Privacy Policy
Last updated: January 15, 2025 ย ยทย Effective: January 15, 2025
1. Introduction
ChatLoop HQ, Inc. ("ChatLoop HQ", "we", "our", or "us") operates the ChatLoop HQ platform, including our website at chatloophq.com and our API services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you access or use our Service.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with its terms, please discontinue use of the Service immediately.
Our principal place of business is located at: 40, Fetuga Str, Bariga, Lagos, Nigeria. You may also reach us by phone at (+234) 8036871737 or by email at [email protected].
2. Information We Collect
2.1 Information You Provide Directly
- Account Registration: Name, email address, password (hashed), company name, and billing information when you create an account.
- API Credentials: API keys and webhook URLs you configure within the dashboard.
- Support Communications: Any information you submit when contacting our support team.
2.2 Information Collected Automatically
- Usage Data: IP address, browser type, pages visited, timestamps, and referring URLs collected via server logs and analytics tools.
- API Activity Logs: Request metadata such as endpoint called, HTTP status codes, latency, and session identifiers. We do not log the content of your WhatsApp messages.
- Device Information: Operating system, device identifiers, and network information.
- Cookies & Tracking: Session cookies, preference cookies, and analytics cookies. See Section 8 for details.
2.3 WhatsApp Message Data
ChatLoop HQ acts as a transport layer. We transmit messages on your behalf but do not read, store, or analyze the content of messages sent or received through the API beyond the minimum required for delivery confirmation and error handling. Message payloads are held in volatile memory only during the delivery attempt and are not persisted to any database.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service.
- Process transactions and send billing receipts.
- Monitor and analyze usage to improve performance and detect abuse.
- Respond to support requests and communicate about your account.
- Send transactional emails (e.g., password resets, usage alerts). Marketing emails are opt-in only.
- Comply with legal obligations and enforce our Terms & Conditions.
- Detect, prevent, and address fraud, security incidents, and technical issues.
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
4. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, our legal bases for processing personal data are:
- Contract Performance: Processing necessary to deliver the Service you have subscribed to.
- Legitimate Interests: Fraud prevention, security monitoring, and service improvement.
- Legal Obligation: Compliance with applicable laws and regulations.
- Consent: For optional marketing communications and non-essential cookies.
5. Data Sharing and Disclosure
We share personal information only in the following circumstances:
- Service Providers: Third-party vendors who assist us in operating the Service (e.g., cloud hosting, payment processors, email delivery), bound by confidentiality agreements and GDPR-compliant data processing agreements where applicable.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before your data becomes subject to a different privacy policy.
- Legal Requirements: When required by law, court order, or government authority.
- Protection of Rights: To protect the rights, property, or safety of ChatLoop HQ, our users, or the public.
6. Data Retention
We retain personal data for as long as your account is active or as needed to provide the Service. Specifically:
- Account data: Retained for the lifetime of your account plus 90 days after deletion.
- API activity logs (metadata): Retained for 30 days on a rolling basis.
- Billing records: Retained for 7 years to comply with financial regulations.
- Support tickets: Retained for 3 years.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal retention requirements.
- Portability: Receive your data in a structured, machine-readable format.
- Objection / Restriction: Object to or restrict certain processing activities.
- Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
8. Cookies
We use the following categories of cookies:
- Strictly Necessary: Session management and authentication. Cannot be disabled.
- Analytics: Aggregate usage statistics via privacy-preserving analytics (no cross-site tracking). Opt-out available.
- Preferences: Store UI preferences such as theme (dark/light mode).
You can manage cookie preferences through your browser settings or our cookie banner.
9. Data Security
We implement industry-standard security measures to protect your data, including:
- TLS 1.2+ encryption for all data in transit.
- AES-256 encryption for sensitive data at rest.
- Role-based access controls limiting internal data access.
- Regular penetration testing and security audits.
- SOC 2 Type II certified cloud infrastructure providers.
No method of transmission over the internet is 100% secure. In the event of a data breach affecting your rights and freedoms, we will notify affected users and relevant authorities as required by law within 72 hours.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your own, including the United States. We ensure adequate protection through Standard Contractual Clauses (SCCs) approved by the European Commission and the UK International Data Transfer Agreement where applicable.
11. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us at [email protected] and we will promptly delete it.
12. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies.
13. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by email or via a prominent notice on our website at least 14 days before the change takes effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
14. Contact Us
For privacy-related inquiries, please contact our Data Protection Officer:
ChatLoop HQ / Botiva Systems
Attn: Data Protection Officer
๐ 40, Fetuga Str, Bariga, Lagos, Nigeria
๐ง [email protected]
๐ (+234) 8036871737
