Legal

Privacy Policy

Last updated: [DATE PLACEHOLDER]

Placeholder notice: This is placeholder content and has not been reviewed by legal counsel — replace before processing real customer data at scale.

1. Who we are

EurekaDigital (“we”, “us”) is a boutique AI consulting studio that designs, builds, and operates custom WhatsApp scheduling agents and AI-driven social marketing systems for business clients. This policy covers two distinct kinds of data handling:

Data we collect directly from visitors to eurekadigital.io (for example, when you submit our contact form), where we are the data controller; and

Client business data that our systems process on behalf of our clients (for example, end-customer names, phone numbers, and booking details flowing through a WhatsApp agent we operate), where our client is the data controller and we act as a data processor. If you are an end customer interacting with one of our clients’ WhatsApp agents, please contact that business directly to exercise your rights — they own the relationship and the data.

2. Data we collect directly

Contact form submissions. When you use the lead-capture form on this site, we collect the name, email address, company name, and any message content you provide. We use this solely to respond to your inquiry and, if you become a client, to manage our engagement with you.

Website analytics. We may use privacy-respecting, aggregate analytics to understand site traffic (pages visited, approximate region, device type). We do not run advertising trackers or sell visitor data.

Communication records. If you email us or book a call, we retain the correspondence so we have context for our ongoing relationship.

3. Client business data we process

For active engagements, our systems process end-customer data strictly on our clients’ instructions: typically customer name, phone number, requested services, appointment times, and conversation history within WhatsApp threads. We use this data only to deliver the contracted service — booking appointments, sending reminders, recovering no-shows, and reporting on outcomes.

We do not sell client data, use it to train general-purpose models without explicit written agreement, or repurpose it for any other client’s benefit. Conversation data is stored in systems we control for the duration of the engagement and handled according to the data-processing terms in each client contract.

4. How long we keep data

Contact-form inquiries: up to 24 months if we don’t establish a business relationship, then deleted.

Client engagement data (including processed end-customer conversations): retained for the life of the engagement plus a reasonable wind-down period agreed in the client contract, after which it is deleted or returned at the client’s election.

Analytics data is kept in aggregate form and does not identify individuals.

5. Third-party processors

Our services necessarily rely on third-party infrastructure. Depending on the engagement, data may be processed by:

Meta / WhatsApp Business API — for message delivery and conversation storage within WhatsApp, subject to Meta’s own terms;

Calendar providers such as Google Calendar — when we read/write appointments on a client’s behalf;

Stripe — when a client elects to collect deposits or payments through a booking flow we build; payment card data goes directly to Stripe and never touches our servers;

Cloud hosting and LLM inference providers — used to host our systems and power conversational features, under agreements that restrict the use of customer data.

We select processors carefully and pass along equivalent confidentiality and security obligations wherever possible.

6. Your rights

Depending on where you live (for example under GDPR, UK GDPR, PIPEDA, or CCPA), you may have rights to access, correct, export, or delete your personal information, and to object to certain processing.

If your data was collected by this website (contact form), email us and we’ll action your request directly.

If your data exists because you interacted with one of our clients’ WhatsApp agents, contact that business first. Where a verified request comes from a client controller, we will support them in fulfilling it promptly.

7. Security & international transfers

We apply industry-standard safeguards: encryption in transit, least-privilege access controls, and restricted production access for engineering staff. No system is perfectly secure, but we treat client and end-customer data as sensitive by default.

Our team and providers may process data in jurisdictions other than your own (notably Canada and the United States). Where required, we rely on appropriate transfer mechanisms with our processors.

8. Changes to this policy

We may update this policy as our services evolve. Material changes will be reflected by updating the “last updated” date above, and where practical we will notify affected clients in advance.