Skip to content
Legal

Privacy Policy

Last updated: October 2026 · Provided by HexaHub Business Services

1. Who we are

chatworx is a customer messaging platform and website at chatworx.cc. It is a product of HexaHub Business Services, registered in Pakistan ("we", "us"). This policy explains what personal data we handle, why, who we share it with, and how you can have it deleted.

To ask about this policy or your data, use our contact form.

2. Our website

Contact form

When you fill in our contact form, we receive your name, email address and, if you provide them, your company, the channels you use, your expected message volume and your message. The form is sent to our team by email. We use it only to reply to you and to discuss chatworx with you.

To protect the form from abuse, we use your IP address to limit how often it can be submitted. The IP address is kept briefly in server memory for this purpose and is not saved to a database.

Browser storage

The website itself sets no cookies. It saves a few settings in your browser's local storage: your light or dark theme, and whether you have dismissed the announcement bar and the privacy notice. These stay on your device and are not sent to us. You can clear them in your browser settings.

Chat widget

Our website runs the chatworx chat widget so you can message our team. If you use it, we receive your messages, any details you enter (such as your name or email address), your IP address, your browser's user agent and the page you came from. The widget keeps a session token in your browser's local storage so your conversation continues across visits. It does not set cookies.

Analytics and fonts

We use a self-hosted, cookieless analytics tool to see how the website is used: pages viewed, links clicked, and device and browser type. The data is not shared with anyone else or used for advertising. We do not use advertising or cross-site tracking tools. The chat widget loads fonts from Google Fonts, which means Google receives your IP address and browser details when the fonts load. See Google's Privacy Policy.

3. The chatworx platform

Businesses ("customers") use chatworx to talk to their own customers ("end users") across channels such as WhatsApp, Facebook Messenger, email and website chat. Each customer has its own account, and its data is kept separate from other customers' data.

Cloud and self-hosted

chatworx is available as a cloud service that we run, or as a self-hosted version that a customer runs on its own servers. This section describes the cloud service. With the self-hosted version, the customer runs the servers, connects channels with its own accounts and apps (such as its own Meta app), and its own privacy policy applies. We only access a self-hosted installation when the customer gives us access, for example for setup or support, and then only on its instructions.

Who controls the data

The customer decides which channels to connect, who to message and what to keep, so the customer controls its end users' data. We process that data on the customer's behalf, only to provide the service. If you have messaged a business that uses chatworx, that business is responsible for your data, and you should contact it first.

What the platform stores

  • Customer users: name, email address, a securely hashed password, sign-in times, IP addresses and browser details, and settings.
  • End-user contacts: name, phone number, email address, channel identifiers (such as a WhatsApp number or Facebook ID), profile name, and any details the customer adds.
  • Conversations: messages, attachments, delivery and read status, internal notes, assignments and satisfaction ratings. Files are scanned for viruses when they are uploaded.
  • Activity records: audit logs of actions in an account, including the IP address and browser used, and server logs used to run and secure the service.

How we use it

We use this data only to provide the service: to deliver and display messages, run the automations and chatbots the customer sets up, show reports, provide support, and keep the service secure. Authorised staff may access an account to provide support or fix a problem, and that access is logged.

We do not use customer or end-user data to train AI models, and we do not make automated decisions about people that have legal or similarly significant effects on them.

4. WhatsApp and other Meta products

Customers can connect WhatsApp through Meta's WhatsApp Business Platform (Cloud API), and can connect Facebook Pages for Messenger conversations and page comments. Customers currently connect these channels using their own Meta app, and we process the data on their behalf as their service provider. When a customer connects one of these channels:

  • Messages, media, phone numbers and delivery status pass between chatworx and Meta so that messages can be sent and received.
  • We receive the end user's WhatsApp phone number and profile name (or Facebook user ID and name) from Meta, and use them only to support conversations with that person.
  • We use data received from Meta only to provide chatworx to that customer. We do not sell it, use it for advertising or profiling, or share it with anyone except as needed to run the service or as the law requires.
  • The customer must get end users' consent before sending them WhatsApp messages, and must honour requests to stop, as required by Meta's WhatsApp Business Messaging Policy.

Meta handles this data under its own Privacy Policy and the WhatsApp Business Terms. We follow Meta's Platform Terms. If a security incident affects data received from Meta, we will notify Meta and the affected customers.

5. Google and Microsoft email accounts

Customers can connect a Gmail or Microsoft 365 / Outlook mailbox by signing in with Google or Microsoft. When they do:

  • We access the connected mailbox to read incoming emails and send replies, and we receive the mailbox's email address. Emails are shown as conversations in the customer's chatworx account.
  • We store the access tokens needed to stay connected, encrypted. We use the mailbox data only to provide the email features the customer has turned on, not for advertising, and we do not sell it or use it to train AI models.
  • To disconnect a mailbox, ask us through our contact form. Access can also be revoked at any time in the Google account permissions page or the Microsoft My Apps page.

chatworx's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google handles data under its own Privacy Policy.

6. Who we share data with

We do not sell personal data. We share it only with:

  • Messaging channels the customer connects, such as Meta (WhatsApp and Facebook Messenger) and the customer's own email provider (including Google or Microsoft if the customer signs in with them), so that messages can be delivered.
  • Services the customer chooses, such as webhooks, bots or an AI provider the customer configures. Data sent there is handled under that service's own terms.
  • Providers that help us run the service, such as hosting and font services, only as needed for their part. Emails from the cloud service and this website are sent through our own mail server.
  • Authorities, when the law requires it.

We do not sell personal information or share it for targeted advertising.

Each cloud customer's data is hosted in the region agreed with that customer, and we tell customers which providers and countries hold their data. These services may be in other countries, so your data may be processed outside the country where you live. Where data protection law requires it, we use appropriate safeguards for these transfers, such as the European Commission's Standard Contractual Clauses.

7. Why we are allowed to use data

Where laws such as the GDPR apply, we rely on these legal grounds:

  • Contract: to provide chatworx to customers and their users, and to take steps you ask for before signing up.
  • Legitimate interests: to reply to enquiries and chat messages, and to keep the website and service secure, for example by limiting form submissions and keeping logs.
  • Legal obligation: where the law requires us to keep or share data.
  • The customer's instructions: for end-user data we process on a customer's behalf, the customer decides and is responsible for the legal ground.

8. Security

Connections to chatworx use HTTPS. Passwords are hashed, and channel credentials and access tokens are encrypted before they are stored. Each customer's data is kept separate, and access within an account depends on each user's role. No system is completely secure, but we work to protect the data we hold and will tell affected customers if a breach involves their data.

9. How long we keep data

  • Contact form enquiries: kept in our email for as long as we need them to reply and follow up, or until you ask us to delete them.
  • Platform data: kept while the customer's account is active, or until the customer deletes it or asks us to.
  • After an account closes or a channel is disconnected: we delete the related data, including data received from Meta, Google or Microsoft, within 90 days, unless the law requires us to keep it.
  • Server logs: deleted automatically after 7 to 30 days.

10. Your rights and deleting your data

Depending on where you live, you may have the right to see, correct or delete your personal data, to object to how it is used, or to complain to a data protection authority. See Data Deletion for how to ask us to delete data. If your data came from a business that uses chatworx, contact that business first. We will help it respond.

11. Children

chatworx is a service for businesses and is not directed at anyone under 16. If you think a child has given us personal data, use our contact form and we will delete it.

12. Changes to this policy

We may update this policy as chatworx changes. We will post the new version on this page and update the date at the top. If a change materially affects how we handle customer data, we will tell customers before it takes effect.