Privacy Policy

Last Updated: September 12, 2026

Company: Rockybits Technologies Ltd (RC 8848920)

Address: Lagos State, Nigeria

Website: https://automateit.rockybits.com

Contact Email: [email protected]

1. Introduction

Rockybits Technologies Ltd ("we," "our," or "us") operates the AutomateIt platform ("the Platform"), an AI-powered customer service assistant for businesses. A business connects the channels its customers already message it on — WhatsApp, Facebook Messenger, Instagram, Telegram or a chat widget on its own website — and the Platform answers those customers on the business's behalf. We are a verified Meta WhatsApp Tech Provider.

This Privacy Policy explains how we collect, use, disclose, and safeguard information when:

  • A business ("Client") uses our Platform to answer their customers on the channels they have connected.
  • An end customer ("End User") messages a Client on any connected channel and is answered by an AI agent powered by our Platform.
  • Anyone visits our website at https://automateit.rockybits.com.

We are committed to protecting your privacy and complying with the Nigeria Data Protection Act 2023 (NDPA), the Meta Platform Terms, the WhatsApp Business Messaging Policy, the Messenger Platform and Instagram Messaging Policy, and applicable international privacy frameworks.

2. Information We Collect

2.1 Information Collected from Clients

When a business signs up for AutomateIt, we collect:

CategoryExamplesPurpose
Account InformationBusiness name, email address, phone number, billing addressAccount creation, billing, support
WhatsApp Business Account DataPhone number ID, WABA ID, access tokensConnecting to WhatsApp Cloud API via Embedded Signup
Business ConfigurationAI system prompts, business policies, product catalogs, operating hoursConfiguring the Client's AI agent
Third-Party Service CredentialsAPI keys and OAuth tokens for the services a business connects — Google Sheets, Docs, Gmail and Calendar (see Section 12), payment gateways, CRM and messaging toolsLetting the assistant act in the tools the business already uses
Billing InformationPayment method details (processed by Paystack/Stripe; we do not store full card numbers)Subscription billing
Usage DataMessages sent/received, features used, dashboard activityAnalytics, billing, platform improvements

2.2 Information Collected from End Users

When an end customer interacts with a Client's WhatsApp AI agent, we process:

CategoryExamplesPurpose
Message ContentText messages, media attachments sent to the Client's WhatsApp numberDelivering the AI automation service
MetadataPhone number, message timestamp, delivery statusMessage routing, analytics for the Client
Conversation ContextChat history with the Client's businessEnabling multi-turn conversations and memory features (Phase 4+)

2.3 Information Collected from Website Visitors

CategoryExamplesPurpose
Server LogsIP address, browser type, and the pages requested, recorded automatically by our serversSecurity, preventing abuse, and diagnosing faults
Contact InformationName, email, message content (if you use our contact form)Responding to inquiries

That is the whole of it. We run no analytics, advertising or tracking software on this website— no Google Analytics, no advertising pixels, no session recording, no third-party trackers of any kind. Nobody is profiled for visiting, and nothing about a visit is sold or shared for marketing.

2.4 Cookies

We use cookies only where the site cannot work without them:

  • Signing in. When a business logs into the dashboard, a session cookie keeps them signed in as they move between pages. Without it, every page would ask them to log in again.
  • Connecting WhatsApp.A business connecting their WhatsApp Business Account uses Meta's own sign-up window, which sets cookies belonging to Meta. This happens only inside the dashboard, and only when a business starts that connection themselves.

These are strictly necessary cookies. Under the NDPA General Application and Implementation Directive (GAID) 2025and equivalent rules elsewhere, cookies that are necessary for a service the user asked for do not require consent — consent is required for analytics, advertising and tracking cookies, and we set none. That is why you are not asked to dismiss a cookie banner to read this page.

If we ever add analytics or advertising technology, we will ask for your consent before it runs, make refusing as easy as accepting, and update this section before it goes live.

3. How We Use Information

3.1 Primary Uses

  • Provide the Service: Route WhatsApp messages, process AI responses, execute Business Actions (e.g., payment link generation, calendar booking), and deliver analytics to Clients.
  • Maintain and Improve the Platform: Monitor performance, fix bugs, train AI models (only with aggregated, anonymized data; individual Client data is never used for model training without explicit consent).
  • Billing and Account Management: Process subscription payments, manage account settings, send service-related communications.
  • Security and Compliance: Detect and prevent fraud, abuse, and unauthorized access; comply with legal obligations; enforce Platform Terms and Meta's policies.
  • Client Support: Respond to inquiries, troubleshoot issues, provide technical assistance.

