▸ Legal

Privacy Policy

Last updated: 23 August 2026. Written in plain language on purpose — but everything below is a commitment, not a summary. Our data-processing page carries the sub-processor register and the terms we sign with customers.

The short version

CustomerX is a customer-support tool that connects to your WhatsApp Business account. We process the messages and contact details that flow through your inbox so we can deliver the product — shared inbox, translation, AI drafts, knowledge base, flows, broadcasts and analytics. We never sell your data or share it with advertisers or data brokers. Your data is yours: you can have it exported or deleted at any time.

Who we are

CustomerX is operated by RidexGo MMC (RidexGo Məhdud Məsuliyyətli Cəmiyyəti), a limited liability company registered in the Republic of Azerbaijan (“CustomerX”, “we”, “us”). Privacy questions and requests: hello@customerx.dev.

We wear two hats, and it matters which one:

  • For your account and this website — your name, work email, login, billing details, how you use the product, and anything you send us — we are the controller. This policy is our notice to you.
  • For your customers’ data — the WhatsApp conversations, phone numbers, names and records that flow through your workspace — you are the controller and we are your processor. We process that data only to run the service for you and on your instructions, under the data-processing agreement described on our data-processing page. Your own privacy notice to your customers should cover how you use WhatsApp and CustomerX.

What we process

Your customers’ data (as your processor).

  • WhatsApp conversation content and metadata: message text, captions, the phone number and profile name WhatsApp shares, timestamps, delivery and read status, and call records for inbound WhatsApp calls.
  • Media your customers send (images, documents, video, voice notes). Media files are not stored on our servers — they are fetched from Meta on demand by reference. Voice notes are transcribed and the text transcript is kept with the conversation; the audio is not retained.
  • Translations, AI drafts, summaries and titles generated from a conversation, and satisfaction ratings a customer chooses to give.
  • Customer records you create or import: names, tags, custom fields, notes, and — where you connect one — fields your own systems return about that customer.
  • Broadcasts you send: the template, the audience you chose, and per-recipient delivery status.

Your account and workspace data (as controller). Agent names, work emails and hashed passwords, roles, language and notification settings, your knowledge base and flows, API keys you create, billing and invoicing details, and operational logs needed to run and secure the service (sign-in attempts, usage counts per AI/translation call, audit entries for administrative actions).

Website visitors (as controller). Standard request logs from our hosting provider (IP address, user agent, pages requested — short-lived), one functional cookie that remembers your language choice (see Cookies below), and whatever you send us by email or through the demo-booking calendar. We run no advertising pixels and no analytics trackers on this site.

Why we process it, and on what legal basis

  • To provide the service you contracted — inbox, routing, translation, transcription, AI drafts, flows, broadcasts, dashboards, support, billing. Basis: performance of a contract (Art. 6(1)(b) GDPR). For your customers’ data we act on your documented instructions; the lawful basis towards your customers is yours to establish.
  • To keep the service secure and reliable — sign-in protection, rate limiting, abuse detection, diagnostics, backups. Basis: our legitimate interests (Art. 6(1)(f)) in running a secure platform, which we have assessed do not override your rights.
  • To improve the product — aggregate, de-identified usage statistics (which features are used, how often, at what cost). Basis: legitimate interests (Art. 6(1)(f)). We do not use your or your customers’ message content to train machine-learning models, and our providers do not either (see below).
  • To meet legal obligations — tax, accounting, responding to lawful requests from authorities. Basis: legal obligation (Art. 6(1)(c)).
  • To send you product news — only if you asked us to, and you can opt out at any time. Basis: consent (Art. 6(1)(a)).

We do not profile you or your customers for advertising, and we make no decisions with legal or similarly significant effect by automated means. AI drafts are suggestions a human reviews; nothing free-form reaches a customer unless a person sends it or you publish a flow that does.

Where your data lives

Every workspace runs in its own dedicated database on Railway — not pooled with other customers. Workspaces are hosted in one of two regions: EU — Amsterdam, Netherlands (Railway europe-west4) or US — California (Railway us-west2). We agree the region with you at onboarding and tell you exactly which one your workspace is in; EU hosting is available to any customer who needs it. This website is served by Vercel from its global edge network.

Hosting in the EU does not mean your data never leaves it: WhatsApp delivery runs through Meta, and translation, transcription and AI run through Google’s APIs — see International transfers.

Sub-processors, by name

We never sell your data or share it with advertisers or data brokers. Message content is processed only by the providers required to run the service, each under a data-processing agreement with us, and none of them use your content to train their models:

  • Meta Platforms (WhatsApp Business Platform) — message and call delivery.
  • Google Cloud (Gemini API, Cloud Translation, Speech-to-Text) — AI drafts and summaries, translation, and voice-note transcription. Google does not use API inputs or outputs to improve its models on the paid tier we use; it may keep prompts and outputs for up to 55 days for abuse monitoring.
  • OpenAI — voice-note transcription (Whisper), on workspaces configured to use it instead of Google Speech-to-Text. OpenAI does not use API inputs or outputs to train its models; API data may be kept for up to 30 days for abuse monitoring. We tell you which transcription provider your workspace uses.
  • Railway — application and database hosting.
  • Vercel — hosting for this website.
  • Calendly — only if you book a demo through the calendar on our site; the booking is made with Calendly under its own privacy policy.

