سياسة الخصوصية
آخر تحديث: 25 July 2026
This Privacy Policy explains how Calycks Websites Ltd ("we", "us") collects, uses, shares, and protects personal data when you visit calycks.com, contact us, or use our website, ecommerce, web app, clinic, QR menu, CRM, automation, or support services. We act in accordance with the UK GDPR and the Data Protection Act 2018.
1. Data we collect
- Contact details you provide directly: name, business name, email, phone or WhatsApp number, country, message content, and project type.
- Client and billing data for active clients: company information, billing address, invoice history, project records, and payment status. We do not store full card numbers.
- Service data generated by systems we build or host for you, such as enquiries, bookings, form submissions, menu items, customer records, CRM notes, configuration, logs, and support messages.
- Technical data: IP address, device, browser, referrer, pages viewed, interactions, cookies, and similar analytics data.
2. How we use data
- To respond to enquiries, scope projects, and provide quotes.
- To deliver, operate, secure, and support our services.
- To process payments, invoicing, accounting, and tax records.
- To improve our website, products, support, and fraud prevention.
- To send service updates and, only with your consent, marketing emails.
3. Customer and system data
If we build or host a system that processes your customers' data, you remain responsible for your customer data and for providing privacy notices to your own users. We process that data only to deliver the agreed service, support the system, maintain security, and meet legal obligations.
4. Sharing data
We share data only with trusted providers needed to run our services, including:
- cloud hosting, email, analytics, CRM, support, payment, and AI providers;
- professional advisers such as accountants or legal advisers where needed;
- authorities when required by law or to protect our rights.
We do not sell personal data.
5. International transfers
Some providers may be outside the UK. Where required, we use appropriate safeguards such as the UK International Data Transfer Agreement, Standard Contractual Clauses, or adequacy decisions.
6. Retention
We keep personal data only for as long as needed for the purposes above, including up to 7 years for invoicing and tax records. Service data tied to active client systems is retained while the system is active and for a reasonable wind-down period after closure.
7. Security
We use appropriate technical and organisational measures including access controls, encryption in transit, backups where applicable, and audit logs. No method of transmission or storage is 100% secure.
8. Your rights
Subject to UK GDPR, you may request access, correction, deletion, restriction, objection, data portability, or withdrawal of consent where applicable.
To exercise these rights, email info@calycks.com. You may also complain to the UK Information Commissioner's Office at ico.org.uk.
9. Cookies
We use cookies and similar technologies to operate the site, remember preferences, and measure performance. You can control cookies through your browser settings.
10. Rudood and connected business channels
Rudood is a multi-tenant business inbox, CRM, order, booking, follow-up, and human-support workflow product operated by Calycks Websites Ltd. The connected customer business is normally the controller for its customer conversations. Calycks and Rudood act as its technology and service provider when processing that data on the business's documented instructions. Product-specific information is set out in the Rudood Privacy Policy.
Data processed for Rudood
Depending on the channels and features a business enables, Rudood may process account and business details; Page, Instagram account, WhatsApp Business Account and phone-number identifiers; scoped user identifiers; encrypted access tokens; signed webhook events and delivery status; messages, attachments and media metadata; CRM records; orders; bookings; bot settings; and audit, support, abuse-prevention and security logs.
This data is used to connect official business channels, operate the shared inbox, send and receive replies, provide optional business-specific AI assistance, support human handoff, run CRM workflows, provide support, protect the service, prevent abuse, and meet legal and platform requirements. Rudood uses official Meta Graph APIs, the WhatsApp Cloud API, OAuth/Meta Embedded Signup and signed webhooks. It does not use WhatsApp Web or unofficial QR-session transport.
AI, service providers and transfers
Rudood does not sell Meta Platform Data or use it for advertising. WhatsApp Business Solution Data is not used to create, train, or improve a shared or general-purpose AI model. Contracted cloud, communications, support and AI subprocessors may process the minimum data needed to deliver a connected business's requested service. Where processing involves an international transfer, we use the safeguards described in section 5.
Security, retention and deletion
Rudood applies data minimisation, tenant separation, role-based access controls, encryption in transit, encrypted credential storage and restricted production access. Inbound WhatsApp media may be retrieved from Meta on demand for display or processing and is not permanently written to Rudood's VPS filesystem merely to render it in the inbox.
Data is retained only as needed for the enabled service, security, support and documented legal obligations. Disconnecting a channel triggers prompt access-token revocation and webhook disconnection where supported. A verified deletion request is normally completed without undue delay and within 30 days, unless a documented legal or security hold requires limited retention.
Rudood public product pages
11. Contact
Data controller: Calycks Websites Ltd, Company No. 17192351, 128 City Road, London, EC1V 2NX, United Kingdom. Email: info@calycks.com.
Calycks Websites Ltd - Company No. 17192351 - 128 City Road, London, EC1V 2NX, United Kingdom - info@calycks.com
