Skip to main content

Data, Privacy & Security

GoGHL processes your data to deliver your messages - it does not store it. This page explains what we process, what we never keep, how long the little we hold lasts, and how to request a Data Processing Agreement (DPA) or have your data deleted.

We process your data - we don't store it

GoGHL processes your messages to deliver them; it does not store them. Message content - the text and media your contacts send and receive - is relayed between GoHighLevel and your channel (WhatsApp, iMessage, SMS) and is never stored on GoGHL servers. It passes through, gets delivered, and is gone.

What we process (metadata only)​

To deliver your messages reliably and reflect their status inside GoHighLevel, we process a small amount of operational metadata:

  • Delivery and read statuses, message IDs, and timestamps
  • Phone-number identifiers and contact display names
  • GoHighLevel sub-account identifiers
  • Session and usage data
  • IP address (for authentication and security) and basic device/browser metadata

The operational metadata we process is kept for no more than 14 days, then automatically deleted - we don't retain it beyond what's needed to deliver your messages. We never store message content, and we don't process any special-category (sensitive) personal data.

Third-party platforms

Data held inside GoHighLevel, WhatsApp, or Meta is governed by those platforms' own policies and retention - it sits outside GoGHL and is not covered by this page.

Where your data is processed​

GoGHL runs on enterprise cloud infrastructure in the EU and US, under GDPR-compliant safeguards (Standard Contractual Clauses, SOC 2, ISO 27001). WhatsApp connections are routed through a dedicated residential proxy matched to your device's region (for stability and ban protection) - the proxy only carries the live connection and stores none of your data. A current list of our sub-processors is available on request as part of our DPA.

GDPR & Data Processing Agreement​

For your use of GoGHL, you (your agency or business) are the data controller and GoGHL is the data processor. We offer a GDPR Article 28-compliant Data Processing Agreement (DPA), including the EU Standard Contractual Clauses for international transfers.

Request a DPA: compliance@goghl.ai

Account & data deletion​

You can ask us to delete your account and associated personal data at any time. Operational metadata is already removed automatically on the 14-day cycle; on request, we remove the rest.

Request account or data deletion: support@goghl.ai

Security​

  • Encryption of data in transit
  • Access limited to authorized personnel under confidentiality obligations
  • Separated development, staging, and production environments
  • Personal-data breach notification within 48 hours (per our DPA)
  • Secure software development lifecycle and regular review

Who to contact​

RequestEmail
Data Processing Agreement (DPA)compliance@goghl.ai
Account / data deletionsupport@goghl.ai
General privacy questionsprivacy@goghl.ai

FAQs​

Does GoGHL store my WhatsApp, SMS, or iMessage messages?

No. GoGHL processes your messages to deliver them - message content is never stored on our servers. We process only limited operational metadata (delivery statuses, identifiers, timestamps) and keep it for no more than 14 days before deleting it.

How long is my data kept?

Message content is not stored at all. The limited operational metadata we process is kept for no more than 14 days, then automatically deleted.

How do I get a Data Processing Agreement (DPA)?

Email compliance@goghl.ai and we will provide our GDPR Article 28-compliant Data Processing Agreement, including EU Standard Contractual Clauses.

How do I delete my account and data?

Email support@goghl.ai to request account and data deletion. Operational metadata is also removed automatically on the 14-day cycle.

Is GoGHL GDPR compliant?

Yes. GoGHL acts as a data processor under GDPR Article 28, offers a DPA with EU Standard Contractual Clauses, processes no special-category data, and notifies controllers of any personal-data breach within 48 hours.
Let's connect