Security & compliance
Privacy Policy
Last updated: June 9, 2026
1General information & data protection officer
Chatydesk by Ozprix Studios ("we", "us", or "Chatydesk") values your privacy. This policy explains how we collect, process, and protect data when you use our WhatsApp CRM platform and related scheduling automation services, in compliance with the General Data Protection Regulation (GDPR) and other applicable European laws.
Ozprix Studios is registered in Germany. For questions about this policy, data deletion requests, or your rights, contact our Data Protection Officer at info@chatydesk.com.
2Scope of data collection
We process the data necessary to provide a high-performing, secure CRM:
- Account
- Email, encrypted password hashes, and profile name.
- WhatsApp tokens
- Meta Cloud API tokens, phone number IDs, and app secrets, encrypted at rest with AES-256-GCM.
- CRM data
- Contacts, phone numbers, conversation histories, pipeline stages, deals, and notes.
- Scheduling
- Weekly availability, session prices, and booking details.
- Payments
- Transaction reference IDs (e.g. Stripe checkout IDs) used to confirm appointments. We never store raw card numbers.
3Purposes and legal basis of processing
Under GDPR Article 6, we process data based on:
- Art. 6(1)(b)
- Contractual performance: running the CRM, sending automated messages, syncing WhatsApp chats, and managing subscriptions.
- Art. 6(1)(c)
- Legal obligation: German tax law, billing audit trails, and VAT declarations.
- Art. 6(1)(f)
- Legitimate interest: analyzing server performance, debugging error logs, and optimizing the scheduling engine for reliable uptime.
4Data hosting & third-party processors
Your CRM database runs on secure Supabase servers in the EU. Data is encrypted in transit and at rest.
We integrate third-party APIs to deliver core functionality:
- Meta Inc. (WhatsApp Cloud API) for message transit.
- Stripe Inc. for subscription billing and booking payments.
- Chatydesk Video Rooms (built on open-source Jitsi Meet) for consultation video calls.
Data processing agreements (DPAs) are maintained with our cloud infrastructure partners to ensure GDPR compliance.
5Data retention
We retain your database records for as long as your Chatydesk account remains active. If you delete your account or request data purging, we initiate permanent deletion across active servers and backups within 30 days, except where retention is legally mandated (e.g. invoices).
6Your rights
Under the GDPR you have the right to access your stored data, rectify inaccuracies, request deletion, restrict processing, and export your contact lists. To exercise these rights, email us or use the Help & Feedback panel in your dashboard.
For step-by-step deletion request instructions, see our Data Deletion Instructions.