flexinbox
Security and data protection

Your customer data
is yours alone.

WhatsApp CRM data security rests on three things: where the data is stored, who can access it, and whether you can get it back if something goes wrong. Conversations are kept on servers in Germany, access is granted by role and by line, and critical actions are logged. We do not use your data for advertising and we do not sell it.

Hosted in Germany  ·  Encrypted backups  ·  GDPR tools in the panel

Data residency and access
Server
Germany (Nuremberg)
Transport
Encrypted with TLS
CRM keys
Stored encrypted in the database
Backup
Daily, encrypted, in a separate location
Access
By role and by line
Audit trail
Critical actions are logged

Your data is in Germany,
you decide who reaches it

Data residency

Where the data is stored

Conversations, record matches and media files are kept on servers in Germany. Connections are encrypted in transit; CRM access keys are stored encrypted in the database.

Hosted in Germany

The servers are in Nuremberg. Your data is not used for advertising and is not sold.

Encrypted transport and storage

All connections are encrypted with TLS; CRM keys and platform secrets are never held in plain text in the database.

Media is kept separate

Photos, audio and documents are served separately from the conversation, through a path that verifies access.

Access

You decide who can see what

Authorization

Role, line and session

There are agent, supervisor and admin roles. An agent with the personal role sees only the conversations on their own lines. You choose who can use a line, and withdraw that permission whenever you want.

  • You can require a second factor (2FA) at login
  • When you revoke a user's access, their open session ends within seconds
  • Users come from your CRM; when someone leaves, you remove their panel account
  • Access to your account by our support team requires separate permission and is logged
Audit trail

Who did what is visible

Critical actions such as changing an owner, moving a stage forward, connecting and disconnecting a line are recorded together with the person who performed them. The records are also copied to a separate location on a regular basis; they cannot be quietly changed afterwards.

  • Audit trail screen in the panel: who changed what, and when
  • Records are copied to a separate location every hour, along with their digest
  • Because conversations are written to the customer record, a trail also remains on the CRM side
Continuity

Getting back when something goes wrong

Backups are taken daily, encrypted and kept in a separate location. Restore drills are run regularly: saying 'we have backups' is not enough until you have measured that a backup actually opens.

Daily backup

The database is backed up every night; backups are kept for one week.

Encrypted copy in a separate location

Backups are encrypted and held at a separate provider; they remain even if the main server is lost.

Regular restore drills

We test regularly that a backup really opens; failures are tracked.

GDPR

Deletion requests handled in one place

When your customer says "delete my data", you carry out the request from the panel: the conversation, media and record match for that number are permanently deleted. When you delete a contact on the HubSpot side, the deletion event is reported to us and the related personal data is removed on the FlexInbox side too. Do not treat that alone as a guarantee: if the deletion did not go through as expected, you can run the same request from the panel.

Deletion

The conversation history, media and record match for a number are permanently deleted in a single action.

Export

A contact's data can be exported on request.

Retention period

Conversations stay in your account until you delete them; when the account is closed, the data is removed.

Sub-processors

Which services your data passes through

We list them to be transparent: which services other than us are involved in a message's journey depends on the features you use.

WhatsApp and Telegram

Messages arrive and leave over these platforms; their own rules apply.

Official line provider

A WhatsApp Business API line runs over a Meta partner infrastructure; if you do not use an official line, this path is never involved.

AI provider

When you turn the assistant on, the message in question and the knowledge sources you provide go to the model provider. If you keep the assistant off, this path is never used.

Limits

To be honest

WhatsApp CRM data security pages usually list only the good parts; we write down the limits as well.

End-to-end encryption does not reach us. A WhatsApp message is end-to-end encrypted between the phone and WhatsApp. For it to be readable in the panel, the message has to be decrypted in your account; this is the same situation as with any desktop WhatsApp client.

If the assistant is on, text leaves our systems. When you turn the AI assistant on, the message in question is sent to the model provider. If you keep the assistant off, this does not happen.

We hold no certification. We do not have an ISO 27001 or SOC 2 certificate, and we do not write about a certificate we do not hold. The items above are the technical measures we apply.

Show all technical limitations

A QR code line is subject to WhatsApp rules. Sending bulk or unsolicited messages from a personal number can get the number restricted.

Restoring a backup takes time. In a disaster the service does not continue without interruption; a restore from backup takes minutes, and data written after the last backup can be lost.

Support access is possible. We may need to access your account to resolve your issue; that access requires permission and is logged.

FAQ

About security

Where is my data kept?

Conversations, media and record matches are kept on servers in Germany. Connections are encrypted in transit, and CRM access keys are stored encrypted in the database.

Do you read my conversations?

No. We do not use your data for advertising and we do not sell it. If access to your account is needed to resolve a support request, it requires permission and is logged.

An employee has left. What happens to the conversations?

The conversations stay with the company. When you disable the user, their open session drops within seconds and you can hand the line to someone else; the conversation history and CRM records stay in place.

How do I fulfill a GDPR deletion request?

From the panel, the conversation history, media and record match for that number are permanently deleted. If you use HubSpot, deleting the contact in HubSpot also removes the data on the FlexInbox side.

Do you have ISO 27001 certification?

No. Since we do not hold the certificate, we do not say that we do. The items on this page are the technical measures we apply; if you need detail before signing, write to us and we will walk you through all of it.

Ask your security questions before signing

Write to us about data residency, sub-processors and retention periods; we will walk you through all of it.

No credit card  ·  14 days free