1. Who we are
UniLanguageMessaging is a customer support platform operated by RidexGo Məhdud Məsuliyyətli Cəmiyyəti("RidexGo MMC", "we", "our", "us"), a limited liability company registered in the Republic of Azerbaijan.
For the purposes of the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and analogous Azerbaijani data-protection law, RidexGo MMC is the data controller for personal data processed through this platform.
This policy explains what personal data we collect via our WhatsApp Business API integration, how we use it, who we share it with, how long we keep it, and what rights you have.
2. Data we collect
We collect the following categories of personal data when you message us on WhatsApp:
- Contact identifiers: your WhatsApp phone number and the profile name WhatsApp shares with us (wa_id, profile.name).
- Message content: the text, images, documents, videos, and voice notes you send us, including captions, and the replies our agents send back.
- Voice-note transcripts: text transcriptions of voice notes you send, generated automatically so our agents can read them.
- Conversation metadata: timestamps, detected language of each message, conversation status, the assigned agent, and read-receipt status.
- Satisfaction ratings: the 1-to-5 rating you optionally provide after a conversation is closed.
- AI-generated content: summaries, short titles, and descriptions produced from your conversation to help agents review and classify past interactions.
We do not collect: your email, location, contact list, other apps on your device, your Meta user ID outside of the WhatsApp wa_id, or advertising identifiers.
3. How and why we use data
We process the data above only for these specific purposes:
- Answering your question or resolving the issue you contacted us about.
- Routing your conversation to an available support agent and showing that agent the full thread and prior interactions with you.
- Translating messages between your language and our agent's reading language, so a multilingual team can serve you regardless of which agent picks up the chat.
- Transcribing voice notes you send, so our agents can respond quickly in text.
- Quality assurance: our managers review completed conversations and satisfaction ratings to improve our service and coach our team.
- Generating AI-powered summaries and titles that help our agents quickly understand the context of a past conversation when you contact us again.
We do not use your data for advertising, profiling for marketing, training general-purpose machine-learning models, or any purpose not listed above.
4. Legal basis for processing
Under GDPR / analogous law, we rely on:
- Performance of a contract (Art. 6(1)(b) GDPR): when you message us to request support, processing your message is necessary to respond.
- Legitimate interests (Art. 6(1)(f) GDPR): for quality assurance, conversation history, and internal management of our support team. We have assessed that these interests do not override your privacy rights.
- Legal obligation (Art. 6(1)(c) GDPR): when we must retain or disclose data to comply with tax, accounting, or government-authority obligations.
5. Who we share data with (processors)
We share personal data only with service providers ("processors") that help us operate the platform. Each processor is bound by a data-processing agreement and processes data only on our instructions.
- Meta Platforms Inc. / Meta Platforms Ireland Ltd. — WhatsApp Business Cloud API, which carries messages between you and our platform.
- Google LLC — Google Cloud Translation (language detection and translation of message text), Google Cloud Speech-to-Text (voice-note transcription), and Google Gemini API (AI summary and title generation). Data is sent to these APIs only for single-request processing; Google does not retain it for training.
- Railway Corp. — hosting of our application servers and PostgreSQL database where conversation data is stored.
- OpenAI, L.L.C. — Whisper voice-note transcription (audio sent for single-request processing; OpenAI does not retain it for training).
- Customer.io (Peaberry Software, Inc.) — when CRM sync is enabled, we send your RidexGo driver identifier (already known to Customer.io from the RidexGo platform), applied tags, tag-mutation event timestamps, your latest WhatsApp inbound timestamp, and the 1–5 satisfaction rating you give after a closed conversation, to Customer.io (data center: EU,
cdp-eu.customer.io) for marketing campaign segmentation and triggered campaigns. We do not send your phone number, message content, or the identity of the support agent who handled your conversation. See Customer.io’s privacy policy. - Cloudflare, Inc. — edge proxy, DDoS protection, web application firewall, and optional bot challenge (Turnstile) for
cs.ridexgo.com. Cloudflare terminates TLS at its global edge and forwards filtered requests to our Railway origin. It receives connection metadata (IP address, user agent, request path) for the duration of each request; no message content or persistent user data is shared. See Cloudflare’s privacy policy. - Resend (Resend Inc.)— transactional email delivery for password-reset links. We share the recipient’s email address and the reset URL. We do not share any conversation data.
