Data Policy & Privacy Notice

Data Policy & Privacy Notice

Chatfully is a central place to be heard — where people connect with people. We are committed to forming a movement of open and thoughtful professionals*, wherever they communicate. This policy aims to align with our mission by enabling every business to be accessible and helpful so consumers thrive.

We strive for people to communicate better together on the channels they prefer. Everyone who seeks to understand one another in progressive ways that create opportunities and resolutions is welcome.

When using Chatfully, we respectfully request that people behave openly and thoughtfully by:

  • Using Chatfully as intended
  • Practicing empathy
  • Being a source of empowerment

In situations where people act in dismissive and unhelpful ways that does not maintain it as a place to be heard, we abide by our terms of service and user policy. These guidelines apply to all people who interact with Chatfully’s ecosystem of technologies and influence its purpose.

*if you work towards achieving something, you are a professional

1. Introduction & Definitions

This Data Policy & Privacy Notice is designed to help you understand what information we collect at Chatfully, how we use it, how we protect it, and what choices and rights you have under applicable privacy and data protection laws, including the European Union and United Kingdom General Data Protection Regulation (GDPR / UK GDPR), the Health Insurance Portability and Accountability Act (HIPAA), and the EU-U.S. Data Privacy Framework.

Key terms are defined as follows throughout this document:

  • Chatfully LLC (“Chatfully”, “we”, “us”, or “our”) is a California limited liability company headquartered in Sunnyvale, California, USA, that operates the Chatfully platform and website.
  • Customer / Subscriber is the business, organization, or individual with whom Chatfully has entered into an agreement to provide the Services.
  • Personal Data is any information relating to an identified or identifiable natural person (“Data Subject”) as defined under the GDPR and applicable privacy legislation.
  • Electronic Protected Health Information (ePHI) is individually identifiable health information transmitted or maintained in electronic media subject to the HIPAA Security and Privacy Rules.
  • Data Controller refers to the entity that determines the purposes and means of the processing of Personal Data (our Customers with respect to their contacts and conversations; Chatfully with respect to subscriber account and billing data).
  • Data Processor / Service Provider refers to the entity that processes Personal Data on behalf of the Data Controller (Chatfully with respect to customer conversations, message logs, and contact CRM data).

2. About Chatfully & Dual Operating Roles

Chatfully provides a collaborative omnichannel conversational commerce platform that allows our Customers to centralize, manage, analyze, and transfer messages between their business systems and their end-consumers across multiple channels, including SMS/MMS, Web Chat, WhatsApp, Facebook Messenger, Email (Gmail, Outlook/IMAP), and Voice Agents (the “Service”).

Under global privacy frameworks, Chatfully operates in two distinct legal capacities:

  • Chatfully as a Data Processor: When our Customers use the Service to message their contacts, upload CRM contact lists, or receive inbound inquiries, Chatfully processes that data strictly on behalf of and according to the documented instructions of our Customer (the Data Controller), as formalized in our Data Processing Addendum (DPA).
  • Chatfully as a Data Controller: Chatfully acts as a Data Controller for Account Information provided directly by subscribers (e.g., account administrator name, email, billing address, payment details, and website analytics collected on chatfully.io).

3. Collection and Use of Personal Data

Chatfully collects and processes information, including Personal Data, for the following purposes:

  • Providing, maintaining, and managing the Service
  • Routing two-way communications across connected telephony and digital channels
  • Authenticating users and verifying account authorizations
  • Managing billing, invoices, and subscription payments
  • Providing live customer support and technical troubleshooting
  • Detecting, preventing, and mitigating fraudulent, unauthorized, or illegal activity
  • Ensuring compliance with telecommunications regulations (TCPA, CTIA, 10DLC) and privacy laws

This Policy is not intended to place any limits on what we do with data that is aggregated and/or de-identified so that it can no longer be associated with an identifiable natural person or Customer.

Children’s Privacy: Chatfully services are not directed to individuals under the age of 16. If you learn that a child under 16 has provided us with Personal Data without parental consent, please contact us immediately so we can delete such records.

Customer Controlled Data: In the course of providing the Service, Chatfully maintains Personal Data on behalf of our Customers. Our Customers determine what data is collected, how it is used, and how long it is retained. For inquiries regarding how our Customers process your personal information, please contact that business directly.

Account & Billing Information: When an account is created, we collect contact details (name, email, phone number) and billing details. All payment card details are tokenized and processed directly by our PCI-DSS Level 1 certified payment processor (Stripe). Chatfully does not store unencrypted cardholder numbers or CVV security codes on its servers.

