and store on the Customer's behalf:
- the End User's phone number (WhatsApp) or platform-scoped user ID (Messenger / Instagram), display name and profile photo where the platform provides it;
- the content of messages sent and received, including text, images, documents, audio, video, location, stickers, reactions, buttons pressed and list selections;
- message metadata such as timestamps, delivery and read status, conversation category, and template names;
- information the End User chooses to share in a conversation or form, such as their name, appointment preference, order details or address;
- opt-in and opt-out records, so we can prove consent and honour unsubscribe requests.
3.3 Information collected automatically
- Usage data: pages and features used, actions taken in the Platform, agent activity and audit logs.
- Device and log data: IP address, browser type and version, operating system, device identifiers, app version, language settings, referring URLs, crash reports and the dates and times of access.
- Cookies and similar technologies: see section 11.
3.4 Information from third parties
- Meta: WhatsApp Business Account status, phone number quality rating, messaging limits, template approval status, business verification status, webhook events and, for Facebook Lead Ads, the lead form fields the End User submitted.
- Payment processors (for example bKash, Nagad, SSLCommerz or a bank): payment confirmation and transaction references.
- Integrations you enable: data you connect from your CRM, Google Sheets, website forms, e-commerce store or other tools via our API and webhooks.
4. How we use information
We use personal information to:
- Provide the Platform – deliver and receive messages, run auto-replies and chatbots, manage the shared inbox, maintain lead pipelines, schedule appointments and reminders, send broadcasts to opted-in contacts, and generate analytics.
- Set up and verify your account – connect your WhatsApp Business Account, Facebook Page and Instagram account, and support Meta business verification and template approval.
- Bill you – calculate subscription fees and pass-through conversation charges, issue invoices and collect payment.
- Support you – answer questions, troubleshoot issues, and train your team.
- Keep the service safe – detect and prevent spam, fraud, abuse, policy violations and security incidents; enforce our Terms of Service and the WhatsApp Business Messaging Policy.
- Improve the Platform – understand how features are used, fix bugs, and develop new features. We use aggregated or de-identified data for this wherever possible.
- Communicate with you – send service announcements, security alerts, onboarding tips and, with your consent, product news. You can opt out of marketing emails at any time.
- Comply with law – meet legal, tax, accounting and regulatory obligations, and respond to lawful requests from authorities.
We do not use End User message content for advertising, for profiling unrelated to the Customer's instructions, or to train general-purpose AI models. Where a Customer enables AI-assisted replies, message content is processed solely to generate a response for that Customer's conversation.
5. Legal bases for processing
Where data-protection law (such as the Bangladesh Personal Data Protection framework, the EU/UK GDPR, or similar laws) requires a legal basis, we rely on:
- Performance of a contract – to provide the Platform to Customers and to act on their instructions as processor;
- Consent – for marketing communications, non-essential cookies, and where an End User opts in to receive messages from a business;
- Legitimate interests – to secure and improve the Platform, prevent abuse and run our business, balanced against your rights;
- Legal obligation – to keep financial records and respond to lawful requests.
6. WhatsApp, Messenger and Instagram: what you should know
- Messages are transmitted through Meta's infrastructure under the WhatsApp Business Terms of Service, the WhatsApp Business Messaging Policy and the Meta Platform Terms. Meta's own WhatsApp Privacy Policy governs how Meta handles your data on WhatsApp.
- Opt-in: Customers may only send business-initiated (template) messages to End Users who have given prior opt-in through a clear action such as a website form, a WhatsApp click-to-chat button, an in-store sign-up, or a message to the business. We store the opt-in source and time.
- Opt-out: End Users can stop receiving messages from a business at any time by replying STOP (or the opt-out word shown in the message), by using the unsubscribe button in a template, by blocking the business on WhatsApp, or by contacting us. Opt-outs are honoured immediately and automatically.
- 24-hour window: Free-form replies are only sent within 24 hours of an End User's last message; outside that window, only Meta-approved templates are used.
- No scraping, no unsolicited messaging: We do not sell, rent or provide phone-number lists, and we do not allow Customers to import contacts they are not permitted to message.
7. How we share information
We never sell personal information. We share it only as follows:
- With Meta – to send and receive messages, register phone numbers, submit templates and complete verification. Meta processes this data according to its own terms and policies.
- With the Customer you are messaging – if you are an End User, the business you contacted can see your conversation and the information you share, because you are communicating with them.
- With sub-processors who help us run the Platform under written contracts that require them to protect your data and use it only for our instructions. Categories include cloud hosting and storage, content delivery and security, email and SMS delivery, payment processing, error monitoring, customer-support tooling and, where a Customer enables it, AI language-model providers for reply suggestions. A current list of sub-processors is available on request at privacy@trioxen.app.
- With integrations you enable – when a Customer connects a CRM, sheet, store or other tool, data flows to that tool as configured by the Customer.
