Gango Tech Ltda. · WhatsApp Business Platform
Data Deletion Instructions
v1.0 · last updated 12 September 2026
To have your data deleted, e-mail privacy@gango.tech with data deletion in the subject line and the phone number involved. We confirm receipt and answer within 5 business days. Section 1 is the whole instruction.
1.How to ask us to delete your data
Send an e-mail to privacy@gango.tech. Write data deletion in the subject line so that it is routed correctly. There is no account to create, no form to fill in and nothing to install.
Tell us, in the body of the message:
- The phone number, in international format — for a Brazilian number, +55 followed by the area code and the number. This is the only thing that lets us find data about you, so a request without it is a request we cannot act on.
- The name of the business you were exchanging messages with, if you know it. We deliver messages on behalf of the businesses that use our software, and the name shortens the search considerably.
- What you want: to stop receiving messages, to have the messages and your number erased, or both.
We reply to confirm that the request arrived, and answer within 5 business days — either with what was deleted, or with a stated reason for whatever we could not delete.
Do not send us identity documents, a photograph of a document, card numbers or bank account numbers. We never ask for them and we do not need them to act on a request. If we cannot tell that a request comes from the person it concerns, we say so and explain what would let us tell — normally nothing more than a message from the number itself.
2.What this application holds about you, and what it does not
This application does not use Facebook Login and does not request Facebook or Instagram profile data. We therefore hold no data associated with a Facebook user ID. The data we may hold about you is the phone number you used to message a business, and the content of those messages.
Gango Tech Ltda. operates a messaging integration on the WhatsApp Business Platform for the businesses that use our software. We receive the messages a business’s customers send to that business’s WhatsApp number, and we send the messages that business asks us to send. Nothing in that flow reads a Facebook or Instagram profile, follows a social graph or builds one. No table in any of our databases is keyed by a Facebook user ID, because no such identifier ever reaches us.
3.Who is asking
Three kinds of request reach this channel, and what you are entitled to genuinely differs between them. Find yourself below.
You exchanged WhatsApp messages with a business
We know you by a phone number and nothing else: no name, no e-mail address, no profile. And because this application has no Facebook Login, there is no “remove app” control in your Facebook or Instagram settings that reaches us. This page is the mechanism.
What we do, on request:
- We stop messaging you. The request is recorded as a suppression, and suppressions are checked at the moment of delivery rather than only when a message is created — so the stop also catches messages that were already queued and not yet sent.
- Your number and the message content are erased from our delivery log. What remains is the delivery record itself: which message, through which provider, at what time, and whether it was delivered. It carries no address and no content, and it is what answers “did you send it or not?” if you or the business ever ask.
- The stored copy of the incoming notification that carried your message — which we keep so that a repeated delivery from Meta is not processed twice — is erased with the same request.
What we cannot do:
- We cannot delete messages from your phone, or from the phone of the person you were messaging.
- We cannot delete anything held by Meta. Your WhatsApp account and its message history belong to your relationship with Meta, not to us.
- We cannot delete the records the business itself keeps. That business is the controller of its own customer records and we act on its instruction. We forward your request to it within 5 business days and support it technically.
Where the data is held on a business’s behalf, it is deleted either on that business’s instruction or because the law requires us to act without waiting for one. Our answer tells you which of the two applied.
You are a business that connected a WhatsApp number
Disconnecting a number deletes our copy of the access token, the record of the number and the 24-hour service window of every contact on it.
The other half, which we would rather you read here than discover for yourself: deleting our copy does not revoke the token. It stays valid at Meta until you revoke it yourself, in Meta Business Manager. There is no call we can make to revoke it for you. If your intention is to cut our access, revoke the token — our reconciliation notices within minutes and stops using the number.
What survives a disconnection: the delivery history, the delivery receipts, the suppressions, and any queue being held for you, which is released through the next number you connect. Deleting the rest of your data is a request to privacy@gango.tech, answered within 5 business days. In GerTruck it is a hand-run database operation: the product has no automatic purge routine and no tenant-deletion code path, and we write that down rather than imply that a button exists.
You are exercising a right under the LGPD (art. 18)
These rights are exercised per product, because the controller is the business that uses the software, not us. Each product publishes its own policy in Portuguese, and that policy is the controlling disclosure for its users: ternavi.com.br/privacidade and gertruck.com.br/privacidade.
