PappaChat

Privacy Policy

Provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

Last updated: 9 September 2026

This is a convenience translation. The binding version of this document is the Italian one; in case of discrepancy, the Italian text prevails.

This policy describes how PappaChat, acting as the Data Controller, collects and processes the personal data of its business customers, website visitors and demo users. Please read it carefully before using our services.

PappaChat is a multi-tenant SaaS that provides AI assistants operating across multiple channels (including WhatsApp, Instagram, Telegram, website chat and email) for businesses in any sector: the assistant answers customers, takes reservations and orders, and can hand the conversation over to a human operator.

Personal data contained in End Customers' messages (the people who chat with the assistant on the business's channels) is processed by PappaChat as a Data Processor on behalf of the business customer, who is the Controller. That processing is governed by the Data Processing Agreement (DPA), not by this policy: see the "End Customers' conversations" section.

1Data Controller

The Data Controller is Atakan Kayatekin, Sole proprietorship, with registered office and tax domicile at Via Giovanni Paisiello 5, 34148 Trieste (TS), Italy.

  • Name: Atakan Kayatekin (Sole proprietorship)
  • Office: Via Giovanni Paisiello 5, 34148 Trieste (TS), Italy
  • VAT no.: 01452450321
  • Tax code: KYTTKN96M02Z243J
  • Activity (ATECO 62.10.00): Computer programming activities
  • Data protection contact: [email protected]

The Controller has not appointed a Data Protection Officer (DPO), as the conditions making it mandatory under Article 37 GDPR do not apply. For any matter concerning the processing of personal data and the exercise of your rights, you may write to [email protected].

2Categories of data subjects and data processed

This policy concerns the following categories of data subjects: business customers and their representatives and contacts; website visitors and users who try the demo; prospective customers who contact us.

Depending on the interaction, we may process the following categories of personal data:

  • Identification and contact data: first and last name, business/company name, email address, phone number.
  • Account credentials: email address and the OTP code used for authentication (we do not use traditional passwords).
  • Billing and tax data: data needed to issue accounting documents and manage the subscription, handled through Stripe. PappaChat does not store payment card numbers, which are processed directly by Stripe.
  • Content uploaded to configure the assistant: menu, hours, rules and other business information used to train the assistant. Such content may incidentally include third parties' data: entering this data and ensuring its lawfulness are the business customer's responsibility.
  • Usage, technical and log data: IP address, device identifiers, date and time of access, pages visited and actions taken in the service.
  • Demo messages: the text typed into the demo chat available on the website.
  • Communications: the content of the communications you send us (emails, support requests, contact forms).

3Purposes of processing and legal bases

We process personal data for the purposes set out below, each with its corresponding legal basis.

Providing the service and managing the contract and account

To create and manage the account, configure and operate the assistant, and perform the subscription agreement. Legal basis: performance of a contract to which the data subject is party (Art. 6.1.b GDPR).

Customer assistance and support

To respond to support requests and handle reports relating to the service. Legal basis: performance of the contract and pre-contractual measures (Art. 6.1.b GDPR).

Billing, tax and accounting obligations

To issue invoices, manage payments and comply with tax and accounting obligations. Legal basis: compliance with a legal obligation (Art. 6.1.c GDPR).

Operating the website demo and preventing abuse

To operate the demo chat and protect it from automated and abusive use (including via Cloudflare Turnstile). Legal basis: the Controller's legitimate interest in providing and safeguarding the demo (Art. 6.1.f GDPR).

Systems security and fraud prevention

To ensure the security, integrity and availability of the systems and to prevent fraud, unauthorised access and other unlawful acts. Legal basis: the Controller's legitimate interest in the security of its services (Art. 6.1.f GDPR).

Service (transactional) communications

To send communications necessary to manage the relationship (confirmations, technical notices, security alerts, deadlines). Legal basis: performance of the contract (Art. 6.1.b GDPR).

Soft marketing of similar products and services

To send existing customers, by email, communications about products or services similar to those already purchased, with the ability to object (opt out) easily at any time. Legal basis: the Controller's legitimate interest pursuant to Article 130(4) of the Italian Privacy Code (Legislative Decree 196/2003).

Marketing and newsletter subject to consent

To send newsletters and promotional communications by email to those who have requested them. Legal basis: the data subject's consent (Art. 6.1.a GDPR), which may be withdrawn at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Establishment, exercise or defence of legal claims

To assert or defend a right in or out of court. Legal basis: the Controller's legitimate interest (Art. 6.1.f GDPR).

4End Customers' conversations (Processor role)

When the assistant chats with End Customers on the business's channels (including WhatsApp, Instagram, Telegram, website chat and email), the business customer is the Data Controller of the personal data contained in those conversations, while PappaChat acts as the Data Processor (Art. 28 GDPR), processing that data solely on the business customer's instructions and to provide the service.

That processing is governed by the Data Processing Agreement (DPA) entered into between PappaChat and the business customer, and not by this policy.

If you are an End Customer and wish to obtain information about the processing of the data contained in your conversations, or to exercise your rights, you must contact the business you interacted with (the Controller), referring to its own privacy notice.

5Artificial intelligence and model providers

The assistant generates replies using Retrieval-Augmented Generation (RAG) techniques: it answers based solely on the data provided by the business customer (menu, hours, rules) and does not invent information not present in that content.

