Privacy policy
Effective 11 October 2026
This policy explains how trywasal ("trywasal", "we", "us") collects, uses and protects personal data. trywasal is a product of Koredyne, Crystal Tower, 6th Floor, Kuwait City, Kuwait. Contact us at info@koredyne.com.
1. Who this applies to
- Customers: businesses that sign up for trywasal, and the team members they invite ("users").
- End customers: people who message a business through a channel the business connected to trywasal, such as WhatsApp.
For end-customer messages, the business is the controller and trywasal processes that data on the business's behalf to provide the service. If you messaged a business and want to exercise your rights, contact that business; we will help them respond.
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password (stored only as a secure hash), workspace name, team memberships and roles | Users |
| Business information | What the business enters for its AI assistant: services, prices, opening hours, instructions | Customers |
| Connected channel data | WhatsApp Business Account ID, phone number ID, display number, business name, and the access token Meta issues when a business connects | Meta, via the business |
| Conversation data | End customers' phone numbers, WhatsApp profile names, message content, media identifiers, delivery and read status, timestamps | Meta (WhatsApp Business Platform) |
| AI usage data | Which conversations the assistant answered, token counts, handoffs and errors | Generated by trywasal |
| Technical data | IP address and browser user agent for signed-in sessions, server logs | Your browser and our servers |
3. How we use data
- To provide the service: receive and send messages for the business, show them in the business's inbox, and generate AI replies that the business has turned on.
- To hand conversations to the business's staff when the assistant cannot help or the end customer asks for a person.
- To run accounts: sign-in, email verification, password resets and team invitations.
- To keep the service secure and reliable: preventing abuse, troubleshooting, and measuring usage for limits and billing.
- To meet legal obligations.
We do not sell personal data, use it for advertising, or use conversation data or business information to train AI models.
4. AI processing
AI replies are generated by a large language model hosted on Amazon Bedrock in the AWS Europe (Frankfurt) region. To write a reply, we send the business's information and the recent messages of that conversation to the model. AWS does not use this data to train models and does not share it with the model provider. The business can turn AI replies off at any time, for the whole workspace or per channel.
5. Data from Meta platforms
When a business connects WhatsApp (and later Instagram or Messenger), we receive data through Meta's APIs in line with the Meta Platform Terms. We use it only to provide trywasal to that business, store access tokens encrypted in AWS Secrets Manager (never in our database), and delete the data when the business disconnects the channel or closes its account, or when Meta or the user asks us to (see Data deletion).
6. Who we share data with
We use these service providers ("sub-processors") to run trywasal:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, database, file and secret storage, AI model (Amazon Bedrock) | Germany (Frankfurt) |
| Meta Platforms | WhatsApp Business Platform: delivering and receiving messages | Meta's global infrastructure |
| Resend | Sending account emails (verification, password reset, invitations) | Ireland |
| Cloudflare | Domain name (DNS) service | Global |
We may also disclose data if required by law, or to protect the rights and safety of our users, end customers or the public.
7. Where data is stored
trywasal's servers and database run in the AWS Europe (Frankfurt) region. Some providers above process data in other countries; we rely on their contractual and security commitments when they do.
8. How long we keep data
- Account, business and conversation data: while the workspace is active. When a workspace is closed or a channel disconnected, we delete the related data within 30 days, unless the law requires us to keep it longer.
- Server logs: about 30 days.
- Backups: overwritten on a rolling basis.
9. Security
Data is encrypted in transit (HTTPS) and at rest. Access tokens are kept in AWS Secrets Manager. Access to production systems is limited to authorised Koredyne staff using multi-factor authentication, and every workspace's data is separated from other workspaces in the application.
10. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. Users can contact us at info@koredyne.com. End customers should contact the business they messaged; we support businesses in answering these requests.
11. Cookies
The trywasal app uses a strictly necessary session cookie to keep you signed in. We do not use advertising or tracking cookies.
12. Children
trywasal is a business tool and is not intended for people under 18.
13. Changes
We may update this policy. We will post the new version here with a new effective date and, for significant changes, notify customers by email.
14. Contact
Koredyne · Crystal Tower, 6th Floor, Kuwait City, Kuwait · info@koredyne.com