Privacy Policy
Last updated: April 6, 2026
1. Introduction
This Privacy Policy describes how ToroAI ("we", "us", "our") processes personal data when you use the ToroAI operator portal, related websites, and features that may interoperate with WhatsApp Business / Meta products (collectively, the "Service").
This policy is designed to meet common expectations for transparency, including practices relevant to business tools that connect to Meta platforms. It does not replace any terms that apply between you and Meta for WhatsApp, Facebook, or other Meta products.
2. Who is responsible for your personal data?
The entity responsible for the Service (the "controller" under applicable data protection laws) is the organization operating ToroAI as described in your agreement or subscription documentation. If you need the legal name and contact details for your deployment, use the contact methods listed in the Service or contact your account administrator.
3. What data we collect
Account and profile data: for example name, email address, organization or business name, credentials, roles, and preferences you provide when registering or managing your workspace.
Service usage data: for example log data, device/browser type, approximate location derived from IP address where technically generated, timestamps, pages or features accessed, and diagnostic events needed to operate and secure the Service.
Customer messaging data: when you use features connected to WhatsApp or similar channels, we process message content, identifiers (such as WhatsApp phone number or user id), conversation metadata (timestamps, delivery/read receipts when available, conversation status), and configuration you provide (for example business context used to help automated or human replies).
Support and communications: information you send when contacting support or participating in surveys.
We do not knowingly collect sensitive categories of personal data unless you voluntarily provide them in message content or profile fields and such processing is necessary to provide the Service you request.
4. How we use personal data
We use personal data to provide, maintain, and improve the Service; authenticate users; route and display conversations; enable automation or AI-assisted features when configured; detect abuse, fraud, and security incidents; comply with legal obligations; and communicate service-related notices.
Where required by law, we rely on appropriate legal bases such as performance of a contract, legitimate interests (for example securing and improving the Service, provided your interests and rights do not override those interests), or consent when consent is required for specific processing (such as certain cookies or marketing, if offered).
5. WhatsApp, Meta, and other third-party services
If you connect WhatsApp Business or other Meta products, Meta will process data under its own terms and policies, including Meta’s/WhatsApp Business Terms and Commerce Policies where applicable. We are not responsible for Meta’s practices, but we describe our role regarding data that flows through the Service.
We may exchange data with Meta APIs strictly as needed to send/receive messages, manage templates, or verify identifiers you configure in the portal. You must ensure your use complies with Meta policies and applicable law (including obtaining required consents from end users where necessary).
6. AI and automated decision-making
Some features may use artificial intelligence (for example large language models) to draft or suggest replies, summarize threads, or enrich routing. Unless expressly stated otherwise, humans remain responsible for ultimate sending decisions and for compliance with laws and platform rules.
Providers of AI services may process inputs and outputs under contractual safeguards appropriate to the deployment. Do not submit secrets or regulated health/financial data unless your deployment is explicitly designed and approved for that purpose.
7. Sharing and subprocessors
We may share personal data with service providers that host infrastructure, provide logging/monitoring, email delivery, error reporting, or otherwise help us run the Service, subject to confidentiality and processing terms.
We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, and security of users, the public, or the Service.
We do not sell personal data as traditionally defined under U.S. state privacy laws, and we do not share personal data for cross-context behavioral advertising unless you have opted in where required.
8. International transfers
If we transfer personal data across borders, we implement appropriate safeguards consistent with applicable law (for example standard contractual clauses or equivalent mechanisms), unless a specific derogation applies.
9. Retention
We retain personal data only as long as needed for the purposes described in this policy, including legal, accounting, and reporting requirements. Retention periods may depend on your plan, backups, and dispute resolution needs. Messaging content may be retained to operate the inbox and audit trails unless you delete it or we provide a deletion workflow.
10. Your rights and choices
Depending on your location, you may have rights to access, rectify, delete, restrict processing, port data, object to certain processing, and withdraw consent where processing is consent-based. You may also have the right to lodge a complaint with a supervisory authority.
To exercise rights, contact us using the methods identified in the Service. We may need to verify your request and may charge fees where permitted by law.
11. Security
We implement technical and organizational measures designed to protect personal data, including access controls, encryption in transit where appropriate, and least-privilege operations. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
12. Children
The Service is intended for businesses and authorized adult operators. We do not knowingly collect personal data from children under 16 (or the age required by local law) for consumer-marketing purposes. If you believe we have collected such data, contact us and we will take appropriate steps.
13. Cookies and similar technologies
We use cookies or local storage as needed for authentication, session continuity, security, language preferences, and product analytics consistent with your settings and applicable law. You can control cookies through your browser, but some features may not work without them.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a revised "Last updated" date and, where required, provide additional notice (such as email or an in-product banner). Continued use after the effective date constitutes acceptance of the updated policy where permitted by law.
15. Contact
For privacy questions or requests regarding ToroAI, use the contact channels provided in the Service (for example support email or ticketing as published in your deployment) or reach your organization’s administrator for tenant-specific questions.
