GDPR and Chat-t36


Last Updated: July 2026

This GDPR information page explains how Chat-t36 handles personal data, including information processed through connected Facebook Pages, Instagram Business accounts, Messenger conversations, comments, leads and other supported communication channels.

This information should be read together with our Privacy Policy, Terms of Use and Data Deletion Instructions.

 

1. What is the GDPR?

The General Data Protection Regulation, commonly known as the GDPR, is a European Union data protection law designed to protect the privacy and personal data of individuals located in the European Economic Area.

The GDPR gives individuals greater control over how their personal data is collected, used, stored, shared and deleted. It also places obligations on organisations that process personal data.

Depending on the circumstances, Chat-t36 may act as a data controller or a data processor. Businesses using our platform are generally responsible for determining why and how their customers' data is processed through their connected social media accounts.

 

2. What is Personal Data?

Personal data means any information that identifies, relates to, describes or can reasonably be linked to an individual.

Personal data may include:

  • Name and username.
  • Email address and telephone number.
  • Profile image and social media profile details.
  • Facebook Page or Instagram account identifiers.
  • Messages, comments, replies and conversation history.
  • Lead information submitted through forms or conversations.
  • IP address, browser details and device information.
  • Login, security and account activity information.
  • Any other information voluntarily provided by a user.

 

3. Information We Process

We may process information that users provide directly when creating an account, purchasing a subscription, contacting support or using features of the platform.

When a business connects a Facebook Page, Instagram Business account or other supported account, we may also process information made available through the relevant platform permissions.

This may include:

  • Connected Page and account information.
  • Page names, usernames and profile identifiers.
  • Messages received by connected business accounts.
  • Comments and replies on connected posts.
  • Conversation participants and message timestamps.
  • Lead details submitted by customers.
  • Access tokens required to provide authorised services.
  • Automation rules, reply templates and workflow settings.

We only process information that is required to operate the features selected and authorised by the user.

 

4. How We Use Personal Data

We may process personal data to:

  • Create and manage user accounts.
  • Authenticate users and protect account security.
  • Connect authorised Facebook and Instagram business assets.
  • Display and manage messages, comments and conversations.
  • Provide automated and AI-assisted reply features.
  • Send replies according to workflows configured by the user.
  • Capture and organise customer leads.
  • Provide customer support and technical assistance.
  • Process subscriptions, invoices and service-related communication.
  • Maintain security, prevent misuse and investigate suspicious activity.
  • Comply with applicable laws and platform requirements.

We do not sell personal data obtained through connected Facebook or Instagram accounts.

 

5. Legal Basis for Processing

Where the GDPR applies, we process personal data using one or more of the following legal bases:

  • Contract: Processing necessary to provide the service requested by a user.
  • Consent: Processing based on permission provided by the individual.
  • Legitimate Interests: Processing required to operate, secure and improve our services, where those interests do not override individual rights.
  • Legal Obligation: Processing required to comply with applicable laws or lawful requests.

 

6. Facebook, Instagram and Meta Platform Data

Chat-t36 may allow users to connect Facebook Pages, Instagram Business accounts and other Meta business assets.

Information received through Meta products is used only to provide the functionality requested by the authorised user. This may include managing messages, comments, replies, leads and automation workflows.

We process Meta Platform Data in accordance with applicable Meta Platform Terms, developer policies and permission requirements.

Users must not use our service to collect, process, send or store information in violation of Meta policies, applicable law or the rights of another person.

 

7. AI-Assisted Replies

Our platform may provide AI-assisted features that help businesses generate, recommend or automate replies to customer messages and comments.

Depending on the feature used, message or comment content may be processed by an authorised AI service provider for the purpose of generating a relevant response.

Users are responsible for reviewing their automation settings, reply instructions and generated responses before using them in customer communication.

Users should not submit highly sensitive personal information, financial credentials, passwords, government identification numbers, medical records or other unnecessary confidential information through AI-assisted features.

 

8. Responsibility of the Platform Operator

We are responsible for implementing reasonable technical and organisational safeguards for personal data processed through our platform.

Our responsibilities may include:

  • Using secure HTTPS connections.
  • Restricting unauthorised access to systems and databases.
  • Protecting account credentials and access tokens.
  • Maintaining access controls and security monitoring.
  • Applying security updates and vulnerability fixes.
  • Maintaining procedures for data deletion requests.
  • Limiting data processing to legitimate service purposes.

No online system can be guaranteed to be completely secure. However, we take reasonable measures designed to reduce the risk of unauthorised access, alteration, disclosure or destruction.

 

9. Responsibility of Business Users

Businesses using Chat-t36 are responsible for their own customer communications and data processing activities.

