Privacy Policy
1. Controller and contact details
HueChat is operated by Altajriba aldhatiya Company For Communications and Information Technology ("HueChat," "we," "our," or "us"), located at 6611 At Takhassusi Branch, Riyadh 12341, Saudi Arabia. Telephone: 920051129. Privacy and data-protection contact, including DPO enquiries where a DPO is required or appointed: hamad@huechat.ai.
This notice explains how we collect, use, disclose, transfer, retain, and destroy personal data through the HueChat website and service. It is written for transparency and does not replace a customer's own privacy notice for the people the customer communicates with through HueChat.
2. Our role
For customer contacts, conversations, leads, tickets, connected-channel data, and knowledge uploaded by a business account, that business normally determines the purpose and means of processing and HueChat acts as its processor or service provider. For account administration, billing, security, direct support, our website, and our own legal obligations, HueChat may act as controller. If you are an end customer of a business using HueChat, please contact that business first; we will assist it with a verified request.
3. Data, purpose, legal basis, and whether it is required
| Data category | Source and required status | Purpose | Legal basis, as applicable |
|---|---|---|---|
| Account and business details: name, work email, phone, organization, role, settings, and authentication data. | Provided by you. Name, email, and authentication data are required to open and secure an account; phone, company details, and optional profile fields are required only when the relevant feature needs them. | Create and administer the account, authenticate users, provide support, and communicate service or security notices. | Contract or pre-contract steps; legitimate interests in secure service administration; legal obligation where required. |
| Customer and connected-channel data: contacts, messages, attachments, leads, tickets, comments, identifiers, routing data, and channel tokens. | Provided by the customer, its users, its contacts, or a connected provider. Optional until the customer enables that channel or feature. | Deliver the connected messaging, support, sales, automation, and integration functions requested by the customer. | Customer instructions and contract; consent or another basis obtained by the customer where required. |
| Billing and transaction records: plan, invoices, payment status, tax and limited payment metadata. | Provided by the customer and payment provider. Required for a paid plan; HueChat does not need full card details. | Process subscriptions, prevent fraud, keep accounting records, and resolve payment disputes. | Contract and legal obligations, including accounting and tax requirements. |
| Knowledge and AI data: knowledge sources, prompts, relevant conversation snippets, generated replies, retrieval metadata, feedback, traces, and evaluations. | Provided or generated only when an account enables an AI feature. Optional. | Generate, retrieve, classify, evaluate, and improve the configured account feature with safety and quality controls. | Customer instructions and contract; legitimate interests for security and quality where lawful. |
| Device, usage, and security data: IP address, browser/device details, timestamps, logs, audit events, rate limits, and error reports. | Collected automatically. Core security telemetry is necessary; optional product analytics is not. | Protect the service, detect abuse, troubleshoot, audit access, and understand optional website usage. | Legitimate interests and legal obligations for security; consent for optional analytics where required. |
| Website analytics and advertising data: page and campaign events, referrer, cookie identifiers, and ad-attribution data. | Collected only after the applicable CookieChimp Analytics or Marketing choice. Optional and not required to use HueChat. | Measure website performance and, if Marketing is accepted, measure or personalize advertising. | Consent. Marketing remains off when Global Privacy Control is enabled. |
4. Additional categories and sources
Depending on enabled features, we may also process support requests, notification preferences, consent and opt-out evidence, exports, webhook delivery metadata, and information received from WhatsApp, Facebook, Instagram, Messenger, email, SMS/voice, Telegram, payment, or other providers selected by the account.
Meta Platform Data. This may include Meta user, Page, Instagram business, WhatsApp business, form, message, comment, lead, webhook, ad-account, campaign, delivery, and app-scoped identifiers, plus encrypted or otherwise protected access credentials. We use it only to provide the connected account's requested functions. We do not sell Meta Platform Data or use one customer's private data to train or populate another customer's private agent.
5. AI processing
If an account enables AI, HueChat sends only the content and metadata reasonably needed for the selected generation, embedding, retrieval, reranking, evaluation, or safety task to the configured provider. Authorized account users and limited authorized HueChat personnel may review outputs for support, security, debugging, and quality. Customer data is not enabled for general model training by HueChat unless a separate, specific disclosure and control is provided.
