1. Parties involved and privacy roles
TURINGLAB SOCIETA' A RESPONSABILITA' LIMITATA SEMPLIFICATA, with registered office in Catanzaro, Via Lucrezia Della Valle snc, c/o Le Aquile Business Center, VAT no. IT04036580795, operates the Meta application and the Studio Pro/VisitaPro platform.
For client or patient data and conversation content, each professional or practice determines the purposes, legal bases, and retention periods and generally acts as an independent controller. TuringLab processes this data to provide the service under the practice’s instructions and the applicable agreements, generally as a processor. TuringLab acts as controller for the data needed to manage its own accounts, contractual relationship, security, support, and integration onboarding.
2. How the integration works
TuringLab uses its own Meta application to connect multiple independent practices to the WhatsApp Business Platform. Each practice authorizes the connection of its own WhatsApp Business Account and business number. The same technical application can serve multiple practices, but settings, permissions, and conversations are segregated by practice and are not made available to other practices.
Incoming messages and related updates are received through Meta webhooks; replies requested by the practice are sent through the Graph API. The portal can display the conversation, associate the contact with a patient, download attachments, record delivery status, and send manual replies from an authorized, unlocked browser. Delayed automatic replies are disabled so that the practice private key or a reversibly stored contact number is not made available to the server.
3. Categories of data processed
- Practice and integration data: name, authorized users, Business Portfolio, WhatsApp Business Account (WABA) and phone number identifiers, displayed number, permissions, tokens, and configuration status.
- Contact data: WhatsApp number or identifier (wa_id), profile name made available by WhatsApp, and any association with a patient registered by the practice.
- Communication data: text, images, audio, video, documents, stickers and other attachments, date and time, direction, message identifier, origin, sending, delivery or read status, and any errors.
- Technical and security data: webhook payloads, signatures and technical checks, application events, logs, session information, and data needed to diagnose faults or prevent abuse.
4. Health-related content and practice responsibilities
Because the service is also intended for healthcare professionals, a conversation may contain health data or other special categories of data. The practice must limit information to what is necessary, provide its own notice to data subjects, and identify a valid legal basis under Articles 6 and 9 GDPR. Clients or patients must not use WhatsApp for medical emergencies.
TuringLab does not use data obtained through WhatsApp for advertising, commercial profiling, or profile enrichment, does not sell it, and does not make it available to other practices. Data is used only to provide the requested messaging features, protect the service, and comply with applicable obligations.
5. Purposes and legal bases
Processing enables the Meta connection to be activated and administered, messages to be received and displayed, practice-selected replies to be sent, attachments and statuses to be managed, conversations and patients to be associated, support to be provided, security and continuity to be maintained, and legal obligations to be met.
Where TuringLab is controller, the legal bases are performance of a contract or pre-contractual steps, legal obligations, and the legitimate interest in service security and proper operation. For data processed on behalf of the practice, purposes and legal bases are determined by the practice; authorization granted through Meta technically enables the integration but does not replace the legal basis required by the GDPR.
6. Recipients, Meta, and transfers
Data is accessible to authorized practice users and, where necessary, to authorized TuringLab personnel bound by confidentiality. It may be processed by hosting, database, storage, email, support, and security providers. Meta Platforms Ireland Limited and/or the other entities identified in the applicable terms provide WhatsApp and the WhatsApp Business Platform and process data under their own terms and notices.
Some providers may process data outside the European Economic Area. Where applicable, transfers rely on adequacy decisions, standard contractual clauses, or other safeguards recognized by law.
7. Security and encryption
The integration uses HTTPS connections, webhook signature verification, authorization checks, and logical segregation by practice. Meta tokens and technical secrets are encrypted at rest with AES-256-GCM using a dedicated server key, are not returned by the APIs, and are shown only as masked values. The verification token is stored as an HMAC.
Conversation text, names, contact numbers, and related attachments are encrypted at rest with RSA-OAEP-256 and AES-256-GCM using the practice public key. The database and storage retain ciphertext only; decryption occurs in the unlocked browser. Contact data used for lookup and matching is replaced by a separate per-practice HMAC. Plaintext necessarily exists only for the technical duration of a Graph API call or receipt of a Meta webhook, without being persisted or logged. Meta continues to process messages on its own systems.
8. Retention
Configuration data is retained while the integration remains active or as needed to manage the relationship. In the Privacy and Compliance center, the practice manager can configure retention for WhatsApp conversations and attachments, SMS, completed notifications, handled public requests, and audit logs, preview eligible records, and run deletion. Clinical records and tax documents are not deleted by generic time limits: erasure requires a data-subject case and a review of legal obligations. Backups follow a separate expiry and secure-deletion procedure.
WhatsApp and Meta independently apply the retention periods described in their own terms and notices for data processed on their systems.
9. Revoking access and deleting data
An authorized practice owner or administrator can disable the integration in Studio Pro/VisitaPro, revoke the application’s permissions in Meta Business settings, and ask TuringLab to delete the associated data. Requests must be sent to visitapro.support@turing-lab.it and include the practice name, WhatsApp Business number, and, where available, the WABA ID and Studio Pro account ID. Do not send tokens, passwords, or copies of conversations.
After verifying the requester’s identity and authority, TuringLab disables credentials and stops new data flows, then deletes or returns data under the practice’s instructions and the applicable agreements, except where retention is required for law, security, abuse prevention, backups, or the protection of rights. Revoking access only through Meta stops new access but does not automatically delete data already stored in the portal.
A client or patient wishing to exercise rights over messages should first contact the practice with which they communicated, as that practice can identify the conversation and instruct TuringLab.
10. Rights, complaints, and updates
Where Articles 15-22 GDPR apply, data subjects may request access, rectification, erasure, restriction, portability, and objection and may withdraw consent where processing relies on it. They also have the right to lodge a complaint with the competent supervisory authority. Requests concerning data processed directly by TuringLab may be sent to the contact listed on this page.
This notice may be updated when features, providers, or legal requirements change. The current version is the one published at this address with its update date.