Legal
Privacy policy
This policy explains what Wasoli collects, why, and what happens to it — for the operators who run the software, for the subscriber data those operators upload, and for the Android and iOS apps their staff carry in the field.
Last updated: 21 August 2026
Who we are
Wasoli is billing, collection and recovery software for internet and cable service providers. Each operator that signs up gets a private instance and a private database at their own address, in the form yourcompany.wasoli.net.
For anything in this policy — a question, a correction, or a request about your data — write to hello@wasoli.net. That is our one contact address and it reaches a person.
Controller vs. processor
This is the single most important distinction in this policy, because it decides who you should ask.
For an operator's own account — the business details, billing relationship, and the logins the operator's staff use to reach Wasoli — Wasoli is the data controller. We decide why that data is collected and how it is used, and this policy is our account of that.
For an operator's subscribers — the names, addresses, phone numbers, packages, bills and payments an operator loads into their own instance — the operator is the data controller and Wasoli is the data processor. The operator decides what subscriber data to hold and what it is used for. We host it, keep it available, and do not use it for our own purposes. If you are a subscriber of an internet or cable operator who uses Wasoli, your relationship is with that operator, not with us — seewhat we process on an operator's behalf below.
What we collect from operators
When a business signs up to run Wasoli, we collect, as the controller:
- Account and company details: business name, address, and the contact person we deal with
- Contact information: email address and phone number for the account holder and any staff added to the account
- Billing information needed to invoice the operator for their Wasoli subscription
- Support correspondence: anything sent to hello@wasoli.net, and records of calls or messages made to resolve an issue
- Authentication data: usernames and passwords for the web panel, stored as bcrypt hashes — never as plain text
- Server logs: request timestamps, the page or endpoint requested, IP address, and user agent, kept for security and fault diagnosis
What we process on an operator's behalf
An operator's own instance holds the records they run their business on. That is their data, and we process it only to provide the service — never for our own purposes, never to build profiles, and never to sell or share it. It typically includes:
- Subscriber records: names, addresses, phone numbers, and the packages they are billed on
- Bills, receipts and payment history
- Complaint tickets raised against a connection
- Message logs — the SMS templates an operator sends and when they were sent
- Dealer and staff records the operator maintains
We do not read, export or use this data except to keep the operator's instance running, to fix a fault they report, or where the operator asks us to for support. An operator's subscriber is not a Wasoli account holder and does not interact with us directly.
The mobile apps
Wasoli publishes a companion admin app for Android and iOS, used by an operator's own field and office staff — not by the operator's subscribers. The app is a lookup tool: it lets staff check the collection ledger, defaulters, a subscriber's bill history, message logs, and area, package and dealer lookups while they are away from a desk. As shipped today, the app reads this data; it does not post payments or make other changes — those actions stay in the web panel.
The app, on both platforms:
- Accesses the network, to sign in and to fetch the ledger data listed above
- Authenticates against the operator's own instance, using the same staff login the operator issued — there is no shared Wasoli account and no pool of data behind multiple operators
- Transmits data over HTTPS to that operator's instance only. It never sends data to a third party or to a Wasoli-run server that mixes operators together
- May write a report to device storage if a staff member chooses to save one, and nowhere else
The app does not collect advertising identifiers, does not include analytics or tracking SDKs, and does not track a device's location — in the background or otherwise.
Permissions
The app asks for the following device permissions, and no others:
- Network access — required to sign in and load ledger data from the operator's instance. Without it the app cannot function.
- Storage — requested only at the moment a staff member chooses to save a report to the device. If you never save a report, this permission is never used.
The app does not request location, contacts, camera, microphone or SMS permissions. It does not track your location in the background, and it does not sell data of any kind, to anyone.
Data safety at a glance
A short mapping of what the mobile apps handle, for Google Play's Data safety section and Apple's App privacy label:
| Data type | Purpose | Shared with third parties |
|---|---|---|
| Staff login credentials | Authenticate to the operator's own instance | No |
| Subscriber ledger data (bills, receipts, balances) | Display collection, defaulter and bill-history views to staff | No |
| Message logs | Show what was sent to a subscriber, and when | No |
| Area, package and dealer lookups | Populate filters and reference lists in the app | No |
| App diagnostics (crash and error logs) | Diagnose and fix faults in the app | No |
None of this data is used for advertising, and none of it is sold. All of it stays within the operator's own instance and the app's connection to it.
Legal bases for processing
We process personal data on these bases:
- Contract — to provide the service an operator has signed up for, including running their instance and billing their subscription
- Legitimate interests — to keep the service secure, diagnose faults, and maintain server logs, in each case weighed against the individual's interests
- Legal obligation — where we must keep a record, such as a financial or tax record, for a set period
- Consent — for anything not covered by the above, such as marketing correspondence, which an operator can withdraw at any time
Where Wasoli acts as a processor for an operator's subscriber data, the legal basis for collecting and using that data is decided by the operator, as controller, not by us.
Sub-processors and hosting
We keep the number of parties who can see any data to a minimum, and we do not name vendors here because the categories below can change without changing what they do:
- A server hosting provider, which runs the physical or virtual machine an operator's instance and database live on
- A certificate authority, which issues the TLS certificate that secures traffic to each operator's address
- An email delivery service, used only to send account, support and notification email — never marketing lists bought or shared with anyone else
None of these parties are given access to operator or subscriber data beyond what is required to perform their specific function, and none of them are permitted to use it for their own purposes.
Retention
We keep operator account data for as long as the account is active, plus a limited period afterwards to handle billing queries and legal obligations.
If an operator's agreement with Wasoli ends, their instance and database — including all subscriber data it holds — is deleted within 30 days of termination, except for records we are required to keep for a longer statutory period, such as financial records for tax purposes. An operator can also request earlier deletion; see our data deletion page for how.
Server logs are kept for a limited window for security purposes and then discarded.
Security measures
We take a small number of concrete, specific measures rather than a long list of promises:
- Web panel passwords are stored as bcrypt hashes — never in plain text, and never reversible
- All traffic to the web panel, the mobile apps, and every operator address is served over HTTPS, with a TLS certificate issued to that address
- Each operator's data lives in a separate database, on a separate process, at their own address — one operator's instance cannot read another's
- Access to production systems is limited to the people who need it to operate the service
We do not hold a formal security certification, and this policy does not claim one. What we do is described above, plainly, so you can judge it on its own terms.
Your rights
Depending on where you are, you may have the right to ask what personal data we hold about you, to have it corrected, to have it deleted, to receive a copy of it, or to object to certain processing. To exercise any of these for your operator account data, write to hello@wasoli.net.
If your data is held as part of an operator's subscriber records — for example, you are a subscriber of an internet or cable provider that uses Wasoli — that operator is the controller of your data and is who you should contact first. See our data deletion page for the full route, including what we do if the operator cannot be reached.
Children
Wasoli is a business tool for ISP and cable operators and their staff. It is not directed at children, and we do not knowingly collect personal data from children through the service or the mobile apps.
International transfers
Wasoli is operated for operators based in Pakistan. Where data is processed or stored outside the country an operator is based in — for example because a hosting or email sub-processor operates infrastructure elsewhere — we take reasonable steps to keep it protected to the standard described in this policy, wherever it sits.
Changes to this policy
We may update this policy as the service changes. If a change is material, we will tell active operators by email before it takes effect. The date at the top of this page always reflects the version in force.
This policy is effective from 21 August 2026.
How to complain
If you are unhappy with how we have handled your data, write tohello@wasoli.net first, so we can look into it directly. If you are not satisfied with our response, you may also have the right to lodge a complaint with the data protection authority in your own jurisdiction.