Ternavi (veterinary clinics). The clinic operates the tools in its own Privacy screen: confirmation and access as a PDF, portability as JSON, correction, and anonymisation. Anonymisation is built and works — it overwrites the tutor’s name and clears the CPF, the phone number, the e-mail address and the free-text notes; it revokes every portal link, renames it and destroys the stored link credential. It is refused while a hospitalisation is active, because the tutor is who receives the clinical updates. What survives is the animal’s clinical record, kept under art. 16, I of the LGPD and the duty of custody in CFMV Resolution nº 1.321/2020, art. 9, §3º, reflected in a retention floor of 60 months.
GerTruck (truck centres). The truck centre is the controller of its customer, contact and vehicle records, and we act on its instruction. Send the request to the truck centre, or send it to us and we forward it within 5 business days and support it technically. Our own retention here is stated as criteria and not as clocks: charges issued and ledger entries are kept for 5 years counted from the close of the financial year in which the transaction occurred; copies of registration-verification documents are kept while the payments module is active for the company; the audit trail is kept for the duration of the contract and for at least 6 months, under art. 15 of Law nº 12.965/2014. And the sentence that belongs with them: there is no automatic purge routine today. Those periods are the criteria we apply when deletion is carried out, not the description of an automatic process.
4.How long it takes, and when we may refuse
We confirm receipt when the request arrives and answer within 5 business days. Where the request has to be executed inside a product, that period is dimensioned so that the controller business can still meet the deadline the LGPD imposes on it.
We may refuse a request, in whole or in part. There are three grounds, written here in advance so that a refusal is never an unexplained one:
- A legal retention obligation covers the data. We then say which obligation and for how long it runs, delete everything the obligation does not cover, and delete the rest when the period ends.
- There is an active dispute — judicial, administrative or arbitral — in which the data is evidence. We keep only what the dispute needs, say so, and delete the rest.
- We cannot attribute the request to the person it concerns. We do not delete one person’s messages because a different person asked. We explain what would let us attribute the request, and we never ask for an identity document.
In every case, the answer states what was deleted, what was not, and why. You do not have to ask a second time to find out.
5.Limits we write down rather than hide
What this channel does not do automatically
- Execution is manual. There is no self-service deletion screen on our platform. A person locates the data, deletes it and records what was done. The single exception is the clinic-side tools in Ternavi described in section 3, which the clinic itself operates.
- The automatic 90-day clean-up does not reach everything. It erases the recipient address and the message content from the delivery log, deletes expired 24-hour service windows, and strips the recipient’s number from delivery receipts. It does not reach the stored copy of the incoming notification kept for de-duplication, nor events already handed to a product. Those are erased on request, by hand.
- GerTruck has no purge routine at all, and no code path that deletes a tenant.
- In Ternavi, the purge of expired records ships switched off. The clinic decides whether to switch it on, because deleting a clinical record cannot be undone. While it is off, the platform only counts and displays how many records have passed their period. A PDF dossier generated before an anonymisation also still contains the tutor’s CPF, kept on the same legal ground until the end of that period — the number cannot be removed from the document without destroying the evidentiary value that justifies keeping the record at all.
- Deleting here does not delete elsewhere. Not at Meta, not on your phone or the phone of the person you messaged, and not in the records the business keeps as controller.
6.Why these are instructions and not an automated callback
Meta lets an application publish either a data deletion callback URL or data deletion instructions. We publish instructions, and the choice is deliberate.
A callback is invoked with a signed request carrying an app-scoped Facebook user ID. That identifier only exists for applications that use Facebook Login or read Facebook and Instagram data. This application uses neither, so there is no column anywhere in our systems that such an identifier could be matched against. A callback would match nothing and would always answer that there is nothing to delete — useless to the person asking, and evasive to anyone checking. An instruction that produces a real deletion is the more honest answer to the same requirement.
If we ever add Facebook Login or Meta’s Embedded Signup, the callback becomes the required mechanism and this page changes together with it. The design for that callback is already written down internally, so the change is a build and not a decision.
7.If our answer does not resolve it
- The business you were messaging, where it is the controller of the record. Our products publish a privacy channel of their own: ternavi.com.br/privacidade and gertruck.com.br/privacidade.
- The Autoridade Nacional de Proteção de Dados (ANPD), Brazil’s data protection authority. You may complain to it at any time. You are not required to come to us first, and nothing on this page asks you to give that up.
Our channel is privacy@gango.tech. Gango Tech Ltda. is a small-scale processing agent under Resolution CD/ANPD nº 2/2022, and publishes a channel for data subjects rather than a formally appointed officer.
This page is also published in Portuguese, at /pt-br/legal/exclusao-de-dados. Between Gango Tech Ltda. and its clients, the Portuguese version prevails.