3.2 Uses Specific to Meta Channels

A business may connect WhatsApp, a Facebook Page (Messenger) or an Instagram professional account. On each of them we process messages solely for:

  • Delivering AI-powered automated responses as configured by the Client.
  • Routing messages between End Users and the Client's designated AI agents.
  • Reading a public comment on the Client's Facebook or Instagram post so it can be answered, and sending a single private reply to the person who wrote it. Where the Client has switched it on, we may also post one short public line under the comment saying that a private reply has been sent.
  • Providing conversation logs to the Client, so a person at the business can read any conversation and take it over.
  • Ensuring compliance with the WhatsApp Business Messaging Policy and the Messenger Platform and Instagram Messaging Policy, including opt-out handling, messaging windows and quality monitoring.

We do not:

  • Read, mine, or use message content for advertising purposes.
  • Sell message data to third parties.
  • Initiate conversations with End Users independently of the Client's configuration.

4. How We Share Information

4.1 With the Client (Business)

All End User interactions processed through a Client's WhatsApp number belong to that Client. The Client has access to:

  • Conversation histories with their End Users.
  • Analytics derived from their End Users' interactions.
  • Any data stored in the Client's configured third-party integrations (Google Sheets, CRM, etc.).

4.2 With Meta (WhatsApp)

As a Tech Provider, we share data with Meta as required to operate the WhatsApp Business Platform, including:

  • Message content and metadata for delivery.
  • Template submissions for approval.
  • Quality and compliance data as required by Meta's policies.

All data shared with Meta is governed by Meta's Data Policy and WhatsApp Business Terms of Service.

4.3 With Third-Party Service Providers

We use the following third-party services to run the Platform. Each processes data only to provide the service described, and the country is where that processing takes place.

Service ProviderPurposeData SharedProcessed in
Meta Platforms (WhatsApp, Messenger, Instagram)Delivering and receiving messages on the channels a business has connectedMessage content, phone numbers, account identifiersUnited States
SupabaseThe database and file storage where conversations, contacts, products and uploaded media are keptAll Platform dataGermany
Amazon Web ServicesGenerating replies (Bedrock), transcribing voice notes (Transcribe), and encrypting stored credentials (KMS)Message content, voice recordings, images sent by customersUnited States
Meta Platforms (Meta Model API)Generating replies. See section 11 — this is billed on a tier under which data may be used to improve the provider's productsMessage content and the conversation context needed to answerUnited States
RailwayHosting the application that receives and answers messagesAll Platform data in transitUnited States
VercelHosting the dashboard, the storefront and the website chat widgetAll Platform data in transitUnited States
ResendSending notification emails to a business, such as when a conversation needs a person or a payment receipt arrivesExtracts of message content, contact namesUnited States
Paystack / Flutterwave / StripePayment processing. Where a business connects its own payment account, payments are made to that business directly and we are not the merchant of recordOrder amounts and references; billing details for our own subscriptionsNigeria, United States

Businesses may additionally connect their own third-party tools to the Platform. Where they do, data is shared with those tools at the business's direction and under that provider's own terms.

4.4 Legal Disclosures

We may disclose information if required by law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to:

  • Comply with legal obligations.
  • Protect the rights, property, or safety of Rockybits Technologies Ltd, our Clients, or the public.
  • Prevent or investigate potential violations of our Terms of Service or Meta's policies.

4.5 Business Transfers

If Rockybits Technologies Ltd is involved in a merger, acquisition, or sale of assets, Client and End User data may be transferred as part of that transaction. We will notify Clients of any such change in ownership or control.

5. Multi-Tenancy & Data Isolation

AutomateIt is a multi-tenant platform serving multiple business Clients simultaneously. We implement strict technical and organizational measures to ensure complete data isolation:

  • Tenant-Scoped Data: All data (messages, configurations, credentials) is tagged with a unique client_id and logically separated.
  • Attribute-Based Access Control (ABAC): Every database query and AI retrieval operation is filtered by client_id. Cross-tenant access is automatically blocked and logged as a security event.
  • Isolated Credential Storage: Client API keys and access tokens are encrypted per tenant in a secure vault.
  • Encrypted Credentials: Access tokens and payment credentials are protected with envelope encryption using AWS Key Management Service, under a separate data key per tenant. If the key service cannot be reached, the operation is refused rather than falling back to weaker encryption.
  • Zero Cross-Tenant AI Training: Client data from one tenant is never used to train or fine-tune AI models that serve another tenant.

