Security and data
What Atenta does with your business's and your customers' data, and what it doesn't. Site version: /seguridad. Privacy notice: /privacidad. Terms: /terminos.
Where it lives
- Your base, your conversations and your customers live on Kalia Code servers in the cloud, managed by us.
- They only pass through the third parties needed for Atenta to work: Meta (the official WhatsApp Business API, to receive and send messages) and the AI model (to write the reply).
- The payment gateway sees what it needs to charge; Atenta doesn't store cards.
How it travels
- Everything is encrypted in transit: between your browser and the app, between WhatsApp and Atenta, and between Atenta and the AI. The site and the app are served over HTTPS only, with security headers (HSTS, CSP, no
unsafe-eval). - The webhooks Atenta sends to your integrations are signed and go only to public
httpsaddresses (Integrations).
Who sees it
- You enter your app with a single-use link sent to your WhatsApp or email; there are no passwords. The session expires on its own.
- If someone on your team gets in, it's because you gave them access. Nobody else sees your conversations.
- The Kalia Code team doesn't read your conversations unless you ask us to in order to fix a problem.
- Integration tokens (MCP, API) are shown once and can be revoked from the app.
Which AI
- Atenta uses Anthropic's Claude models through their commercial API. Your conversations don't train Anthropic's or anyone's models: they're only used to reply to your customer.
- The golden rule (if it isn't in your base, it doesn't make it up; it asks you) is written in Atenta's code, not only in the instructions to the model.
How it's deleted
- A customer is deleted from your app in two steps (with the confirmation text the app dictates) and it's really gone.
- If you leave Atenta, your base is kept 30 days in case you come back and then removed. Write to us and we delete it sooner.
- Your customers can opt out of promotions in any message and it's honored.
What we don't do
- We don't sell or share your data or your customers' data.
- We don't send promotions to anyone without their recorded consent (yes + date + text).
- We don't decide for you: special quotes, exceptions and complaints are seen by a person.
- We don't use pirate apps or WhatsApp Web sessions: only Meta's official API. The number is yours.
If you find something
If you think you found a security flaw, email [email protected] with what you saw. We reply, we review it and we tell you what we did.