LEGAL • PRIVACY
Privacy Policy
This Privacy Policy explains how Nexera Group processes, protects, retains, shares and manages personal information when Meta Gateway is used to connect authorized business applications with supported Meta and other enabled services.
Overview
Meta Gateway is an integration platform developed and operated by Nexera Group.
The platform provides infrastructure for connecting authorized business applications with supported Meta services and other configured integrations, including approved messaging, API and webhook workflows.
This policy describes the categories and sources of personal information that may be processed, why information is processed, how it may be shared or transferred, how long it is retained, the safeguards used to protect it, and the privacy choices and rights that may be available.
The exact information processed depends on the services, permissions and business workflows enabled for a connected organization. Some rights and responsibilities also depend on whether Nexera Group acts as a data controller or as a data processor for the relevant processing activity.
Who we are
Meta Gateway is developed and operated by Nexera Group, a software engineering company based in Kigali, Rwanda.
Nexera Group designs software applications, integration platforms, APIs and infrastructure used by businesses and organizations to manage digital operations.
Our privacy role
Nexera Group's role depends on the purpose and context of the processing.
Nexera Group may act as a data controller where it determines why and how personal information is processed, for example for Meta Gateway administration, account management, service security, support, operational records, privacy requests and legal compliance.
Where Meta Gateway processes communication, integration or platform information on behalf of a connected organization and according to that organization's instructions, the organization may be the data controller and Nexera Group may act as its data processor.
When Nexera Group acts as a processor, the connected organization is generally responsible for determining the lawful purpose of the processing, providing required notices to its users and handling privacy requests relating to the organization's own use of the data. Nexera Group will support those obligations as required by applicable law and applicable contractual arrangements.
Information we may process
Depending on the integration, account configuration and permissions enabled, Meta Gateway may process the following categories of information.
Account identifiers
Identifiers associated with connected Meta business accounts, pages, messaging accounts, integrations or authorized users.
Message information
Message content and related information where required to provide an enabled messaging or communication workflow.
Message metadata
Information such as message identifiers, timestamps, delivery status, sender or recipient identifiers and event type.
Webhook and integration events
Supported events delivered by Meta or other configured services to Meta Gateway for processing and routing.
Technical and security information
Request identifiers, timestamps, IP or network-related information where available, service events, authentication events, logs and diagnostic information required to operate, secure or troubleshoot the service.
Business and configuration information
Information supplied by organizations or authorized users to configure supported integrations, accounts and business communication workflows.
Support and privacy-request information
Information provided when an organization or individual contacts Nexera Group for support, privacy questions, rights requests or data deletion.
Meta Gateway is designed to limit processing to information that is relevant to an enabled integration, legitimate operational needs or applicable legal requirements.
How we obtain information
Personal information processed by Meta Gateway may come from:
- organizations and authorized users that configure or use Meta Gateway;
- individuals who communicate with a connected organization through an enabled messaging or communication channel;
- Meta services, including supported APIs, messaging services and webhook events, where the required permissions and authorization exist;
- other business applications or services intentionally connected to Meta Gateway by an authorized organization; and
- Meta Gateway itself, through technical, security, authentication, audit, service and diagnostic events generated while operating the platform.
Where personal information is not obtained directly from the individual, its source will depend on the connected service and business workflow.
How information is used
Information processed through Meta Gateway may be used for the following purposes.
Provide integration services
Process authorized requests between connected business applications and supported Meta or other enabled services.
Process messages and events
Receive, route and process supported messages, delivery events, webhook notifications and related integration events.
Protect the platform
Authenticate requests, validate operations, manage access, detect misuse and support fraud, abuse and security prevention.
Operate and maintain services
Diagnose failures, monitor availability, maintain infrastructure, investigate incidents and support reliable service operation.
Support users and organizations
Respond to support, privacy, data deletion, account and integration-related requests.
Improve reliability
Understand technical failures and improve system stability, maintainability, resilience and operational performance.
Meet legal and regulatory obligations
Maintain records or disclose information where required to comply with applicable law, valid legal process or regulatory obligations.
Nexera Group does not use personal information for a materially incompatible purpose without taking any additional steps required by applicable law.
Legal bases for processing
Where applicable law requires a lawful basis for processing, Nexera Group relies on the basis appropriate to the specific processing activity and its role in that activity.
Contract
Where processing is necessary to provide Meta Gateway services requested under an agreement or to take steps connected with such services.
Legitimate interests
Where permitted by applicable law, for interests such as securing the platform, preventing abuse, maintaining service reliability, supporting users and protecting Nexera Group, its customers and other users, provided those interests are not overridden by applicable privacy rights.
