AUTOCHATPLUS PRIVACY POLICY

Last Updated: July 22, 2026

IMPORTANT IMPLEMENTATION NOTE

Before publishing this policy, replace every item shown in square brackets with your actual legal and operational information. The published policy must accurately reflect how AutoChatPlus actually collects, stores, uses, shares, secures, and deletes data.

Required replacements:
[LEGAL ENTITY NAME]
[REGISTERED BUSINESS ADDRESS]
[COUNTRY / STATE]
[PRIVACY EMAIL]
[SUPPORT EMAIL]
[DATA HOSTING LOCATIONS]
[PAYMENT PROVIDER NAME]
[ANALYTICS PROVIDERS, IF ANY]
[AI SERVICE PROVIDERS, IF ANY]


1. INTRODUCTION

This Privacy Policy explains how AutoChatPlus, operated by [LEGAL ENTITY NAME] (“AutoChatPlus,” “we,” “us,” or “our”), collects, uses, stores, shares, transfers, protects, and deletes information when users access or use our websites, web applications, software, artificial intelligence agents, automation tools, communication tools, social media integrations, messaging integrations, APIs, and related services (collectively, the “Service”).

AutoChatPlus enables businesses to create and manage AI agents, connect business knowledge sources, integrate communication channels, manage customer conversations, automate workflows, and collaborate through a shared workspace.

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. Where consent is legally required, we will request consent before processing the relevant information.


2. WHO WE ARE

The entity responsible for this Privacy Policy is:

[LEGAL ENTITY NAME]
Trading name: AutoChatPlus
Registered address: [REGISTERED BUSINESS ADDRESS]
Country or state of registration: [COUNTRY / STATE]
Privacy email: [PRIVACY EMAIL]
Support email: [SUPPORT EMAIL]

Depending on the circumstances, AutoChatPlus may act as:

a. A data controller when we determine the purposes and means of processing information, such as account registration, billing, website analytics, service security, and direct customer support.

b. A data processor or service provider when we process customer conversations, connected-platform data, knowledge-base content, or other information on behalf of a business customer.


3. SCOPE OF THIS PRIVACY POLICY

This Privacy Policy applies to information processed through:

- The AutoChatPlus website
- The AutoChatPlus application
- User and administrator dashboards
- AI agents and automated workflows
- Shared inbox and collaboration features
- Knowledge-base features
- Social media and messaging integrations
- Meta integrations, including Facebook, Instagram, Messenger, and WhatsApp Business Platform integrations
- Google authentication and connected Google services
- Other third-party integrations made available through the Service
- Customer support and service communications

This Privacy Policy does not govern third-party websites, applications, or services that are independently controlled by other organizations. Those third parties may have their own privacy policies and terms.


4. INFORMATION WE COLLECT

We collect information in several ways: directly from users, automatically through use of the Service, from connected third-party platforms, and from business customers that use AutoChatPlus to communicate with their own customers.


4.1 ACCOUNT AND AUTHENTICATION INFORMATION

When a user creates an account, signs in, joins a workspace, or uses an identity provider such as Google, we may collect:

- Full name
- Email address
- Profile image
- Authentication identifier
- Account creation date
- Login history
- Account status
- Workspace membership
- User role and permissions
- Language and regional preferences
- Security and authentication events

When Google sign-in is used, AutoChatPlus does not receive or store the user’s Google password.


4.2 BUSINESS AND WORKSPACE INFORMATION

When a user creates or manages a workspace, we may collect:

- Business or organization name
- Business website
- Industry
- Business description
- Business contact details
- Workspace name and identifier
- Team member information
- User roles and permissions
- Workspace settings
- Notification settings
- Brand voice and response rules
- Agent configurations
- Automation and workflow configurations
- Tags, assignments, routing rules, and internal notes


4.3 KNOWLEDGE-BASE CONTENT

Users may upload, create, connect, or import business information into a knowledge base. Depending on the user’s configuration, this may include:

- PDF files
- Word documents
- Spreadsheets
- CSV files
- Text files
- Product catalogs
- Service descriptions
- Policies
- Frequently asked questions
- Internal instructions
- Customer-support documentation
- Website pages
- Sitemap content
- Help-center content
- Blog content
- Information from connected cloud-storage services
- Information from CRM, support, or business systems

Business customers are responsible for ensuring that they have all rights, permissions, and legal bases necessary to provide this content to AutoChatPlus.


4.4 CONNECTED PLATFORM DATA

When an authorized user connects a third-party platform, AutoChatPlus may receive data made available by that platform according to the permissions approved by the user and the platform.