6. Recipients, providers, countries, and safeguards
We disclose data only as needed to operate the service, follow customer instructions, protect rights or security, complete a transaction, or meet law. The recipient depends on the feature selected:
| Recipient or provider | Purpose and data | Processing location and transfer safeguard |
|---|---|---|
| DigitalOcean, LLC | Production compute, managed PostgreSQL, Valkey, storage, and operational infrastructure. | Primary production region is FRA1, Germany. Contractual, access-control, encryption, and provider security measures apply. |
| Cloudflare, Inc. | DNS, CDN/proxy, traffic security, abuse prevention, and IP/device request data. | Global edge network. Provider data-protection terms and appropriate contractual and technical safeguards apply to cross-border processing. |
| Moyasar and applicable financial institutions | Subscription payment processing and limited billing/transaction data. | Saudi Arabia and locations required by the payment network. Payment data is separated from customer conversation content. |
| Brevo / Sendinblue SAS or the active transactional-email provider | Account, security, billing, and service email delivery. | Provider service regions, which may include the EEA. Contractual and security controls apply. |
| Meta and other customer-selected channel providers | Connected messaging, leads, comments, ads, delivery, and channel administration. | Locations disclosed by the selected provider. Transfer occurs only when the customer enables the integration and is governed by the provider terms and our customer agreement. |
| Customer-selected commerce providers: Salla, Zid, Shopify, WooCommerce, BigCommerce, Wix, Nuvemshop / Tiendanube, Ecwid, PrestaShop, Adobe Commerce / Magento, Shopware, Odoo eCommerce, VTEX, SHOPLINE, Haravan, Sapo and Cafe24 | Connected commerce data needed for the integration the account enables. | Locations disclosed by the selected provider; the transfer is governed by its terms and our customer agreement. |
| Customer-selected payment providers: Stripe, PayTabs, Moyasar, Tap Payments, HyperPay, Tabby, Tamara and MIS Pay | Transaction and customer data needed to create hosted payment links for the integration the account enables. For Tabby, Tamara and MIS Pay installments this includes the customer's name, phone, email, delivery address and order items, which the provider uses for its checkout and eligibility check. Card details are collected by the selected provider, not HueChat. | Locations disclosed by the selected provider; the transfer is governed by its terms and our customer agreement. |
| Customer-selected SMS providers: Taqnyat, Unifonic, Msegat, Corbit, Infobip and Twilio | Customer phone number and appointment reminder text needed to send the SMS reminders the account enables, and the phone number an administrator enters to send a test SMS. | Locations disclosed by the selected provider; the transfer is governed by its terms and our customer agreement. |
| Account-enabled AI and quality providers, which may include OpenAI, Anthropic, Google, Jina AI, Braintrust, Groq, DeepSeek, and the following optional Social AI providers: OpenRouter, Stability AI, ElevenLabs, Fal.ai, Runway, Kuaishou, ByteDance, MiniMax, Pika, HeyGen, Synthesia, D-ID, Sonix and Vizard | The limited prompts, source media, generated media, content, identifiers, and telemetry needed for an enabled AI, voice, image, video, avatar, caption, or quality function. Availability depends on account and operator configuration. | The provider regions disclosed in its terms or the customer agreement, potentially including the EEA, United States, and other disclosed regions; minimization, contractual restrictions, and technical controls apply. |
| CookieChimp, Google Analytics/Tag Manager, Microsoft Clarity, and Meta Pixel | Consent records and optional website analytics or advertising data. | Provider locations stated in their privacy terms. Non-essential collection is consent-gated, and the current website inventory appears in the Cookie Policy. |
We assess transfers and use appropriate contractual, organizational, and technical safeguards where required. Contact us for the safeguards relevant to your account and enabled providers.
7. Sale, sharing, targeted advertising, and GPC
HueChat does not sell personal data for money. Some laws define disclosure to advertising providers as "sharing" or processing for targeted advertising. You may opt out at any time through Your Privacy Choices / Do Not Sell or Share. We recognize the browser-based Global Privacy Control signal on this website; when GPC is present, Marketing consent and Meta/targeted-advertising events remain disabled. GPC does not prevent essential service processing.
