hettos.io

Privacy Policy

Last updated: 26 August 2026

Who we are

Hettos (“Hettos”, “we”, “us”) provides a software platform that businesses (“customers”) use to manage their customer conversations across email, WhatsApp, Instagram, Facebook Messenger and website live chat, together with related CRM, quotation and reporting tools. This policy explains what personal data we handle, why, and the choices available to you. For any privacy question, contact support@hettos.io.

Two roles: controller and processor

Information we handle

Why we process it

Platform terms we honour

Use of data received from Meta platforms complies with the Meta Platform Terms and the WhatsApp Business Terms. Use of data received from Microsoft or Google APIs complies with those platforms’ API terms, including the Google API Services User Data Policy’s Limited Use requirements where applicable. Channel connections can be revoked by the customer at any time, which stops further data flow.

Where data lives and who helps us run the service

Hettos runs on vetted infrastructure sub-processors, currently including Vercel (application hosting), Neon (database hosting) and Pusher (realtime notifications), plus the channel platforms a customer chooses to connect. Each sub-processor is bound by data-protection terms. A current list is available on request.

Retention and deletion

Workspace data is retained while the customer’s subscription is active. When a workspace is closed, its data is deleted or irreversibly anonymised within 60 days, except where law requires longer retention (e.g. invoices). Customers can request export or deletion of their workspace data at any time via support@hettos.io.

Your rights

Depending on your location, you may have rights to access, correct, export, delete or restrict processing of your personal data. If you are an end customer of a business that uses Hettos, please contact that business first — they control your data, and we will assist them in fulfilling your request. Otherwise, contact us directly and we will respond within 30 days.

Security

Data is encrypted in transit; credentials and channel tokens are stored encrypted; access within a workspace is governed by per-user roles and module permissions. We notify affected customers without undue delay in the event of a personal-data breach.

Cookies

The application uses strictly necessary cookies for sign-in sessions. The public website does not use advertising or cross-site tracking cookies.

Changes to this policy

We will update this page when our practices change and revise the date above. Material changes are announced to workspace administrators.

Contact

Hettos — support@hettos.io