Data Processing
Last updated: August 2026
Roles
When a business (Customer) uses Hilo to serve its own end customers, the Customer acts as the controller of those contacts' data, and Hilo acts as processor: we process that data only to provide the service, following the Customer's instructions as reflected in normal use of the platform.
Categories of data processed
Contact identifiers (WhatsApp number, Instagram handle, profile name), message content and attachments, conversation metadata (dates, status, channel, tags, assigned agent), and, if the Customer configures it, additional information it chooses to record about its contacts (e.g. notes or sale data).
Sub-processors
To provide the service, Hilo relies on the following sub-processors: Meta (WhatsApp Cloud API / Instagram Graph API) for sending and receiving messages; Xano for storage and backend logic; Vercel for hosting the application; and, when the Customer enables AI features, a language model provider (e.g. OpenAI) to generate replies.
Customer instructions
Hilo processes a Customer's contact data according to the configuration the Customer itself sets in the platform (connected channels, assignment rules, AI usage, tags, campaigns). We don't use that data for purposes other than providing the service to the Customer.
Deletion at end of service
When the relationship with a Customer ends, its data can be deleted or returned upon request, except for information we must retain for legal obligations or backups for a reasonable period.
Contact
For requests related to data processing, book a call or email us at adrian5digo@gmail.com.