Last updated: 7 September 2026
Using Raddai (WhatsApp Business Platform)? If you are a business connecting a WhatsApp Business Account through our Raddai platform, or a person messaging a business that uses it, please see Section 12 — Raddai and the WhatsApp Business Platform (Meta Integration). That Section sets out exactly what data we obtain through Meta’s WhatsApp Business Platform, how we use, store, share and delete it, and the binding commitments we make in respect of it.
Astra Telecom ("Astra", "we", "us" or "our") is a telecommunications and IT services company founded in 2020 and based in Hebron, West Bank, Palestine. We provide wireless and fiber Internet connectivity, web and domain hosting, Cloud and VPS services, VoIP and telecom solutions, Bulk SMS, business messaging services through the WhatsApp Business Platform, and technical support services.
We understand that the services we operate carry some of the most sensitive information our customers have — their identity documents, their traffic, their calls and their business data. This Privacy Policy explains what information we collect, why we collect it, how we use and protect it, and what rights you have over it. It applies to the astra.ps website, to every service we deliver to our subscribers and business clients, and to Raddai (raddai.io), the business messaging platform owned and operated by Astra Telecom.
1. Information We Collect
a. Information you provide to us. When you subscribe to a service, we collect the details needed to establish and maintain your account: your full name or company name, national ID or commercial registration number, service and installation address, contact telephone numbers, email address, and billing and payment details.
b. Network and service usage data. In the course of delivering connectivity we necessarily process technical records, including assigned IP addresses, session start and end times, bandwidth and data volumes consumed, connection quality and signal measurements from your equipment, and the DNS queries handled by our resolvers. For VoIP services we process call detail records — the numbers called, the time and the duration of a call. We do not listen to, record, or retain the content of your calls, messages, or browsing sessions except where a specific service you have requested requires it, or where we are compelled by a lawful order.
c. Hosting, Cloud and VPS data. If you host a website, domain, mailbox or virtual server with us, our systems store the content and databases you place there, along with server, access and error logs, and any backups taken as part of the service. Domain registrations additionally require registrant details to be passed to the relevant registry.
d. Bulk SMS data. For Bulk SMS customers we process sender IDs, recipient numbers, message metadata, delivery reports and traffic volumes in order to route messages and to prevent abuse of the platform.
e. Support and communications. We keep records of support tickets, maintenance visits, and correspondence by email, telephone or WhatsApp, and any details you submit through the contact or newsletter forms on our website.
f. Website data. Our website collects standard technical information such as IP address, browser type and pages visited, together with cookies as described in Section 8.
2. How We Use Your Information
We use the information above to:
- Provision, activate, configure and deliver the services you have subscribed to;
- Issue invoices, collect payment and maintain accurate financial records;
- Provide technical support, diagnose faults and carry out maintenance;
- Operate, secure and plan the capacity of our network — including detecting and mitigating attacks, spam, abuse and fraud;
- Communicate with you about outages, scheduled maintenance, service changes and account matters;
- Send you offers and news about our services, where you have not opted out; and
- Comply with our legal, regulatory and licensing obligations.
We do not sell your personal information, and we do not rent or trade our subscriber lists to advertisers or data brokers.
3. Legal Basis and Consent
We process your information because it is necessary to perform the service contract between us, because we have a legitimate interest in operating and protecting our network, or because we are required to do so by Palestinian law and the terms of our operating licence. Where we rely on your consent — for example for marketing messages — you may withdraw it at any time without affecting the services you subscribe to.
4. When We Share Information
We share personal information only in the following circumstances:
- Service partners and suppliers — upstream carriers, transit and interconnect providers, domain registrars, payment processors and equipment vendors, strictly to the extent needed to deliver your service;
- Legal and regulatory disclosure — to courts, the Palestinian Ministry of Telecom and Information Technology, or law enforcement authorities, where we receive a valid and lawful request. We disclose only what the request actually requires;
- Protection of rights and safety — where disclosure is necessary to investigate abuse, enforce our Terms of Service, or protect the rights, property or safety of Astra, our customers or the public;
- Business transfer — if Astra is involved in a merger, acquisition or transfer of assets, customer information may transfer with the business, subject to this Policy.
