On this page
COMPLIANCE AND SECURITY
PII
Personally identifiable information (PII) is any data that can identify a specific person on its own or combined with other data: names, phone numbers, email addresses, postal addresses, government IDs, photos, and, in a messaging system, the conversation content tied to a number. Data protection laws regulate its collection, use, storage and deletion.
encryption at restgdprdpdp actrole based access
Why it matters
Everything a WhatsApp CRM holds is PII by definition. That sets the security bar (encryption, roles, audit) and the process bar (consent, retention, deletion). It also shapes what should never go into templates, broadcasts or an AI knowledge base: a customer's medical or financial details have no place in a message that thousands receive.
In VGraple CRM
PII fields are encrypted at rest with searchable blind indexes, exports and deletions are permissioned and logged, retention is configurable, and the AI features send only the conversation in question to the model provider under the DPA. The security page describes the controls in full.