- For legal reasons – if required by law, court order or a governmental authority, or to protect the rights, property or safety of Trioxen, our Customers, End Users or the public.
- In a business transfer – if Trioxen is involved in a merger, acquisition or sale of assets, personal information may be transferred; we will notify affected Customers before their data becomes subject to a different privacy policy.
8. How long we keep information
| Data | Retention period |
|---|---|
| Customer account data | For the life of the account, then deleted from primary systems within 30 days of closure and from backups within 35 days of closure (except records we must keep by law). |
| End User conversations, contacts and lead data | For as long as the Customer keeps them in the Platform. Customers can delete individual contacts or conversations at any time. This data is deleted from primary systems within 30 days after the Customer's account is closed and from backups within 35 days of closure, except records retained as described below. |
| Media attachments | Stored on the Customer's account as above; original files retrieved from Meta are cached for no longer than 30 days unless saved by the Customer. |
| Opt-in / opt-out records | Kept while the contact exists and for 3 years afterwards to demonstrate compliance. |
| Invoices and payment records | 7 years, as required by tax and accounting law. |
| Server logs and security logs | Up to 12 months. |
| Backups | Encrypted backups are rotated within 35 days; deleted data leaves backups on that cycle. |
9. How we protect information
- Encryption in transit (TLS 1.2+) for all connections, and encryption at rest for databases, file storage and backups.
- Role-based access control, two-factor authentication for Trioxen staff and optional two-factor authentication for Customer accounts, and audit logs of agent actions.
- Access to Customer data by our staff is limited to what is needed to provide support or maintain the service, and is logged.
- Segregated environments, regular patching, vulnerability scanning and dependency monitoring.
- An incident-response process. If a personal-data breach affects you, we will notify affected Customers without undue delay and, where required, the relevant authority, and we will help Customers notify End Users.
No system is perfectly secure. Please use a strong, unique password, enable two-factor authentication and tell us immediately at security@trioxen.app if you suspect unauthorised access.
10. International transfers
Our primary servers are hosted with reputable cloud providers, and Meta processes messages on its global infrastructure. This means information may be stored or processed outside Bangladesh, including in Singapore, the European Union and the United States. Where we transfer data internationally we use appropriate safeguards such as contractual data-protection clauses with our sub-processors, and we only work with providers that maintain recognised security certifications.
11. Cookies and similar technologies
Our Website and Platform use a small number of cookies and local-storage entries:
| Type | Purpose | Can you disable it? |
|---|---|---|
| Strictly necessary | Keep you signed in, remember your language, protect forms against abuse and balance load. | No – the Platform would not work without them. |
| Preferences | Remember dashboard settings such as inbox filters and theme. | Yes, via your browser; some settings will reset. |
| Analytics | Privacy-respecting, aggregated statistics about how the Website is used so we can improve it. IP addresses are truncated. | Yes – via the cookie banner or your browser settings. |
We do not use advertising cookies or cross-site tracking on our Website. If a Customer places a Meta Pixel or similar tag on their own website or landing page, that is governed by the Customer's privacy notice.
12. Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you and receive a copy;
- Correct inaccurate or incomplete information;
- Delete your information (see our Data Deletion Instructions);
- Export your data in a machine-readable format (Customers can export contacts and conversations from the dashboard at any time);
- Object to or restrict certain processing, including direct marketing;
- Withdraw consent at any time where processing is based on consent, without affecting processing that already happened;
- Complain to a data-protection authority in your country.
To exercise any right, email privacy@trioxen.app from the address linked to your account, or message us on WhatsApp at +880 1337-447744. We will verify your identity, respond within 30 days, and never charge a fee for a reasonable request.
If you are an End User of a business that uses Trioxen, the fastest route is to contact that business directly. You may also contact us; we will pass your request to the business and assist them in fulfilling it, or act on it ourselves where we are permitted to.
13. Children
Our Website and Platform are intended for businesses and adults. We do not knowingly collect personal information from anyone under 18 as a Customer, and Customers must not use Trioxen to target minors in violation of WhatsApp's minimum-age requirements (13 years, or 16 in the European Region). If you believe a child has provided us with personal information, contact us and we will delete it promptly.
14. Third-party links and services
Our Website may link to third-party sites such as Meta's documentation or payment providers. Their privacy practices are their own; we encourage you to read their policies.
15. Changes to this policy
We may update this policy as our service or the law changes. We will post the new version here with a new "last updated" date and, for material changes, notify Customers by email or an in-app notice at least 14 days before they take effect. Continued use of the Website or Platform after that date means you accept the updated policy.
16. How to contact us
Trioxen Limited – Privacy Team
175 North Avenue, Gulshan-2, Dhaka 1212, Bangladesh
Email: privacy@trioxen.app (privacy requests) · support@trioxen.app (general support)
WhatsApp / phone: +880 1337-447744
Website: https://trioxen.app
Related documents: Terms of Service · Data Deletion Instructions