Privacy Policy
Last updated: 9 September 2026
This English text is the binding version. An Arabic translation is available at /ar/privacy.
RIDKK ("RIDKK", "we", "us") provides a software platform at app.ridkk.com that lets businesses create and operate AI-powered employees for customer service and sales across WhatsApp, website chat, and email (the "Service"). This policy explains what data we collect, how we use it, and the choices available to you.
1. Who this policy covers
- Clients — businesses that create a RIDKK workspace and subscribe to the Service.
- End customers — people who message a client's business through channels connected to RIDKK (for example a WhatsApp number, website chat widget, or support mailbox). For end-customer data, our client is the data controller and RIDKK acts as a processor on their behalf.
2. Data we collect
- Account data — at registration: name, email address, password (stored hashed) and preferred interface language. Later: a phone number (optional, from Preferences) and company details (name, industry, country, timezone, website) when the workspace is created. If you sign in with Google or Microsoft we receive your name, email address and profile picture from that provider.
- Conversation data — messages exchanged between end customers and a client's AI employees or human agents, including sender identifiers (such as a WhatsApp phone number or email address), message text, media sent in the conversation (images, video, voice notes, documents) and transcripts of voice notes, and details derived from the conversation that are kept on the contact record (name, interests, appointments, leads).
- Knowledge data — website content, documents, and text a client uploads to train their AI employees, plus inventory and service lists.
- Channel data — connection metadata for WhatsApp Business accounts (via Meta), email mailboxes (via Google or Microsoft OAuth), website chat, and Facebook Pages / Instagram accounts connected for marketing (page ids and names), including access tokens that are stored encrypted.
- Usage and billing data — feature usage, message and AI-processing volumes, subscription and invoice records. Payment cards are processed by Stripe and never reach our servers.
- Technical data — IP addresses, browser information, and logs needed to secure and operate the Service.
3. How we use data
- To provide the Service: routing messages, generating AI responses, retrieving answers from client knowledge, booking appointments, recording leads, and enabling human handover.
- To meter usage and bill subscriptions.
- To secure, monitor, troubleshoot, and improve the Service.
- To communicate with clients about their account, billing, and Service updates.
We do not sell personal data. We do not use one client's private data to serve another client — every workspace is strictly isolated.
4. AI processing
Message content — including WhatsApp, email and website-chat messages and transcripts of voice notes — together with the relevant client knowledge is sent to large-language-model providers under contract with RIDKK solely to generate responses and carry out tasks (such as booking an appointment or drafting a quotation) on the client's behalf. AI outputs are constrained by client-configured guardrails. We do not permit our model providers to use this content to train their general-purpose models.
5. Third-party platforms
- Meta / WhatsApp — when a client connects a WhatsApp Business account through the WhatsApp Business Platform, message data is exchanged with Meta under the Meta Terms for WhatsApp Business, the Business Solution Terms and the WhatsApp Business Messaging Policy. RIDKK uses WhatsApp Business Platform data to operate that client's conversations, which includes AI processing of the messages as described in section 4 and storing media inside the client's workspace.
- Google / Microsoft — when a client connects a mailbox, RIDKK accesses it under the scopes the client approves, only to read incoming customer emails and send replies on the client's behalf. RIDKK's use of Google user data complies with the Google API Services User Data Policy, including its Limited Use requirements.
- Facebook Pages / Instagram — when a client connects a Page for marketing we store the access tokens and page ids needed to publish the posts the client's team approves. Deauthorizing the app on Facebook deletes those tokens immediately (see the data deletion status page); it does not affect conversations stored in the workspace.
- Stripe — payment processing.
6. Retention and deletion
- Conversation and knowledge data are retained while the client's workspace is active.
- Clients can delete knowledge sources, AI employees and contacts at any time from their dashboard; deleting a contact removes that person's conversations, media and derived details with it.
- End customers on WhatsApp (or any other channel): to access or delete your data, message the business you spoke with on the same number with "delete my data", or email privacy@ridkk.com with your phone number (or email address) and the business name. The business deletes your contact record from its dashboard, which removes your messages, media, phone number and any details derived from the conversation within 30 days; we support our clients in fulfilling such requests and follow up on requests that reach us directly. Note that deauthorizing the Facebook app does not delete chat history.
- A workspace owner can close the workspace from the Billing page ("Close workspace"). When a workspace is closed — by its owner or after its subscription ends — its data is deleted or irreversibly anonymized within 30 days by an automated purge, and backups roll over within a further 30 days, except records we must keep for legal or accounting reasons (invoices and subscription records, never conversation data).
- A suspension for non-payment or an expired trial does not delete data; it stays available for reactivation until the workspace is closed.
7. Security
Data is encrypted in transit (TLS) and sensitive credentials are encrypted at rest. Access to production systems is restricted and logged. Workspaces are isolated at the application and database layer. We maintain daily backups and audit logs of sensitive actions.
8. International transfers
Our infrastructure is hosted in the European Union, and data may be processed by sub-processors (LLM, email, and messaging providers) in other jurisdictions under appropriate safeguards.
9. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Contact us at privacy@ridkk.com and we will respond within 30 days.
10. Changes
We will post any changes to this policy on this page and, for material changes, notify clients by email or dashboard notice.
11. Contact
RIDKK — privacy@ridkk.com