Skip to content

Legal

Privacy Policy

Last updated: October 1, 2026

1. Introduction

This Privacy Policy describes how VOOM Digital ("we," "us," or "our"), the publisher and operator of the SafqAI software brand, collects, uses, and shares information when you use our WhatsApp Business Platform and related services ("Services").

VOOM Digital is a Zoho partner and integrator. SafqAI Studio is developed and operated by VOOM Digital to connect SafqAI with Zoho CRM. The Studio section added on October 1, 2026 describes its additional processing. The September 26, 2026 policy below continues to describe our existing services, including the Claude connector. This addition does not replace or reduce commitments already applicable to those services or their data.

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Data Controller Contact: hello@safq.ai

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, phone number, company name, billing information
  • Business Data: Customer lists, conversation histories, product information
  • Communication Data: Messages and media shared through our platform
  • Payment Information: Processed securely through Stripe (we don't store card details)

2.2 Automatically Collected Information

  • Usage Data: Features used, conversation metrics, API calls
  • Device Information: IP address, browser type, operating system
  • Log Data: Access times, pages viewed, system activity
  • Location Data: Approximate location based on IP address

2.3 Information from Third Parties

  • Social Media Platforms: When you connect WhatsApp, Instagram, Facebook Messenger
  • OAuth Providers: Profile information from Google or Facebook login

3. How We Use Your Information

3.1 Primary Purposes

  • Provide and maintain our Services
  • Process conversations and messaging automation
  • Handle customer support and respond to inquiries
  • Process payments and manage subscriptions
  • Send service updates and important notifications

3.2 Legal Basis for Processing (GDPR)

  • Contract Performance: To provide Services you've requested
  • Legitimate Interests: To improve our Services and ensure security
  • Consent: For marketing communications
  • Legal Obligations: To comply with applicable laws

4. Data Sharing and Disclosure

4.1 We share data with:

  • Communication Providers: Meta (WhatsApp, Instagram, Messenger)
  • Infrastructure Providers: DigitalOcean (inbox platform and its database, Frankfurt, Germany), Railway (website, account database and the Claude connector)
  • Payments: Stripe (we don't store card details)
  • Email Providers: Resend (account emails), smtp2go (emails sent by the inbox platform)
  • AI Assistants: Anthropic, only when you connect Safqai to Claude (see Using Safqai with Claude)

4.2 We do NOT:

  • Sell your personal data
  • Share data for third-party marketing
  • Transfer data outside the EU without appropriate safeguards

5. Data Retention

  • Active Account Data: As long as your account is active
  • Conversation Data: 3 years after last activity (configurable)
  • Financial Records: 7 years per legal requirements
  • Marketing Data: Until consent withdrawn

Upon account termination, we delete or anonymize your data within 30 days, except where retention is required by law.

6. Your Rights

You have the right to:

  • Access: Request copies of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion ("right to be forgotten")
  • Portability: Receive your data in a machine-readable format
  • Restriction: Limit processing of your data
  • Object: Oppose certain processing activities
  • Withdraw Consent: At any time for consent-based processing

To exercise these rights, contact: hello@safq.ai. Response time: Within 30 days.

7. Cookies and Tracking

7.1 Types of Cookies We Use

  • Essential Cookies: Required for platform functionality
  • Analytics Cookies: Performance monitoring
  • Functional Cookies: Remember preferences and settings

8. Data Security

We implement industry-standard security measures:

  • Encryption in transit (TLS/SSL)
  • Encryption at rest for sensitive data
  • Regular security audits
  • Access controls and authentication

9. International Data Transfers

Your data is primarily processed in secure data centers. When transferred internationally, we use Standard Contractual Clauses (SCCs) and ensure adequate protection levels.

10. Children's Privacy

Our Services are designed for business use. We do not knowingly collect data from individuals under 16.

11. Using Safqai with Claude

When you connect Safqai to Claude, an AI assistant made by Anthropic, Claude can read and act on your Safqai data through the Safqai connector. It works with your own Safqai user and permissions: Claude sees and does only what you can.

What the connector accesses

Only what a request you make in Claude needs: conversations, messages, contacts, labels, templates, campaigns, reports and inbox settings in the Safqai accounts your user can access.

What we keep

The connector does not store your conversations or contacts. We keep:

  • The authorisation linking your Claude connection to your Safqai user, until you disconnect or we revoke it.
  • Technical logs for operating and debugging the connector: time, the Safqai user making the request, the tool used, the names of the parameters sent (not their values), success or failure, and duration. Message text is not logged. Logs are kept only as long as our hosting provider retains service logs.

