Blucript Technology Trading and Services LLC (“Blucript”, “we”, “us”, or “our”) respects your
privacy and is committed to protecting personal data. This Privacy Policy explains how we collect, use,
disclose, store, and safeguard personal information when you visit our website or use our cloud-based
software-as-a-service platform, including our WhatsApp API and related services (collectively, the
“Services”).
By using the Services, you agree to the collection and use of information in accordance with this Privacy Policy.
This Privacy Policy is designed to comply with applicable laws in the State of Qatar, generally accepted
international data protection principles, and Meta / WhatsApp platform requirements.
1. Company Information
Legal Name: Blucript Technology Trading and Services LLC
Commercial Registration: CR 202885
Country of Incorporation: Qatar
Registered & Operational Address:
Office B11, Hub Business Center,
Building No. 78, Street No. 840, Area No. 39,
Al Naaser, Doha, Qatar
Website:https://blucript.com Support Email: support@blucript.com Privacy Contact: privacy@blucript.com
2. Definitions
Account means a unique account created to access the Services.
Company refers to Blucript Technology Trading and Services LLC.
Customer means a business entity using our Services.
End User means an individual communicating with a Customer via WhatsApp.
Personal Data means any information relating to an identified or identifiable individual.
Service refers to our website and SaaS platform.
You means the individual or legal entity accessing or using the Services.
3. Scope of This Privacy Policy
Website visitors
Business customers using our SaaS platform
Authorized users of customer accounts
End users communicating with businesses via WhatsApp using our platform
This Privacy Policy does not replace or override the privacy policies of Meta or WhatsApp, which govern
their independent processing of personal data.
4. Our Role: Data Controller & Data Processor
4.1 Data Controller
Blucript acts as a Data Controller when processing personal data for its own business purposes, including:
Account registration and administration
Billing and subscription management
Customer support
Website and platform operations
4.2 Data Processor
Blucript acts as a Data Processor when processing personal data on behalf of Customers, including:
WhatsApp messages and media
End-user phone numbers and profile names
Messaging-related metadata processed via WhatsApp Business API
5. Personal Data We Collect
5.1 Business Customer Data
Name
Email address
Phone number
Login credentials
Billing and payment details
Usage logs and system activity data
5.2 End-User (WhatsApp User) Data
Phone numbers
Profile names
Message content
Media files (images, videos, documents)
Blucript does not independently initiate communication with or market to End Users.
5.3 Sensitive & Health Data
We do not intentionally collect Sensitive Personal Data (such as health or medical information). If a Customer or End User transmits such data through our Services, it is processed under the strict assumption that the Customer has obtained the necessary explicit, documented consent from the End User as required by applicable data protection laws before utilizing our Services.
6. Meta / Facebook Embedded Signup
WhatsApp Business API activation requires completion of Meta’s Embedded Signup process.
Customers authenticate directly with Meta. Blucript does not receive Facebook login credentials
or social profile data.
Blucript may receive limited technical identifiers such as:
WhatsApp Business Account ID
Meta Business Manager ID
Associated WhatsApp phone number
Authorization tokens
7. Message Storage & Data Retention
Data is stored only while a subscription is active
After termination, data is retained for 30 days
Data is permanently deleted thereafter unless legally required
Data is deleted from active systems within 30 days of termination. Residual copies held in
encrypted backups are purged on a rolling cycle and are not used to restore terminated accounts.
8. Purpose of Processing
Provide and operate the Services
Enable WhatsApp Business API functionality
Manage accounts and subscriptions
Provide customer and technical support
Analyse message content to detect intent and sentiment and to generate replies, analytics, and insights (see Section 10)
Maintain security and compliance
9. Data Security
Encryption at rest and in transit
Role-based access controls
Audit logging
Secure cloud infrastructure
While we implement strong safeguards, no system can be guaranteed to be completely secure.
10. AI & Automated Processing
AI analysis is optional and is switched off by default. A Customer may turn it on, and turn it
off again at any time, under Settings → Business Details in the Blucript dashboard. Where it is
enabled, we use automated systems, including third-party artificial intelligence services, to
analyse message content in order to detect customer intent and sentiment, generate suggested or
automated replies, and produce analytics and insights for the Customer.
Message content, including the text of messages exchanged between Customers and End Users, is
transmitted to Google’s Vertex AI service for this analysis.
