Last Updated: September 12, 2026
Company: Rockybits Technologies Ltd (RC 8848920)
Address: Lagos State, Nigeria
Website: https://automateit.rockybits.com
Contact Email: [email protected]
Rockybits Technologies Ltd ("we," "our," or "us") operates the AutomateIt platform ("the Platform"), an AI-powered customer service assistant for businesses. A business connects the channels its customers already message it on — WhatsApp, Facebook Messenger, Instagram, Telegram or a chat widget on its own website — and the Platform answers those customers on the business's behalf. We are a verified Meta WhatsApp Tech Provider.
This Privacy Policy explains how we collect, use, disclose, and safeguard information when:
We are committed to protecting your privacy and complying with the Nigeria Data Protection Act 2023 (NDPA), the Meta Platform Terms, the WhatsApp Business Messaging Policy, the Messenger Platform and Instagram Messaging Policy, and applicable international privacy frameworks.
When a business signs up for AutomateIt, we collect:
| Category | Examples | Purpose |
|---|---|---|
| Account Information | Business name, email address, phone number, billing address | Account creation, billing, support |
| WhatsApp Business Account Data | Phone number ID, WABA ID, access tokens | Connecting to WhatsApp Cloud API via Embedded Signup |
| Business Configuration | AI system prompts, business policies, product catalogs, operating hours | Configuring the Client's AI agent |
| Third-Party Service Credentials | API keys and OAuth tokens for the services a business connects — Google Sheets, Docs, Gmail and Calendar (see Section 12), payment gateways, CRM and messaging tools | Letting the assistant act in the tools the business already uses |
| Billing Information | Payment method details (processed by Paystack/Stripe; we do not store full card numbers) | Subscription billing |
| Usage Data | Messages sent/received, features used, dashboard activity | Analytics, billing, platform improvements |
When an end customer interacts with a Client's WhatsApp AI agent, we process:
| Category | Examples | Purpose |
|---|---|---|
| Message Content | Text messages, media attachments sent to the Client's WhatsApp number | Delivering the AI automation service |
| Metadata | Phone number, message timestamp, delivery status | Message routing, analytics for the Client |
| Conversation Context | Chat history with the Client's business | Enabling multi-turn conversations and memory features (Phase 4+) |
| Category | Examples | Purpose |
|---|---|---|
| Server Logs | IP address, browser type, and the pages requested, recorded automatically by our servers | Security, preventing abuse, and diagnosing faults |
| Contact Information | Name, email, message content (if you use our contact form) | Responding to inquiries |
That is the whole of it. We run no analytics, advertising or tracking software on this website— no Google Analytics, no advertising pixels, no session recording, no third-party trackers of any kind. Nobody is profiled for visiting, and nothing about a visit is sold or shared for marketing.
We use cookies only where the site cannot work without them:
These are strictly necessary cookies. Under the NDPA General Application and Implementation Directive (GAID) 2025and equivalent rules elsewhere, cookies that are necessary for a service the user asked for do not require consent — consent is required for analytics, advertising and tracking cookies, and we set none. That is why you are not asked to dismiss a cookie banner to read this page.
If we ever add analytics or advertising technology, we will ask for your consent before it runs, make refusing as easy as accepting, and update this section before it goes live.
A business may connect WhatsApp, a Facebook Page (Messenger) or an Instagram professional account. On each of them we process messages solely for:
We do not:
All End User interactions processed through a Client's WhatsApp number belong to that Client. The Client has access to:
As a Tech Provider, we share data with Meta as required to operate the WhatsApp Business Platform, including:
All data shared with Meta is governed by Meta's Data Policy and WhatsApp Business Terms of Service.
We use the following third-party services to run the Platform. Each processes data only to provide the service described, and the country is where that processing takes place.
| Service Provider | Purpose | Data Shared | Processed in |
|---|---|---|---|
| Meta Platforms (WhatsApp, Messenger, Instagram) | Delivering and receiving messages on the channels a business has connected | Message content, phone numbers, account identifiers | United States |
| Supabase | The database and file storage where conversations, contacts, products and uploaded media are kept | All Platform data | Germany |
| Amazon Web Services | Generating replies (Bedrock), transcribing voice notes (Transcribe), and encrypting stored credentials (KMS) | Message content, voice recordings, images sent by customers | United States |
| Meta Platforms (Meta Model API) | Generating replies. See section 11 — this is billed on a tier under which data may be used to improve the provider's products | Message content and the conversation context needed to answer | United States |
| Railway | Hosting the application that receives and answers messages | All Platform data in transit | United States |
| Vercel | Hosting the dashboard, the storefront and the website chat widget | All Platform data in transit | United States |
| Resend | Sending notification emails to a business, such as when a conversation needs a person or a payment receipt arrives | Extracts of message content, contact names | United States |
| Paystack / Flutterwave / Stripe | Payment processing. Where a business connects its own payment account, payments are made to that business directly and we are not the merchant of record | Order amounts and references; billing details for our own subscriptions | Nigeria, United States |
Businesses may additionally connect their own third-party tools to the Platform. Where they do, data is shared with those tools at the business's direction and under that provider's own terms.
We may disclose information if required by law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to:
If Rockybits Technologies Ltd is involved in a merger, acquisition, or sale of assets, Client and End User data may be transferred as part of that transaction. We will notify Clients of any such change in ownership or control.