Depending on the connected service, this may include:

- Platform account identifiers
- Business account identifiers
- Page identifiers
- Professional account identifiers
- User or customer identifiers
- Account names
- Profile information
- Access tokens
- Refresh tokens
- Authorization scopes
- Webhook events
- Message identifiers
- Message content
- Message timestamps
- Sender and recipient identifiers
- Delivery and read status
- Comments
- Mentions
- Replies
- Reactions
- Media metadata
- Attachment metadata
- Connected-channel settings
- Business portfolio information
- Contact information made available by the connected platform

AutoChatPlus accesses connected-platform data only after an authorized user grants the required permissions or otherwise configures an approved integration.


4.5 META PLATFORM DATA

When a user connects a Meta product or service, including Facebook, Instagram, Messenger, or WhatsApp Business Platform, AutoChatPlus may process Meta Platform Data only for the features activated by the authorized business user.

Depending on the permissions granted and the integration used, AutoChatPlus may process:

- Facebook Page identifiers and names
- Instagram professional account identifiers and names
- WhatsApp Business Account identifiers
- WhatsApp phone number identifiers
- Meta business portfolio information
- Page or account access tokens
- Long-lived or system-user tokens where applicable
- Authorization scopes
- Message and conversation identifiers
- Message content
- Message timestamps
- Sender and recipient identifiers
- Message status information
- Comments, mentions, replies, and reactions
- Media and attachment metadata
- Webhook events
- Connected account configuration
- Customer profile information made available through the applicable Meta API

AutoChatPlus may use this information to:

- Connect an authorized Facebook Page
- Connect an authorized Instagram professional account
- Connect an authorized WhatsApp Business Account
- Receive customer messages
- Display conversations in a shared inbox
- Send replies on behalf of an authorized business
- Route or assign conversations
- Trigger configured workflows
- Generate AI-assisted responses
- Apply tags and internal notes
- Measure delivery and workflow performance
- Maintain integration and authentication status
- Provide support for the connected integration

AutoChatPlus does not sell Meta Platform Data.

AutoChatPlus does not use Meta Platform Data for targeted advertising.

AutoChatPlus does not use Meta Platform Data to build, augment, or sell advertising profiles.

AutoChatPlus does not process Meta Platform Data for purposes unrelated to the features requested and configured by the authorized user.

AutoChatPlus may share Meta Platform Data only with service providers acting on our behalf where necessary to operate, secure, support, or provide the Service, and only subject to appropriate contractual and confidentiality obligations.


4.6 CONVERSATION AND MESSAGING DATA

When a business uses AutoChatPlus to manage communications, we may process:

- Customer messages
- Business replies
- Conversation history
- Contact identifiers
- Contact names or profile information
- Attachments
- Media files
- Message status information
- Internal notes
- Tags
- Assignments
- Workflow events
- Agent-generated suggestions
- AI-generated replies
- Human-approved replies
- Dates and timestamps
- Channel information
- Conversation metadata

This information is generally processed on behalf of the business that controls the connected communication channel.


4.7 AI AGENT AND AUTOMATION DATA

When users create or operate AI agents and workflows, we may process:

- Agent names and descriptions
- Agent instructions
- Prompts
- Knowledge sources
- Conversation context
- Workflow triggers
- Workflow conditions
- Workflow actions
- Generated responses
- Classification results
- Routing decisions
- Extracted information
- Tool-call results
- Error and execution logs
- Human approvals or corrections

Where configured, this information may be sent to third-party AI or infrastructure providers acting as subprocessors.


4.8 TECHNICAL, DEVICE, AND USAGE INFORMATION

We may automatically collect technical and usage information, including:

- IP address
- Approximate location derived from IP address
- Browser type
- Browser version
- Device type
- Device identifiers
- Operating system
- Language
- Time zone
- Session identifiers
- Cookie identifiers
- Login timestamps
- Feature usage
- Pages viewed
- Actions performed
- Referral information
- Application performance information
- Crash reports
- Error logs
- Security logs
- API request logs
- Audit logs
- Fraud-prevention signals


4.9 BILLING AND SUBSCRIPTION INFORMATION

If a customer purchases a paid plan, we may collect or receive:

- Billing name
- Billing address
- Subscription plan
- Billing period
- Invoice information
- Tax information
- Payment status
- Transaction identifiers
- Limited payment metadata
- Subscription history

Payment card information may be processed directly by [PAYMENT PROVIDER NAME]. AutoChatPlus generally does not store full payment card numbers.


