Skip to main content
GoGHL is built around a simple principle: we process your messages to deliver them; we do not store them. Message content passes through, gets delivered, and is gone — it is never stored on GoGHL servers.

What we process (metadata only)

We handle a minimal amount of operational metadata needed to deliver and track messages:
  • Delivery and read statuses
  • Message IDs and timestamps
  • Phone identifiers and contact names
  • Session data
The operational metadata we process is kept for no more than 14 days, then automatically deleted.

Key data-handling principles

  • Processing, not storage. GoGHL processes your messages to deliver them; it does not store the message content.
  • Minimal retention. Only operational metadata is retained, and only for up to 14 days.
  • No proxy storage. WhatsApp connections route through regional residential proxies that store none of your data.

Where data is processed

Infrastructure operates in the EU and US regions, with GDPR-compliant safeguards:
  • Standard Contractual Clauses (SCCs)
  • SOC 2
  • ISO 27001

GDPR compliance

Organizations using GoGHL act as the data controller, while GoGHL functions as the data processor under GDPR Article 28. We offer a GDPR Article 28-compliant Data Processing Agreement (DPA), including the EU Standard Contractual Clauses. To request a DPA, contact compliance@goghl.ai.

Data deletion

You can request account deletion at any time. Because operational metadata auto-deletes after 14 days, on request we remove the rest.

Security measures

  • Encryption in transit
  • Access controls
  • Environment separation
  • Breach notification within 48 hours, per the DPA terms

Contact