Data Deletion
How to remove a WhatsApp Business connection from RegFin and how to request deletion of the data tied to that connection.
01 What This Page Covers
This page explains how to remove a WhatsApp Business connection from RegFin and how to request deletion of the data tied to that connection. It applies to firms and users who have connected a WhatsApp Business number so their business conversations are archived for regulatory recordkeeping.
Meta requires this page for apps that use the WhatsApp Business Platform. For how RegFin handles data across the platform, see our Privacy Policy.
02 What RegFin Stores From a WhatsApp Business Connection
A compliance officer or advisor connects a WhatsApp Business number through Meta’s Embedded Signup flow. When you connect a number, RegFin stores two kinds of data.
Connection details
- WhatsApp Business Account ID: The identifier for the connected business account
- Phone Number ID and Display Number: The identifier and the visible phone number for the connected line
- Business Access Token: A token Meta issues for the connected account, stored with application-level encryption, that lets us receive the account’s conversations
We do not store Facebook or WhatsApp profile data from the person who signs in to authorize the connection.
Archived conversations
After the number is connected, Meta delivers the business conversations on that number to RegFin. This includes messages, images, video, documents, and edit and deletion events. RegFin archives this content on behalf of your firm as regulatory records. RegFin does not send WhatsApp messages for your firm and does not post to Meta platforms.
03 How to Remove a Connection
You can disconnect a WhatsApp Business number inside RegFin. Go to Archive Settings, open the WhatsApp section, and choose Disconnect. Only users with a compliance role can do this.
Disconnecting does three things. RegFin stops archiving new conversations from that number. RegFin deletes the stored business access token. And when no other connected number remains on the same WhatsApp Business Account, RegFin unsubscribes that account from Meta so Meta stops delivering its conversations.
The connection details for records already archived, such as the account ID and phone number, stay attached to those records. They are part of the compliance trail and cannot be removed while the records are under their retention period. See Section 5.
04 How to Request Deletion of Connection Data
If you cannot use the in-app disconnect, or you want written confirmation that connection data has been removed, email us at [email protected]. Put “Data deletion” in the subject line and include the WhatsApp Business number involved.
We respond within 30 days. Before we act on a request, we verify your identity and your authority to act for the firm that owns the connection. When the deletion is complete, we send written confirmation of the data that was deleted and the date it was deleted.
05 Archived Communications and Regulatory Retention
RegFin archives business communications so firms can meet their recordkeeping duties under SEC Rule 204-2 and Exchange Act Rule 17a-4. These records are stored in write-once storage for the firm’s retention period, which defaults to 10 years and is configurable per firm (see our Privacy Policy).
Because of these rules, archived communications cannot be deleted before the retention period ends, even on request. Disconnecting a number stops new archiving. It does not remove conversations that are already archived.
The archived records belong to the customer firm. If a request concerns archived business communications, send it to that firm’s chief compliance officer, who decides what happens to the firm’s records within the limits of these rules.
06 Contact Us
If you have questions about removing a connection or deleting connection data, please contact us.
RegFin Compliance
1905 N Sherman St, Ste 200 #2297
Denver, CO 80203