MORFX S.A.S.

Data Deletion Instructions

Last updated: July 27, 2026

This page explains, in plain language, how to ask MORFX S.A.S. to delete personal data — and what happens after you ask. It is the Data Deletion Instructions page we declare for our Meta apps, and it is also our standing procedure for anyone exercising the right to erasure under the EU General Data Protection Regulation (GDPR), Colombian Law 1581 of 2012 and Decree 1377 of 2013. There is no account to create, no form to fill in and no fee: a single email or WhatsApp message starts the process.

About this page

MORFX S.A.S. operates a customer-relationship platform that businesses use to talk to their customers over WhatsApp, Facebook Messenger and Instagram. Because we handle personal data on behalf of those businesses — and some personal data of our own — we publish one public procedure for deleting it, rather than leaving it to be negotiated case by case.

This page is the "Data Deletion Instructions URL" we declare in the Meta App Dashboard. The Meta Platform Terms require developers to "provide the User a clear and easily accessible way to request modification or deletion" of Platform Data (section 3.d.i.1), and to explain "how Users can request deletion of that data. The right to request deletion must be provided to all Users" (section 4.b). What follows is that explanation.

It is written to satisfy, at the same time:

  • Regulation (EU) 2016/679 (GDPR) — Articles 12, 17 and 19.
  • Meta Platform Terms — sections 3.d.i and 4.b.
  • Colombia — Ley 1581 de 2012 (Habeas Data) and Decreto 1377 de 2013, article 13.
  • Colombia — Estatuto Tributario article 632, which limits what we are permitted to delete.

Plain language is the point

GDPR Article 12(1) requires information of this kind to be given "in a concise, transparent, intelligible and easily accessible form, using clear and plain language". We have tried to do that rather than hide the procedure inside legal boilerplate. If any part of this page is unclear, write to us and we will explain it.

— ❦ —

Who we are and what role we play

MORFX S.A.S., NIT 902.052.328-5, is a Colombian company domiciled at Carrera 38 # 42 - 17, Apartamento 1601B, Bucaramanga, Santander, Colombia. Email: morfx.colombia@gmail.com. Phone and WhatsApp: +57 313 754 9286.

Which role we play depends on whose data it is, and that determines who you should approach first:

  • Your data as an administrator of a MorfX workspace — the person who signed up, configured the agents and receives our invoices. Here MORFX is the data controller. Ask us directly.
  • Your data as a consumer who messaged a business through WhatsApp, Facebook Messenger or Instagram. Here the business you were talking to is the data controller, and MORFX is only its data processor: we hold that data on the business's instructions. Ask the business first; we step in if you cannot reach it.
  • Your data as a visitor to morfx.app — server access logs and any analytics or cookie identifiers. Here MORFX is again the data controller. Ask us directly.

Why the distinction matters to you

This split is not a way of passing you from one door to another. It is how the law allocates responsibility, and it is set out in more detail in section 7 of our Privacy Policy. Whichever route applies to you, we commit to answering — including when the answer is that another party has to make the decision, in which case we will tell you who they are and how to reach them.

— ❦ —

Who is this page for?

Find yourself in one of the three groups below, then go straight to the section that matches. If more than one applies to you — for example, you run a business on MorfX and you have also chatted as a customer with another business that uses it — send a separate request for each.

  • (a) End consumer — you sent or received messages from a business through WhatsApp, Facebook Messenger or Instagram, and that business runs on MorfX. Go to section 6.
  • (b) Administrator user — you have, or had, an account on the MorfX platform for your own business. Go to section 5.
  • (c) Site visitor — you browsed morfx.app or wrote to us through the site, without ever creating an account. Go to section 7.
— ❦ —

Your rights

Under GDPR Article 17(1), you have "the right to obtain from the controller the erasure of personal data concerning him or her without undue delay", and the controller has "the obligation to erase personal data without undue delay", where one of the following grounds applies:

  • (a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
  • (b) the data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing;
  • (c) the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);
  • (d) the personal data have been unlawfully processed;
  • (e) the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;
  • (f) the personal data have been collected in relation to the offer of information society services referred to in Article 8(1).

If you are in Colombia

Colombian Law 1581 of 2012 gives you an equivalent and in some respects broader set of rights — the derechos ARCO: to know, update and rectify your data; to ask for proof of the authorization you gave; to be told how your data has been used; to complain to the Superintendencia de Industria y Comercio; to revoke your authorization and request suppression; and to access your data free of charge. The Spanish version of this page quotes article 8 of that law in full, and article 9 adds the right to withdraw the authorization you granted.

Two clarifications that save time

Withdrawing consent and deleting data are not the same request. If what you actually want is for the messages to stop, say so — we or the business will stop contacting you, which is faster and leaves your history intact.