Vertex AI is accessed within Blucript’s own Google Cloud project and is governed by Google
Cloud’s data processing terms. Google does not use this content to train its own models.
This analysis currently uses Vertex AI’s global endpoint. Processing may therefore take
place in any region in which Google operates Vertex AI, and not solely within the State of Qatar.
Where a Customer enables Meta’s business AI features, message content is additionally
processed by Meta in order to generate replies.
Only messages received after a Customer switches the feature on are analysed. Switching it off
stops any further analysis; insights already generated remain available to the Customer until
deleted under our retention policy.
Meta’s business AI features are a separate, independent setting that a Customer may enable
or disable on its own.
We do not use message content to train our own models, and we do not sell message content.
This automated analysis does not produce legal effects concerning End Users or similarly
significantly affect them. Customers act as the data controller for their End User data and remain
responsible for informing their End Users of this processing where applicable law requires it.
11. Sub-processors & International Processing
We engage the following third parties to process personal data on our behalf:
Google Cloud Platform — hosting, storage, and database services. Primary region: me-central1 (Doha, Qatar).
Google Vertex AI — AI analysis of message content, as described in Section 10. Global endpoint.
Meta Platforms — WhatsApp Business Platform message delivery, and business AI features where enabled by the Customer.
Google Analytics and Meta Pixel — website analytics and marketing, as described in Section 12.
Customer data is primarily stored in Qatar. As described above, certain processing takes place
outside Qatar. We take reasonable steps to ensure that our sub-processors are bound by obligations
no less protective than those set out in this Privacy Policy, and we will give Customers reasonable
advance notice before adding a new sub-processor that processes message content.
12. Cookies & Website Tracking
We use cookies and similar tracking technologies to track activity on our Services and hold certain information. We use essential cookies for basic functionality and security. We may also use analytics and marketing cookies (such as Google Analytics or Meta Pixel) to improve our Services, analyze usage, and deliver relevant advertisements. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent; however, if you do not accept cookies, you may not be able to use some portions of our Services.
13. Data Subject Rights
Access personal data
Correct inaccurate data
Request deletion
Export data
Object to or restrict processing
Requests may be submitted to privacy@blucript.com.
14. Google Workspace Integrations (Google Sheets & Google Calendar)
Customers may optionally connect their own Google account so that Blucript can write
business records into their Google Sheets or Google Calendar. The connection is made
using Google OAuth 2.0. Customers authenticate directly with Google, and Blucript never
receives or stores Google account passwords.
Blucript requests only the following Google permissions, and only those a Customer grants:
Google Sheets (spreadsheets) — to append rows to the single
spreadsheet the Customer selects, and to read that spreadsheet’s title in order to
confirm the connection is working.
Google Drive (drive.file) — a per-file permission used only to
list spreadsheets the Customer created through, or explicitly opened with, Blucript so they
can choose a destination. Blucript cannot access any other file in the Customer’s Drive.
Google Calendar (calendar.events, calendar.readonly) —
to create a calendar event when a booking is made and remove it if the booking is cancelled,
and to list the calendars the Customer is able to write to so they can choose one.
How this data is handled:
Data flows outward only. Blucript writes booking, contact and message
events into the destination the Customer selects. Blucript does not read, import, index or
store the contents of a Customer’s existing spreadsheets, files or calendar entries.
Google OAuth access and refresh tokens are encrypted at rest and are used solely to carry
out the actions described above on the Customer’s behalf.
Google user data is never sold, never transferred to third parties, never used for
advertising, and never used to train artificial-intelligence or machine-learning models.
Only administrators of the Customer’s own Blucript account can view or change the
connection.
A Customer may disconnect at any time from API Settings inside Blucript, or by revoking
access at
myaccount.google.com/permissions.
Removing the connection in Blucript deletes the stored tokens. Records already written into
the Customer’s own spreadsheet or calendar remain in the Customer’s Google account
and under the Customer’s control.
Limited Use disclosure. Blucript’s use and transfer of information
received from Google APIs to any other app will adhere to the
Google API Services User Data Policy,
including the Limited Use requirements.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with
a revised “Last updated” date.
Contact Us
Email: privacy@blucript.com
Blucript Technology Trading and Services LLC
Doha, Qatar