Privacy Policy
Effective date: 07/28/2026
Last updated: 07/28/2026
1. Introduction
Open Solutions Ltd. (“OpenSolutions,” “we,” “us,” or “our”) operates the OpenSolutions Chatwoot App (“the App”).
The App enables organizations to receive, manage, and respond to customer communications sent through WhatsApp and other supported Meta messaging services using the Chatwoot customer messaging platform.
This Privacy Policy explains:
- What personal information the App processes
- Why the information is processed
- How the information is stored and protected
- When information may be shared
- How long information is retained
- How users may request access, correction, or deletion of their information
By communicating with an organization through a WhatsApp account connected to the App, you acknowledge the practices described in this Privacy Policy.
2. Information We Process
The App may process the following information when you communicate with a business or organization using the App.
2.1 Contact information
We may process:
- Your name
- Your WhatsApp telephone number
- Your WhatsApp profile name
- Other contact information that you voluntarily provide during a conversation
2.2 Messages and conversation content
We may process:
- WhatsApp messages sent to and received from the connected business
- Conversation history
- Message timestamps
- Message delivery and read status
- Customer service requests
- Information voluntarily included in messages
Users should avoid sending sensitive personal information unless it is necessary for the service being requested.
2.3 Media and attachments
The App may process media or files that you send through WhatsApp, including:
- Images
- Documents
- Audio recordings
- Video files
- Other message attachments
2.4 Chatwoot conversation information
The App may process information required to create and manage conversations within Chatwoot, including:
- Contact records
- Conversation identifiers
- Inbox information
- Message assignments
- Conversation status
- Internal labels or categories
- Notes or responses created by authorized agents
Internal notes are intended for authorized personnel managing the relevant customer conversation and are not ordinarily sent to the WhatsApp user.
3. How We Receive Information
Information may be received:
- Directly from you when you send a WhatsApp message
- Through WhatsApp and the Meta platform
- Through the Chatwoot platform
- From the business or organization with which you are communicating
- From authorized customer service agents responding through Chatwoot
The App does not intentionally collect information unrelated to providing customer messaging and support services.
4. Purpose of Processing
We process personal information to provide customer messaging services.
This includes processing information to:
- Receive incoming WhatsApp messages
- Display messages to authorized agents in Chatwoot
- Allow authorized agents to respond to users
- Maintain the context of an active customer conversation
- Route conversations to the appropriate agent or team
- Manage customer questions, requests, complaints, or service cases
- Deliver files, media, and message attachments
- Confirm message delivery and conversation status
- Troubleshoot technical or message-delivery problems
- Protect the App against misuse, unauthorized access, fraud, or security threats
- Comply with applicable legal or regulatory requirements
We do not sell users’ personal information.
We do not use WhatsApp message content for unrelated advertising purposes.
5. Legal Basis for Processing
Depending on the circumstances and applicable law, personal information may be processed because:
- Processing is necessary to provide the messaging service requested by the user
- Processing is necessary to respond to a customer inquiry or service request
- The user has consented to the communication
- Processing is necessary for the legitimate interests of OpenSolutions or the organization receiving the message
- Processing is necessary to comply with a legal obligation
- Processing is necessary to protect users, systems, or services from fraud, misuse, or security threats
Where consent is the applicable legal basis, users may withdraw their consent by stopping communication or contacting us using the details in this policy. Withdrawal does not affect processing that lawfully occurred before consent was withdrawn.
6. Temporary Storage and Retention
Personal information is stored temporarily for the purpose of delivering and managing customer communications.
Information will be retained only for as long as reasonably necessary to:
- Complete the relevant conversation or customer service request
- Maintain operational continuity
- Troubleshoot technical problems
- Meet legal, contractual, security, or audit requirements
- Resolve complaints or disputes
Unless a longer period is required by law or by the organization receiving the message, App-controlled message and contact data will normally be retained for no longer than [INSERT RETENTION PERIOD, FOR EXAMPLE: 30, 60, OR 90 DAYS] after the relevant conversation is closed.
Temporary system copies, backups, and technical records may remain for an additional limited period before being automatically overwritten or securely deleted.
Some information may be retained for longer where:
- The user has requested ongoing support
- The conversation forms part of an active service case
- Retention is required by law
- Retention is necessary to establish, exercise, or defend legal claims
- The connected organization has its own lawful retention requirements
7. Where Information Is Stored
Information processed by the App may be stored on systems operated or managed by:
- Open Solutions Ltd.
- The organization using the App
- Chatwoot or the organization’s self-hosted Chatwoot environment
- Meta Platforms, Inc. and its affiliated companies
- Approved hosting, infrastructure, backup, or security providers
The primary application environment is hosted in [INSERT COUNTRY OR HOSTING REGION].
Information may be processed in countries other than the country in which the user is located. Where required, appropriate contractual, organizational, and technical safeguards will be used for international data transfers.
8. How Information Is Shared
Personal information may be shared only where necessary to operate the messaging service.
Information may be shared with:
8.1 The organization receiving the message
Messages are made available to authorized employees, agents, or representatives of the organization with which the user is communicating.
8.2 Meta and WhatsApp
WhatsApp communications are transmitted through services provided by Meta and WhatsApp. Their processing of information is governed by their respective terms and privacy policies.
8.3 Chatwoot
Messages and contact information are transmitted to or processed through Chatwoot so that conversations can be displayed and managed by authorized agents.
Where Chatwoot is self-hosted by OpenSolutions or the connected organization, information is stored within that controlled hosting environment.
8.4 Service providers
We may use hosting, infrastructure, backup, security, monitoring, or technical support providers. Such providers may process information only to perform services on our behalf and are expected to protect it appropriately.
