01Who is responsible for what

Data-protection law distinguishes between the party who decides why and how personal data is processed (the controller) and the party who processes it on that party’s instructions (the processor). Getting this the wrong way round is the single most common mistake in agreements like this, so we state it plainly.

1.1 What follows from this

This policy sits alongside our Terms of Service and forms part of them. Where we act as your processor, clause 13 of the Terms and this policy together constitute the data-processing terms between us.

02What data we handle

2.1 Data about you, our client (we are controller)

2.2 Data about the people who message you (we are processor)

2.3 Data about visitors to our website

Our marketing site is deliberately minimal. We do not set advertising or tracking cookies, we do not run third-party analytics or advertising pixels on it, and we do not build visitor profiles. Our hosting provider may keep standard server logs (IP address, timestamp, page requested, user agent) for security and diagnostics. The site loads a web font from Google Fonts, which means your browser makes a request to Google’s servers; if you would rather it did not, block third-party font loading in your browser.

If you click a WhatsApp link on our site, you leave our site and enter WhatsApp, where Meta’s own privacy terms apply to that conversation in addition to ours.

03What we use it for

We do not sell personal data. We do not rent, trade or share it for anyone else’s marketing. We do not use the content of your customers’ conversations to market anything to them, or to you. These are absolute commitments, not preferences.

04Our lawful basis

Where we are the controller (clause 2.1 and 2.3), we process on the basis of: performance of our contract with you; our legitimate interests in operating, securing and improving our business, balanced against your rights; and compliance with our legal obligations, including tax and accounting.

Where we are the processor (clause 2.2), we do not have our own lawful basis and do not claim one. We process on your instruction, and you are responsible for establishing and documenting the lawful basis for that processing. You warrant to us that you have one.

We process in accordance with the data-protection framework applicable in the State of Kuwait, including the regulations issued by the Communication and Information Technology Regulatory Authority (CITRA). Where you or your customers are located elsewhere in the GCC or beyond, additional local requirements may apply to you as controller, and meeting them is your responsibility.

05We do not train AI on your data

To be precise about the distinction, because it matters:

If this ever changes, it will require your prior, specific, opt-in consent, sought separately. It will never be introduced by an update to this policy.

06Automated decisions and AI processing

The Assistant generates replies automatically, without a human reviewing each one before it is sent. Your customers are told they are speaking with an automated system.

The Assistant is not configured to make decisions producing legal effects or similarly significant effects on an individual — it does not assess creditworthiness, decide eligibility, price by individual profile, or refuse service to a person. You must not configure it to do so. A human escalation path is available in every conversation, and a customer may ask for a person at any point.

Messages are processed by a third-party model provider (clause 7) in order to generate a reply. That processing is transient and subject to contractual restrictions on retention and reuse.

07Sub-processors

We use a small number of third parties to deliver the Service. Each is bound by contract to protect the data, to process it only on our instructions, and to meet obligations no weaker than those in this policy.

We will give you at least thirty (30) days’ written notice before adding or replacing a sub-processor. If you object on reasonable data-protection grounds, you may cancel under clause 10 of the Terms without penalty. A current list naming each provider is available on request, and we will supply it before you go live.

08Where data is stored and sent

Delivering this Service necessarily involves transferring data outside the State of Kuwait. Meta, the model provider and our hosting provider all operate infrastructure internationally. We cannot provide the Service without such transfers, and by subscribing you instruct us to make them.

Where we transfer personal data internationally we rely on the recipient’s contractual commitments to protect it to a standard consistent with Kuwaiti requirements.

09How long we keep it

On termination we will, at your written request made within thirty (30) days, delete or return Client Data. Absent a request, we delete it within ninety (90) days, except where law requires us to keep it. Deletion is permanent and cannot be reversed — export anything you need first.

10How we protect it

We will not overstate this. No system is perfectly secure, and we do not warrant that ours is. What we commit to is applying appropriate technical and organisational measures, keeping them current, and telling you quickly and honestly if something goes wrong.

Please note that WhatsApp’s end-to-end encryption does not apply in the ordinary way to messages sent to a business using the WhatsApp Business Platform. Messages to a business account are processed by Meta’s systems and by the business’s chosen providers — here, us. Your customers should be told this (clause 13).

11If something goes wrong

If we become aware of a personal-data breach affecting your data, we will notify you without undue delay and in any event within twenty-four (24) hours of becoming aware. We apply the 24-hour standard because it is the tightest clock applicable in this region, and applying the tightest standard everywhere is simpler and safer than tracking several.

Our notification will tell you what happened, what data was involved, how many people are affected so far as known, what we are doing about it, and what we recommend you do. We will keep you updated as we learn more, including where the initial picture turns out to be wrong.

As controller, notifying the regulator and affected individuals is your decision and your responsibility. We will give you the information you reasonably need to make it, promptly and at no charge.

12Rights of individuals

Individuals have rights over their personal data, including to be told how it is used, to obtain a copy, to have inaccuracies corrected, to request deletion, to object to certain processing, and to withdraw consent.

You may also complain to CITRA in Kuwait, or to your local data-protection authority. We would rather you raised it with us first so we have the chance to fix it.

13Your duty to the people who message you

The people messaging your number have no relationship with us. They have one with you. So the duty to tell them what happens to their data is yours, and it is a condition of using the Service.

You must maintain a privacy notice, accessible to your customers, that at minimum tells them:

You must also hold valid opt-in consent for every number you message, and keep evidence of it (clause 6.3 of the Terms). We will provide a short template notice you may adapt — but it is a starting point, not legal advice, and you remain responsible for its accuracy and sufficiency for your business.

14Our own website

We do not use advertising cookies, tracking pixels, session recording or cross-site trackers on gulf.bot. If we ever introduce anything that requires consent, we will ask for it before setting it, and a refusal will leave the site fully usable.

Our site links to WhatsApp and Instagram. Once you follow such a link you are on a third-party platform governed by its own privacy terms, and we have no control over what it collects.

15Children

The Service is sold to businesses and is not directed at children. We do not knowingly process the personal data of anyone under 18 as a client. If a person under 18 messages a client’s number as a customer, that data is processed under the client’s instruction and the client is responsible for any additional protections the law requires. If you become aware that a child’s data is being processed in a way that requires special handling, tell us and we will assist.

16Changes to this policy

We may update this policy. Where a change materially affects how we handle personal data, we will give you at least thirty (30) days’ written notice before it takes effect, and you may cancel under clause 10 of the Terms if you do not accept it.

The commitment in clause 5 — that we do not train AI models on your data — will never be weakened by an update to this policy. Changing it would require your separate, specific, opt-in consent.

The version and effective date at the top identify the operative text. Earlier versions are kept and available on request.

17How to contact us

For any question about this policy, or to exercise a right:

If you are considering GulfBot and your lawyer wants to review this before you sign, send them here. We would rather answer their questions now than have a disagreement about data later.