Aria ("Aria", "we", "us") is software for real-estate brokers, based in Dubai, United Arab Emirates. This policy explains what data we collect from the WhatsApp Business account you connect, how we use and protect it, and how you can access or delete it. It is not less protective than, and is intended to be consistent with, Meta's terms and policies for the WhatsApp Business Platform.
Our user is the broker or real-estate business ("you") who signs up and connects their own WhatsApp Business account. We process the data in that account on your behalf and on your instruction. Each user's data is kept in a separate, isolated workspace; one user can never see another's data.
Aria connects through Meta's official WhatsApp Business Platform (Cloud API), which you authorise yourself through Meta's secure sign-up flow. We use only this official integration; we do not use unofficial or third-party WhatsApp clients. Messaging runs over the WhatsApp Business Platform with Meta acting as a processor.
Gmail is connected with a Google App Password that you create in your own Google account and paste into Aria. Aria uses it only to read your mailbox and to send email from your address when you ask it to (over IMAP and SMTP, the same standard your email app uses). The password is stored encrypted (AES-256-GCM) and is deleted the moment you press Disconnect. We never see your Google account password. Calendar is connected by pasting your calendar's secret iCal address (read-only; stored encrypted) and bookings are made by emailing a standard calendar invite from your own Gmail. YouTube is connected by giving us your public channel link; we read only public channel data. Disconnect any of these at any time in Connections; the stored address, link and password are deleted immediately.
We use your data solely to build and operate your CRM and the assistant features that act on it — organising your conversations, and drafting messages and documents for you. Aria reads your connected account to keep your CRM current; the sync itself is read-only. Where you explicitly approve an outbound campaign, Aria sends WhatsApp-approved template messages to the contacts you selected, from your business number; opt-out requests (e.g. “STOP”) are honoured automatically and suppressed from future sends. We do not repurpose your WhatsApp data for any unrelated use, do not share it with or across other customers, do not sell it, and do not use your client conversations to train third-party AI models.
AI-generated replies ("Aria replies as me"). Aria can also, if you choose, answer clients on your behalf: within WhatsApp's 24-hour customer-service window (i.e. after a client has messaged you), you may allow Aria to send AI-generated free-form replies to specific conversations, or to conversations by default, from your own WhatsApp Business number and in your name. This feature is off by default; you enable it per conversation or as a default, and you can switch it off per conversation or globally at any time. Replies are generated from your connected conversation, your client book and the training material you have given Aria, using the AI model providers listed in section 6. Opt-out requests (e.g. "STOP") are always honoured, including in AI-handled conversations. Outside the 24-hour window, the only way to message a client first remains an approved template message, and campaigns always require your explicit approval.
We process this data on the basis of your explicit consent and instruction, recorded with a timestamp when you connect your account. You are the data controller of your clients' information; Aria acts as your processor. You are responsible for having a lawful basis to process your own contacts' data and for honouring their rights and opt-outs.
We share the minimum necessary with providers who process data on our behalf under contract:
These are our current sub-processors; we update this list when they change.
Your data lives in your own isolated workspace — a private machine and encrypted storage volume hosted in Singapore. If you access Aria from the UAE or elsewhere, this involves a cross-border transfer, carried out under appropriate contractual safeguards. All access is over HTTPS.
We keep your CRM and connected-account data while your account is active. Note that under the WhatsApp Business Platform (Cloud API), Meta retains message content for a limited window of up to 30 days for delivery purposes. When you disconnect WhatsApp or close your account, we delete the associated data as described below; limited records may be retained only where required for legal, tax or audit obligations.
You can, at any time and at no cost:
Full steps are on our Data Deletion page.
Data is encrypted in transit and at rest, and isolated per user. Privileged credentials are never stored on the machines that run individual users' agents; those machines hold only a scoped token and reach privileged services through a controlled gateway. Every access to your data by Aria staff is recorded and visible to you in the app (Connections → Who has accessed your data).
This policy is intended to be no less protective than, and not inconsistent with, Meta's terms and the WhatsApp Business Platform policies. Your use of WhatsApp is also governed by WhatsApp's own terms and privacy policy.
We'll post changes here with a new effective date. Questions or data requests: support@aria-app.dev, Aria, Dubai, United Arab Emirates.