Privacy Policy
Last updated: 29 August 2026
This policy explains how HelpDeskAI — a product of GETMEPAID DIGITAL SOLUTIONS — collects, uses and protects data when organizations and their customers use the platform. GETMEPAID DIGITAL SOLUTIONS is the legal business operating HelpDeskAI.
1. Information we process
HelpDeskAI processes the information organizations provide when using the service: account details (name, email), organization settings, private knowledge base content, uploaded documents, contacts, conversation messages, support tickets and usage/credit records. When customers message an organization's WhatsApp number, the message content and sender phone number are processed to generate replies.
2. How we use information
We use this information to operate the service: generating AI replies grounded in each organization's private knowledge, delivering documents and campaigns, handling requests and human handoff, billing and credit accounting, security monitoring, audit logging and platform support. We do not sell personal data.
3. Tenant isolation
Each organization's data is stored in an isolated tenant. The AI answers only from the organization's own knowledge and documents. Organization members only access data belonging to their organization, according to their role.
4. Third-party processors
The service relies on third parties to operate, including Meta (WhatsApp Business Platform) for message delivery, cloud hosting and database infrastructure, AI model providers for reply generation, and Paddle (Paddle.com) as our Merchant of Record, which processes billing and payment data (name, email, billing address, payment details) to complete orders, manage subscriptions, handle tax compliance, invoicing and refunds. These providers process data only as needed to deliver the service, under their own privacy terms. We also share data with professional advisers and authorities where required by law.
5. Data retention
Conversation, document and audit data is retained while the organization's account is active so the service can function and provide history. Organizations can delete knowledge items, documents and contacts from their dashboard. Account deletion requests can be sent to the platform team via the support form in Settings.
6. Security
We apply role-based access control, row-level tenant isolation, audit logging, webhook signature verification and optional multi-factor authentication. No method of transmission or storage is perfectly secure, but we work to protect data with appropriate technical and organizational measures.
7. Your rights
Depending on your location, you may have rights to access, correct, export or delete your personal data. Organization admins manage their tenant's data directly in the dashboard; for anything else, contact us through the support form or the email below.
8. Global availability & regional rights
HelpDeskAI serves organizations worldwide. We honor the data-protection rights that apply in your region — including the EU/UK GDPR, Tanzania's Personal Data Protection Act, Kenya's Data Protection Act, Nigeria's NDPA, South Africa's POPIA, Brazil's LGPD and comparable laws elsewhere. Where your local law grants stronger rights than this policy describes, the stronger rights apply.
9. Legal bases for processing
Where GDPR or similar laws apply, we process data on the basis of contract performance (operating the platform for your organization), legitimate interests (security, fraud prevention, service improvement), consent (where you or your customers give it, for example WhatsApp opt-in and marketing announcements) and legal obligations (tax, accounting and lawful requests).
10. Roles: controller and processor
HelpDeskAI is operated by GETMEPAID DIGITAL SOLUTIONS. For account, billing and platform-security data, GETMEPAID DIGITAL SOLUTIONS acts as the data controller (with Paddle acting as an independent controller/Merchant of Record for payment and order data). For customer conversations, contacts, documents and knowledge belonging to an organization, GETMEPAID DIGITAL SOLUTIONS acts as a data processor on behalf of that organization, which is the controller and is responsible for lawful collection and opt-in of its contacts.
11. WhatsApp and message data
Inbound and outbound WhatsApp messages, media, phone numbers, delivery receipts and template metadata pass through Meta's WhatsApp Business Platform and are subject to Meta's own policies. We store message content and metadata so organizations have conversation history, audit trails and analytics. Contacts can opt out at any time by replying STOP (or the equivalent) and are then excluded from bulk communication.
12. AI processing
To answer a message, relevant excerpts of your organization's knowledge and documents plus recent conversation context are sent to AI model providers. Content is treated as untrusted input, is scoped strictly to your tenant, and is not used to train shared public models by us. Automated replies never make legally significant decisions without human handoff being available.
13. Cookies and local storage
We use strictly necessary cookies and browser local storage to keep you signed in, remember your active organization and preserve interface preferences. We do not use advertising cookies or cross-site tracking.
14. International transfers
Our infrastructure providers and AI providers may process data in regions outside your country. Where required, transfers rely on appropriate safeguards such as standard contractual clauses offered by those providers.
15. Retention periods
Conversations, documents and contacts are retained while your organization is active and for up to 90 days after account closure, unless a longer period is required by law. Security and audit events are retained for up to 24 months. Billing and credit records are retained as required by accounting rules. Backups are rotated on a rolling schedule.
16. Data breach handling
If we become aware of a personal-data breach that is likely to create risk, we investigate immediately, contain the incident and notify affected organization owners and, where required, supervisory authorities within the applicable statutory deadlines.
17. Children
The platform is intended for organizations and their staff, not for children. Where an organization such as a school processes information relating to minors, that organization remains the controller and is responsible for parental or guardian consent.
18. Exercising your rights
Organization admins can export, edit or delete tenant data directly in the dashboard. For access, correction, portability, erasure, restriction or objection requests, or to withdraw consent, contact us using the contact page or support@helpdeskai.cloud. We respond within 30 days and may ask for verification of identity or authority.
19. Changes & contact
We may update this policy from time to time as the service, laws or Meta's requirements evolve. For material changes we will give at least 30 days' notice by email and/or a prominent notice on this page and in the dashboard, and the updated policy will show a new "Last updated" date. Minor clarifications may take effect when posted. Continued use after the effective date means you accept the updated policy. Questions about privacy can be raised through the in-app support form or by contacting the platform team at support@helpdeskai.cloud.