8. Retention and secure destruction
We apply the shortest period needed for the purpose, contract, security, and applicable law. A legal hold or statutory duty may require a longer period. Current public commitments and criteria are:
| Record | Retention trigger or period | Deletion or destruction |
|---|---|---|
| Account, profile, conversation, contact, ticket, lead, attachment, and configured AI data | While the account is active and needed for the requested service. After termination, access is disabled and a verified return or deletion request is handled through support; the completion scope and timing are confirmed in writing. | Support-operated removal from available active systems, with legal-hold, provider, queue, vector, object, and backup handling tracked for the request. |
| OAuth tokens and channel credentials | Until the integration is disconnected, the credential expires, or the account is deleted. | Revoked, disabled, and removed from ordinary use. |
| Website consent and optional tracking records | For the duration shown in the consent tool and live cookie/vendor inventory, or until withdrawal; vendor-side records follow the disclosed vendor period. | Optional collection stops immediately after withdrawal. Matching cookies/storage are cleared where technically supported and expire under their stated lifetimes. |
| Billing, tax, dispute, fraud, security, audit, and rights-request evidence | For the applicable statutory, limitation, chargeback, security, or legal-defense period. | Minimized during retention, then securely deleted or anonymized when the purpose and hold end. |
| Operational logs, queues, caches, and backups | Limited operational lifecycles based on security and recovery need. Backup copies expire under controlled schedules and are not restored into ordinary use after a valid deletion. | Automatic expiry, overwrite, deletion, anonymization, and restore-time deletion controls, as appropriate to the medium. |
Secure destruction may include database deletion, object removal, token revocation, cryptographic erasure, anonymization, scheduled overwrite, and instructions to a processor. Selective removal from an immutable backup may not be immediate; the data remains unavailable for ordinary use and must be re-deleted before restored systems return to service.
9. Security
Safeguards include TLS in transit, protection of sensitive secrets, access controls, tenant isolation, least privilege, audit logging, webhook verification where supported, monitoring, and incident response. No system is risk-free; we investigate and notify affected parties or authorities when applicable law requires it.
10. Your rights and how to exercise them
Depending on applicable law, you may request to be informed, access a copy, correct, complete, delete, restrict, object, withdraw consent, or obtain portable data. Email hamad@huechat.ai with the account or relationship involved and the right requested. Account owners may open deletion or data-access requests in the product; full-account exports are produced through a verified support-operated workflow. We verify identity and authority before disclosure or deletion and confirm the available scope and timing in writing.
You can also submit an access, correction, restriction, objection or deletion request through the data-rights form on the HueChat Trust Center, which also lists our subprocessors, security policies and Data Processing Agreement.
For requests governed by the Saudi Personal Data Protection Law, we aim to respond within 30 days after receiving a complete, verified request. If the permitted extension is needed because a request is complex or numerous, we will explain the extension and expected date. There is normally no charge unless law permits one for a manifestly unfounded or excessive request.
11. Withdrawing consent and objecting
Website consent can be changed immediately through the footer privacy-choice link or CookieChimp floating control. Withdrawing consent is as easy as giving it and does not affect processing already lawfully completed. For direct marketing or another consent-based activity, email us or use the unsubscribe/opt-out method in the communication. We record and apply the choice within the timeframe required by the relevant law.
12. Complaints
Please contact hamad@huechat.ai so we can investigate. You may also complain to the competent authority. In Saudi Arabia, information and complaint channels are available through the Saudi Data & AI Authority (SDAIA) Personal Data Protection portal. Contacting us first does not limit your right to approach an authority.
13. Children
HueChat is a general-audience business service and is not directed to children. A business-account user must have the legal capacity and organizational authority required to create or use that account. We do not knowingly use website tracking to profile children; if we learn that a child provided account data directly, we will take appropriate deletion steps.
14. Changes
We may update this notice when our processing, providers, or legal duties change. We will post the new date here and provide a prominent, email, or in-app notice before a material change where required.