4.10 SUPPORT AND COMMUNICATION INFORMATION

When users contact us, we may collect:

- Name
- Email address
- Workspace information
- Support request
- Message content
- Screenshots
- Files or attachments
- Technical logs
- Communication history
- Feedback
- Survey responses


5. HOW WE USE INFORMATION

We may use information to:

- Create and manage accounts
- Authenticate users
- Verify account access
- Create and administer workspaces
- Provide the Service
- Connect authorized third-party accounts
- Receive, display, organize, route, and send messages
- Operate shared-inbox functionality
- Generate AI-assisted responses
- Execute configured automation workflows
- Build and operate workspace-specific AI agents
- Process customer-provided knowledge
- Maintain conversation history
- Enable collaboration and team assignments
- Provide analytics and reporting
- Process subscriptions and payments
- Send transactional and service communications
- Respond to support requests
- Troubleshoot errors
- Monitor system reliability
- Protect against fraud and misuse
- Detect and respond to security incidents
- Maintain audit and security logs
- Improve performance and usability
- Comply with legal obligations
- Enforce our Terms of Service
- Protect the rights, safety, and security of users, customers, AutoChatPlus, and third parties


6. AI PROCESSING

The Service may use artificial intelligence to:

- Generate response suggestions
- Generate automated replies
- Classify messages
- Summarize conversations
- Detect intent
- Extract structured information
- Route conversations
- Recommend workflow actions
- Search connected knowledge
- Answer questions using customer-provided content
- Perform other tasks configured by a business customer

Information submitted to an AI feature may be processed by [AI SERVICE PROVIDERS, IF ANY] or other infrastructure providers acting on our behalf.

We require service providers to process information under our instructions and subject to appropriate security, confidentiality, and data-protection obligations.

Business customers are responsible for determining whether AI use is appropriate, providing required notices, obtaining required consent, reviewing AI-generated content where necessary, maintaining human oversight, avoiding prohibited or high-risk uses, and ensuring generated messages comply with applicable laws and platform rules.

AI-generated content may be inaccurate, incomplete, outdated, or inappropriate. Users should review important outputs before relying on them.


7. LEGAL BASES FOR PROCESSING

Where applicable law requires a legal basis, we may process personal information based on:

- Performance of a contract
- Steps taken at the user’s request before entering into a contract
- User consent
- Compliance with legal obligations
- Protection of vital interests
- Our legitimate interests in operating, improving, securing, and supporting the Service
- The legitimate interests of a business customer
- Instructions from a business customer acting as data controller
- Establishment, exercise, or defense of legal claims

Where we rely on legitimate interests, we consider the nature of the information, the expected use, the impact on individuals, and available safeguards.


8. HOW WE SHARE INFORMATION

We may share information in the circumstances described below.


8.1 SERVICE PROVIDERS AND SUBPROCESSORS

We may use service providers for:

- Cloud hosting
- Database hosting
- Content storage
- Authentication
- AI processing
- Email delivery
- Customer support
- Error tracking
- Security monitoring
- Analytics
- Billing
- Payment processing
- Infrastructure maintenance

These providers may process information only as necessary to perform services for us and under appropriate contractual obligations.


8.2 CONNECTED THIRD-PARTY PLATFORMS

When a user activates an integration, information may be transmitted to or received from the connected platform, such as Meta, Google, Telegram, a CRM provider, a customer-support platform, or a cloud-storage provider.

Use of a third-party platform is also subject to that platform’s own terms and privacy practices.


8.3 BUSINESS CUSTOMERS AND WORKSPACE USERS

If an individual communicates with a business that uses AutoChatPlus, authorized users of that business workspace may access conversation data and other information associated with the connected business account.

Workspace administrators may access:

- User accounts
- Roles and permissions
- Conversation data
- Knowledge sources
- Agent configurations
- Workflow history
- Usage information
- Security and audit information


8.4 LEGAL, SAFETY, AND SECURITY DISCLOSURES

We may disclose information where reasonably necessary to:

- Comply with applicable law
- Respond to valid legal process
- Respond to lawful government requests
- Protect the security of the Service
- Investigate suspected fraud or misuse
- Enforce agreements
- Protect legal rights
- Protect users or third parties from harm
- Respond to an emergency involving danger to a person


8.5 BUSINESS TRANSFERS

Information may be transferred in connection with:

- A merger
- An acquisition
- A financing
- A corporate restructuring
- A sale of assets
- A bankruptcy
- A change of control

Any transfer will remain subject to applicable law and appropriate confidentiality protections.


9. DATA RETENTION

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy.

Retention periods may depend on:

- Whether an account or workspace remains active
- Whether a connected integration remains authorized
- Contractual obligations
- Legal obligations
- Billing and tax requirements
- Security requirements
- Fraud prevention
- Dispute resolution
- Legal claims
- Backup rotation

Access tokens and connected-platform credentials are retained only for as long as necessary to maintain an authorized integration, unless longer retention is legally required.

When a valid account or workspace deletion request is completed, associated information will generally be deleted or de-identified from active production systems within 30 days, unless a longer retention period is required by law or necessary for security, fraud prevention, billing, dispute resolution, or legal claims.

