Skip to content
Hiwar
FeaturesHow it works
Sign inOpen console

Sub-processors and Security

Last updated 2026-08-26

Running Dafatir means a small number of other companies necessarily touch information we hold for merchants — the company whose servers we run on, the company that carries WhatsApp messages, the bank that collects a payment. This page names every one of them, and sets out how the information is protected. Questions go to admin@dafatir.app.

What a sub-processor is

A sub-processor is a company we engage that handles personal information in order to do a job for us. Each one is bound by a contract to protect that information, may use it only to perform that job, and may not use it for anything of its own. We remain responsible to the merchant for what they do.

Who we use

The complete list, across every Dafatir product.

ProviderWhat it doesWhere
Meta Platforms IrelandCarries WhatsApp and Instagram messages and calls to and from a merchant's own number, and reports what each conversation cost.Ireland and the United States
Amazon Web ServicesThe servers, databases and queues every Dafatir product runs on.Frankfurt, Germany
CloudflareStored media, encrypted backups, and protection in front of our websites.European Union
SentryError diagnostics. Message content, credentials and personal identifiers are stripped before a report leaves our systems.United States
StatsigFeature flags and product measurement, on technical and usage signals rather than on message content.United States
Banks and payment providers in Palestine and JordanCollecting subscription payments by bank transfer, Jawwal Pay, PalPay, e-Sadad, and cash reconciled by a representative.Palestine and Jordan
Mobile network operatorsDelivering a sign-in code where it is sent by text message rather than through WhatsApp.Palestine and Jordan

There is no advertising network, no data broker, and no third-party AI service on this list. Message content is never sent to any such service, and no sub-processor here is permitted to train a model on what it handles for us.

When this list changes

We publish a change on this page, with a new date at the top, before a new sub-processor starts handling anything. Where a merchant's written agreement requires advance notice, we give at least 30 days and the merchant may object. If an objection cannot be resolved, the merchant may end the affected subscription and we refund the unused part of the period.

How the information is protected

Protecting a merchant's books and their customers' conversations is the basis of the product, not a feature of it.

  • Traffic between a merchant device and our servers travels over HTTPS. Stored media sits in private object storage reachable only through the product, never by a public link.
  • WhatsApp access tokens and the PIN Meta issues for a number are encrypted with AES-256-GCM. They are never displayed in the product, never returned by our API, and never written to a log.
  • Every record belongs to exactly one merchant, and every query the products run is confined to that merchant; the database carries row-level rules drawn on the same boundary.
  • Changes are written to an audit log, so who did what, and when, is answerable after the fact.
  • Message content and credentials are stripped from diagnostics before they leave our systems.
  • Backups are encrypted at rest and held in the European Union. We restore from them regularly, because a backup nobody has restored is a backup nobody has.
  • Our staff do not read a merchant's conversations except where a named person needs to for support the merchant asked for, a security investigation, or a legal obligation — and every such access is recorded.

No service can promise perfect security. If a breach affects a merchant's information, we will tell that merchant without undue delay, and explain what happened and what we did about it.

If something goes wrong

We tell the affected merchant without undue delay, and in any case within 72 hours of establishing that a breach has occurred. We say what happened, what information was involved, what we have done about it, and what the merchant should do. Where the merchant is the controller — for their own customers' information — we give them what they need to meet their own notification duty, rather than notifying their customers over their head.

Reporting a vulnerability

If you have found a weakness in a Dafatir product, tell us before you tell anyone else and we will work with you on it. We do not take legal action against anyone who reports a genuine finding in good faith, and we credit researchers who ask to be credited. Write to:

Ask about a sub-processor, or report a weakness

admin@dafatir.app

Write to this address. We answer questions about who handles what, and we work with anyone who reports a genuine finding.

Other legal documents

Privacy PolicyTerms of ServiceData DeletionAcceptable UseBack to the home page
Hiwar

Conversational commerce for Arabic-speaking shops — bilingual and RTL-native.

Hiwar is a Dafatir product.

Product

Open consoleFeaturesSign in

Channels

  • WhatsApp Cloud API
  • Instagram · Messenger
  • TikTok Business

Legal

Privacy PolicyTerms of ServiceData DeletionAcceptable UseSub-processors & Security
© 2026 Hiwar·Built for conversation commerce·All rights reserved.