1. How to ask
Email us with the word “delete” and enough for us to find you:
Please include:
- The identifier the data is held against — the email address you contacted us from, or the phone number that received WhatsApp messages, including its country code.
- The business you heard from, if the messages came from a company using our platform rather than from SoraFabric itself. The sender name in WhatsApp is enough.
- What you want deleted, if it is not everything.
Send it from the address concerned where you can. If you cannot, we will ask for something else that verifies the request — we have to be sure a deletion request comes from the person whose data it is, because acting on a forged one is itself a breach.
2. If a business messaged you over WhatsApp
SoraFabric operates WhatsApp messaging on behalf of business clients. When a company sends you a message through us, that company decides who is contacted and why — they are the controller of that data, and we act on their instructions. See Scope and roles in our privacy policy.
That does not mean you have to go and find them. If you write to us:
- we will forward your request to the business without delay, and tell you that we have;
- we will delete what we hold on our own systems as soon as their instructions and the law allow;
- we will stop our platform sending you further messages for that business immediately, regardless of how long the rest takes.
You can also stop messages yourself at any time, without asking anyone: reply to the conversation asking to stop, or block the business in WhatsApp. Neither requires our involvement and both take effect at once.
Meta holds message data on the WhatsApp Cloud API for at most 30 days to deliver the service, and deletes user identifiers within 30 days of the last message status update. That period belongs to Meta and neither we nor the business can shorten it.
3. What happens next
- We acknowledge it within two business days, so you know it arrived and is being handled.
- We verify who is asking, which may mean one reply asking you to confirm something.
- We complete it within 30 days of verifying, and sooner where your law requires. If it will take longer we will tell you why before the 30 days are up.
- We confirm in writing what was deleted, what was passed to a client, and anything we kept — with the reason.
Backups expire on their own cycle rather than being edited, so a copy may persist in an encrypted backup for a short period after deletion. It is not restored to live systems, and it goes when the backup does.
4. What we may have to keep
Deletion is not always absolute, and we would rather say so here than in a reply that surprises you. We may retain a limited record where the law requires it or allows it — invoices and tax records, evidence needed for a legal claim, or a minimal suppression record holding nothing but the fact that you asked not to be contacted, which exists precisely so the request is not undone by the next import.
Anything retained is kept only for that purpose, for no longer than necessary, and is not used for anything else.
5. If you are not satisfied
Write to [email protected] and say so — it will be looked at again by someone else. You also have the right to complain to your data protection authority, and nothing on this page affects that right. Our full policy is at Privacy.