Residual encrypted backup copies may remain for up to 90 days before being overwritten or deleted through normal backup rotation.

Aggregated or de-identified information that can no longer reasonably identify an individual may be retained.


10. DATA SECURITY

We use reasonable administrative, organizational, physical, and technical safeguards designed to protect information. These may include:

- Encryption in transit
- Encryption at rest where appropriate
- Role-based access controls
- Authentication controls
- Restricted administrative access
- Credential and token protection
- Secure secret storage
- Logging and monitoring
- Security alerts
- Backup procedures
- Incident-response procedures
- Vendor security review
- Least-privilege access
- Environment separation
- Software update and vulnerability-management processes

No method of transmission or storage is completely secure. We cannot guarantee absolute security.


11. INTERNATIONAL DATA TRANSFERS

Information may be processed in countries other than the country where the user or customer is located, including [DATA HOSTING LOCATIONS].

Where required by applicable law, we use recognized safeguards for international data transfers, which may include contractual protections, adequacy decisions, or other lawful transfer mechanisms.


12. PRIVACY RIGHTS

Depending on location and applicable law, individuals may have the right to:

- Request access to personal information
- Request correction of inaccurate information
- Request deletion
- Request restriction of processing
- Object to processing
- Request data portability
- Withdraw consent
- Opt out of certain processing
- Request information about disclosures
- Lodge a complaint with a data-protection authority

To submit a request, contact:

[PRIVACY EMAIL]

We may request reasonable information to verify identity, authority, and account ownership.

Where AutoChatPlus processes information on behalf of a business customer, we may direct the request to that business customer or assist the business customer in responding.


13. DATA DELETION AND DISCONNECTION

Users may request deletion by:

- Using account or workspace deletion controls where available
- Disconnecting an integration
- Following the instructions at https://autochatplus.com/data-deletion/
- Emailing [PRIVACY EMAIL]

Disconnecting an integration stops future access after authorization is revoked but may not automatically delete historical information stored in the workspace. A separate deletion request may be required for complete deletion.


14. META DATA DELETION

When a Meta user or authorized business user requests deletion of Meta Platform Data, AutoChatPlus will process the request in accordance with applicable law, our contractual obligations, and applicable Meta Platform requirements.

A request may be submitted through:

- AutoChatPlus account settings
- AutoChatPlus integration settings
- The Data Deletion Instructions page
- A valid Meta data-deletion callback, where implemented
- Email to [PRIVACY EMAIL]

AutoChatPlus will delete, de-identify, or otherwise render inaccessible applicable Meta Platform Data unless retention is legally required or otherwise permitted.


15. COOKIES AND SIMILAR TECHNOLOGIES

We may use cookies and similar technologies to:

- Authenticate users
- Maintain secure sessions
- Remember preferences
- Prevent fraud
- Protect the Service
- Measure performance
- Understand Service usage
- Diagnose errors
- Improve user experience

Where required by law, optional cookies will be used only after consent.

Cookie categories may include:

- Strictly necessary cookies
- Preference cookies
- Analytics cookies
- Security cookies

Details about specific cookies should be included in a separate cookie notice if required.


16. CHILDREN’S PRIVACY

The Service is designed for businesses and is not directed to children under 16.

We do not knowingly collect personal information directly from children under 16. If we learn that a child has provided personal information without appropriate authorization, we will take reasonable steps to delete it.


17. THIRD-PARTY SERVICES

The Service may include links to or integrations with third-party services.

AutoChatPlus does not control the independent privacy practices of those third parties. Users should review the privacy policies and terms of each connected service.


18. BUSINESS CUSTOMER RESPONSIBILITIES

Business customers that use AutoChatPlus to process customer data are responsible for:

- Identifying an appropriate legal basis
- Providing required privacy notices
- Obtaining required consent
- Respecting user choices
- Responding to privacy requests
- Configuring appropriate retention periods
- Limiting workspace access
- Using connected-platform data only for authorized purposes
- Complying with applicable marketing and messaging laws
- Complying with the policies of each connected platform


19. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy periodically.

When changes are made, we may:

- Update the “Last Updated” date
- Publish the revised policy
- Provide an in-app notice
- Send an email notice
- Request renewed consent where legally required

Continued use of the Service after an updated policy becomes effective may constitute acknowledgement of the updated policy, where permitted by law.


20. CONTACT US

For questions, requests, or complaints relating to this Privacy Policy, contact:

AutoChatPlus
Operated by: [LEGAL ENTITY NAME]
Registered address: [REGISTERED BUSINESS ADDRESS]
Privacy email: [PRIVACY EMAIL]
Support email: [SUPPORT EMAIL]

Privacy Policy URL:
https://autochatplus.com/privacy-policy/

Data Deletion Instructions:
https://autochatplus.com/data-deletion/