Security & compliance
Privacy Policy
Last updated: August 4, 2026
1General information & data protection officer
Chatydesk by Ozprix Studios ("we", "us", or "Chatydesk") values your privacy. This policy explains how we collect, process, and protect data when you use our WhatsApp CRM platform and related scheduling automation services, in compliance with the General Data Protection Regulation (GDPR) and other applicable European laws.
Ozprix Studios is registered in Germany. For questions about this policy, data deletion requests, or your rights, contact our Data Protection Officer at info@chatydesk.com.
2Scope of data collection
We process the data necessary to provide a high-performing, secure CRM:
- Account
- Email, encrypted password hashes, and profile name.
- WhatsApp tokens
- Meta Cloud API tokens, phone number IDs, and app secrets, encrypted at rest with AES-256-GCM.
- CRM data
- Contacts, phone numbers, conversation histories, pipeline stages, deals, and notes.
- Scheduling
- Weekly availability, session prices, and booking details.
- Payments
- Transaction reference IDs (e.g. Stripe checkout IDs) used to confirm appointments. We never store raw card numbers.
3Purposes and legal basis of processing
Under GDPR Article 6, we process data based on:
- Art. 6(1)(b)
- Contractual performance: running the CRM, sending automated messages, syncing WhatsApp chats, and managing subscriptions.
- Art. 6(1)(c)
- Legal obligation: German tax law, billing audit trails, and VAT declarations.
- Art. 6(1)(f)
- Legitimate interest: analyzing server performance, debugging error logs, and optimizing the scheduling engine for reliable uptime.
4Data hosting & third-party processors
Your CRM database runs on secure Supabase servers in the EU. Data is encrypted in transit and at rest.
We integrate third-party APIs to deliver core functionality:
- Meta Inc. (WhatsApp Cloud API) for message transit.
- Stripe Inc. for subscription billing and booking payments.
- Chatydesk Video Rooms (built on open-source Jitsi Meet) for consultation video calls.
Data processing agreements (DPAs) are maintained with our cloud infrastructure partners to ensure GDPR compliance.
5Google Calendar integration & Google user data
If you choose to connect your Google Calendar, Chatydesk requests the Google OAuth scope "https://www.googleapis.com/auth/calendar.events". We handle Google user data as follows:
- Data accessed
- Calendar events on the Google account you connect, via the calendar.events scope. We only access and manage the events our own service creates for your confirmed bookings — we do not read, use, or store your other calendar entries.
- How we use it
- Solely to create and update a calendar event for each consultation you confirm in Chatydesk — the date and time, the client, and the video-call link — so the appointment appears on your calendar with your own reminders. It is not used for any other purpose.
- Sharing & transfer
- We never sell Google user data or transfer it to third parties, data brokers, or advertisers. It is processed only by the infrastructure providers that run our app (Supabase, Vercel) to deliver this feature.
- Protection
- Your Google OAuth refresh token is encrypted at rest with AES-256-GCM and transmitted only over TLS. Access is scoped to your own account.
- Retention & deletion
- We keep your Google token only while your calendar remains connected. Disconnecting it in Settings, or deleting your Chatydesk account, permanently removes the stored token; deletion completes within 30 days.
Chatydesk's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and we do not use it to develop, improve, or train generalized AI/ML models.
6Data retention
We retain your database records for as long as your Chatydesk account remains active. If you delete your account or request data purging, we initiate permanent deletion across active servers and backups within 30 days, except where retention is legally mandated (e.g. invoices).
7Your rights
Under the GDPR you have the right to access your stored data, rectify inaccuracies, request deletion, restrict processing, and export your contact lists. To exercise these rights, email us or use the Help & Feedback panel in your dashboard.
For step-by-step deletion request instructions, see our Data Deletion Instructions.