Privacy Policy
This Policy describes how Askfy (a product of RPA CLICK LLC) handles personal data on the institutional website askfy.ai, the web application app.askfy.ai, and the Askfy mobile app (Android package ai.askfy.app). Effective date: September 22, 2026.
Who we are
Askfy is a SaaS conversational support platform with AI and human agents. The controller responsible for this Policy, where applicable, is RPA CLICK LLC, under the Askfy brand. Contact: support@askfy.com.br.
Scope and roles
This Policy covers: (a) website visitors and leads; (b) agents and admins using the product (web and mobile); (c) end-customer data processed in support channels (WhatsApp, website widget, and related).
For end customers, the tenant (our customer organization) is generally the controller of that relationship; Askfy processes those data to provide the service under the tenant’s instructions, subject to applicable law.
Institutional website data
When you submit the contact/demo form, we may process name, email, phone, company, website, message, language, source page, anti-abuse signals (including Turnstile) and technical identifiers such as a hashed IP address for security and abuse prevention. Submission requires the consent indicated on the form.
Account and operator data
To create and maintain an agent account we process email, name, role, organization(s), preferences (language, theme) and credentials. Passwords are transmitted securely (HTTPS) and are not stored in clear text on the mobile app. Session tokens are kept in the device secure store when applicable.
Support / attendance data
The product processes conversation content and metadata needed for support: messages, status, attachments (images, audio, files), contact fields provided by the channel, and operational records (transfers, internal notes, etc.). These data belong to the tenant context and are used to operate inbox, customer-configured AI/knowledge, human handoff, reporting and technical support.
Mobile application
In the Askfy Android app we may: (a) register an app-generated device identifier and a push token (via Expo and Firebase Cloud Messaging) for message and call alerts; (b) request microphone, camera, photos/files and notification permissions for voice notes, attachments and alerts; (c) process WhatsApp voice calls over WebRTC, with signaling on our servers and STUN/TURN servers; (d) keep a temporary on-device cache of attendance snippets for offline use (with expiry and clearing on logout or organization switch); (e) send stability diagnostics to Sentry with minimization and scrubbing of sensitive fields.
We do not use the app for advertising and do not collect Advertising ID. We do not collect the agent device’s precise location or the device contact address book.
Purposes
We process data to: provide and improve the service; authenticate users; send operational and support communications; respond to leads; ensure security and abuse prevention; comply with legal duties; and, where allowed, commercial communications about Askfy.
Legal bases
As applicable: performance of a contract / pre-contract steps; legitimate interests (security, product improvement, aggregated metrics); consent (website form and marketing where applicable); and legal/regulatory obligations. For Brazilian users this aligns with the LGPD; other jurisdictions may apply additional rules.
Sharing
We may share data with processors needed to operate the service (hosting, email/SMTP, Expo/Google FCM push, Sentry monitoring, media/TURN infrastructure, and Meta/WhatsApp in the context of the channel connected by the tenant). We do not sell personal data. Legal requirements or protection of rights may require limited disclosure.
International transfers
Cloud providers and processors may process data outside Brazil. We use contractual and technical safeguards as reasonably required for the service.
Retention
We keep data as long as needed for the purposes, the tenant contract, legal duties and defense of rights. The mobile offline cache expires on a short TTL (currently up to 24 hours) and is cleared on logout. Leads and account records follow operational policies and valid deletion requests.
Security
We use HTTPS/TLS in transit, access controls, multi-tenant segregation and telemetry minimization. No method is 100% secure.
Residual mobile risks include: content visible in screenshots or recents; on-device cache on an unlocked device; and possible inclusion of app data in system backups.
Your rights
Subject to applicable law (including LGPD), you may request confirmation, access, correction, anonymization, portability, deletion, information about sharing and withdrawal of consent where applicable. Contact: support@askfy.com.br.
If your data were collected by an Askfy customer (e.g. via that company’s WhatsApp), please exercise rights with that company first; we may assist the tenant as allowed by contract and law.
Agent accounts and deletion
Agent accounts are provisioned by the tenant administrator. To request deactivation or deletion of your agent account and associated data under our control, email support@askfy.com.br or ask your organization admin. End-customer data under the tenant’s control follows that controller’s instructions.
Cookies and similar technologies
The institutional site uses technical features required to operate (including form anti-abuse protection). This version does not run advertising pixels or marketing analytics on the site. If that changes, we will update this Policy.
Children
Askfy is intended for professional/B2B use by adults (18+). We do not target children.
Changes
We may update this Policy. The current version will be published at these URLs with an updated effective date. Material changes may be communicated by reasonable means (website, email or in-product notice).
Contact
Privacy questions: support@askfy.com.br. Website: https://askfy.ai.