5. Data Retention
We retain account, contract and billing records for as long as you remain a customer and thereafter for the period required by Palestinian commercial and tax law. Network logs, DNS query data and call detail records are retained for a limited operational period appropriate to troubleshooting, billing accuracy and regulatory requirements, and are then deleted or aggregated into anonymous statistics. Hosting and VPS content is retained while the service is active; after termination it is deleted following the grace period set out in our Terms of Service.
6. How We Protect Your Information
We apply technical and organisational safeguards proportionate to the sensitivity of the data we hold. These include encryption of data in transit, firewalling and network segmentation, hardened and patched server infrastructure, intrusion and malware detection on our hosting platform, restricted administrative access on a need-to-know basis, and confidentiality obligations binding on our staff. We monitor our infrastructure continuously and investigate anomalies.
No system connected to the Internet can be guaranteed completely secure. If a breach occurs that affects your personal information, we will investigate it, take steps to contain it, and notify affected customers and the competent authorities where required.
7. Your Rights
You may ask us to:
- Confirm what personal information we hold about you and provide a copy of it;
- Correct information that is inaccurate or out of date;
- Delete information we no longer have a lawful or contractual reason to keep;
- Stop sending you marketing communications; or
- Explain a specific processing activity you are concerned about.
To exercise any of these rights, contact us at info@astra.ps. We may need to verify your identity before acting, and some information must be retained where the law requires it. We aim to respond to every request within a reasonable period.
8. Cookies
Our website uses cookies to keep the site functioning correctly, remember your preferences, and understand in aggregate how visitors use our pages. Most browsers allow you to refuse or delete cookies through their settings. Disabling cookies may affect how parts of the site behave, but it will not prevent you from contacting us or using your subscribed services.
9. Third-Party Websites
Our website and our customer portals may link to services operated by others. This Policy does not cover those third parties, and we are not responsible for their privacy practices. We encourage you to read the privacy policy of any external site before providing information to it.
10. Children's Privacy
Our services are contracted by adults. We do not knowingly enter into a service agreement with, or knowingly collect personal information directly from, a person under the age of 18. Where a service is used within a household, the account holder is responsible for supervising use by minors.
11. Hosting Outside Palestine
Some of our platforms and the upstream providers we depend on operate infrastructure outside Palestine. Where your information is processed abroad, we take reasonable steps to ensure it remains protected to the standard described in this Policy.
12. Raddai and the WhatsApp Business Platform (Meta Integration)
This Section applies specifically to Raddai and to any personal data we obtain, process or store through Meta's WhatsApp Business Platform (Cloud API). It supplements the rest of this Policy. In the event of a conflict, this Section prevails in respect of data obtained through the WhatsApp Business Platform.
12.1 Who operates Raddai
Raddai (raddai.io) is a business messaging platform owned, operated and provided by Astra Telecom — a telecommunications and information technology company founded in 2020, registered and based in Hebron, West Bank, Palestine. "Raddai" is a product and brand name of Astra Telecom; it is not a separate legal entity. Astra Telecom is the legal person responsible for the Platform, is the entity that has entered into the applicable agreements with Meta Platforms, Inc. ("Meta"), and is the entity accountable for every commitment made in this Policy.
Astra Telecom acts as a Tech Provider under the WhatsApp Business Solution. Through Raddai we enable our business customers to connect their own WhatsApp Business Accounts to the WhatsApp Business Platform and to send and receive messages with their own customers.
- Operator and data controller: Astra Telecom
- Registered address: Hebron, West Bank, Palestine
- Contact for privacy matters: info@astra.ps
- Telephone: 00972 562 900 009
12.2 The parties, and our role towards each
Two distinct groups of people are involved, and our legal role differs for each:
- A Business Customer is a business that subscribes to Raddai and connects its own WhatsApp Business Account to our Platform.
- An End User is a WhatsApp user who exchanges messages with that Business Customer.
For the Business Customer's own account, registration, subscription and billing data, Astra Telecom is the data controller and processes that data as described elsewhere in this Policy.
