Skip to content

How we protect your data

We list only what we really do.

Last updated:

Built on ISO/IEC 27001:2022

We use the structure of this international standard to manage risk and protect client data.

  • A risk register: each risk to client data scored, with an owner and a date to fix it
  • All 93 controls of the standard reviewed one by one, each marked in place or planned
  • A fixed calendar: a monthly security check, and a yearly internal audit and management review

Clients can ask for a summary of these records.

In place now

  • Encrypted in transit and at rest
  • Named access only: one account per person, with two-step login
  • Roles and an audit log of who did what, where needed
  • Hosting in the EU (Frankfurt) or on your own servers
  • GDPR standards and Lebanon’s Law No. 81 of 2018
  • Paid AI only, never trained on your data
  • Data kept only as long as needed, and deleted on request
  • Support sees your data only with your written approval
  • Security review and backups before launch

WhatsApp Assistant: chats are deleted automatically after 90 days, and all your data within 30 days after you leave. See the privacy policy.

In progress and planned

What we are adding next.

In progress

  • Written internal policies: security, confidentiality, incidents, acceptable use, passwords and privacy
  • A data processing agreement and a security addendum, under legal review

Planned

  • An independent penetration test
  • An independent ISO/IEC 27001 certification audit, when a client’s contract requires it

Where your data lives

Two options: an EU cloud (Frankfurt, Germany) or your own servers (on-premise). The kind of data decides which.

Show which data can live where

Who handles the data

Each handles data only to deliver the service. Nothing is shared between businesses, sold or used for advertising.

Messaging platform
Meta (WhatsApp) carries the messages
WhatsApp connection provider
Connects the assistant to WhatsApp
AI provider
Writes the replies (paid business plan, no training on your data)
Database hosting in the EU
Stores the data in Frankfurt, Germany

The full list of providers is in our client data agreement, and available on request.

What we will not build

Some work we turn down, whatever the price.

  • Tools that watch or track people without a legal basis
  • Tools made to deceive people or to impersonate someone
  • Anything that collects personal data from the web without consent
  • Anything that breaks Lebanese law or GDPR
  • Weapons

How we contact you

Only from hello@baladilabs.com and our official WhatsApp number, once it is listed here. We never ask for passwords or for payment into a personal account. If a message does, do not answer it, and tell us.

Questions from your IT team?

Send them to us. We reply within one working day.

Talk to usTalk to the founderWhatsApp: coming soon