8.5 Legal and security disclosures
Information may be disclosed where reasonably necessary to:
- Comply with applicable law, a court order, or a lawful government request
- Investigate fraud, abuse, or security incidents
- Protect the rights, safety, systems, or property of users, OpenSolutions, or another organization
- Establish, exercise, or defend legal claims
We do not sell or rent WhatsApp contact information, message content, or customer conversation data.
9. Automated Processing and Artificial Intelligence
[SELECT AND RETAIN THE APPLICABLE VERSION.]
Option A — No AI processing
The App does not use artificial intelligence to independently make decisions about users. Messages are reviewed and answered by authorized human agents.
Option B — AI-assisted drafting
The App may use an artificial intelligence service to prepare suggested responses or internal summaries for authorized agents.
Where AI assistance is enabled:
- AI-generated content is intended to assist authorized agents
- Suggested responses should be reviewed by a human before being sent
- The AI service is not authorized to use message content for unrelated advertising
- AI output may be inaccurate and should not be treated as a final decision without human review
- Users may request human assistance
The App does not use automated processing to make legal or similarly significant decisions about users unless this is separately disclosed and lawfully implemented.
10. Data Security
We use reasonable administrative, organizational, and technical safeguards designed to protect personal information.
These safeguards may include:
- User authentication
- Role-based access controls
- Restricted administrative access
- Encrypted network connections
- Secure server configuration
- Access logging
- Security monitoring
- Software updates and vulnerability management
- Backup and recovery controls
- Staff confidentiality obligations
Only authorized personnel with a legitimate operational need should be permitted to access customer conversations.
No internet-based service or storage system can be guaranteed to be completely secure. Users should therefore avoid sending passwords, payment card details, government identification numbers, medical records, or other highly sensitive information through WhatsApp unless specifically requested through an approved and secure process.
11. User Rights
Subject to applicable law, users may have the right to:
- Request confirmation that their personal information is being processed
- Request access to their personal information
- Request correction of inaccurate or incomplete information
- Request deletion of their information
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
- Request a copy of certain information in a portable format
- Lodge a complaint with an applicable data protection authority
These rights may be subject to legal limitations. We may need to verify the requester’s identity before completing a request.
12. How to Request Deletion of Your Data
Users may request deletion of information processed through the App by contacting:
Email: [PRIVACY OR SUPPORT EMAIL ADDRESS]
Deletion-request form: [PUBLIC DATA-DELETION URL, IF AVAILABLE]
Telephone: [OPTIONAL TELEPHONE NUMBER]
A deletion request should include:
- The name associated with the WhatsApp account
- The relevant WhatsApp telephone number
- The approximate date of the conversation
- The organization or WhatsApp account contacted
- A clear statement requesting deletion
Users should not send passwords, one-time codes, or unnecessary identification documents.
We may contact the requester to verify identity and prevent unauthorized deletion. Once verified, we will delete or anonymize eligible App-controlled information within [NUMBER] days, unless retention is required by law or necessary for security, dispute resolution, or legal claims.
Deleting information from systems controlled by OpenSolutions may not automatically delete information independently retained by Meta, WhatsApp, Chatwoot, the receiving organization, or another lawful service provider. Users may need to contact those entities separately.
13. Data Deletion Through Meta
Where Meta provides an App Dashboard, user-data deletion callback, or deletion instructions mechanism, OpenSolutions will maintain an active and publicly accessible data-deletion process.
Users may also remove permissions or disconnect applicable services through their Facebook, Meta, or WhatsApp settings where those options are available.
14. Children’s Privacy
The App is not designed to knowingly collect personal information directly from children without appropriate authorization.
Where the connected organization provides services to children, information should be processed only with the involvement or authorization of a parent, guardian, or other legally authorized person, except where applicable law permits otherwise.
A parent or guardian who believes that a child’s information has been processed inappropriately may contact us to request review or deletion.
15. Third-Party Services
The App depends on third-party platforms, including Meta, WhatsApp, and Chatwoot.
Those providers may collect or process information under their own terms and privacy policies. OpenSolutions is not responsible for privacy practices independently controlled by those providers.
Users should review the relevant privacy information provided by:
- Meta
- Chatwoot
- The organization with which the user is communicating
16. Cookies and Website Information
The messaging integration itself does not require users to visit an OpenSolutions website or accept OpenSolutions cookies merely to send a WhatsApp message.
However, the OpenSolutions website or any connected support portal may use essential cookies, server logs, security controls, or similar technologies. Any website-specific processing should be disclosed in the applicable website privacy or cookie notice.
17. Changes to This Privacy Policy
We may update this Privacy Policy when:
- The App’s functionality changes
- New integrations are introduced
- Data-handling practices change
- Legal or regulatory requirements change
- Security or operational practices are updated
The revised policy will be published at the same publicly accessible URL. The “Last updated” date will identify the latest version.
Material changes may also be communicated through the App, website, WhatsApp account, or another appropriate channel.
18. Contact Information
Questions, complaints, privacy requests, and data-deletion requests may be directed to:
Open Solutions Ltd.
[REGISTERED OR BUSINESS ADDRESS]
Dominica
Email: [PRIVACY EMAIL ADDRESS]
Telephone: [TELEPHONE NUMBER]
Website: [WEBSITE URL]
19. App and Data Controller Information
Depending on the customer relationship:
- Open Solutions Ltd. may act as the data controller where it determines why and how personal information is processed.
- Open Solutions Ltd. may act as a data processor or service provider where it processes information on behalf of the organization using the App.
- The organization receiving the user’s message may be the primary data controller for the conversation and the related customer service request.
Users who contact a specific business, ministry, office, or organization through the App may direct privacy requests to that organization or to OpenSolutions using the contact details above.