Privacy Policy
How We Collect, Use, and Protect Your Personal Information
Last updated: December 28, 2025
Table of Contents
Data Collection and Legal Basis
Legal Basis for Processing
We collect and process your personal data based on the following legal foundations:
- Consent: Where you have voluntarily provided personal data and explicitly consented to its processing
- Contractual Necessity: To fulfill our contractual obligations and service agreements with you
- Legal Obligation: Where required by applicable law or to comply with judicial authorities
- Legitimate Interest: For internal business operations, security, fraud prevention, and service improvement
Categories of Data We Collect
Information You Provide Directly
- Account Information: Full name, email address, phone number, and company information
- Profile Information: Additional details you choose to include in your profile
- Communication Data: Information through support requests, surveys, and feedback
- Payment Information: Billing addresses and transaction details (processed securely through Stripe)
Information Collected Automatically
- Device Information: Device type, operating system, and unique identifiers
- Log Data: IP addresses, browser type, pages viewed, and access times
- Usage Data: Interactions with our Services, feature utilization, and behavioral patterns
- Location Data: General geographic location based on IP address
WhatsApp Business Integration
Powered by Meta (Facebook) WhatsApp Business API
How We Use WhatsApp Business
Our platform integrates with Meta's WhatsApp Business API to enable automated customer communication for our clients. This integration allows businesses to manage conversations, provide customer support, and automate responses through WhatsApp.
WhatsApp Data We Collect
- Phone Numbers: WhatsApp phone numbers of your customers and business accounts
- Message Content: Text messages, emojis, and conversation content sent through WhatsApp
- Media Files: Images, videos, documents, and audio files shared in conversations
- Metadata: Message timestamps, delivery status, read receipts, and conversation metrics
- Business Profile Data: Business name, description, and profile information
How We Use WhatsApp Data
- Conversation Management: Store and display WhatsApp conversations in your dashboard
- AI-Powered Responses: Analyze messages to generate automated, context-aware responses
- Analytics and Insights: Provide conversation metrics, response times, and engagement statistics
- Compliance and Quality: Monitor conversations for compliance with WhatsApp Business policies
- Customer Support: Enable your support team to respond to customer inquiries
Data Sharing with Meta (Facebook)
When you connect your WhatsApp Business account, certain data is shared with and processed by Meta:
Important: Meta processes WhatsApp Business data according to their own WhatsApp Business Policy and Meta Privacy Policy.
Your Control Over WhatsApp Data
As a SaaS platform, we respect that you (our clients) maintain ownership and control over your WhatsApp data:
- Data Ownership: You own all conversations and customer data from your WhatsApp Business account
- Access Control: You can manage which team members have access to WhatsApp conversations
- Data Export: Export your WhatsApp conversation history at any time
- Disconnect Anytime: You can disconnect your WhatsApp account from our platform at any time
Important Notice for End Users: If you are a customer communicating with a business through WhatsApp, please note that the business (our client) controls their WhatsApp account. We process messages on their behalf as a service provider. For questions about how a specific business uses your data, please contact that business directly.
How We Use Your Data
We process your personal data for the following legitimate business purposes:
- Service Provision: Provide, maintain, and improve our AI-powered platform
- Account Management: Create and manage user accounts and authentication
- Communication: Respond to inquiries and provide customer support
- Product Development: Develop new features and enhance functionality
- Analytics and Insights: Analyze usage patterns and improve service performance
- Legal Compliance: Comply with applicable laws and regulations
- Security and Fraud Prevention: Protect against unauthorized access and fraudulent activities
Data Sharing and Third-Party Services
We do not sell your personal information. We share data only in the following circumstances:
Third-Party Service Providers
We use trusted third-party services to operate our platform:
- Meta WhatsApp Business API: For WhatsApp Business API functionality and message delivery
- AI Providers (OpenAI, Anthropic): For AI-powered conversation analysis and response generation
- Cloud Infrastructure (AWS): For secure data storage and infrastructure
- Payment Processing (Stripe): For secure payment processing (we do not store complete payment card information)
Data Security Measures
We implement comprehensive security measures to protect your personal information:
Technical Safeguards
- End-to-end encryption for data in transit (TLS/SSL)
- Role-based access controls and authentication
- 24/7 security monitoring and intrusion detection
Organizational Measures
- Regular security training for all employees
- Periodic security audits and assessments
- Comprehensive data protection policies and procedures
Data Retention Periods
We retain your personal data only as long as necessary for the purposes outlined in this policy:
| Data Type | Retention Period |
|---|---|
| Account Data | Duration of active account + 90 days |
| WhatsApp Messages | 24 months from conversation date |
| System Logs | 12 months |
| Billing Records | 7 years (legal requirement) |
Your Privacy Rights
Rights Available to All Users
Access
Request access to your personal data and details about processing
Rectification
Request correction of inaccurate or incomplete data
Deletion
Request deletion of your personal data when no longer necessary
Data Portability
Export your data in a portable format
How to Exercise Your Rights
To exercise any of your privacy rights, please contact us at:
Submit a Privacy Rights Request โInternational Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your personal information in accordance with applicable data protection laws.
Regional Privacy Compliance
We comply with regional privacy regulations in Latin America:
๐จ๐ฑ Chile - Ley 19.628
Compliance with Law 19.628 on Protection of Private Life
๐ฒ๐ฝ Mรฉxico - LFPDPPP
Compliance with Federal Law on Protection of Personal Data (LFPDPPP)
๐จ๐ด Colombia - Ley 1581
Compliance with Law 1581 of 2012 on Personal Data Protection
๐ฆ๐ท Argentina - PDPA
Compliance with Personal Data Protection Act (PDPA)
Data Breach Notification
In the event of a data breach that affects your personal information, we will notify you and relevant authorities within the timeframes required by applicable law (typically within 72 hours of discovery).
Children's Privacy
Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected data from a child, please contact us immediately.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of any material changes by posting the updated policy on this page and updating the 'Last updated' date. Your continued use of our Services after changes become effective constitutes acceptance of the revised policy.
Questions About Privacy?
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: privacy@tuinkia.com
Data Protection Officer: dpo@tuinkia.com