Data Deletion Instructions
For end-customers, Vendors, and any natural person whose personal data Unisay may hold.
Unisay (operated by AnnFar Global (Pvt) Ltd, a company incorporated in Sri Lanka) processes personal data on behalf of Vendors — small businesses in Sri Lanka using our platform to manage WhatsApp Business, Instagram Direct, and Facebook Messenger conversations. This page explains how to request deletion of your data. It also describes how Unisay honours deletion requests that reach us through Meta’s Data Deletion Callback protocol.
Which route to use
Choose the route that matches how you interacted with Unisay:
- You are a Customer — you messaged a business on WhatsApp, Instagram, or Facebook Messenger and that business uses Unisay behind the scenes to manage its conversations. Use Route A.
- You are a Vendor — you (or your business) created a Unisay account. Use Route B.
- You revoked Unisay from your Meta account (Facebook, Instagram, or WhatsApp Business settings → Apps and Websites). Meta has already told us. See Route C for how to track it.
Route A · You are a Customer of a business that uses Unisay
Because Unisay processes your data as a Processor on behalf of the Vendor business, your first point of contact is the business you were messaging. Please contact them directly. Under the Personal Data Protection Act, No. 9 of 2022 (Sri Lanka), the Vendor is the Controller of your data and is legally required to respond to your deletion request within one month.
If the Vendor does not respond within the statutory timeframe, or if you cannot identify the Vendor, email us at dpo@unisay.ai with:
- The name or WhatsApp phone number of the business you were messaging.
- Your own contact identifier on that channel — your WhatsApp phone number in E.164 format (e.g.
+94771234567), your Instagram handle, or your Facebook Messenger conversation link. - A brief description of the data you want deleted (or “all”).
We will forward the request to the Vendor, ask them to action it, and delete the data from our systems within 30 calendar days of the Vendor’s instruction (or of our escalation if the Vendor does not respond), subject to the tax- record retention obligations described in the Privacy Policy §9.
Route B · You are a Vendor
You can export and delete your data yourself from within the Unisay dashboard:
- Export first (recommended). Settings → Account → Export my data downloads a machine-readable JSON archive of your account and Customer data.
- Then delete. Settings → Account → Close account starts the deletion workflow. You have a 30-day export window after closure, then we delete your data within a further 60 days, subject to the tax-record and audit retention rules in the Privacy Policy §9.
If you would prefer we action the deletion for you, email dpo@unisay.ai from the address on your account. We will verify ownership and confirm the deletion in writing.
Route C · You revoked Unisay from your Meta account
When you remove Unisay from Facebook, Instagram, or WhatsApp Business settings, Meta sends us a signed Data Deletion Request. Our system:
- Verifies Meta’s signature on the incoming callback at
https://api.unisay.ai/api/legal/data-deletion-callback. - Immediately revokes any Meta access tokens we hold for your account and clears the associated Meta connection.
- Returns a confirmation code to Meta so you can look up the status of the deletion.
- Asynchronously deletes the personal data associated with the affected Meta user id across all Vendor tenants Unisay was acting on.
To look up the status of a request — copy the confirmation code from Meta’s notification and open https://api.unisay.ai/api/legal/data-deletion-status (add ?code=<your-code>). You’ll see a plain-HTML status page confirming whether the request is PENDING, IN_PROGRESS, or COMPLETED.
What gets deleted
- Your name, phone number, address, and other contact details on file.
- Your conversation content across WhatsApp Business, Instagram Direct, and Facebook Messenger.
- Your Instagram-Scoped ID, Page-Scoped ID, and WhatsApp profile id.
- Order history, delivery details, and any credit account state we hold about you.
- Meta access tokens, per-Page access tokens, and webhook secrets tied to your Meta connection.
What we are legally required to retain
Under Sri Lankan law we must keep certain records even after a deletion request. Where this applies, we anonymise or pseudonymise the retained records so they are no longer linked to your identity in the operational database:
- Tax records — invoices, tax invoices, and their line items must be retained for 5 years from the end of the relevant taxable period under Inland Revenue Act, No. 24 of 2017 §123.
- Audit logs of financial mutations — retained for 5 years for the same reason.
- Backup snapshots — expire on the standard 30-day sub-processor rotation.
- Aggregated analytics that do not identify any data subject.
Response timeline
We respond to verified rights requests without undue delay and in any event within one (1) month of receipt. Where the request is complex or we receive multiple related requests, we may extend the period by a further two (2) months — totalling no more than three months — and will notify you of the extension within the first month.
If we cannot help
If we do not resolve your request to your satisfaction, you have the right to lodge a complaint with the Data Protection Authority of Sri Lanka at https://www.dpa.gov.lk/.
Contact
AnnFar Global (Pvt) Ltd (trading as Unisay)
Data Protection Officer — dpo@unisay.ai
22/4, Peterson Tower, Havelock City, Havelock Road, Colombo 05, Sri Lanka