Artificial Intelligence (AI) Copilot & Automation: Chatfully provides automated assistance and AI-powered reply suggestions. For standard accounts, AI features utilize deterministic local models or secure enterprise API endpoints. Customer messaging data is never used to train generalized third-party public AI models without explicit consent. In regulated healthcare environments (“HIPAA Mode”), all AI processing is strictly confined to on-premise local models or covered under enterprise Business Associate Agreements.

4. Disclosure & Onward Transfers of Personal Data

Chatfully does not sell, rent, or trade Personal Data to third parties. We disclose Personal Data only in the following limited circumstances:

  • Authorized Subprocessors & Service Providers: We engage reputable third-party service providers to facilitate platform operations, including telecommunications carriers (Twilio, Telnyx, Bandwidth), cloud infrastructure hosting (Google Cloud, AWS), data storage (Backblaze B2), payment processing (Stripe), and transactional email delivery (SendGrid). These subprocessors are bound by written agreements requiring them to maintain equivalent security safeguards and process data strictly according to our instructions.
  • Business Transfers: If Chatfully is involved in a merger, acquisition, corporate reorganization, bankruptcy, or asset sale, customer information may be transferred subject to standard confidentiality protections.
  • Compliance with Laws & Public Authorities: We may disclose Personal Data if required to do so by law, lawful court order, or subpoena, or to meet national security or law enforcement requirements in accordance with applicable legal standards.
  • Protection of Rights & Safety: We may disclose information when necessary to enforce our Terms of Service, prevent fraud or security threats, or protect the vital interests and safety of users or the public.

5. Your Rights (GDPR, UK GDPR, and California Privacy)

If you reside in the European Economic Area (EEA), the United Kingdom, Switzerland, or California, you possess statutory rights regarding your Personal Data under the GDPR, UK GDPR, and California Consumer Privacy Act (CCPA/CPRA):

  • Right of Access (Art. 15 GDPR): You have the right to request confirmation of whether we process your Personal Data and to receive a copy of that data.
  • Right to Rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate or incomplete Personal Data.
  • Right to Erasure / “Right to be Forgotten” (Art. 17 GDPR): You have the right to request the permanent deletion of your Personal Data where statutory grounds apply.
  • Right to Restriction of Processing (Art. 18 GDPR): You have the right to request that we restrict the processing of your data under specific conditions.
  • Right to Data Portability (Art. 20 GDPR): You have the right to receive your Personal Data in a structured, commonly used, and machine-readable format (e.g. JSON or CSV).
  • Right to Object (Art. 21 GDPR): You have the right to object at any time to the processing of your data for direct marketing purposes. You can opt out of SMS marketing at any time by replying STOP.
  • Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw your consent at any time without affecting prior lawful processing.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local Data Protection Authority (DPA) or Supervisory Authority.

Requests Regarding Customer Data: Where Chatfully processes Personal Data on behalf of a Customer (as a Data Processor), data subjects should direct their access, deletion, or correction requests directly to that Customer. We provide automated tools for Customers to export, rectify, or cryptographically purge contact records upon request.

Direct Requests: For data for which Chatfully is the Data Controller, you may submit a request by emailing hello@chatfully.io. We will respond within thirty (30) days following verification of your identity.

6. How We Protect Personal Data (Security & Technical Safeguards)

Chatfully implements robust Technical and Organizational Measures (TOMs) designed to ensure a level of security appropriate to the risk, satisfying the requirements of GDPR Article 32, the HIPAA Security Rule, and SOC 2 Trust Services Criteria:

  • Encryption in Transit: All data transmitted across public networks is encrypted using Transport Layer Security (TLS 1.2 and TLS 1.3) with Perfect Forward Secrecy and Strict Transport Security (HSTS).
  • Encryption at Rest: Platform database stores, backups, and media attachments are protected using industry-standard AES-256 encryption.
  • Multi-Tenant Data Segregation: Customer organizations are partitioned using dedicated organization identifiers and access controls to prevent unauthorized cross-tenant data access.
  • Identity & Access Governance: Access to production systems is governed by least-privilege principles, multi-factor authentication (MFA/2FA), and continuous session validation.
  • Centralized Audit Logging & Monitoring: System activity, administrative actions, and authentication events are recorded in centralized, tamper-evident audit logs retained for security investigations.
  • Vulnerability Management: We conduct regular automated vulnerability scanning, dependency auditing, and independent third-party penetration testing.

7. Healthcare Information & HIPAA Safeguards

Chatfully provides HIPAA-eligible configurations for Customers that are Covered Entities or Business Associates under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the HITECH Act.

For qualified healthcare organizations, Chatfully will enter into a formal Business Associate Agreement (BAA) governing the creation, receipt, maintenance, and transmission of Electronic Protected Health Information (ePHI). When “HIPAA Mode” is enabled:

  • Sessions automatically log off after fifteen (15) minutes of inactivity;
  • Multi-Factor Authentication (MFA) is strictly mandated for all team members;
  • Granular audit trails log every read and write access to patient records, maintained for a minimum of six (6) years;
  • All AI processing is restricted to local on-premise models or covered under verified enterprise healthcare BAAs.

Notice Regarding SMS Communications: Cellular SMS is transmitted across third-party carrier networks in unencrypted form. Covered Entities utilizing SMS to communicate with patients must obtain prior affirmative patient consent following a clear disclosure of risks, or utilize Chatfully’s secure web portal links for transmitting sensitive clinical details.

8. Data Retention, Account Deletion & Cryptographic Purge

We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, including providing the Service, resolving disputes, and satisfying statutory legal, accounting, and reporting requirements.

Account Termination & Erasure: Customers may terminate their subscription and request account deletion at any time via Settings > Billing or by contacting hello@chatfully.io. Upon confirmed deletion of an organization account, Chatfully initiates a cascading purge that permanently deletes:

  • All conversation feeds, message transcripts, and internal notes;
  • All CRM contact lists, custom fields, and segments;
  • All uploaded media attachments, photos, audio recordings, and campaign files.

Basic account identification, licensing history, and transactional financial records may be retained in encrypted archives for up to five (5) years solely to satisfy statutory tax, accounting, and regulatory compliance obligations, after which they are securely sanitized.

9. Cookie Policy & Tracking Consent

Chatfully uses cookies, web beacons, and similar technologies to facilitate session management, authenticate users, remember preferences, and analyze website usage.

  • Strictly Necessary Cookies: Essential for the operation of the Service, enabling navigation, login sessions, and security verification. These cookies do not require consent and cannot be switched off.
  • Performance & Analytics Cookies: With your consent, we utilize analytics tools (such as Google Analytics) to understand visitor interactions and improve website performance. These cookies are gated and deployed only after affirmative opt-in consent on our website.

You can customize your cookie preferences or withdraw consent at any time via our Cookie Settings banner. You may also configure your browser to block cookies, although disabling necessary cookies will impair platform functionality.

10. International Cross-Border Data Transfers (EU-U.S. DPF & Standard Contractual Clauses)

Chatfully operates its primary cloud infrastructure and data processing facilities in the United States. When Personal Data is transferred from the European Economic Area (EEA), the United Kingdom, or Switzerland to the United States, we ensure that an adequate level of data protection is provided through approved legal transfer mechanisms.

EU-U.S. Data Privacy Framework (EU-U.S. DPF):
Chatfully complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union, the United Kingdom (and Gibraltar), and Switzerland to the United States. Chatfully has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) and the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles).

If there is any conflict between the terms in this Data Policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

Standard Contractual Clauses (SCCs):
In addition to our DPF commitments, Chatfully offers and executes the European Commission’s Standard Contractual Clauses (SCCs) (Implementing Decision (EU) 2021/914, Module 2 for Controller-to-Processor and Module 3 for Processor-to-Processor transfers) as well as the UK Information Commissioner’s International Data Transfer Addendum. Our standard SCCs are incorporated directly into our Data Processing Addendum (DPA) to guarantee a resilient, lawful transfer framework under Article 46 of the GDPR.

Accountability for Onward Transfers:
Under the DPF Principles, Chatfully remains liable if our third-party agents or subprocessors process personal information in a manner inconsistent with the Principles, unless we prove that we are not responsible for the event giving rise to the damage.

Regulatory Authority & Enforcement:
The Federal Trade Commission (FTC) has jurisdiction over Chatfully’s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.

Dispute Resolution & Recourse:
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Chatfully commits to resolve DPF Principles-related complaints about our collection and use of your personal information. European Union, UK, and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the DPF should first contact Chatfully at hello@chatfully.io.

If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, you may seek resolution through an independent dispute resolution body at no cost to you. Under certain conditions, more fully described on the Data Privacy Framework website, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.

11. Changes to this Data Policy

This Data Policy may be updated periodically to reflect evolving legal, technical, or business developments. When we update this Policy, we will revise the “Last updated” date at the top of this page. If material changes are made, we will provide prominent notice through the Service or via email prior to the changes taking effect.

We encourage you to review this Data Policy periodically to stay informed about our data protection commitments.

12. Contact Us & Data Protection Officer

If you have any questions, comments, or complaints regarding this Data Policy, our privacy practices, or your rights, please contact our Data Protection Officer:

Chatfully LLC
Attn: Data Protection Officer / Legal Privacy Team
830 Stewart Dr, Sunnyvale, CA 94085, USA
Email: hello@chatfully.io
Phone: +1 (844) 939-2428

Canadian individuals may also contact:
The Office of the Privacy Commissioner of Canada
Call: 1-800-282-1376 | Visit: www.priv.gc.ca

← Back to Legal