Privacy Policy
How EngageAI collects, uses, shares and protects personal information in the AI Front Desk platform.
Last updated:
This Privacy Policy explains how EngageAI (“AI Front Desk”, “we”, “us”) handles personal information when you use our website, our application, and the WhatsApp Business messaging services we provide to businesses.
AI Front Desk is a customer-communication platform. Businesses (“Clients”) use it to message their own customers over the WhatsApp Business Platform, to capture and qualify leads, to book appointments, and to request reviews.
1. Two different roles, two different responsibilities
Which part of this policy applies to you depends on how you came into contact with us.
- If you are a Client (you or your business holds an account with us) we are the data controller for your account information. We decide what we collect and why, and this policy governs it in full.
- If you are a customer of one of our Clients — for example, you messaged a business on WhatsApp and it replied through our platform — that business is the data controller of your conversation, and we act as its data processor. We handle your information on that business's instructions. You may contact us directly and we will action your request or route it to the responsible business; see Your rights.
2. Information we collect
2.1 Information Clients give us
- Account details — name, email address, password (stored only as a salted hash), role, and profile photo.
- Business details — brand or business name, logo, contact details, business hours and time zone.
- Billing details — the plan you are on, subscription status and billing period.
- Contact lists — the customer records a Client imports or creates, which may include name, phone number, email address, tags and notes.
2.2 Information we receive from Meta / WhatsApp
When a Client connects a WhatsApp Business account, we receive information from Meta's WhatsApp Business Cloud API, including:
- the WhatsApp Business Account ID, phone number IDs, display names and quality ratings of the Client's numbers;
- message templates the Client has registered with Meta and their approval status;
- inbound messages sent to the Client's WhatsApp number — the message content, the sender's WhatsApp phone number and WhatsApp profile name, any attached media, and the message timestamp;
- delivery, read and failure receipts for outbound messages.
We request only the permissions needed to send and receive messages on the Client's behalf and to manage the Client's own WhatsApp assets. We do not access a Client's personal Facebook profile, friends, or ad data.
2.3 Information generated by using the service
- Conversations and messages exchanged between a Client and its customers, including replies drafted by our AI assistant.
- Leads — details captured through automated conversation flows, such as name, phone, email, and answers to the Client's qualifying questions, together with a lead score and grade.
- Appointments — bookings, reschedules and cancellations made through the platform.
- Reviews and feedback — ratings and any private feedback a customer submits on a Client's review page.
- Security and audit logs — sign-in and failed sign-in events with IP address, browser user agent and timestamp; and, when enabled by an administrator, a log of inbound webhook requests.
3. How we use personal information
- To deliver the service — routing messages to and from WhatsApp, running conversation flows, capturing and scoring leads, booking appointments and sending reminders.
- To generate AI replies — see Section 5.
- To operate accounts — authentication, brand switching, subscription and plan enforcement, and in-app notifications.
- To keep the platform secure — verifying the cryptographic signature on every inbound webhook, rate-limiting public endpoints, and recording sign-in activity so suspicious access can be investigated.
- To support Clients — responding to enquiries and diagnosing faults.
- To meet legal obligations — including WhatsApp Business Platform policy, tax and accounting rules, and lawful requests from authorities.
We do not sell personal information. We do not use the contents of a Client's conversations to advertise to anyone, and we do not share them with other Clients.
4. Legal bases (UK/EU GDPR and comparable laws)
- Performance of a contract — providing the platform to Clients who have subscribed to it.
- Legitimate interests — securing the platform, preventing abuse, and improving reliability, balanced against your rights.
- Consent — where required, for example marketing messages sent to customers who opted in. Consent can be withdrawn at any time; on WhatsApp, replying STOP to a Client's number unsubscribes you from its broadcasts.
- Legal obligation — where the law requires us to retain or disclose information.
5. Automated processing and AI
AI Front Desk includes an AI assistant that can draft or send replies on a Client's behalf. To produce a reply, the relevant message content and the Client's own configured instructions and knowledge-base material are sent to our AI provider for processing.
- Message content is used only to generate that reply.
- It is not used to train the AI provider's models.
- Automated conversation flows may score and grade a lead. This affects how a business prioritises follow-up; it produces no legal or similarly significant effect on you, and a human at the business can always take over the conversation.
6. Who we share information with
We share personal information only with the following categories of recipient:
| Recipient | Why |
|---|---|
| Meta Platforms, Inc. | WhatsApp Business Cloud API — delivery and receipt of your WhatsApp messages. |
| Anthropic PBC | AI assistant that drafts replies. Message content is sent for processing and is not used to train models. |
| Hosting & infrastructure provider | Application hosting, database storage and encrypted backups. |
| The Client you messaged | Your conversation, and any lead, appointment or review details you provided, are visible to the business you contacted. |
| Authorities and legal advisers | Where disclosure is required by law, or to establish or defend legal claims. |
| An acquirer | If our business is merged or acquired, subject to this policy continuing to apply. |
Messages you exchange on WhatsApp are also subject to WhatsApp's own Privacy Policy.
7. International transfers
We and our providers may process personal information in countries other than your own, including outside the UK, the EEA and India. Where we transfer personal information across borders, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with technical measures including encryption in transit.
8. How long we keep information
- Account and business records — for as long as the account is active, and up to 90 days after closure, unless a longer period is required by law.
- Conversations, contacts and leads — for as long as the Client keeps them. Clients control this and can delete records at any time; operators may configure automatic pruning of older messages.
- Completed and abandoned conversation flows, and read notifications — pruned automatically on a rolling schedule.
- Sign-in and webhook logs — retained for security auditing, then cleared.
- Deletion requests — the record of your request is kept for 180 days so we can evidence that we honoured it, then removed.
Backups are encrypted and overwritten on a rolling cycle, so deleted data may persist briefly in backup media before being expunged.
9. Security
- All traffic is encrypted in transit over HTTPS/TLS.
- Passwords are stored as salted hashes and are never recoverable in plain text.
- Every inbound WhatsApp webhook is verified against Meta's cryptographic signature before it is processed.
- Access is role-based, and each Client's data is isolated to its own brand — one Client cannot see another's contacts, conversations or leads.
- Public endpoints are rate-limited, and sign-in activity is logged.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant regulator where the law requires it.
10. Your rights
Depending on where you live, you may have the right to:
- Access a copy of the personal information we hold about you;
- Correct information that is inaccurate or incomplete;
- Delete your personal information — see below;
- Object to or restrict certain processing;
- Portability — receive your information in a machine-readable format;
- Withdraw consent at any time, without affecting processing already carried out;
- Complain to your local data protection authority.
To delete your data, use our Data Deletion page. You will receive a confirmation code and can track the request without needing an account. You can also email privacy@engageai.in. We respond within 30 days and never charge for a first request.
Where we act as a processor for a Client, we will forward your request to that business and support it in responding.
11. Cookies
We use only cookies that are strictly necessary to run the service: a session cookie that keeps you signed in, a CSRF token that protects forms from cross-site request forgery, and a preference cookie that remembers your light or dark theme. We do not use advertising or cross-site tracking cookies, and we run no third-party analytics that profile you.
12. Children
The platform is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16 (or the minimum age in your jurisdiction). If you believe a child's information has reached us, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the service or the law changes. The “Last updated” date at the top always reflects the current version, and we will notify Clients in-app before a material change takes effect.
14. Contact us
- Privacy & data protection: privacy@engageai.in
- General support: support@engageai.in