Privacy Policy
Last updated: 26 August 2026
Who we are
Hettos (“Hettos”, “we”, “us”) provides a software platform that businesses (“customers”) use to manage their customer conversations across email, WhatsApp, Instagram, Facebook Messenger and website live chat, together with related CRM, quotation and reporting tools. This policy explains what personal data we handle, why, and the choices available to you. For any privacy question, contact support@hettos.io.
Two roles: controller and processor
- For our own website and customer accounts (visitors to hettos.io, people who sign their company up, billing contacts) we act as a data controller.
- For the conversation data inside a customer’s workspace (their end customers’ messages, contact details, tickets, quotations) we act as a data processor: that data belongs to the business using Hettos, and we handle it only on their instructions to provide the service.
Information we handle
- Account data — names, work email addresses, roles and login credentials of the people a customer invites into their workspace.
- Conversation and business content — messages, email content and attachments, contact records, tickets, notes, quotations, bookings and invoices that a customer’s team creates or receives through the platform.
- Connected-channel data — when a customer connects a channel, we receive data from that platform strictly to operate the inbox: messages and sender profile information from the WhatsApp Business Platform, Instagram and Facebook Messenger (Meta Platforms), and email content from connected mailboxes (e.g. Microsoft 365). Access tokens for these connections are stored encrypted and used only to send and receive the customer’s own conversations. We do not sell this data, use it for advertising, or use it to train artificial-intelligence models.
- Usage and technical data — logs, device/browser information and diagnostics needed to keep the service secure and reliable.
- Billing data — subscription and payment status. Card details are collected and stored by our payment provider, never by Hettos.
Why we process it
- To provide, secure and support the service (performance of contract).
- To route, thread and display conversations across connected channels.
- To send service communications such as CSAT surveys or quotation links on a customer’s behalf.
- To bill subscriptions and prevent abuse (legitimate interest / legal obligation).
Platform terms we honour
Use of data received from Meta platforms complies with the Meta Platform Terms and the WhatsApp Business Terms. Use of data received from Microsoft or Google APIs complies with those platforms’ API terms, including the Google API Services User Data Policy’s Limited Use requirements where applicable. Channel connections can be revoked by the customer at any time, which stops further data flow.
Where data lives and who helps us run the service
Hettos runs on vetted infrastructure sub-processors, currently including Vercel (application hosting), Neon (database hosting) and Pusher (realtime notifications), plus the channel platforms a customer chooses to connect. Each sub-processor is bound by data-protection terms. A current list is available on request.
Retention and deletion
Workspace data is retained while the customer’s subscription is active. When a workspace is closed, its data is deleted or irreversibly anonymised within 60 days, except where law requires longer retention (e.g. invoices). Customers can request export or deletion of their workspace data at any time via support@hettos.io.
Your rights
Depending on your location, you may have rights to access, correct, export, delete or restrict processing of your personal data. If you are an end customer of a business that uses Hettos, please contact that business first — they control your data, and we will assist them in fulfilling your request. Otherwise, contact us directly and we will respond within 30 days.
Security
Data is encrypted in transit; credentials and channel tokens are stored encrypted; access within a workspace is governed by per-user roles and module permissions. We notify affected customers without undue delay in the event of a personal-data breach.
Cookies
The application uses strictly necessary cookies for sign-in sessions. The public website does not use advertising or cross-site tracking cookies.
Changes to this policy
We will update this page when our practices change and revise the date above. Material changes are announced to workspace administrators.
Contact
Hettos — support@hettos.io