6. Data Retention

6.1 Client Data

  • Account Information: Duration of the Client's account + 90 days after account closure.
  • Message Content and Logs: 90 days (default) or as configured by the Client (30, 90, or 365 days for Phase 4+ Enterprise plans).
  • AI Configuration and Prompts: Duration of the Client's account.
  • Billing Records: 7 years (for legal and tax compliance).

6.2 End User Data

End User data is retained according to the Client's configured retention period. End Users may request data deletion by contacting the Client directly or by emailing us at [email protected].

6.3 Data Deletion

Upon account closure or data deletion request:

  • Client data is permanently deleted within 30 days.
  • Backups are purged within 90 days.
  • Aggregated, anonymized data may be retained indefinitely.

7. Data Subject Rights

Under the Nigeria Data Protection Regulation (NDPR) and other applicable privacy laws, individuals have the following rights:

  • Right to Access: Request a copy of your personal data.
  • Right to Rectification: Request correction of inaccurate data.
  • Right to Erasure: Request deletion of your data ("right to be forgotten").
  • Right to Restrict Processing: Request limited processing of your data.
  • Right to Data Portability: Request your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Withdraw previously given consent at any time.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) or your local data protection authority.

8. How an End User Stops Receiving Messages

On WhatsApp. End Users may stop receiving automated messages from any Client at any time by:

  • Sending STOP, UNSUBSCRIBE, CANCEL, or REMOVE as a WhatsApp message to the Client's number.
  • Our Platform automatically processes these opt-out keywords and blocks further automated messages to that phone number for that Client.
  • Opt-out requests are effective immediately, and the message is not shown to the AI agent.

On Messenger and Instagram.We do not process opt-out keywords on these channels, and we do not need to: the assistant only replies inside a conversation the End User themselves started, within the messaging window Meta allows. We do not send marketing, broadcast or campaign messages on Messenger or Instagram at all. An End User who wants no further contact can simply stop writing, or block the business using Facebook's or Instagram's own controls, and we will not message them.

9. Security Measures

We implement industry-standard security measures to protect all data:

  • Encryption in Transit: All data transmitted between End Users, Meta, our servers, and third-party services is encrypted using TLS 1.3.
  • Encryption at Rest: All stored data is encrypted using AES-256.
  • Access Controls: Strict role-based access controls; multi-factor authentication for administrative access.
  • Audit Logging: All data access, modifications, and agent actions are logged for security monitoring.
  • Penetration Testing: Regular security assessments and vulnerability testing.

10. International Data Transfers

Rockybits Technologies Ltd is registered in Nigeria, and most of the businesses using the Platform, and their customers, are in Nigeria. Our infrastructure is not: the services listed in section 4.3 process data outside Nigeria, principally in Germany — where the database holding conversations is located — and the United States, where messages are sent to be answered and where the application and dashboard are hosted.

This means personal data, including the content of a customer's messages, is transferred out of Nigeria in the ordinary course of providing the service. Where such transfers occur we rely on the safeguards in our agreements with each provider, including standard contractual clauses and data processing terms. A business or an End User may contact us at any time to ask where their data is held.

11. AI Model Providers & Data Usage

To answer a customer, the Platform sends that customer's message, and enough of the conversation to make sense of it, to an AI model provider. It may also send a photograph or a voice recording the customer attached, so the assistant can respond to what was actually sent. The providers are:

  • Amazon Web Services (Bedrock): generating replies and reading images a customer sends. AWS does not use content submitted through Bedrock to train its models.
  • Amazon Web Services (Transcribe):converting a customer's voice note into text so it can be answered. Amazon may temporarily store audio to improve its service; a business may ask us to disable this for their account.
  • Meta Platforms (Meta Model API): generating replies. We currently use a pricing tier under which the data sent may be used to improve Meta's products. This is the one provider on this list that does not exclude training, and we state it here rather than leave it implied.

Where a business supplies its own model provider and API key, messages go to that provider instead, under that provider's terms rather than ours.

We do not sell personal data, and we do not share one business's data with another. Except as stated above for the Meta Model API, we do not permit AI providers to train on Platform data.

