Our commitment to European data protection standards
We are fully committed to protecting the privacy and rights of EU residents under the General Data Protection Regulation (GDPR). Our platform is designed with privacy by default and privacy by design principles.
We process personal data only when we have a lawful basis, which includes:
Contract Performance
Processing necessary to deliver our services as agreed.
Legitimate Interests
Platform security, fraud prevention, and service improvement.
Legal Obligation
Compliance with applicable laws and regulations.
Consent
For marketing communications and non-essential cookies.
Right to Access (Art. 15)
Request a copy of all personal data we hold about you.
Right to Rectification (Art. 16)
Correct inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
"Right to be forgotten" — request deletion of your data.
Right to Portability (Art. 20)
Receive your data in a structured, machine-readable format.
Right to Restrict (Art. 18)
Limit how we process your personal data.
Right to Object (Art. 21)
Object to processing based on legitimate interests.
When data is transferred outside the EU/EEA, we ensure adequate protection via Standard Contractual Clauses (SCCs) and adequacy decisions. Key subprocessors include:
Meta Platforms (WhatsApp Business API)
Region: USA
Amazon Web Services (AWS)
Region: EU-West / Mumbai
Razorpay / Stripe
Region: India / USA
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours as required by GDPR Article 33. Affected users will be notified without undue delay when the breach poses a high risk to their rights and freedoms.
Data Protection Officer (DPO)
To exercise your GDPR rights or for data protection inquiries:
📧 dpo@chatpro365.com