Security Policies
Technical and organizational measures that protect your data.
Last updated: August 11, 2026
At Isa Pankei Group, SRL we take all reasonable measures to protect the information of our business customers and their end customers. We follow recognized industry practices so that information is not misused, altered, disclosed or destroyed.
1. Secure transmission
All communication between your browser and our servers is encrypted with TLS 1.2 or higher. Certificates renew automatically and we enforce HTTPS across every site and portal route.
2. Storage and encryption
- WhatsApp Business access tokens and other credentials are stored encrypted.
- Passwords are never stored in plain text; we use salted derivation functions.
- We collect only the minimum information needed to provide the service.
- Backups are encrypted and kept under the same protection as production data.
3. Access control
- Mandatory authentication for all access to the administration portal.
- Per-business roles and permissions, under the least-privilege principle.
- Logical isolation: each business can only read and write its own data.
- Our staff's access to production data is restricted, justified and logged.
4. Monitoring and auditing
- Audit logs for sign-ins, configuration changes and sensitive actions.
- Monitoring of message delivery events and integration errors.
- Alerts on anomalous usage patterns or unauthorized access attempts.
5. Payments
When a business enables online payments, those payments are processed by certified third parties. We do not store CVV codes or full card credentials. Processors comply with the PCI-DSS standard and, where applicable, apply 3D Secure authentication (Verified by Visa, Mastercard ID Check).
We recommend also reviewing the payment provider's privacy and security policies.
6. Incident management
We maintain an incident response procedure covering containment, investigation, remediation and communication. If an incident affects a business customer's personal data, we notify them without undue delay with the available information about scope and measures taken.
7. Recommendations for your business
- Use unique, strong passwords and enable two-step verification where available.
- Give each team member only the role they need, and revoke access when they leave.
- Check that the URL is correct before entering credentials.
- Never share tokens, passwords or verification codes over WhatsApp, phone or social media.
- Report suspicious activity immediately to hola@waffledo.com.
8. Vulnerability reporting
If you find a possible vulnerability, write to hola@waffledo.com with the subject "Simple Restaurant Security". Please do not disclose the finding publicly until we can fix it. We appreciate and acknowledge responsible reports.
Contact Information
- Legal entity:
- Isa Pankei Group, SRL
- RNC:
- 131998151
- Email:
- hola@waffledo.com
- Phone / WhatsApp:
- 1 809-752-0045
- Address:
- Máximo Avilés Blonda 13, 102, Plaza Las Lilas, Ens. Julieta, D.N., Santo Domingo, República Dominicana
- Support hours:
- Monday to Friday, 9:00 AM - 6:00 PM (GMT-4)