Responsible WhatsApp messaging with Kshana API
Operational guidance for customers using templates, campaigns, inbox replies, automation flows, and the WhatsApp Business Platform through Kshana API.
Last updated: August 7, 2026
This page summarizes product controls and customer responsibilities. Official Meta and WhatsApp policies remain authoritative and may change independently of Kshana API.
Recipient permission
Before contacting a person on WhatsApp, the sending business must have the person's phone number and appropriate permission confirming that the person expects the relevant messages. The business is responsible for the opt-in method, notices, evidence, and legal basis.
Permission for one purpose does not automatically authorize unrelated marketing, calls, or another message category. Imported contacts and segments must not be treated as opted in merely because a phone number is available.
Opt-out enforcement
Businesses must honor requests to stop, block, discontinue, or opt out of communications. Kshana API records supported STOP and START consent changes and blocks campaign or automation sends where an opted-out contact must not receive the message.
Do not design an automation that continues promotional or template messaging after an opt-out acknowledgment. Re-enrollment should occur only after a clear user request or another valid consent event.
Templates and the customer service window
Business-initiated conversations must use an approved Meta message template. Free-form replies are generally limited to the customer service window following the user's latest message. Template status, category, variables, content, and purpose must remain compliant when sent.
Meta may approve, reject, pause, disable, or reclassify a template. Kshana API displays provider status but cannot guarantee template approval or continued availability.
Automation and human support
Automation may answer eligible inbound messages, evaluate conditions, update contact data, route work, and initiate handoff steps. Flows must wait for required customer input rather than treating a missing reply as a successful condition.
Customer-facing automation should identify the business accurately and provide a practical escalation route such as agent transfer, phone, email, web support, a support form, or another suitable human channel.
Data and prohibited content
Do not use WhatsApp-derived data for unrelated profiling or share one customer's conversation with another. Do not request full payment card numbers, account credentials, full government identifiers, or other sensitive data through ordinary messaging workflows.
Customers must review Meta and WhatsApp restrictions for prohibited organizations, unlawful activity, regulated goods and services, discrimination, offensive content, commerce, government use, and any country- or age-specific requirements relevant to their business.
Enforcement
Meta and WhatsApp control WABA quality, messaging limits, template review, policy enforcement, account restrictions, and appeals. Kshana API may independently pause or restrict activity that appears unsafe, unauthorized, non-compliant, or harmful to recipients or platform integrity.