Legal obligation
Where processing is necessary for Nexera Group to comply with an applicable legal or regulatory obligation.
Consent
Where applicable law requires consent or where a specific optional activity is based on consent. Consent may be withdrawn where the law provides that right, without affecting processing already lawfully carried out before withdrawal.
Where Nexera Group acts only as a processor, the connected organization is responsible for establishing the lawful basis for the processing it instructs Nexera Group to perform, subject to applicable law and contractual requirements.
If consent is relied upon for a specific activity, you may have the right to withdraw that consent. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Meta platform data
Meta Gateway may receive information from supported Meta services only where the connected organization has enabled the relevant integration and the required permissions or authorization exist.
Depending on the integration, this may include information associated with WhatsApp Business, Instagram or other supported Meta services.
Meta platform information is processed to provide the configured integration functionality and related operational, security, support and compliance activities.
Integrations operate within the permissions and capabilities configured for the connected account.
Platform information is processed for configured integration, operational, security and legally required purposes.
Meta Gateway is designed to avoid collecting information that is not required for the enabled workflow or legitimate operational requirements.
Sensitive information
Meta Gateway is not designed to require sensitive personal information merely to operate an integration. However, message content or business workflows may contain information that is considered sensitive, special-category or otherwise subject to additional protection under applicable law.
Connected organizations are responsible for ensuring that any sensitive information they choose to process through enabled workflows is necessary, lawful and subject to appropriate safeguards. Where Nexera Group acts as controller for a processing activity involving sensitive information, it will apply the additional requirements required by applicable law.
Service providers and subprocessors
Nexera Group may use carefully selected service providers to support infrastructure, hosting, security, monitoring, communications, support or other functions required to operate Meta Gateway.
Where a provider processes personal information on behalf of Nexera Group or a connected organization, Nexera Group uses contractual and organizational measures appropriate to the processing and applicable law. Providers are expected to process information only for authorized purposes and subject to applicable confidentiality, security and data-protection requirements.
Additional information about categories of service providers or relevant subprocessors may be made available to connected organizations through applicable service documentation, contractual arrangements or upon an appropriate request.
International data transfers
Meta Gateway may interact with services, infrastructure or recipients located in countries other than the country in which an individual or connected organization is located.
Before personal information is transferred internationally, Nexera Group applies the transfer requirements that are relevant to its role and the applicable law. Depending on the circumstances, these requirements may include regulatory authorization, contractual safeguards, consent or another lawful transfer condition.
Where Rwanda's data-protection law applies, transfers of personal data outside Rwanda are handled in accordance with the applicable requirements governing cross-border transfers, including required safeguards and contractual responsibilities.
Where European or other international transfer rules apply, additional lawful transfer mechanisms or safeguards may be used as required by the relevant law.
You may contact Nexera Group for information about safeguards applicable to a specific transfer for which Nexera Group is responsible.
Data retention
Personal information is retained only for as long as necessary for the purpose for which it is processed, subject to applicable legal, contractual, security and operational requirements.
Because Meta Gateway supports different integrations and customers, a single retention period does not apply to every category of information. Relevant retention criteria may include:
- the duration of an active account, contract or integration;
- the time required to complete the configured communication or business workflow;
- security, audit, fraud-prevention and incident-investigation needs;
- applicable legal, tax, accounting, regulatory or record-keeping obligations;
- the period reasonably necessary to establish, exercise or defend legal claims; and
- backup, disaster-recovery and secure deletion cycles.
Retained only for the period necessary to provide or support the relevant business workflow and associated obligations.
Retained for a period appropriate to security monitoring, auditing, incident investigation and applicable obligations.
Information no longer required is deleted, anonymized or securely disposed of in accordance with applicable retention requirements and technical deletion cycles.
Where a connected organization's contract or configuration establishes a more specific lawful retention period, that period may apply to information processed on that organization's behalf.
Security
Meta Gateway is designed with technical and organizational controls intended to protect integration infrastructure and information processed through the platform.
Depending on the service and environment, controls may include authentication, authorization, encrypted communications, request validation, credential protection, least-privilege access, logging, monitoring, audit controls and protections against replayed, malformed or unauthorized requests.
No system can guarantee absolute security. Nexera Group maintains measures intended to reduce risk and responds to suspected security incidents in accordance with applicable operational and legal requirements.
Learn more about Meta Gateway securityTokens and credentials
Meta Gateway may use access tokens, application credentials, cryptographic keys or other integration secrets required to communicate securely with supported external services.
