Wappuccino

Privacy Policy

Last updated: 11 October 2026. See also the Terms of Service.

1. Data controller

Squadd SRL ("SQUADD"), VAT IT06256330876, Via San Domenico Savio 13, Caltagirone (CT), Italy, email info@squaddcrm.com. This policy covers the Wappuccino service (an app for GoHighLevel that connects WhatsApp to sub-accounts) under Regulation (EU) 2016/679 (GDPR).

2. What data we process

  • Installation and GHL account: agency (company) and sub-account (location) identifiers, installation status, plan and number slots, GHL users enabled on a number, and GHL OAuth tokens, stored encrypted.
  • Linked WhatsApp numbers: the number, the link status and the WhatsApp Web session credentials (stored encrypted), and the IP address of the proxy assigned to the number.
  • Messages: messages pass through us between WhatsApp and GHL or your API integrations. For each message we store direction, type, status, delivery times, the contact's phone number (or WhatsApp identifier) and the text: in full for messages received and sent after the link, and the first 1000 characters for the history WhatsApp sends when you link a number. In groups we also store who wrote. We store the match between a WhatsApp contact and a GHL contact, the names of groups and channels, and the profile picture (as a preview) of contacts, groups and channels, when visible to the linked number.
  • Attachments: for photos, videos, audio and documents we store type, name, size and the technical data needed to download them again from WhatsApp. We download the file only when you request it through the API and keep it for 30 days.
  • Consent and change log: contact opt-in and opt-out, where recorded, and a log of changes to settings.
  • Technical logs: service events, errors, metrics and IP addresses of requests, for security and operation.

3. Purposes and legal basis

  • Providing the service you requested by installing the app (performance of a contract, art. 6.1.b GDPR).
  • Security, abuse prevention, diagnosis and improvement of the service (legitimate interest, art. 6.1.f).
  • Administrative, tax and legal obligations (art. 6.1.c).

4. Our role

For the data of your contacts (numbers, messages, consents) you, the agency or business, are the data controller and SQUADD acts as data processor under art. 28 GDPR: we process it only to provide the service and on your instructions. You must inform your contacts and have a legal basis (for example consent) to write to them. For account and usage data we are the controller. If you need a written data processing agreement (DPA), write to us.

5. Retention

Account and link data stay while the app is installed and the service is active. Messages (number, text, sender in groups), names of groups and channels and profile pictures stay while the number is present in the service, and are deleted on request or when the number is removed; pictures refresh about every 7 days. Attachments downloaded on request are deleted after 30 days. Proxy health data is deleted after 30 days and resolved technical alerts after 90; other logs are kept as technically needed. After uninstalling, we delete leftover data on your request; we keep only what the law requires.

6. Recipients and sub-processors

We do not sell data and we do not use it for advertising. We use providers that process data on our behalf:

  • GoHighLevel: the platform the app is connected to, from which messages and contacts arrive and to which they return;
  • hosting and server (VPS) providers that run the service and the database;
  • IPRoyal: provider of the residential proxies through which the connection of each WhatsApp number passes;
  • Cloudflare: network, DNS and domain protection;
  • WhatsApp (Meta): messages are sent and received through its network, under its rules.

Some of these providers may process data outside the European Economic Area, with the safeguards the GDPR requires (for example standard contractual clauses). We may disclose data to authorities if the law requires it.

7. Security

Tokens and WhatsApp credentials are encrypted. API access requires keys or a GHL session, and data is separated by sub-account. No system is 100% secure: in case of a data breach we will notify as the law requires.

8. Your rights, including erasure (art. 17)

You have the right of access, rectification, erasure ("right to be forgotten", art. 17 GDPR), restriction, portability and objection, and the right to withdraw consent you gave. To exercise them, write to info@squaddcrm.com. To ask us to delete your data or a contact's data, send the request from that address with the sub-account and the number concerned. If you are a contact of an agency that uses Wappuccino, contact the agency first, as it controls your data; we can help it answer. You can also lodge a complaint with the Italian data protection authority, the Garante (garanteprivacy.it).

9. Changes

We update this policy when the service changes; the date at the top shows the latest version.