Security & compliance

Privacy Policy

Last updated: August 4, 2026

1General information & data protection officer

Chatydesk by Ozprix Studios ("we", "us", or "Chatydesk") values your privacy. This policy explains how we collect, process, and protect data when you use our WhatsApp CRM platform and related scheduling automation services, in compliance with the General Data Protection Regulation (GDPR) and other applicable European laws.

Ozprix Studios is registered in Germany. For questions about this policy, data deletion requests, or your rights, contact our Data Protection Officer at info@chatydesk.com.

2Scope of data collection

We process the data necessary to provide a high-performing, secure CRM:

Account
Email, encrypted password hashes, and profile name.
WhatsApp tokens
Meta Cloud API tokens, phone number IDs, and app secrets, encrypted at rest with AES-256-GCM.
CRM data
Contacts, phone numbers, conversation histories, pipeline stages, deals, and notes.
Scheduling
Weekly availability, session prices, and booking details.
Payments
Transaction reference IDs (e.g. Stripe checkout IDs) used to confirm appointments. We never store raw card numbers.

4Data hosting & third-party processors

Your CRM database runs on secure Supabase servers in the EU. Data is encrypted in transit and at rest.

We integrate third-party APIs to deliver core functionality:

  • Meta Inc. (WhatsApp Cloud API) for message transit.
  • Stripe Inc. for subscription billing and booking payments.
  • Chatydesk Video Rooms (built on open-source Jitsi Meet) for consultation video calls.

Data processing agreements (DPAs) are maintained with our cloud infrastructure partners to ensure GDPR compliance.

5Google Calendar integration & Google user data

If you choose to connect your Google Calendar, Chatydesk requests the Google OAuth scope "https://www.googleapis.com/auth/calendar.events". We handle Google user data as follows:

Data accessed
Calendar events on the Google account you connect, via the calendar.events scope. We only access and manage the events our own service creates for your confirmed bookings — we do not read, use, or store your other calendar entries.
How we use it
Solely to create and update a calendar event for each consultation you confirm in Chatydesk — the date and time, the client, and the video-call link — so the appointment appears on your calendar with your own reminders. It is not used for any other purpose.
Sharing & transfer
We never sell Google user data or transfer it to third parties, data brokers, or advertisers. It is processed only by the infrastructure providers that run our app (Supabase, Vercel) to deliver this feature.
Protection
Your Google OAuth refresh token is encrypted at rest with AES-256-GCM and transmitted only over TLS. Access is scoped to your own account.
Retention & deletion
We keep your Google token only while your calendar remains connected. Disconnecting it in Settings, or deleting your Chatydesk account, permanently removes the stored token; deletion completes within 30 days.

Chatydesk's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and we do not use it to develop, improve, or train generalized AI/ML models.

6Data retention

We retain your database records for as long as your Chatydesk account remains active. If you delete your account or request data purging, we initiate permanent deletion across active servers and backups within 30 days, except where retention is legally mandated (e.g. invoices).

7Your rights

Under the GDPR you have the right to access your stored data, rectify inaccuracies, request deletion, restrict processing, and export your contact lists. To exercise these rights, email us or use the Help & Feedback panel in your dashboard.

For step-by-step deletion request instructions, see our Data Deletion Instructions.