1. Requesting access, correction, export or deletion
Use available account settings or email privacy@clases.community from the address associated with the account. Identify the community and relevant channel, but never send a password, access token, full payment-card number or a copy of an entire private conversation. Community-authored records may first require coordination with that community. We also accept valid provider callbacks, including Meta’s signed deletion request.
2. Verification and safety
We verify enough information to protect the account and other people. A Meta callback is processed only after its HMAC signature, algorithm and issue time are validated. Invalid, expired, altered or malformed requests do not trigger a lookup or deletion and do not reveal whether a person or provider identity exists. Direct requests may require authentication or limited additional proof.
3. What deletion covers
Eligible account or channel data is deleted or irreversibly de-identified. For a provider-connected business administrator, this can include the affected connection credential, channel identity links, pairing requests, queued or quarantined message content, conversation references, delivery/idempotency records, provider-specific templates and account telemetry. We block affected connections before destructive work so new sends cannot race the request. Deletion does not remove data controlled independently by a community or provider; contact them for their copy.
4. Channel-specific scope
WhatsApp and Meta
Meta sends an app-scoped administrator identity, not a member’s phone number. We use it only to locate WABAs authorized by that connector. A valid request disconnects affected WABAs, deletes encrypted credentials and eligible community WhatsApp operational data, and prevents future delivery until a new authorized connection is made. Meta may keep records under its own policy.
Telegram
We remove eligible Telegram identity links, bot conversation references, pending content and connection credentials under our control. Stopping or blocking a bot and contacting Telegram may also be necessary for Telegram’s independent records.
Slack
We remove eligible workspace identity mappings, pending content and encrypted OAuth credentials under our control. A workspace administrator should also uninstall/revoke the app and use Slack’s process for workspace-controlled data.
Microsoft Teams
We remove eligible tenant/user mappings, conversation references, pending content and credentials under our control. Tenant administrators should also uninstall/revoke the app and use Microsoft/organization processes for tenant-controlled records.
SMS
We remove eligible queued content and ordinary profile/delivery data, but retain a minimized suppression record when needed to honor STOP and prevent an unwanted resubscription. Carriers and SMS providers control their own delivery records. Deletion does not silently opt a number back in.
5. Records we may retain
We may retain minimized records necessary for security, fraud prevention, financial/accounting duties, legal claims, sanctions, or proof of consent and opt-out. Such records are separated from ordinary product use, limited to authorized purposes, and deleted when the applicable obligation expires. Controlled backups expire on rotation. We do not retain a message merely because it might be useful later.
6. Timing
Eligible live channel data is targeted for immediate processing after valid verification. Complex account requests may take the period allowed by applicable law. Provider delivery, independent community systems and backup rotation can finish later. We will explain a permitted extension or denial when the law requires it.
7. Provider confirmation and status
A valid Meta callback receives an opaque confirmation code and a public status URL. The URL shows only generic received, processing or complete state; it contains no provider user ID, phone number, access token or message. Repeated valid callbacks return the same idempotent result instead of running deletion twice.
8. Questions, appeals and complaints
Reply to the decision or email privacy@clases.community if you believe the scope is wrong. Depending on location, you may appeal, appoint an authorized agent, or complain to a data-protection or consumer authority. We do not discriminate for exercising a legal right.
9. Contact
Privacy and rights: privacy@clases.community. General support: support@clases.community. Include only the minimum information needed to locate the request safely.
