Last updated: January 2, 2025 · Effective date: January 2, 2025
Welcome to RPAChat. We (“RPAChat”, “we”, “us” or “our”) understand how important your personal information is to you, and we do our utmost to keep it safe and secure. We are committed to maintaining your trust and to processing your personal information lawfully, fairly, on a need-only basis and in good faith. This Privacy Policy (this “Policy”) explains how we collect, use, store, share and transfer your information when you use our products or services, and the ways in which you can access, update, delete and protect that information.
Please read this Policy carefully before you use our products or services, in particular the clauses that exclude or limit liability, the clauses on rights and licences, and the clauses on the use of information. Content highlighted in bold deserves your special attention. If you do not agree with this Policy or any part of it, please stop using our services immediately.
This Policy will help you understand the following:
1.1 “Personal information” means any kind of information relating to an identified or identifiable natural person, recorded electronically or by other means, excluding information that has been anonymised. “Sensitive personal information” means personal information that, once leaked or used unlawfully, may easily lead to the infringement of a natural person's dignity or endanger their personal or property safety, including biometric data, religious beliefs, specific identity, medical and health data, financial account data and location tracking data, as well as the personal information of minors under the age of 14.
1.2 We follow the principles of legitimacy, lawfulness and necessity, and collect and use the information required to administer the service for the purposes described in this Policy. If you are a corporate user registering for the first time, you need to provide your email address and set a password. We will send a verification email to that address inviting you to supplement your contact information (including name, mobile number and how you heard about us) and your company information (including company or organisation name, customer size, business model and industry). After we receive this information, we will contact you through the details you have left in order to discuss product details and the scope of service to be activated.
If you are an authorised user registering for the first time, the administrator of the organisation you belong to will first collect your email address, enter it into the product and send you an account registration invitation link. You then open the registration page through the link in the email and set a password. The above information is necessary to activate your account; if you do not provide it, you will not be able to configure account permissions or use the technical support services we provide.
1.3 For the purposes of the technical support service, please note that a corporate user may, for the purposes of organisational management and operation, collaborative work or the management of a specific team, collect and process the information available about its authorised users during their use of the product. The purposes and means of processing such personal information are determined by the corporate user; we merely provide technical support and process such information in accordance with the corporate user's instructions and the agreement between us and the corporate user, for the purpose of providing the relevant services and features to authorised users.
Please note that, under applicable law, where we apply technical and other necessary measures to personal information such that the recipient of the data can no longer re-identify a specific individual and the data cannot be restored, the use of such anonymised data does not require separate notice to you or your consent, including for commercial purposes.
RPAChat is a business messaging platform that connects our customers' applications with chat apps including WhatsApp, WeChat, QQ and others. This section explains, specifically and in plain terms, what message data we handle on behalf of our customers.
When a corporate user connects a chat app account to RPAChat and end users exchange messages with that account, we collect and process the content of those messages and the data that accompanies them, including:
We use the above data only for the following purposes:
We do not sell your messages. We do not use the content of your WhatsApp or other chat app messages for advertising or marketing to you, we do not disclose them to unrelated third parties, and we do not use them to train general-purpose artificial intelligence models, unless the corporate user that controls the account has expressly instructed or authorised us to do so for its own purposes.
For message data exchanged through a corporate user's business account, the corporate user is the party that decides why and how that data is processed, and we process it on their behalf and under their instructions. If you are an end user who has messaged a business that uses RPAChat, and you wish to exercise your rights over that conversation, you may contact that business directly, or contact us using the details in section 8 and we will pass your request to them and support them in responding to it.
We retain message data for as long as the corporate user's account remains active and the retention period they have configured has not expired. Message data is deleted or anonymised when the corporate user deletes it, when their account is closed, when the agreed retention period expires, or when we receive a valid deletion request — see section 5.2 for how to make one. Where the law requires us to keep certain records for longer, we retain only what the law requires and for no longer than it requires.
