1. Introduction
This Privacy Policy explains how HiQBot, a sole proprietorship registered with the Federal Board of Revenue (FBR), Government of Pakistan, with its registered office at 113-A3 Block, Gulberg III, Lahore, Pakistan (“HiQBot,” “we,” “us,” or “our”), collects, uses, stores, shares, and protects personal data.
This Policy applies to all users of the HiQBot platform, including the web application and all related services at hiqbot.com, all APIs, embeddable widgets, channel integrations, and related services.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. For questions, contact us at support@hiqbot.com.
2. Our Role: Data Controller & Data Processor
As Data Controller: We control data you provide during registration and account management (name, email, company, team size, payment info).
As Data Processor: We process End-User data on your behalf, with messages, conversations, contact info, and leads flowing through the Service. This is handled solely under your instructions per our Terms of Service.
3. Data We Collect
3.1 Account Data (Business Clients)
When you register and use the Service, we collect:
- Name, email address, company name, Team Size, and phone number
- Account preferences, settings, and configuration data.
3.2 End-User Data (On Behalf of Clients)
When your End Users interact with the Service through your configured channels, the following data may be processed on your behalf:
- Messages and conversation content across all channels (Web widget, WhatsApp, Instagram, Facebook Messenger, Telegram).
- Contact information: name, phone number, email address.
- Conversation metadata: timestamps, channel source, session duration, agent assignments.
- PII detected in conversations (tokenized and stored securely, see Section 8).
- Lead and booking information captured through conversations.
- CSAT survey responses.
- Voice messages and audio data (when voice features are used).
- Media files shared in conversations.
3.3 Usage & Technical Data
We automatically collect:
- IP addresses, browser type, operating system, and device information.
- Pages visited, features used, and time spent in the application.
- Error logs and performance data for service improvement.
3.4 Payment Data
Payment information is processed exclusively by Paddle.com Market Limited, our Merchant of Record. HiQBot never collects, stores, or has access to your payment card details. We receive only transaction identifiers, subscription status, plan type, and billing email from Paddle. For details on how Paddle handles your payment data, see Paddle's Privacy Policy.
4. Use of Data
4.1 Service Delivery
- Route and process messages across all connected channels.
- Power AI agent responses using your configured knowledge base.
- Enable live chat and AI-to-human handoff with context preservation.
- Capture and manage leads, bookings, and contact information.
- Process voice messages (speech-to-text and text-to-speech).
- Deliver real-time notifications and alerts.
- Manage team assignments, routing, and working hours.
4.2 Service Improvement
- Aggregated, non-identifying usage analysis to improve features.
- Bug identification, diagnostics, and fixes.
- Feature development and platform optimization.
4.3 Communication
- Service announcements, updates, and support notifications.
- Marketing communications (only with your explicit consent, and easily unsubscribable).
4.4 Security & Compliance
- Fraud prevention and abuse detection.
- GDPR compliance operations (data erasure, portability, retention enforcement).
- Audit logging and access controls.
4.5 AI Processing
We do not use your conversation data or End-User data to train AI models for other customers. Each organization's data is processed in isolated environments. AI responses are generated using your configured knowledge base only. Fully anonymized and aggregated data may be used to improve general service quality.
5. Legal Basis for Processing (GDPR Article 6)
Where the EU General Data Protection Regulation (GDPR) or UK GDPR applies, we process personal data on the following legal bases:
| Legal Basis | Purpose |
|---|---|
| Contract Performance: Art. 6(1)(b) | Providing the Service, processing messages, managing your account and subscription. |
| Legitimate Interest: Art. 6(1)(f) | Security monitoring, fraud prevention, aggregated analytics, service improvement. |
| Consent: Art. 6(1)(a) | Marketing communications, optional analytics. You may withdraw consent at any time. |
| Legal Obligation: Art. 6(1)(c) | Tax record retention, compliance with lawful government requests. |
6. Data Sharing & Sub-Processors
We share personal data only as necessary to provide the Service and as described below. We do not sell personal data. We do not share data for advertising or profiling purposes.
Sub-Processors
| Sub-Processor | Purpose |
|---|---|
| Amazon Web Services (AWS) | Cloud hosting, data storage, computing infrastructure |
| Google Cloud Platform (GCP) | Cloud hosting, data storage, computing infrastructure |
| Cloudflare | CDN, DDoS protection, Web Application Firewall (WAF) |
| Paddle.com Market Limited | Payment processing, invoicing, tax collection |
| Meta Platforms | WhatsApp, Instagram, Facebook Messenger message delivery |
| Telegram | Telegram Bot API message delivery |
We use third-party AI service providers to generate responses and process voice/text data. These providers act as sub-processors under our instructions. We maintain Data Processing Agreements with all sub-processors. A current list of AI sub-processors is available upon request at support@hiqbot.com. Changes to our sub-processor list will be communicated via email to affected clients.
Business customers requiring a signed Data Processing Agreement (DPA) with HiQBot may request one at support@hiqbot.com. Our DPA incorporates Standard Contractual Clauses (SCCs) for international data transfers where required.
7. Messaging Channel Data
7.1 WhatsApp
WhatsApp messages are delivered via the Meta Cloud API. Meta acts as a sub-processor for message delivery. End-User opt-in consent is required before messaging. WhatsApp conversation data is subject to Meta's data policies in addition to this Privacy Policy.
