1. Data controller
The data controller is Merktop LLC, operator of Merkchat. Address: 1613 G St, Aurora, Nebraska 68818 (USA). Contact for privacy matters: [email protected].
2. Our role: controller and processor
Merkchat is a tool for businesses (B2B). We therefore act in two distinct capacities:
- As controller: for the account data of our customers (the person or company that subscribes to Merkchat) and service usage data.
- As processor: for the personal data of end customers (the contacts who message the business via WhatsApp, Instagram, Telegram, etc.). In that case, the business using Merkchat is the controller and we process the data following its instructions, under Art. 28 GDPR. A Data Processing Agreement (DPA) is available on request.
3. What data we process
Account data (customer): name, email, password (stored hashed), organization/workspace, role and preferences.
Customer's contact data (processed on the business's behalf): name, phone number, channel identifiers (WhatsApp/Instagram/Telegram/etc.), message content, attachments (audio, images, documents), internal notes, tags, pipeline stage, estimated value and other CRM fields.
Channel integrations: access tokens for the accounts the customer connects (WhatsApp/Evolution, WhatsApp Cloud, Meta/Instagram, Telegram, IMAP email). Tokens are stored encrypted.
Payment data: we use Stripe for billing; we do not store full card details.
Technical and usage data: IP address, device and browser type, activity logs, usage metrics and error diagnostics.
4. Purposes and legal basis
- Providing the service (receiving/sending messages, AI drafting, CRM, broadcasts, payments). Basis: performance of the contract (Art. 6(1)(b)).
- Managing the account, billing and support. Basis: performance of the contract and legal obligation (Art. 6(1)(c)).
- Improving and securing the service (diagnostics, abuse/fraud prevention, aggregated metrics). Basis: legitimate interest (Art. 6(1)(f)).
- Service and, where applicable, marketing communications. Basis: legitimate interest or consent (Art. 6(1)(a)), revocable at any time.
5. Artificial intelligence and automation
To draft suggested replies, the relevant conversation content (chat history and instructions) is sent to our language-model provider. We may also transcribe voice notes and describe images via AI providers. This data is processed solely to generate the suggestion and is not used to train third-party models without a valid legal basis.
Human control: by default, no message is sent without a person's approval. We do not make decisions producing legal effects based solely on automated processing within the meaning of Art. 22 GDPR; the AI only proposes and a human decides (unless the customer explicitly enables automatic sending per chat).
6. Providers and sub-processors
We rely on providers that process data on our behalf, under contract and with adequate safeguards:
- AI providers (reply drafting, transcription and vision).
- Meta Platforms (Instagram, Messenger, WhatsApp Cloud) for the channels connected by the customer.
- Stripe (payment processing and billing).
- Infrastructure/hosting provider (servers, database and cache).
- Transactional email provider (service emails).
- Error-monitoring tool (technical diagnostics).
We keep an up-to-date list of sub-processors available on request at [email protected].
7. International transfers
Some of our providers are located outside the European Economic Area. When we transfer personal data outside the EEA, we do so with the safeguards required by the GDPR (e.g., adequacy decisions or Standard Contractual Clauses from the European Commission), together with additional measures where appropriate. You can request more information about these safeguards by contacting us.
8. Retention periods
We keep data while the account is active and for as long as necessary for the described purposes, or to comply with legal obligations (e.g., tax and accounting). After account closure, we delete or anonymize the data within a reasonable period, unless legally required to retain it.
9. Security
We apply appropriate technical and organizational measures: encryption of secrets and tokens, role-based access control, authentication, per-workspace data isolation (multi-tenant), backups and activity logging. No system is 100% secure, but we work to protect your data.
10. Your rights
Under the GDPR, you have the right to:
- Access your data.
- Rectify inaccurate data.
- Erasure (“right to be forgotten”).
- Restriction of processing.
- Portability of your data.
- Object to processing based on legitimate interest.
- Withdraw consent at any time.
To exercise them, write to [email protected]. If the data belongs to an end customer, direct your request to the business that uses Merkchat (we will assist them as processor). You also have the right to lodge a complaint with the competent supervisory authority.
11. Data deletion
You can request deletion of your account and its data by writing to [email protected]. For data obtained through Meta platforms (Instagram/Messenger/WhatsApp), you can request deletion by the same means and we will process it in accordance with those platforms' requirements.
12. Minors
Merkchat is intended for businesses and professionals. It is not directed to children under 16 and we do not knowingly collect their data.
14. Changes to this policy
We may update this Policy. We will publish the current version on this page with its update date and, if changes are material, notify you by a reasonable means.
15. Contact
For any privacy question, write to [email protected].