For message content and End User data flowing through the Platform, the Business Customer is the data controller and Astra Telecom acts solely as a data processor, processing that data only on the Business Customer's documented instructions and only to provide the service. We do not determine the purposes for which our Business Customers message their own customers.
Meta, in providing the Cloud API, likewise acts as a processor or service provider on behalf of the business. WhatsApp's own handling of user data is governed by the WhatsApp Privacy Policy, which is not controlled by us.
12.3 How the connection to Meta is authorised
When a Business Customer connects a WhatsApp Business Account to Raddai, they are directed to Meta's own Embedded Signup / Facebook Login flow, which is hosted and controlled entirely by Meta. There the Business Customer authenticates using their own Meta credentials and explicitly reviews and grants the permissions requested.
Astra Telecom never sees, receives, requests or stores a Business Customer's Facebook, Meta or WhatsApp password. Upon authorisation, Meta issues us an access token, which we store in encrypted form and use solely to operate the services the Business Customer has asked us to provide. The Business Customer may revoke that authorisation at any time, either from within Raddai or directly from their Meta Business settings.
We request the following permissions, each strictly for the purpose stated:
whatsapp_business_messaging— to send and receive messages on behalf of the Business Customer;whatsapp_business_management— to register phone numbers and manage the WhatsApp Business Account, its profile and its message templates;business_management— to identify and link the business assets the Business Customer has chosen to connect;public_profileandemail— to identify the authorising user and create their Platform account.
We request no permission beyond what is necessary to deliver the service, and we do not use any permission for a purpose other than those listed above.
12.4 Information we access through the WhatsApp Business Platform
- Account identifiers: WhatsApp Business Account (WABA) ID, phone number and phone number ID, verified display name, quality rating and messaging limits;
- Business profile information: business description, address, email, website and profile photograph as published by the Business Customer;
- Message templates and their submission and approval status;
- Message content — the text and, where sent, the media (images, documents, audio, video, location and contact cards) exchanged between the Business Customer and End Users;
- End User identifiers — the End User's WhatsApp phone number and their WhatsApp profile display name;
- Message metadata — timestamps, direction, delivery, read and failure statuses, conversation category and pricing information;
- Webhook event payloads delivered to us by Meta in the ordinary operation of the API;
- The access token issued by Meta upon authorisation.
12.5 Why we process this information
- To deliver the messaging service the Business Customer has subscribed to — routing, sending, receiving, queuing and retrying messages;
- To display conversations in the Business Customer's inbox and preserve their conversation history so they can serve their own customers;
- To provide delivery, quality and performance reporting to the Business Customer;
- To operate automations, chatbots and automatic replies that the Business Customer has themselves configured;
- To calculate billing based on conversation and message volume;
- To maintain security and to detect and prevent spam, abuse, fraud and violations of Meta's policies;
- To provide technical support and diagnose faults, at the Business Customer's request;
- To comply with applicable law and with Meta's terms and policies.
12.6 What we do not do
We make the following binding commitments in respect of all data obtained through the WhatsApp Business Platform. We do not:
- Sell, rent, trade or otherwise make available message content, End User phone numbers, or any other data obtained through the WhatsApp Business Platform;
- Use message content or End User data for our own advertising or marketing purposes;
- Use WhatsApp data to build advertising or behavioural profiles, or share it with data brokers, ad networks or analytics services for their own purposes;
- Use message content to train artificial intelligence or machine learning models, whether our own or those of any third party;
- Share one Business Customer's data with another Business Customer;
- Access message content except where strictly necessary to operate the service, to resolve a support request raised by the Business Customer, to protect the security and integrity of the Platform, or where we are compelled by a valid and lawful order;
- Use the data for any purpose that is incompatible with the Meta Platform Terms, the Meta Developer Policies or the WhatsApp Business Messaging Policy.
12.7 Opt-in and the responsibilities of the Business Customer
Each Business Customer is solely and fully responsible for:
- Obtaining and maintaining a valid, documented opt-in from every End User before messaging them, as required by the WhatsApp Business Messaging Policy and by applicable law;
- Honouring opt-out, "stop" and unsubscribe requests promptly;
- The lawfulness, accuracy and content of every message they send;
- Publishing their own privacy notice to their End Users and complying with the data protection law that applies to them;
- Using the Platform in accordance with the WhatsApp Business Messaging Policy and the WhatsApp Commerce Policy.