Deletion is irreversible. Once a conversation history is erased we cannot restore it, and neither can the business you were talking to. If you may need a record of what was agreed — an order, a quote, an appointment — save it before you ask.

— ❦ —

How to request deletion — administrator user

This is the route for people who hold, or held, an account on the MorfX platform. It has four steps.

Step 1 — Send the request

Email morfx.colombia@gmail.com from the address registered on your MorfX account, with the subject line "Data deletion request". Writing from the registered address is itself the first layer of identity verification, which is why we ask for it.

Step 2 — Tell us what to delete

Include the following, so that we can find the right records and act on them without ambiguity:

  • The name of your workspace as it appears in the platform.
  • The email address of the account holder.
  • Whether you want the entire workspace deleted, or only your own administrator profile.
  • The sentence: "I authorize the deletion of the personal data associated with my MorfX account."

Step 3 — We confirm receipt and verify your identity

We reply within two business days to confirm that the request arrived. If we have reasonable doubts about who is asking — for instance, the request comes from an address that is not the registered one — GDPR Article 12(6) permits us to request additional information to confirm your identity, and we will. We do not delete anything on an unverified first message.

If your workspace has other administrators, deleting the whole workspace also removes their access and the end-consumer data your business keeps there. We will point this out before proceeding and ask you to confirm a second time.

Step 4 — We delete, and we tell you what we kept

Deletion completes within 30 days of a verified request. We then send you written confirmation setting out what was erased, what was retained under section 9 and on what legal basis, and the date on which the retained data becomes deletable.

— ❦ —

How to request deletion — end consumer

If you exchanged messages with a business over WhatsApp, Facebook Messenger or Instagram and that business runs on MorfX, it is the business — not MORFX — that decides what happens to your data, because it is the data controller. That is why the first route below is the right one. The second exists so that you are never left without an answer.

Primary route — ask the business you talked to

Contact the business directly, through the same channel you used to talk to it or through the contact details on its website, and ask it to delete your personal data. The business obtained your authorization, it decides the purposes, and it can instruct us to erase your record. Under Colombian law this step is also a precondition for escalating to the regulator — see section 11.

Fallback route — write to us

If you cannot identify or reach the business, or it does not answer within the deadlines in section 8, write to us on WhatsApp at +57 313 754 9286, or by email to morfx.colombia@gmail.com with the subject "Data deletion request". Include:

  • Your full name.
  • The phone number or social media account you used to talk to the business.
  • The name of the business, or anything that identifies it — the product you asked about, the page you wrote to.
  • Roughly when the last conversation took place.

How we verify that it is you

We match the phone number or account you write from against the conversation records, and we check the details you give us — the business, the approximate date of the last interaction — against what we hold. If they do not line up, we will ask you for more information rather than delete someone else's data by mistake.

What we do next

As the business's data processor, we notify it that you have requested erasure and we coordinate the deletion with it. We confirm receipt to you within two business days and tell you the outcome within the applicable deadline in section 8. If the business instructs us not to delete, we will say so plainly and give you its contact details so you can pursue the matter with the controller, or escalate as described in section 11.

— ❦ —

How to request deletion — site visitor

This route is for people who only visited morfx.app — no account, and no conversation with a business through our platform. The data involved is limited: server access logs, and any analytics or cookie identifiers your browser sent us.

Email morfx.colombia@gmail.com with the subject "Data deletion request — site visitor" and include whatever you can:

  • The approximate date or dates on which you visited the site.
  • The IP address you used, if you know it.
  • Your browser and operating system.
  • Any email address or phone number you gave us through a contact form.

What to expect

Because this data is not tied to an account, an exact match is not always possible. We will delete everything we can attribute to you, and we will tell you honestly if we cannot isolate a record rather than claim a deletion we did not perform. Deletion completes within 30 days.

— ❦ —

Response timelines

The clock starts when we receive a complete request from a verified requester. If we have to ask you for more information, the time we spend waiting for your reply does not run against us — but we will not use verification as a way of stalling.

  • Acknowledgement of receipt — two business days, in every case.
  • GDPR, Article 12(3) — the controller shall provide information on action taken "without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests." We commit to the one-month figure, and will invoke the extension only in genuinely complex cases, telling you why and when.
  • Colombia, consulta — a question about what data we hold and how we have used it: ten (10) business days, extendable by five (5) further business days, under article 14 of Ley 1581 de 2012.
  • Colombia, reclamo — a request to correct, update or delete, which is what this page is about: fifteen (15) business days, extendable by eight (8) further business days, under article 15 of Ley 1581 de 2012.
  • Incomplete requests — article 15 of Ley 1581 de 2012 requires us to ask you to complete the request within five (5) days of receiving it; the deadline then runs from the complete request.
  • Where two regimes both apply to you, we apply whichever deadline is shorter.
— ❦ —

Exceptions to deletion

We will not always be able to erase everything, and we would rather tell you that here than after you have asked. Two exceptions apply in practice.