Where

Your Safqai inbox data stays on our servers in Frankfurt, Germany. The connector itself runs on Railway and passes data between Safqai and Claude without storing it.

Sharing

Data the connector returns to Claude is processed by Anthropic under your agreement with Anthropic and Anthropic's privacy policy. We don't sell it, use it for advertising, or use it to train AI models.

Actions

Claude asks for your confirmation before sending messages or broadcasts, submitting templates to Meta, sending conversion events to Meta, changing your public business profile, or deleting data. Reading and searching don't need confirmation.

Control

You can disconnect Safqai in Claude's settings at any time. To revoke access from our side or ask a question, write to hello@safq.ai. Setup and troubleshooting are covered in Connect Safqai to Claude.

SafqAI Studio for Zoho CRM

Section added October 1, 2026 · Section ajoutée le 1er octobre 2026

Confidentialité Studio — français

Cette section décrit les traitements propres à Studio. Les engagements des services SafqAI existants restent applicables aux données du compte partagé, de la plateforme de messagerie et du connecteur Claude qu’ils couvrent. Votre organisation choisit les champs CRM utilisés pour la messagerie, les boîtes de réception et les utilisateurs autorisés ; VOOM Digital exploite Studio et son assistance.

Les traitements nécessaires au compte et à l’assistance reposent sur l’exécution du contrat de service ; la sécurité et la prévention des abus reposent sur l’intérêt légitime de VOOM Digital. Pour les données de ses clients issues du CRM et de la messagerie, votre organisation détermine les finalités et reste responsable de leur utilisation ; VOOM Digital les traite pour son compte afin de fournir les fonctions Studio demandées.

Données conservées et finalités

Studio conserve les identités des utilisateurs, l’organisation Zoho et le compte de messagerie associés, les membres, rôles et accès aux boîtes de réception. Il enregistre la structure CRM découverte, les champs autorisés, le champ téléphone utilisé pour retrouver les conversations et les règles associant les fiches aux boîtes de réception. Les configurations antérieures, y compris leurs libellés et finalités, restent conservées selon les modalités décrites ci-dessous, même si la fonction correspondante n’est plus disponible. Ces informations permettent de maintenir votre espace et de contrôler les opérations autorisées. Les textes libres et libellés peuvent contenir des données personnelles. Les jetons de connexion Zoho et de messagerie sont conservés chiffrés ; les tentatives de connexion et de révocation laissent également des traces techniques nécessaires à leur traitement.

Fiches CRM, conversations et permissions

La connexion administrateur permet de découvrir la structure CRM. Chaque employé autorise séparément la lecture utile à la messagerie, sous ses propres droits Zoho et les restrictions de Studio. Ces parcours ne demandent pas de droits d’écriture dans le CRM. Studio lit le champ téléphone sélectionné et les champs nécessaires aux règles de routage pour retrouver les conversations accessibles à cet utilisateur. Ces fonctions n’enregistrent pas une copie des fiches ou de l’historique des conversations dans Studio.

Les messages consultés, modèles et paramètres d’envoi transitent également par Studio. Un message envoyé reste enregistré dans le service de messagerie connecté et utilise le canal concerné, notamment WhatsApp. Les boîtes accessibles dépendent des droits Studio et du jeton personnel de messagerie ; un lecteur ne peut pas envoyer. Les cookies servent à l’authentification ; le navigateur peut conserver temporairement les identifiants du contexte d’une fiche lors de son ouverture hors du widget.

Hébergement et IA

L’application Studio et sa base de données sont hébergées par Railway en Californie, aux États-Unis. Les données échangées avec Zoho, le service de messagerie et ses canaux relèvent aussi de ces services. L’absence de copie applicative décrite ci-dessus ne signifie pas qu’aucune trace technique ou copie fournisseur n’existe ; elle ne garantit pas non plus un stockage limité à l’Union européenne. Pour connaître les conditions contractuelles applicables à votre service et aux transferts, contactez hello@safq.ai.

La version Studio décrite ici n’active aucune fonction d’IA et ne transmet pas les données CRM ou de messagerie à un fournisseur de modèles d’IA. Les traitements du connecteur Claude, lorsqu’il est utilisé séparément, restent décrits dans sa section dédiée ci-dessus.

Conservation, retrait et demandes

Les données propres à l’espace, sa configuration et ses identités sont conservées pour maintenir cet espace jusqu’à sa clôture. Pour demander la clôture ou l’effacement, contactez hello@safq.ai. Le compte SafqAI partagé et l’abonnement sont traités séparément. Les accès OAuth servent tant que la connexion est active ; après retrait, l’usage local est bloqué et les secrets nécessaires à une révocation encore en attente restent chiffrés jusqu’à sa confirmation.

