Privacy policy

Last updated: 31 August 2026

This policy explains what Digicore does with personal data: both the data of the businesses who use our product, and the data of their customers whose WhatsApp messages pass through it. Those are two different things and the law treats them differently, so we have set them out separately below.

Who we are

Digicore is a trading name of DIGICORE IT LTD, a company registered in England and Wales under company number 15984126.

Registered office: 124 City Road, London, England, EC1V 2NX.

Contact: info@digicore.uk

The two roles we play

Which role we are in decides who is answerable for the data, and who you should approach about it.

For account data, we are the controller

When you sign up, invite colleagues and run a workspace, we decide how that information is used. We are responsible for it, and this policy governs it.

For conversation data, we are the processor

The WhatsApp conversations between a business and its customers belong to that business. They are the controller. We only handle those messages on that business’s instructions, under the terms of our data processing agreement.

If you are a customer of a business that uses Digicore and you want to know why they hold your messages, or you want them deleted, please ask that business. We cannot make those decisions on their behalf, but we will help them act on your request.

Personal data we handle

Account data

Conversation data

Technical data

Why we handle it, and our lawful basis

What forLawful basis
Providing the product to a business that has signed upPerformance of a contract
Processing customer conversations on a business’s behalfThe business’s own lawful basis, on their documented instructions
Keeping the service secure, and investigating misuseLegitimate interests
Improving the product through aggregate usage dataLegitimate interests
Meeting our legal and accounting obligationsLegal obligation
Sending marketing about our own productConsent, which you can withdraw at any time

WhatsApp and Meta

Digicore is built on the official WhatsApp Business Platform. Messages travel through Meta’s infrastructure before they reach us and after they leave us, and Meta handles them under its own terms and privacy policy, which we cannot vary. Connecting a WhatsApp number to Digicore does not change your relationship with Meta.

WhatsApp is a trademark of Meta Platforms, Inc. Digicore is not affiliated with, endorsed by, or acting on behalf of Meta.

Who else processes your data

We use a small number of suppliers to run the service. Each is bound by a written contract that holds them to the same standards this policy sets.

ProviderWhat they do for usWhat they handleWhere
Meta Platforms Ireland LtdThe WhatsApp Business Platform (Cloud API) that carries the messagesMessage content, phone numbers, WhatsApp profile namesPer Meta’s own terms
Supabase, Inc.Database, sign-in and file storageAll workspace and conversation dataUnited Kingdom (London)
Vercel, Inc.Application hostingRequests in transit; no durable message storageUnited Kingdom (London)
Inngest, Inc.Background processing of incoming messages and delivery receiptsMessage content, sender numbers, delivery statusesUnited States
Functional Software, Inc. (Sentry)Error monitoring, when enabledTechnical error data. Not message contentUnited States
PostHog, Inc.Product analytics, when enabledUsage events and account identifiersEuropean Union

We do not sell personal data, and we do not use messages or customer details to train machine-learning models, ours or anyone else’s.

Where your data is held

Workspace and conversation data is stored in the United Kingdom, in London. Some suppliers listed above operate outside the UK. Where personal data is transferred abroad, we rely on the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, together with the checks those require.

How long we keep it, and how to have it deleted

DataRetention
Account data, after a workspace is closed or an account deleted90 days, then permanently deleted
Conversation data, after the agreement endsDeleted or returned within 30 days, sooner on request
Workspace audit log24 months
Records we must keep by law, such as accounting recordsAs long as the law requires

Deleted data may persist briefly in encrypted backups. Those are overwritten within a further 30 days, so nothing survives more than 120 days past deletion.

One exception, stated plainly: if you delete your own account but the workspace you belonged to stays open, we keep the empty shell of your record so the workspace’s audit log does not develop holes. At the 90-day mark your name, email address and sign-in are erased from it and your sign-in credentials are destroyed. What is left identifies nobody and cannot be used to sign in.

Asking us to delete your data

If you hold a Digicore account, you can delete it yourself in the product under Settings → Account, or delete an entire workspace under Settings → Workspace. Either will start the retention clock above.

You can also email info@digicore.uk from the address on the account and ask us to delete it. We will confirm once it is done, and in any event within one month.

If you are the customer of a business that uses Digicore, that business decides whether your conversation is deleted. Ask them directly. If you tell us, we will pass the request on and help them carry it out.

Your rights

Under UK data protection law you have the right to ask for a copy of your personal data, to have it corrected, to have it deleted, to restrict or object to how it is used, and to receive it in a portable form. Where we rely on consent, you can withdraw it at any time.

To exercise any of these, email info@digicore.uk. We respond within one month. There is no charge unless a request is clearly unfounded or excessive.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk, or by calling 0303 123 1113. We would rather you came to us first so we can put it right.

Security

Data is encrypted in transit and at rest. Access to production systems is limited to the people who need it, sign-in is by one-time email code rather than a stored password, and a workspace’s data is isolated from every other workspace at the database level. Significant actions are recorded in an audit log.

No system is perfectly secure. If a breach affects your personal data and is likely to put your rights at risk, we will tell you and the ICO within the time limits the law sets.

Children

Digicore is a product for businesses and is not intended for children. We do not knowingly collect data from anyone under 16. If you believe we have, tell us and we will delete it.

Changes to this policy

We may update this policy. If a change materially affects you we will tell you before it takes effect, by email or in the product. The date at the top always shows the current version.

Contact us

For anything in this policy, including a request about your own data, email info@digicore.uk or write to us at the registered office above.