Business users must:

  • Obtain all required permissions and lawful consent.
  • Provide appropriate privacy notices to their customers.
  • Use connected account data only for legitimate business purposes.
  • Avoid sending spam, deceptive or unlawful communication.
  • Respect opt-out and unsubscribe requests.
  • Protect account credentials and connected social media accounts.
  • Review automation rules and AI-assisted replies.
  • Respond to customer privacy and data deletion requests.
  • Comply with the GDPR and other applicable privacy laws.

 

10. User Responsibilities

Users are responsible for maintaining the confidentiality of their login credentials and for all activities performed through their account.

Users should:

  • Use a strong and unique password.
  • Limit account access to authorised team members.
  • Disconnect former employees or unauthorised users.
  • Review account permissions regularly.
  • Report suspected unauthorised access promptly.
  • Avoid sharing passwords, access tokens or confidential credentials.

 

11. Data Minimisation

We aim to collect and process only the information reasonably necessary to operate the platform, provide requested features, maintain security and comply with legal requirements.

Business users should also avoid collecting unnecessary personal information from their customers.

 

12. Data Retention

Personal data is retained only for as long as reasonably necessary to provide the service, maintain legitimate business records, resolve disputes, protect platform security and comply with legal obligations.

Retention periods may vary depending on the type of information, the user's account status, connected platform requirements and applicable law.

When an account is deleted, we will delete or anonymise personal data within a reasonable period, unless continued retention is required for legal, security, fraud-prevention or compliance purposes.

 

13. Data Deletion

Users may request deletion of their account and associated personal data through the available account settings or by contacting us.

Users may also disconnect connected Facebook Pages, Instagram Business accounts or other supported integrations.

When an authorised deletion request is received, we will take reasonable steps to remove or anonymise the relevant data, subject to legal and technical retention requirements.

Account deletion may be irreversible. Users should export any required business information before submitting a deletion request.

 

14. Individual Rights Under the GDPR

Where applicable, individuals may have the following rights:

  • The right to access personal data.
  • The right to correct inaccurate or incomplete data.
  • The right to request deletion of personal data.
  • The right to restrict certain processing.
  • The right to object to certain processing.
  • The right to data portability.
  • The right to withdraw consent.
  • The right to lodge a complaint with a supervisory authority.

Some requests relating to messages, comments or lead information may need to be submitted directly to the business that collected the information through its Facebook Page, Instagram account or other connected channel.

 

15. Cookies and Sessions

We may use cookies, sessions and similar technologies to authenticate users, maintain login sessions, remember preferences, prevent fraud and improve platform performance.

Some cookies are essential for the service to function. Users may control optional cookies through browser settings or any cookie controls made available on the platform.

Logging out may end the active session, but certain security or preference cookies may remain for a limited period.

 

16. Security

We use reasonable administrative, technical and organisational measures designed to protect personal data.

These measures may include:

  • HTTPS encryption.
  • Password hashing.
  • Database and server access restrictions.
  • Authentication and authorisation controls.
  • Logging of security-related activity.
  • Software updates and security patches.
  • Backups and recovery procedures.
  • Monitoring for suspicious activity.

Users must notify us promptly if they believe their account, credentials, connected social account or customer data has been compromised.

 

17. Data Breach Response

If we become aware of a personal data breach affecting information under our control, we will investigate the incident and take reasonable steps to contain and address it.

Where required by applicable law, we may notify affected users, business customers, regulators or other relevant parties.

 

18. Third-Party Service Providers

We may use trusted third-party service providers for hosting, database management, payment processing, email delivery, analytics, customer support, security and AI-assisted functionality.

These service providers may process personal data only as necessary to provide their services and are expected to use appropriate data protection measures.

 

19. International Data Transfers

Personal data may be processed or stored in countries other than the country in which the user is located.

Where required, we use appropriate safeguards for international data transfers, such as contractual protections or other legally recognised transfer mechanisms.

 

20. Marketing and Bulk Messaging

The use of our platform for bulk or automated messaging is not automatically GDPR compliant merely because a person previously contacted a Facebook Page or Instagram account.

Business users must independently determine whether they have a valid legal basis to send each communication.

Business users must ensure that:

  • The recipient has consented or another lawful basis applies.
  • The message is relevant to the recipient's interaction.
  • The communication complies with Meta messaging policies.
  • The recipient can opt out where legally required.
  • Opt-out requests are respected promptly.
  • Messages are not misleading, abusive or unsolicited spam.

Chat-t36 does not guarantee that a user's campaign, automation or message is compliant with the GDPR or any other law. Compliance depends on how the business configures and uses the service.

 

21. Policy Updates

We may update this GDPR information page periodically to reflect changes in our services, legal obligations, security practices or third-party platform requirements.

Material updates may be communicated through the platform, website, email or another appropriate method.

 

22. Contact Us

For GDPR enquiries, privacy requests or data deletion requests, please contact us using the contact information displayed on our website.

Please include sufficient information to identify your account and describe your request. We may need to verify your identity or authority before completing certain requests.

 

By using Chat-t36, you acknowledge that you have read and understood this GDPR information page.