7.2 Instagram & Facebook Messenger
Messages are delivered via the Meta Graph API. We implement Meta-required deauthorization and data deletion callbacks. When a user removes the app from their Meta account, we process the deauthorization and delete associated data upon request.
7.3 Telegram
Messages are delivered via the Telegram Bot API. Telegram is a privacy-oriented platform. Data processing complies with Telegram's Bot Developer Terms.
7.4 Web Chat Widget
Website visitors interacting with the HiQBot web chat widget should be informed of data collection through the client's own privacy policy. Clients are responsible for disclosing the widget's presence and data practices on their websites.
8. PII Detection & Protection
The Service includes automated tools that can help detect and protect limited personally identifiable information (PII) in conversation data (such as email addresses and phone numbers). These tools run on our own infrastructure and/or through third-party AI service providers acting as sub-processors under our instructions. Detected PII is encrypted in transit and at rest, access to it is restricted by role-based permissions, and PII may be masked in logs or non-essential displays. PII handling behaviour can be configured per organization to match your compliance needs.
9. International Data Transfers
HiQBot is registered in Pakistan. Our infrastructure is hosted on Amazon Web Services (AWS) and Google Cloud Platform (GCP), with data processed and stored in the United States. Both providers maintain industry-leading security certifications (ISO 27001, SOC 2, GDPR-compliant data processing addenda).
We protect your data with technical safeguards such as encryption in transit and at rest, access controls, and data isolation.
For transfers of EU/EEA personal data to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by technical safeguards including encryption.
10. Data Retention
Data retention is configurable by you, the client. We do not impose fixed retention periods on your data. You control how long your data is kept. You may export your data and keep your own copy for as long as you want.
We delete or restrict data when it is no longer needed for its purpose or when you ask us to. Upon account termination, we purge your data within 30 days. Backup copies are purged within the normal backup rotation cycle. Billing and transaction records are held by Paddle (for tax requirements). We may retain some data longer only when required by law.
11. Your Rights
11.1 EU/EEA Residents (GDPR)
If you are located in the EU or EEA, you have the following rights:
- Access: Request a copy of your personal data.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your personal data.
- Restriction: Request restriction of data processing.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interest.
- Consent Withdrawal: Withdraw consent at any time (without affecting prior processing).
- Supervisory Authority: Lodge a complaint with your local data protection authority.
These rights may be limited in certain circumstances as permitted by applicable law.
11.2 UK Residents (UK GDPR)
UK residents have the same rights as listed above under the UK GDPR. The Information Commissioner's Office (ICO) is the relevant supervisory authority.
11.3 California Residents (CCPA/CPRA)
California residents have the right to know what personal information is collected, to request deletion, and to opt out of the sale of personal information. We do not sell personal data. You will not receive discriminatory treatment for exercising your rights.
11.4 How to Exercise Your Rights
To exercise any of these rights, contact us at support@hiqbot.com. We will respond to verified requests within 30 days. We may request verification of your identity before processing your request.
11.5 Payment Data
For data held by Paddle (payment and billing information), please contact Paddle directly through their privacy portal.
11.6 End-User Data
If you are an End User whose data is processed through HiQBot on behalf of a business client, please contact the business directly to exercise your data rights. The business is the Data Controller and is responsible for responding to your requests.
12. Data Security
We implement industry-standard technical and organizational measures to protect your data, including encryption, access controls, network and infrastructure security, and monitoring and incident response processes appropriate to the nature of the Service. This includes encryption in transit using TLS 1.3 and encryption at rest using AES-256 (or equivalent controls provided by our infrastructure providers).
In the event of a security breach affecting your personal data, we will notify you without undue delay and no later than 72 hours after becoming aware of the breach, in accordance with applicable data protection laws.
14. Children's Privacy
HiQBot serves both business and individual users but is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child under 16, we will take steps to delete it promptly. If you believe a child has provided personal data to us, please contact us at support@hiqbot.com.
15. Data Deletion & Meta Deauthorization
We support multiple ways to delete data associated with your use of the Service:
- Meta Deauthorization Callback: When a user removes HiQBot from their Meta account (Instagram or Facebook), we receive and process the deauthorization event, logging the removal and updating the connection status.
- Meta Data Deletion Callback: We process data deletion requests from Meta, issue a confirmation code, and provide a status tracking URL for verification.
- Account-Level Deletion: On request, we delete account data and associated content from our active systems in line with our retention practices.
- Direct Request: Contact support@hiqbot.com to request data deletion at any time.
- Self-Service: Clients can delete data directly through the platform dashboard.
16. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' advance notice via email or through the Service. The “Last updated” date at the top of this page indicates the most recent revision. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
17. Contact Us
If you have any questions about this Privacy Policy, your data, or your rights, please contact us:
| Entity | HiQBot, a sole proprietorship registered with the FBR, Government of Pakistan |
| Address | 113-A3 Block, Gulberg III, Lahore, Pakistan |
| support@hiqbot.com | |
| EU Data Protection Contact | For EU data protection matters, contact support@hiqbot.com. |
| Website | hiqbot.com |