How we protect your data
We list only what we really do.
Last updated:
Built on ISO/IEC 27001:2022
We use the structure of this international standard to manage risk and protect client data.
- A risk register: each risk to client data scored, with an owner and a date to fix it
- All 93 controls of the standard reviewed one by one, each marked in place or planned
- A fixed calendar: a monthly security check, and a yearly internal audit and management review
Clients can ask for a summary of these records.
In place now
- Encrypted in transit and at rest
- Named access only: one account per person, with two-step login
- Roles and an audit log of who did what, where needed
- Hosting in the EU (Frankfurt) or on your own servers
- GDPR standards and Lebanon’s Law No. 81 of 2018
- Paid AI only, never trained on your data
- Data kept only as long as needed, and deleted on request
- Support sees your data only with your written approval
- Security review and backups before launch
WhatsApp Assistant: chats are deleted automatically after 90 days, and all your data within 30 days after you leave. See the privacy policy.
In progress and planned
What we are adding next.
In progress
- Written internal policies: security, confidentiality, incidents, acceptable use, passwords and privacy
- A data processing agreement and a security addendum, under legal review
Planned
- An independent penetration test
- An independent ISO/IEC 27001 certification audit, when a client’s contract requires it
Where your data lives
Two options: an EU cloud (Frankfurt, Germany) or your own servers (on-premise). The kind of data decides which.
Show which data can live whereHide details
| Kind of data | What it is | Where it can live |
|---|---|---|
| General | Public or low-risk information, such as opening hours or a public price list | EU cloud |
| Sensitive | Personal or private business information, such as customer chats, bookings and staff records | EU cloud with named access and two-step login, or your own servers |
| Secret | Information that must never leave your organisation | Your own servers (on-premise) |
Who handles the data
Each handles data only to deliver the service. Nothing is shared between businesses, sold or used for advertising.
- Messaging platform
- Meta (WhatsApp) carries the messages
- WhatsApp connection provider
- Connects the assistant to WhatsApp
- AI provider
- Writes the replies (paid business plan, no training on your data)
- Database hosting in the EU
- Stores the data in Frankfurt, Germany
The full list of providers is in our client data agreement, and available on request.
What we will not build
Some work we turn down, whatever the price.
- Tools that watch or track people without a legal basis
- Tools made to deceive people or to impersonate someone
- Anything that collects personal data from the web without consent
- Anything that breaks Lebanese law or GDPR
- Weapons
How we contact you
Only from hello@baladilabs.com and our official WhatsApp number, once it is listed here. We never ask for passwords or for payment into a personal account. If a message does, do not answer it, and tell us.
Questions from your IT team?
Send them to us. We reply within one working day.