3.1.1 To improve the efficiency and accuracy of information processing and to reduce its cost, we may need to entrust other parties, such as technical service providers and other partners, with the processing of your personal information. Where we do so, we agree with the entrusted party on the purpose, duration and method of processing, the categories of personal information involved, the protective measures and the rights and obligations of both parties, and we supervise their personal information processing activities. Our service providers have no discretion over the purposes or means of processing your personal data and have no right to use the shared personal information for any other purpose. The technical service providers involved in such scenarios mainly provide the “sign-in” service, for which we share your business mobile number.
We require every company, organisation and individual to whom we provide personal information to process it in accordance with our instructions, this Policy and any other applicable confidentiality and security measures.
Through our products you may connect to third-party services or websites — for example, third-party services that a corporate user connects through the relevant interfaces on our platform. Those third-party services are operated by external third parties. Such third parties do not obtain any user information through us; they must request it from you directly.
Your use of such third-party services (including any personal information you provide to them) is governed by that third party's terms of service and privacy policy, which you should read carefully. This Policy applies only to information collected by us and does not apply to services provided by any third party or to a third party's rules on the use of information. If you have any question or objection regarding a third party's collection or use of personal information, please contact that third party directly.
Where you communicate with a business over WhatsApp, your use of WhatsApp itself is additionally governed by the privacy policy of WhatsApp and Meta.
3.3.1 We share your personal information subject to the principles of lawfulness and legitimacy, data minimisation and purpose specification. We carry out a personal information protection impact assessment before any sharing activity, and apply effective technical safeguards to the output format, transfer and use of the data. At the contractual level, we impose strict information protection obligations and liabilities on our partners and sign data security agreements with business partners before any cooperation begins.
3.3.2 We will not share your information with any third party outside our company, except in the following circumstances:
3.4.1 We will not publicly disclose your personal information to any third party outside our company, except in the following circumstances:
We attach the greatest importance to the security of our users' personal information. We apply security technologies and organisational and management safeguards that meet industry standards, in order to minimise the risk of your information being leaked, damaged, misused, accessed without authorisation, disclosed without authorisation or altered.
Please note that, although we will do our utmost to secure any information you send us, the internet is not a one hundred per cent secure environment, and we do not accept liability for any risk or loss arising from or connected with that fact.
In the unfortunate event of a personal information security incident, we will inform you in accordance with the requirements of laws and regulations of: the basic circumstances of the incident and its possible impact, the measures we have taken or will take in response, suggestions on how you can protect yourself and reduce risk, and the remedies available to you. We will notify you of the relevant procedures promptly by email, letter, telephone or push notification. Where it is difficult to notify each data subject individually, we will publish an announcement in a reasonable and effective manner. We will also report our handling of the incident to the regulator as required.
Despite the reasonable and effective measures described above and our compliance with the standards required by applicable law, please understand that, given the limitations of technology and the possible existence of various unforeseeable means of attack, it is not possible in the internet industry to guarantee the security of information one hundred per cent of the time, however much effort is put into security measures.
You therefore acknowledge and understand that the systems and communication networks you use to access our services may experience problems due to factors outside our control. We strongly recommend that you take active steps to protect the security of your personal information, including but not limited to not scanning QR codes casually with the relevant account and not disclosing your personal information to others.
Once you leave our services and browse or use other websites, services or content resources, we have neither the ability nor a direct obligation to protect any personal information you submit to software or websites outside our services, regardless of whether you signed in to, browsed or used them via a link or a referral from us.
We take your control over your personal information seriously, and we do our utmost to guarantee your rights of access, rectification, deletion and withdrawal of consent, along with your other statutory rights, so that you are fully able to protect your privacy and the security of your personal information.
