Skip to content

Security & Legal

Data Deletion Instructions

Last updated:

Template for legal counsel review — this document has not yet been reviewed by counsel and may not reflect final terms.

This page explains how to have your data deleted from Xelp, operated by Blaze Technologies Inc ("Xelp"), whether you are a Xelp customer (business), an End User who messaged a business that uses Xelp, or a user who connected a Meta (Facebook / WhatsApp) account to Xelp. It supplements the Privacy Policy and the DPA.

If you are an End User (you messaged a business on WhatsApp or another channel)

The business you messaged is the data controller; Xelp processes your conversation and related data on its behalf (see the Privacy Policy, Section 3).

  1. Ask the business directly to delete your conversation and contact data — replying in the same conversation works.
  2. If you cannot reach the business, email privacy@xelp.io with the phone number or handle you used and the business name. We will refer your request to the controller and assist them in responding.

If you are a Xelp customer

  1. Sign in as an admin and go to Settings → Business → Privacy. To delete or export individual contacts and conversations, submit a User Rights request (right to be forgotten, portability, or rectification).
  2. For full account deletion, use Delete workspace on the same screen. The workspace is disabled immediately and all of its data (contacts, conversations, connected channels, bots, broadcasts, commerce and AI data) is permanently deleted after a 7-day grace period, during which you can cancel the deletion from the same screen.
  3. Alternatively, email privacy@xelp.io from an admin account specifying the scope of deletion.
  4. You can export your data (contacts, conversations, commerce data) using the Service's export features at any time before deletion.

Meta data-deletion callback (Facebook / WhatsApp connected accounts)

Xelp implements Meta's Data Deletion Request callback. If you connected a Meta account (for example when linking WhatsApp, Instagram or Messenger) and you remove the app from your Facebook settings or request deletion via Meta:

  1. Meta sends Xelp a signed data-deletion request for your user ID. Requests with a missing or invalid signature are rejected.
  2. Xelp deletes the stored access token and account configuration held for the account(s) connected with that Meta user ID, and returns a confirmation code and status URL to Meta, which you can use to track the request.

To trigger this from Facebook: Settings & Privacy → Settings → Apps and Websites → Xelp → Remove, then choose to delete data.

Deauthorize callback

Xelp also implements Meta's Deauthorize callback. When you remove Xelp's access to your Meta account, Meta notifies us and we delete the stored access token and configuration we hold for that account.

Timelines and scope

  • Meta-initiated deletion (data-deletion / deauthorize callbacks): the stored access token and account configuration are deleted on receipt of the verified request.
  • Self-serve workspace deletion: disabled immediately; permanently deleted from our production systems after the 7-day cancellable grace period.
  • Inactive accounts: if an account shows no usage, we notify the account owner, and the account's data may be deleted after 90 days of continued inactivity following that warning (Privacy Policy, Section 10).
  • Legal retention: data we must retain by law (for example invoicing and tax records) is kept only as long as the law requires, or as necessary to establish, exercise, or defend legal claims, and then deleted.

Contact

For any deletion question or to escalate a request: privacy@xelp.io. We will respond within the timeframe required by applicable law. Data Protection Officer: Renuka Vivek, renuka@xelp.io.