  • Tax and accounting records. Article 632 of the Colombian Estatuto Tributario requires invoices and their supporting documents to be kept for five years, in conditions that guarantee their consultation, integrity and authenticity. Personal data contained in an invoice we issued — name, tax identification number, address — therefore cannot be deleted until that period has run. Under the GDPR this falls squarely within Article 17(3)(b), which disapplies the right to erasure where processing is necessary "for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject".
  • Records needed to defend a legal claim. Where data is necessary "for the establishment, exercise or defence of legal claims" — GDPR Article 17(3)(e) — for example an open dispute over a payment or a fraud investigation, we keep the minimum necessary until the matter is closed, and delete it afterwards.

What we do when an exception applies

Three things. We delete everything that the exception does not cover. We tell you exactly what we kept and on what legal basis. And we tell you the date on which the retained data becomes deletable, so the retention has a visible end.

Retained data stays restricted to the purpose that justified keeping it. We do not carry on using it for anything else — no messaging, no analytics, no model training.

— ❦ —

How we propagate deletion to sub-processors

Your data does not sit in a single place. To run the service we rely on a set of specialised providers, and a deletion that stopped at our own database would be worth very little. GDPR Article 19 requires the controller to "communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort", and to inform the data subject about those recipients if they ask.

We honour that across the following providers:

  • Supabase — database, authentication and file storage.
  • Vercel — application hosting, edge network and server logs.
  • Anthropic — large language models used by the conversational agents.
  • OpenAI — large language models used by the conversational agents.
  • Google AI — language, vision and speech models used by the conversational agents.
  • Meta — WhatsApp Business Platform, Facebook Messenger and Instagram messaging.
  • Inngest — background job and workflow execution.
  • Onurix — SMS delivery.

Two honest caveats

Some of these providers are themselves controllers of the data you gave them through their own channels. Meta in particular holds your WhatsApp, Messenger or Instagram messages under its own terms: deleting your record with us does not delete your account or your message history with Meta, and for that you have to use Meta's own tools. We will point you to them if you ask.

Where erasure at a sub-processor is technically impossible or would involve disproportionate effort — for example, data already absorbed into a provider's aggregated, non-identifying operational logs — we will tell you so and explain what we did instead. We would rather report the limit than imply a deletion that did not happen.

If you want the full, current list of the recipients to whom your specific data was disclosed, ask us and we will provide it.

— ❦ —

Authority of control and escalation

If you are not satisfied with how we handled your request, you can escalate it. In Colombia the competent authority is the Superintendencia de Industria y Comercio (SIC), through its Delegatura para la Protección de Datos Personales.

One condition applies first. Article 16 of Ley 1581 de 2012 provides that the data subject or their successor may only file a complaint with the Superintendencia de Industria y Comercio once they have exhausted the consulta or reclamo procedure before the data controller or the data processor. In practice: write to us — or to the business, where the business is the controller — wait for the deadline in section 8 to pass, and only then go to the SIC. A complaint filed before that will be rejected for failing this requirement.

The SIC's contact details are:

  • Superintendencia de Industria y Comercio — Delegatura para la Protección de Datos Personales.
  • Address: Carrera 13 N°. 27-00, Bogotá D.C., Colombia — postal code 110311.
  • Switchboard: (601) 587 0000.
  • Service line: (601) 592 0400.
  • Toll-free national line: 01 8000 910165.
  • Email: contactenos@sic.gov.co — use the subject "Queja por Protección de Datos Personales".
  • Online: sedeelectronica.sic.gov.co

If you are in the European Union or the United Kingdom

You may also lodge a complaint with the supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement, as GDPR Article 77 provides. Doing so does not require you to go through the SIC first.

— ❦ —

Effective date, governing law, and disputes

This page takes effect on July 27, 2026 and replaces any previous deletion instructions. We keep it current: if the procedure, the contact channels or the list of sub-processors change, we update this page and the "last updated" date shown at the top. Requests are handled under the version in force on the day we receive them.

This procedure is governed by the laws of the Republic of Colombia. Any dispute arising from it is subject to the courts of Bucaramanga, Santander, Colombia, consistent with the jurisdiction clause in our Terms of Service. Nothing on this page limits any mandatory right you hold under the data protection law of your own country of residence, including the right to complain to your local supervisory authority.

This page complements, and does not replace, our Privacy Policy and our Terms of Service. Where those documents and this one genuinely conflict on the procedure for deleting data, this page prevails.