5.1.1 Except as provided by laws and regulations, you have the right to access and correct the basic information of your personal account at any time, which you can do through the Admin Centre. We will take every appropriate technical step to ensure that you can access, update and correct your own information and the other personal information you provided when using our services, unless disclosing such information would materially and adversely affect the rights of another party. Where you dispute the accuracy of certain personal data or request its correction, you may also ask us to restrict the processing of that data while it is being verified.
5.1.2 To access or correct other personal information generated during your use of our products and services, please contact us at any time. We will respond to your request in the manner and within the period set out in this Policy.
5.2.1 You may request that we delete your personal information, using the contact details in section 8, in any of the following circumstances:
5.2.2 How to request deletion. Send a request to info@dpclouds.com from the email address associated with your account, or — if you are an end user who has messaged a business that uses RPAChat — stating the chat app account (for example the WhatsApp phone number) concerned. We will respond within 15 days telling you how we will handle your request and by when, and we will then permanently delete or anonymise the personal information concerned, or refuse the request and explain why. Corporate users may additionally delete conversations and their associated message data directly in the product.
5.2.3 Once your account is closed or its hosting arrangement is terminated, all service materials and data under that account for the service concerned will be handled in accordance with the Terms of Service. Deletion is irreversible and the data cannot be recovered.
5.3.1 You may change the scope of your authorisation for us to continue collecting personal information, or withdraw your authorisation, by deleting information, turning off device features, adjusting privacy settings and similar means. You may also withdraw your authorisation for us to continue collecting your personal information in its entirety by closing your account.
5.3.2 Please understand that the platform services may require the collection of certain necessary personal information in order to function. When you withdraw your consent, we will no longer be able to provide the corresponding service, but this does not affect the processing already carried out on the basis of your prior authorisation.
5.4.1 If you need to close your account or end a hosting arrangement, please contact us using the details in this Policy and we will tell you how to do so. After closure, we will stop providing the service to you and will delete or anonymise your personal information as instructed by the corporate user, except where laws and regulations provide otherwise.
5.4.2 After your account is closed, the content, information, data and records under that account will be deleted or anonymised (except where laws and regulations or a regulator require otherwise). Account closure is irreversible once complete and cannot be undone.
For information collected on the basis of your consent, you may obtain a copy of the data from us and, where technically feasible, have your personal data transferred from our database to another party.
When exercising this right you must not adversely affect the rights and freedoms of others, and this right does not apply where we act in the public interest or to comply with a legal requirement of the state.
5.6.1 If you are unable to exercise your rights in the ways described above, you may contact us using the details in this Policy. To keep your account secure, we may first ask you to verify your identity before we process your request.
5.6.2 We do not, as a rule, charge for reasonable requests, but we may charge a reasonable cost-based fee for repetitive requests that go beyond what is reasonable. We may refuse requests that are unreasonably repetitive, require disproportionate technical effort, create a risk to the lawful rights and interests of others, or are highly impractical.
5.6.3 Exceptions. We will not be able to respond to your request where it:
Personal information collected and generated in the course of our operations within the People's Republic of China is stored within China. We will provide your personal information to an entity outside China, after performing our obligations under the law, only where:
Where the service is provided to you by our international operating entity, your information may be processed and stored in the jurisdiction in which that entity or its service providers operate, and we apply the safeguards described in section 4 to it in the same way.
Because our services and the technologies behind them are updated and optimised regularly to meet the needs of you and other users, we may update this Privacy Policy. Such changes and revisions form part of this Policy and have the same effect as it. However, we will not restrict the rights you are entitled to under this Policy without your explicit consent.
For material changes, we will also provide a more prominent notice (for certain services this includes an official announcement or an SMS notification, with a link to the updated text explaining what has changed).
Material changes include, but are not limited to:
You can always find the current version of this Policy on this page.
If you wish to make any of the requests described in this Policy, or you have any question, comment or suggestion, please contact us at info@dpclouds.com. We will respond within 15 days of receiving your request.
International operations by GroComm Inc., 440 N Wolfe Road, #240, Sunnyvale, CA 94085, USA.