- Meta Platforms Inc. (Embedded Signup)— when a business connects their WhatsApp Business Account to RidexGo Messaging via Meta’s official Embedded Signup flow, we receive a one-time authorization code that we exchange for an access token scoped to that business’s WABA. The token authorizes us to send and receive messages on the business’s behalf. No personal data from your messages is shared with Meta beyond what WhatsApp itself routes for delivery.
We do not sell personal data. We do not share personal data with advertisers, data brokers, or any third party for marketing purposes.
6. International data transfers
Our processors (Google, Railway, Meta, Customer.io, Cloudflare, Resend, OpenAI) operate infrastructure in the United States and the European Economic Area, plus Cloudflare's global edge network of 200+ points of presence. Where personal data is transferred outside Azerbaijan or the EEA, the transfer is protected by the processor's Standard Contractual Clauses, supplementary security measures, and encryption in transit and at rest.
7. Data retention
We keep personal data only for as long as it serves the purposes above:
- Active conversations: until the conversation is closed, then for 24 months in our history so you receive consistent service on follow-up.
- Voice-note transcripts and AI summaries: same retention window as the parent conversation (24 months after closure).
- Satisfaction ratings: 24 months, linked to the conversation.
- Aggregated, de-identified metrics: retained indefinitely for internal reporting; contains no personal identifiers.
- Government-request records: at least 5 years, per our Government Request Handling Policy.
- Deleted on your request: within 30 days of a verified deletion request (see section 9).
After the retention windows above, personal data is deleted or irreversibly anonymized.
8. Security
- All traffic to and from the platform is encrypted in transit over HTTPS/TLS.
- The PostgreSQL database is encrypted at rest on managed Railway infrastructure.
- Agent passwords are stored as bcrypt hashes; passwords themselves are never stored in plaintext.
- Access to customer data is limited to authorized support agents and managers and is logged server-side.
- Media files (images, documents, videos) are not stored on our servers; they are referenced by WhatsApp media ID and fetched from Meta on demand.
- We regularly review access, patch dependencies, and audit deployed changes through a git-tracked change log.
9. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your personal data ("right to be forgotten").
- Restrict or object to certain processing, including processing based on legitimate interests.
- Port your data in a structured, machine-readable format.
- Withdraw consent at any time where we rely on consent.
- Lodge a complaint with a supervisory authority — in Azerbaijan, the relevant authority under the Law on Personal Data.
To exercise any of these rights, email privacy@ridexgo.com from the phone number or account you used to contact us, or WhatsApp us and ask to speak with the privacy officer. We will respond within 30 days. We may ask for reasonable verification of identity before acting.
10. Government and regulatory requests
When a public authority (court, regulator, law-enforcement agency) asks us to disclose personal data, we handle the request under our published Government Request Handling Policy. In summary: every request is reviewed by our Responsible Officer for legal validity, we disclose only the minimum data strictly required, we challenge requests we consider unlawful, and we document every request and response. Where lawful, we notify the affected person. We do not provide bulk or automated access to any authority.
11. Children
Our platform is intended for adult users contacting a business support channel. We do not knowingly collect personal data from children under 16. If you believe a child has used our service, please contact us at privacy@ridexgo.com and we will delete their data promptly.
12. Changes to this policy
We may update this policy from time to time. Material changes will be posted on this page with an updated version number and effective date. Continued use of the support channel after the effective date constitutes acknowledgement of the updated policy.
13. Contact
Data controller: RidexGo MMC, Azerbaijan.
Privacy enquiries and data-subject requests: privacy@ridexgo.com.
Responsible Officer for government and regulatory requests: Javid Dashdamirov — javid.dashdamirov@ridexgo.com.