On plans with AI included (Starter, Pro, Max), the model providers, namely Anthropic (Claude models) and Google (Gemini models), act as sub-processors on PappaChat's behalf. On the Base plan (BYO key), the business customer uses its own API key and the model provider is contracted directly by the customer, who assumes the related responsibility.

The content of conversations and business data is transmitted to the model provider solely to generate the reply. In accordance with the providers' API terms, such data is not used to train their foundation models.

The service does not involve automated decision-making that produces legal effects or similarly significantly affects the data subject within the meaning of Article 22 GDPR.

6Recipients and external processors

Personal data may be disclosed to: persons authorised to process data under the Controller's authority (Art. 29 GDPR); professional advisors (e.g. accountant, legal advisors); public authorities, where required by law.

Data may also be processed by the following external providers, appointed as Data Processors pursuant to Article 28 GDPR:

ProviderService and purposeLocation and transfer safeguards
Meta Platforms Ireland LtdMessaging over WhatsApp and InstagramIreland (EU); any transfers to the USA are covered by the EU-US Data Privacy Framework and Standard Contractual Clauses
SendSeven GmbHRouting and handling of Instagram channel messages (delivered through the linked Facebook Page)Germany (EU); processing within the European Union
Anthropic, PBCGenerating the assistant's replies (Claude models) on plans with AI includedUSA; Standard Contractual Clauses (Art. 46 GDPR)
Google Ireland LtdGenerating the assistant's replies (Gemini models) and the website demoIreland (EU) / USA; EU-US Data Privacy Framework and Standard Contractual Clauses
Stripe Payments Europe LtdPayment processing and subscription billingIreland (EU) / USA; EU-US Data Privacy Framework and Standard Contractual Clauses
Resend, Inc.Sending transactional emails (sign-up, notifications, confirmations)USA; Standard Contractual Clauses (Art. 46 GDPR)
Amazon Web Services EMEA SARLFile and backup storage (data centres in the European Union)EU; EU-US Data Privacy Framework and Standard Contractual Clauses for any non-EU services
DigitalOcean LLCHosting of the application infrastructure (data centres in the European Union)EU (Amsterdam); Standard Contractual Clauses
Cloudflare, Inc.Anti-abuse protection (Turnstile), CDN and network securityUSA; EU-US Data Privacy Framework and Standard Contractual Clauses
Personal data is never sold or transferred to third parties for their own commercial purposes.

7Transfers outside the EU

Some of the providers listed above are based in, or process data, outside the European Economic Area (EEA). In such cases, transfers take place in compliance with Chapter V of the GDPR, on the basis of adequacy decisions (including, where applicable, the EU-US Data Privacy Framework) and/or the Standard Contractual Clauses adopted by the European Commission (Art. 46 GDPR), together with supplementary measures where necessary.

You may request a copy of the safeguards adopted by writing to [email protected].

8Retention period

We retain personal data for as long as strictly necessary for the purposes for which it was collected, in line with the data minimisation principle (Art. 5 GDPR). In particular:

  • Account and contract data: for the entire duration of the contractual relationship.
  • Billing, tax and accounting data: up to 10 years, in accordance with Article 2220 of the Italian Civil Code and tax law.
  • Demo messages: for a limited period (up to 12 months), after which they are deleted or anonymised.
  • Data processed for marketing purposes: until consent is withdrawn or the data subject objects.
  • Log and technical data: for a limited period, consistent with security purposes.

At the end of the periods indicated, data is irreversibly deleted or anonymised, unless further retention is required by law or necessary for the establishment, exercise or defence of a legal claim.

9Security measures

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, pursuant to Article 32 GDPR, including:

  • encryption of data in transit (TLS);
  • access controls and user authentication;
  • least-privilege principle in granting access;
  • hosting of the application infrastructure in data centres within the European Union;
  • periodic backups and recovery procedures;
  • monitoring and logging of access to the systems.

10Data subject rights

As a data subject, you have the right to exercise, within the limits and conditions set out in Articles 15-22 GDPR:

  • right of access to your personal data (Art. 15);
  • right to rectification of inaccurate or incomplete data (Art. 16);
  • right to erasure («right to be forgotten») (Art. 17);
  • right to restriction of processing (Art. 18);
  • right to data portability (Art. 20);
  • right to object to processing based on legitimate interest, including marketing (Art. 21);
  • right to withdraw consent at any time, without affecting the lawfulness of prior processing.

You can exercise your rights by writing to [email protected]. We will respond without undue delay and, in any event, within one month of receiving the request.

You also have the right to lodge a complaint with the supervisory authority, the Italian Data Protection Authority (Garante per la protezione dei dati personali) (www.garanteprivacy.it), if you believe that the processing of your data infringes applicable law.

12Changes to this policy

This policy may be updated over time, for example to reflect changes in law or in the service. The date of the last update is shown at the top of this page. In the event of material changes, we will provide notice by appropriate means.

13Contact

For any matter concerning the processing of personal data and the exercise of your rights: [email protected].

For general enquiries: [email protected].

By post: Atakan Kayatekin, Via Giovanni Paisiello 5, 34148 Trieste (TS), Italy.