AutomateIt is a multi-tenant platform serving multiple business Clients simultaneously. We implement strict technical and organizational measures to ensure complete data isolation:
client_id and logically separated.client_id. Cross-tenant access is automatically blocked and logged as a security event.End User data is retained according to the Client's configured retention period. End Users may request data deletion by contacting the Client directly or by emailing us at [email protected].
Upon account closure or data deletion request:
Under the Nigeria Data Protection Regulation (NDPR) and other applicable privacy laws, individuals have the following rights:
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) or your local data protection authority.
On WhatsApp. End Users may stop receiving automated messages from any Client at any time by:
On Messenger and Instagram.We do not process opt-out keywords on these channels, and we do not need to: the assistant only replies inside a conversation the End User themselves started, within the messaging window Meta allows. We do not send marketing, broadcast or campaign messages on Messenger or Instagram at all. An End User who wants no further contact can simply stop writing, or block the business using Facebook's or Instagram's own controls, and we will not message them.
We implement industry-standard security measures to protect all data:
Rockybits Technologies Ltd is registered in Nigeria, and most of the businesses using the Platform, and their customers, are in Nigeria. Our infrastructure is not: the services listed in section 4.3 process data outside Nigeria, principally in Germany — where the database holding conversations is located — and the United States, where messages are sent to be answered and where the application and dashboard are hosted.
This means personal data, including the content of a customer's messages, is transferred out of Nigeria in the ordinary course of providing the service. Where such transfers occur we rely on the safeguards in our agreements with each provider, including standard contractual clauses and data processing terms. A business or an End User may contact us at any time to ask where their data is held.
To answer a customer, the Platform sends that customer's message, and enough of the conversation to make sense of it, to an AI model provider. It may also send a photograph or a voice recording the customer attached, so the assistant can respond to what was actually sent. The providers are:
Where a business supplies its own model provider and API key, messages go to that provider instead, under that provider's terms rather than ours.
We do not sell personal data, and we do not share one business's data with another. Except as stated above for the Meta Model API, we do not permit AI providers to train on Platform data.
A business may connect its own Google account so the assistant can do specific jobs on that business's behalf. Nothing here happens unless a business connects the service and signs in to Google itself. This section describes how AutomateIt accesses, uses, stores and shares Google user data.
drive.file. Reaches only the individual files the business picked itself through Google's own file picker. It cannot see anything else in their Drive. Used to read a supplier list or a price sheet the business keeps there, and to add rows or notes when they ask the assistant to.gmail.send. Sends an email from the business's own address when a customer asks for something in writing — an order summary, product details, a receipt. It cannot read, search, or open any email.We deliberately do not request any permission that would let the assistant see a business's mail.calendar.events.owned. Reads and creates events on calendars the business owns, so the assistant can tell a customer when the shop is free and book an appointment once they agree a time. It does not reach calendars shared with them by other people.Google user data is used only to deliver the feature the business switched on, in response to that business's own customers, and at the moment it is needed. We do not use it for advertising, we do not use it to build profiles, and we do not use it for credit or lending decisions.
Where a connector reads— a calendar lookup, a row from a sheet, the text of a document — what comes back is given to the AI model provider described in Section 11 so it can compose the reply the customer asked for. This is the same handling as any other message content, and it is the only onward transfer of Google user data that occurs. A business that would rather this did not happen should not connect the reading connectors; Gmail sends only and never returns mail content.
The access and refresh tokens Google issues are held in our credential vault, encrypted with AWS Key Management Service envelope encryption. The encryption is bound to the business it belongs to, so one business's Google credentials cannot be decrypted as another's. We store no copy of a business's Google files, mail or calendar beyond what appears in the conversation it was needed for, which follows the retention rules in Section 6.
AutomateIt's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, we do not transfer it to third parties except as described above to deliver the feature, and we do not permit humans to read it except with the business's consent, for security, or where the law requires it.
A business can disconnect any Google service at any time from the Connect page in their AutomateIt dashboard, which deletes the stored tokens. They can also revoke our access directly at myaccount.google.com/permissions. Either way the assistant loses access immediately and will say so rather than fail silently.
As a Meta Tech Provider application, we provide the following endpoints for Meta compliance:
https://automateit.rockybits.com/api/v1/meta/deauthorize— Triggered when someone removes our app from their Facebook account. We verify the signed request and immediately mark that business's Facebook and Instagram connections as needing to be reconnected, because the access tokens are no longer valid. Nothing is deleted: removing an app is not a request to erase a business's data, and their records, conversations and other connected channels are untouched.https://automateit.rockybits.com/api/v1/meta/data-deletion— Triggered when a person asks Meta to have their data deleted. We verify the signed request, delete the conversations, messages and contact records we hold for that person, and return a confirmation URL where they can check the status of the request.You can also ask us directly, at any time, by emailing [email protected]. We complete deletion requests within 30 days.
Rockybits Technologies Ltd operates AutomateIt in compliance with:
This privacy policy is effective as of September 12, 2026. It supersedes any prior versions.
Rockybits Technologies Ltd | RC 8848920 | Lagos State, Nigeria | https://automateit.rockybits.com
Join 500+ businesses using AutomateIt to drive sales, support customers, and scale operations instantly.
No credit card required to start • Cancel anytime