01 · Guide
What data you actually need
The principle is minimization: hold what the relationship requires and nothing else.
- Contact details and language preference
- Opt-in status and its timestamp
- Order and booking history
- Conversation context needed for service
02 · Guide
Opt-in as the privacy cornerstone
Opt-in is not just a Meta rule — it is the legal basis for marketing contact under PDPL and GDPR. Store it with a timestamp and a channel, and treat its absence as a blocker.
- A timestamped record of consent
- Consent specific to WhatsApp marketing
- Instant opt-out handling and removal
- No pre-checked boxes that imply consent
03 · Guide
PDPL and GDPR in practice
Saudi PDPL and GDPR differ in details and agree on the spine: consent or a legitimate basis, the right to be forgotten, and transparency about what you hold.
- Saudi PDPL governs Saudi customer data
- GDPR governs EU customers wherever you operate
- Both require a deletion path for customer data
- Both require you to know what you hold and why
04 · Guide
The data you should never hold
Some data has no business in a chat workspace.
- Payment card numbers — processed by the gateway, never stored by you
- Verification codes — expire and vanish, never archive them
- Government IDs beyond what the law requires
- Bulk raw numbers without consent
05 · Guide
Retention and deletion
Delete what you do not need: conversations settle, opt-outs close, and stale data is a liability. A deletion path for customer requests is a requirement, not a courtesy.
06 · Guide
The privacy notice you can actually keep
The best privacy notice is the one that matches reality: what you collect, why, how long you keep it, and how a customer deletes it. Write it to describe what you actually do — a notice that promises less protection than you practice is a legal risk in itself.
- List the data you actually collect: contact, orders, bookings, opt-in records
- State retention: how long conversations and records stay
- Publish the deletion path and honor it in days, not months
- Review the notice when your data practices change
07 · Guide
How Wutt helps
Wutt stores opt-in per contact with timestamps, enforces opt-out, and keeps access control on the workspace; the security page documents the current controls. Privacy practices like retention and deletion remain the business's job — Wutt gives you the levers.
Last updated 5 August 2026
Common questions
For marketing, yes — a timestamped opt-in record. For service messages tied to an active relationship, no.
Yes. PDPL governs how Saudi customer data is collected and processed, including marketing consent.
No. Cards are processed by the payment gateway; never store them yourself.
As long as the relationship needs them, and no longer. A deletion path is required.
Honor the deletion request across contacts, lists, and campaign histories.