Privacy Policy
Last updated: 27 April 2026 · Effective date: 27 April 2026
This Privacy Policy explains how WhatIBot ("we", "us") collects, uses, stores and shares personal data when you use the SaaS platform at whatibot.com (the "Service"). It is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the Spanish LOPDGDD, the Italian Codice Privacy, the Moroccan Law 09-08, and applicable laws in Lithuania and France.
1. Data Controller
WhatIBot is the data controller for the personal data of customers who sign up for the Service. WhatIBot acts as data processor for personal data of your end-users (people who chat with your bot) — you, the customer, are the controller for that data. Contact: whatibotsupport@gmail.com.
2. Data We Collect
From customers (account holders)
- Identity: name, email, business name, country, language preference.
- Authentication: hashed password or SSO identifier.
- Billing: name, billing address, last 4 digits of card, VAT number. Full card data is handled by our merchant of record (PCI-DSS compliant) and never stored on our servers.
- Usage: messages sent/received counts, plan tier, login timestamps, IP address.
- Support: emails and chat transcripts you send to us.
From end-users (people chatting with your bot)
- Phone number, name, profile photo (as provided by WhatsApp/Telegram/Instagram).
- Message content (text, images, voice notes) sent to or from the bot.
- Bookings, orders, lead form data captured by the bot.
- Conversation timestamps and platform metadata.
3. How We Use Data
- Provide the Service — host conversations, route messages, store bookings, send follow-ups (legal basis: contract).
- AI processing — message content is sent to Anthropic's Claude API for natural-language understanding and reply generation. Anthropic does not train models on this data (legal basis: contract / legitimate interest).
- Billing — process subscription payments (legal basis: contract).
- Service emails — onboarding, billing receipts, security alerts (legal basis: contract).
- Marketing — only to customers who opted in (legal basis: consent — withdraw any time from your account or via the unsubscribe link).
- Security & fraud — detect abuse, prevent unauthorized access (legal basis: legitimate interest).
- Legal compliance — tax, accounting, regulatory reporting (legal basis: legal obligation).
4. Subprocessors
We use the following subprocessors to deliver the Service. Each is bound by a data-processing agreement (DPA) and appropriate safeguards (Standard Contractual Clauses for non-EU transfers).
- Cloudflare Workers — application hosting (global edge, EU data residency available).
- Supabase — Postgres database (EU region).
- Anthropic — Claude AI inference (US, no training on customer data, DPA in place).
- Meta Platforms (WhatsApp Business, Instagram) — message delivery.
- Telegram — message delivery.
- Paddle — merchant of record, billing, tax.
- Resend / Postmark — transactional email.
- Google Workspace — internal email and customer support.
5. International Transfers
Some subprocessors are based outside the EU/EEA (notably Anthropic, Meta and Cloudflare in the US). These transfers are protected by Standard Contractual Clauses approved by the European Commission and supplementary measures including encryption in transit and at rest.
6. Data Retention
- Conversation history: 90 days by default, configurable from 7 days to 2 years per tenant.
- Bookings and orders: kept for the lifetime of the customer account, deleted 30 days after account closure.
- Billing records: 10 years (legal obligation in most jurisdictions).
- Marketing emails opt-in records: 5 years after withdrawal of consent.
- Server logs: 30 days.
7. Security
We use HTTPS/TLS 1.3 for all data in transit, AES-256 encryption at rest for credentials, role-based access control with row-level security in our database, and audit logging for sensitive operations. Customer credentials (third-party API keys, tokens) are encrypted with envelope encryption before storage.
8. Your Rights (GDPR)
You have the right to:
- access your personal data (right of access);
- correct inaccurate or incomplete data (right of rectification);
- delete your data (right to erasure / "right to be forgotten");
- restrict or object to processing;
- request data portability in a machine-readable format;
- withdraw consent at any time;
- lodge a complaint with your local data-protection authority.
Submit requests to whatibotsupport@gmail.com. We respond within 30 days (extendable to 90 days for complex requests).
9. Automated Decision-Making & AI Disclosure
The Service uses large-language-model AI (Anthropic Claude) to generate replies to messages. This processing produces probabilistic, automated responses but does not produce decisions that have legal or similarly significant effects on individuals within the meaning of GDPR Article 22. Customers may configure the bot to escalate sensitive interactions to a human operator. Anthropic does not use Service inputs or outputs to train its models, per our data-processing agreement with Anthropic.
10. Data Breach Notification
In the event of a personal-data breach likely to result in a risk to the rights and freedoms of natural persons, we notify the relevant supervisory authority within 72 hours of becoming aware (GDPR Art. 33) and notify affected customers and end-users without undue delay (GDPR Art. 34). We maintain an internal incident-response procedure and security audit log.
11. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, grants you additional rights:
- Right to know what personal information we collect, use, disclose and sell or share.
- Right to delete personal information we collected from you, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of "sale" or "sharing" of personal information for cross-context behavioral advertising. WhatIBot does not sell or share personal information for advertising purposes.
- Right to limit use of sensitive personal information (e.g. precise geolocation, account credentials).
- Right to non-discrimination for exercising your rights.
To exercise these rights, email whatibotsupport@gmail.com with "California Privacy Request" in the subject. We verify identity before fulfilling. Authorized agents must provide written authorization.
12. Other US State Rights (VA, CO, CT, UT, TX)
Residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comprehensive privacy laws have similar rights of access, deletion, correction, portability and opt-out of targeted advertising. Same procedure as §11.
13. End-User Data (Sub-Processing)
When customers' bots talk to end-users, the customer is the data controller for those conversations and WhatIBot is the data processor. Customers are responsible for obtaining valid consent from their end-users before initiating chats. We sign a Data Processing Agreement with every customer on request.
14. Cookies & Tracking
Our website uses strictly necessary cookies for authentication, language preference, and CSRF protection. We do not use third-party advertising cookies and do not track visitors across other websites. We use privacy-friendly, cookieless analytics (Plausible / self-hosted) for traffic measurement.
15. Children
The Service is intended for businesses and is not directed at children under 16 (or under 13 in the United States, per COPPA). We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal information, contact whatibotsupport@gmail.com and we will delete it promptly.
16. Do Not Track
We do not track visitors with persistent identifiers across third-party sites and we honour Global Privacy Control (GPC) and Do Not Track signals where technically applicable.
17. Changes to this Policy
We may update this Privacy Policy. Material changes will be notified by email or in-app banner at least 30 days before they take effect. The "Last updated" date at the top reflects the latest revision. Historical versions are available on request.
18. Contact & Data Protection
- Email: whatibotsupport@gmail.com
- Postal: WhatIBot, Casablanca, Morocco
- EU/EEA complaints: you have the right to lodge a complaint with your local data-protection authority — e.g. CNIL (France), AEPD (Spain), Garante (Italy), VDAI (Lithuania), ICO (UK).
- Morocco: CNDP (Commission Nationale de contrôle de la protection des Données à caractère Personnel).
This Privacy Policy is written in English. Translations are provided for convenience; in case of conflict, the English version prevails.