Skip to main content

GDPR-compliant use of WhatsApp with FunnelBridge

Florian Wienecke avatar
Written by Florian Wienecke
Updated over 2 weeks ago

FunnelBridge enables communication with applicants via WhatsApp straight from within Recruitee in a GDPR-compliant way. Compared to traditional WhatsApp communication (e.g. between two smartphones), there are key differences regarding compliance with the General Data Protection Regulation (GDPR) and data security.

Traditional WhatsApp use vs. FunnelBridge

In the traditional scenario, messages are exchanged directly between two devices using the private WhatsApp app/WhatsApp Business app.

With FunnelBridge, communication takes place via the official WhatsApp Cloud API, provided by Meta from Recruitee to the candidates device. In this setup, Meta acts as a data processor on behalf of FunnelBridge.

Data protection measures by Meta for the WhatsApp API

Meta has implemented various measures to ensure GDPR-compliant operation of the WhatsApp API endpoint. The most important measures include:

  • Server location selectable within the EU

  • Messages are only stored temporarily for technical transmission purposes

  • Messages are deleted immediately after successful delivery

  • In case of undeliverability, messages are stored for a maximum of 30 days

  • No personalized advertising based on message content

  • Meta employees never have access to the content of messages

A full overview of the data protection measures for the WhatsApp Cloud API can be found here:
πŸ‘‰ Meta Documentation: Data Privacy and Security
​

Further information on FunnelBridge security

Our πŸ”’FunnelBridge Trust Center provides documentation on more than 100 security measures we have implemented to protect your data and ensure the secure operation of our software.

Did this answer your question?