Astra Telecom does not send marketing or promotional messages to End Users on its own behalf through the Platform. We may suspend or terminate a Business Customer's access where we become aware of a breach of these obligations or of Meta's policies.
12.8 Retention and deletion
- Meta retains messages processed by the Cloud API for a maximum of 30 days, in accordance with its own published practice, and deletes user identifiers within 30 days of the last message status update unless directed otherwise;
- On the Platform, message content and conversation history are retained while the Business Customer's account remains active, so that the Business Customer can access their own history;
- A Business Customer may delete individual messages or entire conversations at any time from within the Platform;
- Upon disconnection of a WhatsApp Business Account, the access token is revoked and deleted immediately;
- Upon termination or closure of an account, we delete or irreversibly anonymise the associated message content and End User data within 90 days, except where retention is required by law — for example commercial and tax records — or is necessary to establish, exercise or defend a legal claim;
- Backups containing this data are overwritten on a rolling cycle and are likewise purged within the same period.
12.9 Sharing and sub-processors
In connection with Raddai we share data only with:
- Meta Platforms, Inc. — as the provider of the WhatsApp Business Platform, which is inherent to the service;
- Infrastructure and hosting providers that host the Platform, under contractual confidentiality and security obligations;
- Payment processors — for subscription billing only; message content is never shared with them;
- Courts, regulators and law enforcement — only upon a valid and lawful request, and disclosing only what that request actually requires.
We require every sub-processor to provide protections consistent with this Policy. We do not share message content with any third party for that third party's own purposes.
12.10 International data transfers
The WhatsApp Business Platform is operated by Meta on infrastructure located outside Palestine. Using Raddai therefore necessarily involves the transmission of messages to, and their processing by, Meta's infrastructure abroad. Where we or our sub-processors process data outside Palestine, we take reasonable steps to ensure that it continues to be protected to the standard described in this Policy, relying on appropriate transfer safeguards where these are applicable.
12.11 Your rights, and how to request deletion
Any Business Customer or End User may ask us to confirm what personal data we hold about them in connection with Raddai, to correct it, or to delete it.
To make a request, email info@astra.ps with enough detail to identify the data — for example the WhatsApp phone number concerned. Full step-by-step instructions are published on our Data Deletion page. We aim to respond to every request within 30 days.
Where a request concerns data that we process on behalf of a Business Customer — that is, where we act as processor rather than controller — we will promptly forward the request to that Business Customer as the responsible controller and assist them in responding to it.
12.12 Security of WhatsApp data
In addition to the safeguards described in Section 6, we apply the following specifically to the Platform: encryption of access tokens and credentials at rest; TLS encryption of all data in transit, including every call to Meta's API; role-based access control and least-privilege administration; logical separation of each Business Customer's data so that no tenant can access another's; audit logging of administrative access to message data; confidentiality obligations binding on all staff; and continuous monitoring, patching and a defined breach response and notification procedure.
12.13 Compliance with Meta's terms
Our use of the WhatsApp Business Platform is subject to, and conducted in accordance with, the Meta Platform Terms and Developer Policies, the WhatsApp Business Solution Terms, the WhatsApp Business Messaging Policy and the WhatsApp Commerce Policy. Where any conflict arises between this Policy and Meta's terms in respect of data obtained through the WhatsApp Business Platform, Meta's terms prevail.
13. Changes to This Policy
We may update this Privacy Policy as our services, our infrastructure or the applicable law changes. The revised version will be published on this page with a new "Last updated" date. Where a change materially affects how we handle your information, we will make reasonable efforts to notify you directly.
14. Contact Us
If you have a question, a request or a complaint about privacy at Astra Telecom, please contact us:
- Address: Palestine, West Bank, Hebron
- Phone: 00972 562 900 009
- Email: info@astra.ps
See also our Terms of Service, which govern your use of Astra Telecom services, and our Data Deletion instructions.