Back to home
Draft — not yet reviewed by a lawyer. Replace bracketed placeholders and confirm this meets your actual legal obligations before relying on it.

Privacy Policy

Last updated: [DATE]

1. Who We Are

[COMPANY NAME] (“we”, “us”), based in [JURISDICTION], provides an AI-powered messaging assistant (“the Service”) that businesses (“you”, our customers, referred to below as “tenants”) use to engage their own customers over WhatsApp, Instagram, and Facebook.

This policy covers two different groups of people, because the Service sits between a business and its customers: (a) you, the tenant who signs up for an account, and (b) your customers who message your WhatsApp/Instagram/Facebook number and whose messages the Service processes on your behalf. For (b), you are the data controller and we act as your data processor — see our Data Processing Agreement for the terms governing that relationship. This policy explains both roles in plain language; the DPA is the legally operative document for processor obligations.

[EU representative, if required under GDPR Art. 27: name / contact]

2. What We Collect

When you (the tenant) sign up, we collect your name, email address, company name, and password (hashed, never stored in plain text).

When your customers message your business on WhatsApp, Instagram, or Facebook, we process the content of those conversations — including text, images, voice messages, and (as of [DATE]) documents and videos — in order to generate AI replies and route them to your dashboard. We also collect the customer’s phone number or platform identifier and, where provided, their name.

We do not knowingly collect special-category data (health, religion, political opinions, etc.) by design, but since conversation content is free text written by your customers, it is possible for such data to appear incidentally within a message. We do not use it for any purpose beyond generating a relevant reply.

3. Legal Basis and How We Use It

Where GDPR applies, we (or you, as controller, for your customers’ data) rely on the following legal bases under Article 6:

  • Contract necessity — processing your account data and your customers’ messages is necessary to provide the Service you (or your business) signed up for.
  • Legitimate interests — for security, fraud/abuse prevention, and improving reliability, balanced against the data subject’s rights.
  • Consent — where a data subject has separately agreed (e.g. a customer opting in to receive WhatsApp messages from your business in the first place — that consent is between you and your customer, not something we collect directly).

Conversation content is sent to OpenAI to generate AI replies, transcribe voice messages, analyze images, and score lead quality. It is also used to power the knowledge-base search that grounds AI answers in your uploaded business documents. Account and billing data is used to operate your account, process credit purchases via Stripe, and communicate with you about your account.

4. Data Retention and Deletion

Conversation history is retained for as long as your account is active, so the AI can reference past context. After account closure, tenant data (conversations, uploaded knowledge-base documents, prospect records) is deleted within [X] days, except billing/ledger records we retain longer where required for tax, accounting, or fraud-prevention purposes.

Currently, erasure of a specific customer’s data before account closure is handled as a support request rather than a self-service dashboard control — contact us at [SUPPORT EMAIL] and we will action it manually. Self-service deletion tooling is planned; this section will be updated (and the “last updated” date above changed) once it ships.

5. Your Rights

Depending on where you (or your customers) are located, applicable law — including GDPR for EU/UK data subjects — may give you the right to:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure (“right to be forgotten”) — request deletion, subject to any legal retention obligations we have.
  • Restriction — limit how we process your data in certain circumstances.
  • Portability — receive your data in a structured, commonly used format.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — where processing is based on consent, at any time, without affecting processing already carried out.
  • Lodge a complaint — with your local data protection supervisory authority (in the EU/UK, this is the authority for your country of residence; e.g. [SUPERVISORY AUTHORITY / ICO-EQUIVALENT]).

If you are a customer of one of our tenants (i.e. you messaged a business that uses this Service), the business you contacted is the data controller for your data and is the first point of contact for exercising these rights — we act on their instructions as processor. For anything else, contact us at [SUPPORT EMAIL].

6. Who We Share It With

We share data with the following subprocessors, each bound by their own privacy and security terms:

  • OpenAI — processes message content to generate AI replies, transcriptions, and analysis.
  • Supabase — hosts our database and authentication.
  • Stripe — processes credit purchases. We never see or store your full card number.
  • Meta (WhatsApp/Instagram/Facebook) — the messaging platforms your customers use to reach you; their own privacy policies also apply to that data.

We do not sell your data or your customers’ data to third parties. See our Data Processing Agreement for the full, current subprocessor list and how we notify tenants of changes to it.

7. International Data Transfers

The subprocessors listed above operate globally, including in the United States, which does not have a GDPR adequacy decision. Where we or they transfer personal data of EU/UK data subjects outside the EEA/UK, we rely on [Standard Contractual Clauses / other approved safeguard — CONFIRM ACTUAL MECHANISM WITH EACH SUBPROCESSOR’S OWN DPA before relying on this sentence]. Copies of the relevant safeguards are available on request at [SUPPORT EMAIL].

8. Cookies

The dashboard uses only strictly necessary cookies to keep you signed in (session cookies set by our authentication provider, Supabase). We do not use advertising, tracking, or analytics cookies, and no cookie-consent banner is shown because none of our cookies require consent under applicable ePrivacy rules. If that changes in the future, this section — and a consent mechanism — will be updated first.

9. Security

Data is isolated per business account using database-level row security, so one tenant’s data is never visible to another. Passwords are hashed. Payment data is handled entirely by Stripe and never touches our servers directly.

10. Children's Privacy

The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from individuals under 16 as account holders. If a message sent to a tenant’s business number happens to come from a minor, it is handled the same as any other customer message under this policy and the tenant’s own obligations as controller.

11. Changes to This Policy

We may update this policy as the product evolves. Material changes will be communicated via email or an in-app notice.

12. Contact

Questions about this policy, or to exercise a data-subject right: [SUPPORT EMAIL].