Sub-processors and Security
Last updated 2026-08-26
Running Dafatir means a small number of other companies necessarily touch information we hold for merchants — the company whose servers we run on, the company that carries WhatsApp messages, the bank that collects a payment. This page names every one of them, and sets out how the information is protected. Questions go to admin@dafatir.app.
What a sub-processor is
A sub-processor is a company we engage that handles personal information in order to do a job for us. Each one is bound by a contract to protect that information, may use it only to perform that job, and may not use it for anything of its own. We remain responsible to the merchant for what they do.
Who we use
The complete list, across every Dafatir product.
| Provider | What it does | Where |
|---|---|---|
| Meta Platforms Ireland | Carries WhatsApp and Instagram messages and calls to and from a merchant's own number, and reports what each conversation cost. | Ireland and the United States |
| Amazon Web Services | The servers, databases and queues every Dafatir product runs on. | Frankfurt, Germany |
| Cloudflare | Stored media, encrypted backups, and protection in front of our websites. | European Union |
| Sentry | Error diagnostics. Message content, credentials and personal identifiers are stripped before a report leaves our systems. | United States |
| Statsig | Feature flags and product measurement, on technical and usage signals rather than on message content. | United States |
| Banks and payment providers in Palestine and Jordan | Collecting subscription payments by bank transfer, Jawwal Pay, PalPay, e-Sadad, and cash reconciled by a representative. | Palestine and Jordan |
| Mobile network operators | Delivering a sign-in code where it is sent by text message rather than through WhatsApp. | Palestine and Jordan |
There is no advertising network, no data broker, and no third-party AI service on this list. Message content is never sent to any such service, and no sub-processor here is permitted to train a model on what it handles for us.
When this list changes
We publish a change on this page, with a new date at the top, before a new sub-processor starts handling anything. Where a merchant's written agreement requires advance notice, we give at least 30 days and the merchant may object. If an objection cannot be resolved, the merchant may end the affected subscription and we refund the unused part of the period.
How the information is protected
Protecting a merchant's books and their customers' conversations is the basis of the product, not a feature of it.
- Traffic between a merchant device and our servers travels over HTTPS. Stored media sits in private object storage reachable only through the product, never by a public link.
- WhatsApp access tokens and the PIN Meta issues for a number are encrypted with AES-256-GCM. They are never displayed in the product, never returned by our API, and never written to a log.
- Every record belongs to exactly one merchant, and every query the products run is confined to that merchant; the database carries row-level rules drawn on the same boundary.
- Changes are written to an audit log, so who did what, and when, is answerable after the fact.
- Message content and credentials are stripped from diagnostics before they leave our systems.
- Backups are encrypted at rest and held in the European Union. We restore from them regularly, because a backup nobody has restored is a backup nobody has.
- Our staff do not read a merchant's conversations except where a named person needs to for support the merchant asked for, a security investigation, or a legal obligation — and every such access is recorded.
No service can promise perfect security. If a breach affects a merchant's information, we will tell that merchant without undue delay, and explain what happened and what we did about it.
If something goes wrong
We tell the affected merchant without undue delay, and in any case within 72 hours of establishing that a breach has occurred. We say what happened, what information was involved, what we have done about it, and what the merchant should do. Where the merchant is the controller — for their own customers' information — we give them what they need to meet their own notification duty, rather than notifying their customers over their head.
Reporting a vulnerability
If you have found a weakness in a Dafatir product, tell us before you tell anyone else and we will work with you on it. We do not take legal action against anyone who reports a genuine finding in good faith, and we credit researchers who ask to be credited. Write to: