Privacy Policy
Last updated: 9 August 2026
CHIC EXPERT LTD, trading as ReceptionIQ ("ReceptionIQ", "we", "us"), provides an AI receptionist that businesses ("Customers") connect to their WhatsApp Business, Instagram, Facebook Messenger and website channels so the AI can answer customer enquiries, qualify leads and manage appointments. This policy explains what data we process, why we process it, how long we keep it, who we share it with, and how you can exercise your rights, including deletion.
It applies to our website, the ReceptionIQ application and the chat widget we serve on Customer websites.
1. Who is responsible for your data
- Your account and billing data: ReceptionIQ is the controller. We decide how that data is used to run and bill the service.
- Messages from your own end customers: you (the business) are the controller and ReceptionIQ is a processor acting on your documented instructions, which are the settings, knowledge base and channel connections you configure in the product.
- If you are an end customer messaging a business that uses ReceptionIQ, that business decides how your enquiry is handled. Please contact them first; we will forward requests we receive on their behalf.
2. Data we process
Account data
- Name, email address, profile avatar and authentication identifiers.
- Passwords are never stored in readable form; authentication is handled by our managed auth provider.
- Team members you invite, their role (owner, admin, manager, agent, viewer) and invitation status.
Business configuration data
- Business name, industry, description, website, contact email and phone, address, country and timezone.
- Opening hours, closed dates, services, durations, prices and booking rules.
- AI configuration: assistant name, personality, tone, greeting and farewell messages, escalation rules, confidence thresholds and lead-capture preferences.
- Knowledge base content you upload or write: documents, FAQs, product and service information, and custom instructions. Uploaded documents are stored in a private bucket that is not publicly readable.
Conversation and customer data
- Messages exchanged between your customers and the AI or your team, across the website widget, WhatsApp, Instagram and Messenger.
- Contact details a customer shares in a conversation, such as name, email, phone, city and country.
- Derived data: conversation summaries, sentiment, quality and confidence scores, lead status, lead score, tags and internal notes your team adds.
- Appointments created from conversations, including the customer name, contact details, service, time and any notes.
- AI request logs containing the prompt context, model used, latency, token counts and any error, used for debugging, abuse prevention and billing accuracy.
Connected social platform data
- When you connect a Meta channel, we receive from Meta only what is needed to operate messaging: your WhatsApp Business Account and phone number identifiers, your Facebook Page identifier and name, your Instagram Business account identifier and username, and the access token issued to ReceptionIQ.
- Inbound webhooks from Meta deliver message content plus the platform-scoped sender identifier (a WhatsApp number, an Instagram-scoped ID or a Page-scoped ID). We use these solely to thread the conversation and reply to the right person.
- We do not read your social media followers, contact lists, ad accounts, insights or content unrelated to the messaging inbox, and we do not post to your accounts.
- If you connect Google Calendar, we process calendar identifiers and the events ReceptionIQ creates or updates for bookings.
Billing data
- Subscription plan, status, trial and renewal dates, and the identifiers our payment provider assigns to your customer and subscription records.
- Card and bank details are collected and stored by Stripe, Inc. They are never sent to or stored on our servers.
Technical data
- Log records, IP address, device and browser information, timestamps, request identifiers and error diagnostics.
- Essential cookies that keep you signed in and protect the service, plus analytics and preference cookies only where you have consented. See our Cookie Policy.
3. How and why we use data
- To deliver the service: generate AI replies grounded in your knowledge base, thread conversations across channels, qualify leads, book and reschedule appointments, and notify your team.
- To connect your channels: exchange and refresh Meta access tokens, subscribe your assets to webhooks, and send replies from your own connected accounts.
- To keep the platform secure: webhook signature verification, rate limiting, abuse and fraud detection, and audit logging.
- To bill and support you: manage subscriptions, trials, invoices and support requests.
- To improve reliability: aggregated, non-identifying diagnostics and usage measurement.
We do not sell personal data, we do not use your conversations for advertising, and we do not permit our AI providers to train foundation models on your conversation content.
4. Legal bases (UK and EU customers)
- Contract: providing the service you subscribed to, including channel connections and billing.
- Legitimate interests: securing the platform, preventing abuse, and improving reliability in ways you would reasonably expect.
- Consent: non-essential cookies and optional marketing email, which you can withdraw at any time.
- Legal obligation: tax, accounting and lawful requests.
5. Sharing and third-party services
- Meta Platforms — delivery of WhatsApp, Instagram and Messenger messages for the accounts you connect. Meta processes that message traffic under its own terms and privacy policy.
- Stripe, Inc. — payment processing, subscription management, invoicing, receipts and tax determination. Stripe acts as an independent controller for payment data.
- Google — only if you connect Google Calendar, for appointment synchronisation.
- Cloud hosting, database, storage and authentication providers — the managed infrastructure that runs the application.
- AI model providers — the conversation context needed to generate a reply, under contractual terms that prohibit training on that content.
- Email delivery — transactional and authentication email.
- Professional advisers and authorities — where legally required, or in connection with a merger or acquisition, in which case we will notify you.
6. Storage, security and access control
- Data is encrypted in transit (TLS) and at rest.
- Every workspace record is protected by database-level row-level security, so members of one business cannot read another business's conversations, customers, credentials or channel data.
- Channel access tokens, application secrets and webhook verify tokens are readable only by our server. The application interface receives connection status only, never the raw credential.
- Sensitive integration credentials live in a managed secret store, and inbound webhooks are rejected unless the platform signature and per-channel verify token are valid.
- Access inside ReceptionIQ is limited to staff who need it to operate or support the service.
7. International transfers
Our infrastructure and processors may store or process data outside the United Kingdom and the European Economic Area. Where that happens we rely on adequacy decisions or the UK International Data Transfer Addendum and EU Standard Contractual Clauses, together with technical safeguards such as encryption.
8. Retention
- Conversations, messages, customers, leads and appointments: kept while your account is active so the AI has context and your team has history.
- AI request logs and technical logs: retained for up to 12 months for debugging, security and billing accuracy.
- Channel credentials: deleted immediately when you disconnect a channel; disconnecting also stops all message processing for that channel.
- Account and workspace data: deleted within 30 days of an account deletion request.
- Billing and tax records: retained for up to 7 years where law requires it.
- Backups are rotated on a rolling schedule and purge deleted data within 90 days.
9. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, export a portable copy, restrict or object to processing, withdraw consent, and not be subject to a solely automated decision with legal or similarly significant effects. AI replies are message drafting and routing; they do not make legal or financial decisions about anyone, and you can take over any conversation from your team inbox.
We respond to rights requests within 30 days. Verification may be required so we do not disclose data to the wrong person.
10. How to request deletion
- Disconnect a channel: open Channels in the app and choose Disconnect. This removes the stored access token and stops processing for that channel immediately, even if your subscription has lapsed.
- Delete specific records: conversations, customers, leads, appointments and knowledge base items can be deleted from within the app by an owner or admin.
- Delete your whole account: email dawood@receptioniq.uk from the address on the account with the subject "Account deletion". We confirm within 5 working days and erase your workspace data within 30 days, except records we must keep for legal, tax or fraud-prevention reasons.
- End-customer requests: if you messaged a business using ReceptionIQ and want your messages removed, contact that business. If you contact us directly we will pass your request to them and support them in fulfilling it.
11. Data breaches
If a personal data breach affects your data, we will notify the relevant supervisory authority within 72 hours where required, and notify you without undue delay when the breach is likely to result in a high risk to individuals.
12. Children
ReceptionIQ is a business tool and is not directed at anyone under 16.
13. Changes to this policy
We will post material changes on this page and update the date above. Continued use of the service after a change means you accept the updated policy.
14. Contact us
CHIC EXPERT LTD (trading as ReceptionIQ) — privacy enquiries: dawood@receptioniq.uk
If you are in the UK you may also complain to the Information Commissioner's Office; in the EEA, to your local supervisory authority.