Overview
ChatDaddy (“ChatDaddy”, “we”, “us”) provides a multi-tenant platform for businesses (“customers”, “tenants”) to message their own customers over WhatsApp, and to build automation, AI agents, and analytics on top of that messaging. This policy explains what we collect, why, and the controls you have.
Two different people read this policy: a workspace admin or agent who signs into ChatDaddy directly, and an end customer who messages a ChatDaddy customer’s WhatsApp Business number and never signs into ChatDaddy at all. Both are covered below, and the “Your rights” and data deletion sections apply to each.
What we collect
- Account data — name, work email, password hash, and workspace configuration for anyone who signs up or is invited to a ChatDaddy workspace.
- Contact & message data — the phone numbers, profile names, and message content (text, media, location, interactive replies) that flow through a tenant’s connected WhatsApp Business number, whether sent by an agent, an automation, or an AI agent.
- Usage & device data — IP address, browser/device type, and product analytics events (e.g. which screens are used) needed to operate and improve the service.
- Billing data — plan, usage volume, and billing contact. Card details are collected and stored directly by our payment processor, not by us.
WhatsApp & Meta data
ChatDaddy connects to the WhatsApp Business Platform via the Meta Cloud API. When a tenant connects a WhatsApp Business Account (WABA), Meta shares with us the data needed to send and receive messages on that number: the WABA and phone number ID, message delivery/read receipts, and the content of inbound and outbound messages, delivered to us over a signed webhook.
We do not use WhatsApp message content to train AI models, and we do not sell it. Where a tenant enables an AI agent, message content is sent to the configured AI provider (see sub-processors) only to generate that specific reply.
How we use it
We use data to operate the service the customer configured: routing messages to the right inbox and agent, running the automations and AI agents a tenant builds, computing analytics, billing for usage, securing the platform against abuse, and complying with legal obligations. We do not sell personal data, and we do not use one tenant’s customer data to serve another tenant.
Legal bases (GDPR)
For users in the EEA/UK, we rely on the following legal bases:
- Contract — processing account and messaging data to provide the service the tenant subscribed to.
- Legitimate interests — security, fraud prevention, and product analytics, balanced against the interests of the individuals involved.
- Consent — where a tenant relies on WhatsApp opt-in from their own end customers (see the Acceptable Use Policy), and for optional cookies.
- Legal obligation — tax, accounting, and law-enforcement requests.
Data residency & transfers
Tenants choose a data residency region at signup. Their data does not leave that region except for encrypted backup replication (opt-in) and where a sub-processor operates outside it — see sub-processors for region detail on each. Where personal data leaves the EEA or UK, the transfer relies on Standard Contractual Clauses as set out in the DPA.
Retention & deletion
We keep account and messaging data for as long as the workspace subscription is active. Tenant admins can request data export at any time and full erasure through their workspace settings or by contacting us — see the dedicated data deletion instructions for the exact steps and timelines, including for end customers who are not ChatDaddy users themselves. Backups are retained for 30 days after deletion and then cryptographically erased.
Security
Data is encrypted in transit (TLS 1.3) and at rest (AES-256-GCM), access is scoped per-tenant, and every workspace is isolated at the database layer. Full detail is on the security page, including how to report a vulnerability.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing (GDPR, UK GDPR, CCPA/CPRA, LGPD, and India’s DPDP Act are all honored). Workspace admins can action most of these directly under Settings → Security. Anyone else — including someone who has messaged a ChatDaddy customer on WhatsApp — can use the data deletion instructions or email privacy@chatdaddy.io.
Children’s privacy
ChatDaddy is a business tool and is not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact privacy@chatdaddy.io and we will delete it.
Changes to this policy
We’ll post material changes here with an updated date, and notify workspace admins by email for changes that meaningfully reduce your rights.
Contact us
Privacy questions or requests: privacy@chatdaddy.io. General support: contact page.