1. Supported onboarding
Bodhi may support a new WhatsApp Business Platform number through Meta Embedded Signup v4 and eligible existing WhatsApp Business app numbers through official Coexistence. Where Meta’s official flow offers an access code or “Scan QR code instead”, that QR is part of Meta onboarding—not a WhatsApp Web workaround.
2. Ownership and authorisation
Only the business owner or authorised administrator may connect a WABA/number. Bodhi records asset identifiers and provider state but does not treat an entered ID as verified ownership. Channel access is isolated by tenant, owner, team and client assignment.
3. Chat and contact history
Coexistence contact/chat synchronization occurs only when offered by Meta and explicitly permitted by the business. The business must inform affected contacts where required and configure retention. Declining history sharing should not be misrepresented as a failed connection.
4. Recipient consent
Users must maintain lawful opt-in, purpose, template/category and opt-out evidence. Bodhi supports quiet hours, holidays, channel preferences and opt-out-all. Client data cannot be used for unrelated marketing without separate authority.
5. Templates and sending
Business-initiated templates require provider approval where applicable. A draft or locally scheduled message is not sent. States distinguish scheduled, skipped, template-not-approved, preview-only, sent-to-provider, delivered, read and failed.
6. Inbound attachments
Inbound files are subject to signature verification, scope, size/type validation, malware quarantine, evidence storage and retention. A chat attachment cannot silently become a posted voucher or filing.
7. AI replies
AI may classify messages and prepare replies, document requests or FAQs. Material tax/accounting advice, client consent, payment instructions and filing confirmations require human review. Bots must identify themselves where required and provide escalation.
8. Prohibited messaging
Spam, purchased lists, harassment, impersonation, misleading urgency, unauthorised bulk messaging, illegal content, credential collection and evasion of Meta limits are prohibited.
9. Provider and privacy boundary
Meta independently processes data under its terms. Bodhi stores provider IDs/events needed for workflow and audit. Provider credentials remain server-side and are encrypted where configured. Actual Meta assets are currently NOT_CONFIGURED until verified.
10. Complaints
Recipients can opt out through supported channels. Users must act promptly. Grievance contact: .