Privacy Policy
Last updated: July 2, 2026
Overview
HandleHQ (“we”, “us”, “our”) provides AI-powered customer message handling for businesses. This policy explains what personal data we handle, why, and what rights you have. It covers both visitors to handlehq.net and users of the HandleHQ platform.
Our two roles
We handle personal data in two distinct roles, and different documents apply to each:
- Data controller - for data about our own account holders, applicants, and website visitors (your name, business details, billing, usage). This policy governs that data.
- Data processor - for data about our business customers' end-customers (the people who message those businesses via WhatsApp or email). We process that data on our customers' behalf and under their instructions. Our Data Processing Agreement governs that processing.
If you are an end-customer of a business that uses HandleHQ, that business is the controller of your data. Please direct privacy questions and requests to the business you contacted; we will forward any request we receive directly to them.
What we collect as controller
- Account and application data - name, email address, phone number, and business details provided when you apply, sign up, or contact us.
- Billing data - subscription and payment records. Card details are collected and stored by our payment provider, Stripe; we do not store full card numbers.
- Usage data - basic analytics about how your account uses the platform (conversation volume, response times, channel activity).
- Support communications - messages you send us by email or through the site.
End-customer data we process for our customers
- Message content - messages sent by our customers' end-customers via WhatsApp or email that are routed through HandleHQ.
- Ticket data - structured information extracted from those conversations (for example names, contact details, request types, budgets), stored in the customer's dashboard.
Legal bases (GDPR Article 6)
Where the GDPR or similar law applies to data we control, we rely on:
- Contract - to provide the service you signed up for, including processing messages and billing.
- Legitimate interests - to secure our systems, prevent abuse, and improve the product in ways you would reasonably expect.
- Legal obligation - to keep billing and tax records we are required to keep.
- Consent - for anything else, such as optional marketing communications, which you can withdraw at any time.
Where we act as processor, our customer (the controller) is responsible for the legal basis, and we process only on their instructions.
How we use data
- To provide the HandleHQ service - processing messages, creating tickets, and delivering responses.
- To configure and improve your AI agent based on the business information you provide.
- To communicate with you about your account, updates, and support requests.
- To monitor system health and diagnose technical issues.
We do not sell your data or your customers’ data. We do not use your data or your end-customers’ data to train AI models without your explicit consent.
How AI processing works
Message content routed through HandleHQ is sent to OpenAI's API to extract structured ticket information and generate draft responses. Under OpenAI's API terms, data submitted via the API is not used to train OpenAI's models. AI output is made available to the business you contacted for their review; HandleHQ does not make automated decisions about individuals that produce legal or similarly significant effects.
Third-party services
HandleHQ uses the following providers to operate. Each has its own privacy policy:
- OpenAI - processes message content to extract structured data and generate AI responses. OpenAI Privacy Policy →
- SendGrid (Twilio) - handles inbound and outbound email routing. Twilio Privacy Policy →
- Meta (WhatsApp Cloud API) - receives and sends WhatsApp messages on your behalf. Meta Privacy Policy →
- Stripe - processes subscription payments and stores payment card details. Stripe Privacy Policy →
- Google Fonts - the marketing site loads its typeface from Google's servers, which exposes your IP address and browser user-agent to Google when a page loads. Google Privacy Policy →
- DigitalOcean - cloud infrastructure hosting the application and database in DigitalOcean's Singapore data center region. DigitalOcean Privacy Policy →
Storage and retention
- Data is encrypted in transit (TLS) and at rest, with access restricted to authorized personnel.
- Account, ticket, and conversation data - retained while your account is active, then deleted or anonymized within 30 days of account closure.
- Billing and tax records - retained for as long as tax and accounting law requires, even after account closure.
- Backups - encrypted backups are purged on the normal rotation cycle after live data is deleted.
- You may request earlier deletion at any time by contacting us.
- OpenAI — processes message content to extract structured data and generate AI responses. OpenAI Privacy Policy →
- SendGrid (Twilio) — handles inbound and outbound email routing. Twilio Privacy Policy →
- Meta (WhatsApp Cloud API) — receives and sends WhatsApp messages on your behalf. Meta Privacy Policy →
- Google Fonts — our marketing site (handlehq.net) loads the IBM Plex Mono typeface from Google’s font CDN. When you load a page, your IP address and browser user-agent are visible to Google in order to serve the font. Google Fonts does not set cookies, and this applies only to the public marketing pages — not the client dashboard. Google Privacy Policy →
International transfers
Application data is hosted in DigitalOcean's Singapore data center region, and our other providers (AI, email, messaging, payments) operate primarily in the United States, so your data may be transferred to and processed in Singapore, the US, and other countries. Where data protected by the GDPR or UK GDPR is transferred to a country without an adequacy decision, we rely on Standard Contractual Clauses as described in our Data Processing Agreement.
Your rights
Depending on your location, you may have rights under applicable data protection law (including GDPR, PDPA, and similar frameworks) to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data.
- Object to or restrict certain processing.
- Receive a copy of your data in a portable format.
- Withdraw consent where processing is based on consent.
- Complain to a supervisory authority in your jurisdiction.
To exercise any of these rights, email hello@handlehq.net. We may ask you to verify your identity before acting on a request. We respond within 30 days. If you are an end-customer of a business using HandleHQ, we will forward your request to that business, which is responsible for responding as controller.
Children
HandleHQ is a business service and is not directed to anyone under 18. We do not knowingly collect personal data from children as a controller. If you believe a child's data has reached us, contact us and we will delete it.
Cookies
The handlehq.net marketing site does not use tracking or advertising cookies. The client dashboard (app.handlehq.net) uses session cookies solely for authentication purposes.
Changes to this policy
We may update this policy as the product evolves. Material changes will be communicated by email to active account holders. The “last updated” date at the top of this page reflects the most recent revision.
Contact
Questions about this policy or your data? Reach us at hello@handlehq.net. Our data protection point of contact is the founder, reachable at the same address.