These credentials are treated as sensitive system information and are intended to remain within protected backend infrastructure, secret-management systems or other appropriately controlled environments.
Do not send passwords, access tokens, private keys, application secrets or other credentials through public contact, support or data-deletion forms.
Your privacy rights
Depending on the applicable law, the type of processing and Nexera Group's role, you may have rights concerning personal information associated with you.
These rights may include the right to:
- request confirmation of whether personal information about you is processed;
- request access to and a copy of personal information associated with you;
- request correction or rectification of inaccurate or incomplete information;
- request deletion or erasure where the applicable legal conditions are met;
- request restriction of processing in applicable circumstances;
- object to certain processing where applicable law provides that right;
- request portability of information in a structured and readable format where applicable;
- ask about the source of personal information that was not obtained directly from you;
- ask whether information has been transferred to another country and, where applicable, request information about relevant safeguards;
- withdraw consent where processing is based on consent, without affecting processing lawfully carried out before withdrawal; and
- exercise applicable rights concerning solely automated decisions that produce legal or similarly significant effects.
These rights are not absolute and may be subject to conditions, limitations or exceptions under applicable law.
Where Nexera Group processes information only on behalf of a connected organization, we may direct or transmit your request to that organization because it is responsible for the relevant processing decision.
We may request information reasonably necessary to verify identity, authority, account ownership or the integration connected with a request. Do not provide credentials or unnecessary sensitive information for verification.
Automated decision-making
Meta Gateway uses automated systems to perform technical functions such as routing messages, processing webhook events, validating requests, applying security controls and operating integrations.
Nexera Group does not use Meta Gateway personal information to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals unless that processing is separately disclosed and carried out in accordance with applicable law.
A connected organization may independently configure systems or workflows that make decisions using information delivered through an integration. Where that organization determines the purpose and means of such decision-making, its own privacy notice and legal obligations apply.
Data deletion
You may request deletion of personal information associated with your use of Meta Gateway where the applicable legal conditions are satisfied.
A deletion request should contain enough information for Nexera Group to identify the relevant account, organization, integration or processing activity, but should never include passwords, access tokens, private keys or other sensitive credentials.
Some information may need to be retained where required or permitted by law, for security purposes, to resolve disputes, to enforce agreements or where another lawful retention obligation applies. Where appropriate, information may instead be anonymized or isolated from active processing.
Follow the steps for submitting and verifying a deletion request.
Third-party services
Meta Gateway communicates with external services as part of configured integrations.
Those services may operate under their own terms, policies and data-handling practices. Nexera Group is not responsible for the independent privacy practices of a third party where that party determines its own purposes and means of processing.
Organizations using Meta Gateway are responsible for ensuring that external services they enable are appropriate for their intended business use and that they have the permissions, notices and other lawful grounds required for the resulting processing.
Children
Meta Gateway is a business integration service and is not directed to children as a consumer service.
Connected organizations are responsible for determining whether their communication workflows involve children or minors and for meeting any consent, notice, age-verification or other requirements that apply to those interactions.
Where Nexera Group becomes aware that personal information has been processed in circumstances that do not satisfy applicable requirements concerning children, Nexera Group will take appropriate steps within its role, which may include working with the responsible connected organization to restrict or delete the information.
Regional privacy requirements
Meta Gateway is operated from Rwanda and may support organizations or communications involving individuals in other jurisdictions. Privacy rights and obligations may therefore vary according to the applicable law, the location of the relevant individuals, the connected organization's activities and Nexera Group's role.
Where Rwanda's Law relating to the protection of personal data and privacy applies, Nexera Group processes personal information subject to the rights and obligations established by that law.
Where laws such as the EU General Data Protection Regulation, the UK GDPR or other applicable privacy legislation govern a particular activity, Nexera Group applies the requirements relevant to its role in that processing.
If a jurisdiction grants additional privacy rights that apply to a particular processing activity, those rights may be exercised even if they are not described exhaustively in this policy.
Changes to this policy
Nexera Group may update this Privacy Policy when Meta Gateway, its integrations, legal requirements, service providers or operational practices change.
The current version will be published on this page with an updated revision date. Where required by applicable law or where a change materially affects how personal information is processed, Nexera Group will provide additional notice through an appropriate channel.
Contact and complaints
Questions about this Privacy Policy, Meta Gateway's processing of personal information or an applicable privacy right can be directed to Nexera Group.
You may also have the right to complain or appeal to the competent data-protection supervisory authority. In Rwanda, the supervisory authority is the Data Protection & Privacy Office.
If another supervisory authority has jurisdiction over your information, you may also have the right to lodge a complaint with that authority.