Retirez les connexions CRM personnelles et de messagerie, puis la connexion d’organisation. Le retrait messagerie supprime la copie du jeton dans Studio, sans le révoquer chez le service source. Désinstaller l’extension Zoho ne supprime pas automatiquement les données Studio, les fiches CRM ou les messages déjà transmis. Les instructions figurent dans le guide Studio.

Vous pouvez contacter hello@safq.ai pour l’accès, la correction ou la suppression de vos données, et pour exercer les autres droits prévus par la législation applicable. Nous vérifions votre identité et votre habilitation avant une intervention sur un espace. Une demande à Studio ne modifie pas automatiquement les systèmes CRM et de messagerie de votre organisation. N’envoyez aucun jeton ni conversation complète au support. Les coordonnées de VOOM Digital figurent en fin de page.

Studio privacy — English

This section describes processing specific to Studio. Existing SafqAI service commitments continue to apply to the shared account, messaging platform and Claude connector data they cover. Your organisation chooses the CRM fields used for messaging, inboxes and authorised users; VOOM Digital operates Studio and its support.

Processing necessary for the account and support is based on performance of the service contract; security and abuse prevention rely on VOOM Digital's legitimate interests. Your organisation determines the purposes and remains responsible for its use of customer data from CRM and messaging; VOOM Digital processes that data on its behalf to provide the requested Studio functions.

Stored information and purposes

Studio keeps user identities, the linked Zoho organisation and messaging account, members, roles and inbox permissions. It stores the discovered CRM structure, permitted fields, the phone field used to find conversations and rules associating records with inboxes. Earlier configurations, including their labels and purposes, remain stored under the retention terms below, even when the corresponding feature is no longer available. These support your workspace and access controls. Free text and labels may contain personal information. Zoho and messaging connection tokens are stored encrypted; connection and revocation attempts also leave technical records needed to process them.

CRM records, conversations and permissions

The administrator connection discovers the CRM structure. Each employee separately authorises the reads needed for messaging, subject to their own Zoho permissions and Studio restrictions. These flows do not request CRM write permissions. Studio reads the selected phone field and fields needed by routing rules to find conversations accessible to that user. These functions do not save a copy of CRM records or conversation history in Studio.

Viewed messages, templates and sending parameters also pass through Studio. A sent message remains stored in the connected messaging service and uses the relevant channel, including WhatsApp. Inbox access depends on Studio permissions and the personal messaging token; viewers cannot send. Cookies support authentication, and the browser may temporarily keep record-context identifiers when a record is opened outside the widget.

Hosting and AI

The Studio application and its database are hosted by Railway in California, United States. Data exchanged with Zoho, the messaging service and its channels is also processed by those services. The absence of an application copy described above does not mean that no technical logs or provider copies exist, or guarantee storage exclusively within the European Union. Contact hello@safq.ai for the contractual terms applicable to your service and international transfers.

The Studio version described here has no active AI features and does not send CRM or messaging data to an AI model provider. Processing by the Claude connector, when used separately, remains described in its dedicated section above.

Retention, withdrawal and requests

Workspace-specific data, configuration and identities are kept to maintain the workspace until its closure. To request closure or erasure, contact hello@safq.ai. The shared SafqAI account and subscription are handled separately. OAuth access is used while its connection remains active; withdrawal blocks local use, while secrets needed for a pending remote revocation remain encrypted until revocation is confirmed.

Withdraw personal CRM and messaging connections before the organisation connection. Disconnecting messaging removes Studio's token copy without revoking the token at its source. Uninstalling the Zoho extension does not automatically erase Studio data, CRM records or messages already sent. See the Studio guide for instructions.

Contact hello@safq.aito request access, correction or erasure, or to exercise other rights under applicable law. We verify your identity and authority before acting on a workspace. A Studio request does not automatically change your organisation's source CRM or messaging systems. Do not send tokens or complete conversations to support. VOOM Digital's contact details are below.

12. Changes to This Policy

We may update this policy periodically. Material changes will be notified via email or platform notification 30 days before taking effect.

13. Contact Us

  • Publisher and operator / Éditeur et opérateur : VOOM Digital — SafqAI software brand / marque logicielle SafqAI
  • Email: hello@safq.ai
  • Website: safq.ai
  • Headquarters / Siège : Sharjah Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
  • Morocco address / Adresse au Maroc : Sidi Maarouf, Lotissement Hafid Al Khair n°107, Casablanca, Maroc

Effective Date: September 26, 2026

Studio section added: October 1, 2026 · Ajout de la section Studio : 1er octobre 2026