Tobachat helps businesses communicate with their customers via WhatsApp. In doing so, we process personal data carefully and in accordance with the GDPR. Below we explain what data we process, why, and what rights you have.
1. Our role
There are two situations to distinguish:
- For you as a customer we are the controller for your account data, such as your name, billing details, login, and contract.
- For the messages and contacts of your customers we are the processor. You decide what happens to that data; we only process it on your instructions through our software. Under the GDPR (article 28), this requires a data processing agreement (DPA). It is part of your agreement with us. You can request a copy at info@tobachat.nl.
Did you receive a WhatsApp message via Tobachat? We are not the sender; one of our customers is. For questions about that message, please contact that business directly.
Did you message Tobachat's WhatsApp number to try a demo? Then we are responsible for that processing ourselves. We process your phone number, profile name and messages to run the demo: an AI answers your questions as if it were the assistant of the company named in the demo (legitimate interest, art. 6(1)(f) GDPR; you start the conversation yourself). That company is not involved and cannot see the conversation. We keep the conversation no longer than needed to run the demo and follow up on your question, and delete it on request via info@tobachat.nl. The recipients are listed in section 4.
2. What data do we process?
- From you as a customer: contact details (name, email, phone number, company name), billing details, and technical data such as logs and IP address. When you send a request or sign up, we also keep how you found us: the page you first landed on, the site or email that sent you, and the click ID if you came in through an ad.
- From your customers (as processor): the content of WhatsApp messages, phone numbers and profile names, and metadata such as timestamps and delivery status.
3. What do we use it for?
- To give you access to the dashboard and to deliver messages via WhatsApp (performance of the contract, GDPR art. 6(1)(b)).
- For invoicing and our administration (legal obligation, GDPR art. 6(1)(c)).
- To prevent abuse and improve the platform (legitimate interest, GDPR art. 6(1)(f)).
- To learn which pages, emails, and ads bring in requests and new accounts (legitimate interest, GDPR art. 6(1)(f)).
- To find out where people get stuck in the dashboard and with the assistant, so we can fix it. Your conversations with the assistant are used for your own organization only (legitimate interest, GDPR art. 6(1)(f)).
- To enable the technical connection with Meta (performance of the contract, GDPR art. 6(1)(b)).
We do not make automated decisions that have a significant impact on you.
4. Who do we share data with?
Only with parties we need to deliver the service. In short:
- Meta / WhatsApp Ireland Ltd.: for delivering messages via the WhatsApp network.
- EU hosting: for secure data storage and login.
- A payment provider: for handling payments and invoicing.
- An email service: for sending emails about your account, such as confirmations and notifications.
- A network service for the website: for hosting the website, relaying messages, and storing encrypted backups.
- An AI service: for the AI features, on the instructions of the business that uses them. The model then receives the messages, the contact's name and the fields that business keeps, and never data from another business. The provider does not train on it.
We never sell your data. We are sometimes legally required to share data with a competent authority (for example the police, the public prosecutor, or the Dutch Tax Authority) when a valid and legally binding request obliges us to do so. You can read how we handle this in our legal requests policy.
5. Data outside the EU
When you use WhatsApp, Meta transfers data to its global infrastructure under the terms of the WhatsApp Business Data Transfer Addendum. Where we use other suppliers outside the EU, this takes place on the basis of standard contractual clauses (SCCs) or another mechanism recognized under the GDPR, set out in our agreement with that supplier. For Google, the EU-US Data Privacy Framework also applies, see the cookies section below.
6. How long do we keep data?
- Account data: for as long as you are a customer, plus seven years for tax purposes. If a request never turns into a customer relationship, we delete it without undue delay once it has been dealt with.
- Chat history: for as long as you keep it in your dashboard. You can always delete messages yourself. After the contract ends we delete it without undue delay.
- Messages that pass through the AI: The provider of the AI model keeps what the model receives and its reply for a limited time to detect abuse, and does not train on it. What is in your dashboard is kept according to the rule above.
If you would like us to erase your data sooner, under your right to be forgotten (GDPR art. 17), see our data deletion page.
7. Security
We take appropriate technical and organizational measures to protect your data against misuse and unauthorized access, including encryption and access management. No method of transmission or storage is completely secure, but we continuously improve our security.
8. Your rights
You have the right to access, rectify, and erase your personal data, to restrict its processing, to data portability, and to object to its processing. Where processing is based on your consent, you can withdraw it at any time. You can export your contacts yourself in the dashboard. For conversations or any other request, email info@tobachat.nl or use the data deletion page for erasure. Not satisfied with how we handle this? You can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
You can object at any time, and it costs you nothing. Where we process your data on the basis of our own legitimate interest, you can object at any time by emailing info@tobachat.nl. If it concerns direct marketing, we always stop, and you do not have to give a reason. That right is set out in GDPR art. 21.
9. Cookies
Without your consent we place only strictly necessary cookies. Statistics and marketing cookies are placed only after you accept them in the cookie banner. If you refuse, nothing is sent to Google.
- Necessary: remembering your language choice and your cookie choice. These are our own cookies and require no consent. We keep your cookie choice for 6 months.
- Statistics (Google Analytics 4): measuring how many visitors we have and which pages they view, so we can improve the site. Legal basis: your consent. Recipient: Google Ireland Limited. We have disabled Google Signals, so your data is not linked to a Google account. Retention: Google's default setting of 2 years for these cookies.
- Marketing (Google Ads): measuring which ad or search term led to a contact request or a sign-up, so we can spend our advertising budget sensibly. Legal basis: your consent. Recipient: Google Ireland Limited. Retention: 90 days, Google's default setting for the Conversion Linker cookie.
Google may transfer data to the United States. This happens under the EU-US Data Privacy Framework, for which Google is certified, supplemented by a data processing agreement.
You can withdraw your choice at any time. Withdrawing is just as easy as giving consent:
10. How we obtain business email addresses
Did a first email from us arrive without you ever giving us your address? Then we looked it up ourselves in public sources. Because that data did not come from you, GDPR art. 14 requires us to set out the following.
- Who processes it: Tobachat (Ciro Byte Solutions), reachable at info@tobachat.nl.
- Why, and on what basis: to send your company a short series of at most three emails about Tobachat, and to reply if you write back. The basis is our legitimate interest (GDPR art. 6(1)(f)): offering our own service to businesses it may be useful to. We use only business contact details the company published itself, we write about work, and one word is enough to make it stop.
- What we hold: company name, sector, town, website, business email address, phone number, registration number and legal form where those are public, what the site offers by way of contact, and the date we looked. We also record which email we sent when and what followed. If the address contains a person's name it is personal data, and everything below applies to it in full.
- Where it came from: public sources: public business registers, open map data, and the company's own website.
- Who else sees it: our email and office software. No one else. We never sell the list or share it with anyone.
- How long we keep it: until twelve months after our last email to your company. If you ask for erasure sooner, that comes first. One thing we do keep after that: your email address on a blocklist, so you never hear from us again. That, and nothing else, is what we still use it for.
You have the same rights as everyone else in this statement: access, rectification, erasure, restriction and portability. One email to info@tobachat.nl is enough. If you disagree with how we handle it, you can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Objecting takes one word. Reply with stop, or email info@tobachat.nl. We then stop using your data for these emails straight away. You do not have to give a reason and it costs nothing. That right is set out in GDPR art. 21.