Optional integrations you switch on yourself (for example a CRM or marketing platform) receive only the fields you configure, and only while you keep them enabled. The full register — entity, purpose, location and transfer mechanism for each provider — lives on our data-processing page. We give customers 30 days’ notice by email before adding or replacing a sub-processor, with the right to object. Beyond these, we disclose data only where the law requires.

International transfers

Some of our providers process data in the United States, and our own team operates from Azerbaijan. Where personal data from the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, the transfer is protected by an approved mechanism:

  • Meta — WhatsApp message delivery for European businesses is provided by WhatsApp Ireland Limited; onward transfers to WhatsApp LLC and Meta Platforms, Inc. in the US are governed by Meta’s WhatsApp Business Data Processing Terms and Data Transfer Addendum (EU Standard Contractual Clauses, and the EU–US Data Privacy Framework where applicable).
  • Google — Google Cloud Data Processing Addendum with the EU Standard Contractual Clauses; Google LLC is certified under the EU–US Data Privacy Framework.
  • OpenAI — OpenAI’s Data Processing Addendum incorporating the EU Standard Contractual Clauses; OpenAI, L.L.C. is certified under the EU–US Data Privacy Framework.
  • Railway — Data Processing Addendum incorporating the EU Standard Contractual Clauses and the UK Addendum.
  • Vercel — Data Processing Addendum incorporating the 2021 EU Standard Contractual Clauses and the UK IDTA.
  • CustomerX (Azerbaijan) — access to your workspace by our team for support and operations is covered by the data-processing agreement we sign with you, which incorporates the EU Standard Contractual Clauses, together with the technical and organisational measures below.

How long we keep it

  • Conversations, contacts, knowledge base, flows: for as long as your workspace is active. When you leave, or when you ask, we delete the workspace and its data within 30 days. You can also have us apply a rolling retention limit to your workspace so that deleted customer records are permanently purged after a number of days you choose.
  • Media and voice audio: not stored by us — fetched from Meta on demand and subject to WhatsApp’s own retention.
  • Per-recipient broadcast reports: 90 days after a broadcast finishes (the summary and the CSV you download remain).
  • Operational logs — sign-in attempts, per-call usage records, integration sync logs: 30 days.
  • Account and billing records: for the life of the contract and as long afterwards as tax and accounting law requires.
  • Website: hosting request logs are short-lived; the language cookie lasts 12 months.

Security

  • Everything in transit is encrypted (TLS).
  • Each workspace has its own database; databases are managed by Railway and encrypted at rest.
  • Individual logins for every agent, role-based access so people only see what they should, bcrypt-hashed passwords, session expiry and forced sign-out when access is revoked, and rate-limited sign-in.
  • Inbound WhatsApp webhooks are signature-verified; API access uses per-key secrets you can rotate or revoke.
  • Administrative actions are audit-logged; access to customer data by our team is limited to what support and operations require.

Your rights

Under the GDPR and similar laws you can ask to access the personal data we hold about you, correct it, delete it, restrict or object to certain processing (including processing based on legitimate interests), receive it in a portable format, and withdraw consent where we rely on it. You also have the right to lodge a complaint with a data-protection supervisory authority — the one where you live or work, or where you believe a breach happened.

  • Your own data (account, website): email hello@customerx.dev. We answer within 30 days and may ask you to verify your identity first.
  • Your customers’ data: if a customer sends a request to you, tell us — we delete or export properly, including message history and voice transcripts. If a customer contacts us directly, we pass the request to you without delay and help you answer it.

If something goes wrong

If we become aware of a personal-data breach affecting your workspace, we notify you without undue delay and in any case within 72 hours, with what we know about the nature of the breach, the data and people affected, the likely consequences, and what we are doing about it — so you can meet your own notification duties.

Cookies on this website

This site sets one cookie, cx-locale, which remembers the language you picked in the menu (12 months, functional, no tracking). Nothing else is set by us. If you book a demo, the embedded Calendly calendar sets its own cookies under Calendly’s policy.

Children

CustomerX is a business tool and this site is not directed at children under 16. We do not knowingly collect their data; if you believe a child has given us personal data, email us and we will delete it.

Changes

We may update this policy as the product evolves. The date at the top always tells you the current version, and we email customers about any change that materially affects how their data is handled before it takes effect.

Contact

Privacy questions, requests, or the data-processing agreement: hello@customerx.dev.

Privacy Policy — CustomerX