12. Google Workspace Connections

A business may connect its own Google account so the assistant can do specific jobs on that business's behalf. Nothing here happens unless a business connects the service and signs in to Google itself. This section describes how AutomateIt accesses, uses, stores and shares Google user data.

What we ask Google for, and what each permission allows

  • Google Sheets and Google Docs drive.file. Reaches only the individual files the business picked itself through Google's own file picker. It cannot see anything else in their Drive. Used to read a supplier list or a price sheet the business keeps there, and to add rows or notes when they ask the assistant to.
  • Gmailgmail.send. Sends an email from the business's own address when a customer asks for something in writing — an order summary, product details, a receipt. It cannot read, search, or open any email.We deliberately do not request any permission that would let the assistant see a business's mail.
  • Google Calendar calendar.events.owned. Reads and creates events on calendars the business owns, so the assistant can tell a customer when the shop is free and book an appointment once they agree a time. It does not reach calendars shared with them by other people.

How the data is used

Google user data is used only to deliver the feature the business switched on, in response to that business's own customers, and at the moment it is needed. We do not use it for advertising, we do not use it to build profiles, and we do not use it for credit or lending decisions.

Where a connector reads— a calendar lookup, a row from a sheet, the text of a document — what comes back is given to the AI model provider described in Section 11 so it can compose the reply the customer asked for. This is the same handling as any other message content, and it is the only onward transfer of Google user data that occurs. A business that would rather this did not happen should not connect the reading connectors; Gmail sends only and never returns mail content.

How the data is stored

The access and refresh tokens Google issues are held in our credential vault, encrypted with AWS Key Management Service envelope encryption. The encryption is bound to the business it belongs to, so one business's Google credentials cannot be decrypted as another's. We store no copy of a business's Google files, mail or calendar beyond what appears in the conversation it was needed for, which follows the retention rules in Section 6.

Limited Use

AutomateIt's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, we do not transfer it to third parties except as described above to deliver the feature, and we do not permit humans to read it except with the business's consent, for security, or where the law requires it.

How a business disconnects

A business can disconnect any Google service at any time from the Connect page in their AutomateIt dashboard, which deletes the stored tokens. They can also revoke our access directly at myaccount.google.com/permissions. Either way the assistant loses access immediately and will say so rather than fail silently.

13. Deauthorize & Data Deletion Callbacks

As a Meta Tech Provider application, we provide the following endpoints for Meta compliance:

  • Deauthorize Callback: https://automateit.rockybits.com/api/v1/meta/deauthorize— Triggered when someone removes our app from their Facebook account. We verify the signed request and immediately mark that business's Facebook and Instagram connections as needing to be reconnected, because the access tokens are no longer valid. Nothing is deleted: removing an app is not a request to erase a business's data, and their records, conversations and other connected channels are untouched.
  • Data Deletion Callback: https://automateit.rockybits.com/api/v1/meta/data-deletion— Triggered when a person asks Meta to have their data deleted. We verify the signed request, delete the conversations, messages and contact records we hold for that person, and return a confirmation URL where they can check the status of the request.

You can also ask us directly, at any time, by emailing [email protected]. We complete deletion requests within 30 days.

14. Compliance Statement

Rockybits Technologies Ltd operates AutomateIt in compliance with:

  • Nigeria Data Protection Act 2023 (NDPA) — Nigeria's primary data protection law, and the one that governs us as a company registered here.
  • Nigeria Data Protection Regulation (NDPR) 2019 — which the NDPA builds on and which remains in force alongside it.
  • Meta Platform Terms — including the WhatsApp Business Messaging Policy, the Messenger Platform and Instagram Messaging Policy, and the Commerce Policy.
  • Meta Tech Provider Terms — governing our status as a verified WhatsApp Tech Provider.
  • General Data Protection Regulation (GDPR) — for any data subjects within the European Union, and because our database is hosted there.
  • Google API Services User Data Policy — including the Limited Use requirements, which govern the Google Workspace connections described in Section 12.

This privacy policy is effective as of September 12, 2026. It supersedes any prior versions.

Rockybits Technologies Ltd | RC 8848920 | Lagos State, Nigeria | https://automateit.rockybits.com

Ready to put your WhatsApp on Autopilot?

Join 500+ businesses using AutomateIt to drive sales, support customers, and scale operations instantly.

No credit card required to start • Cancel anytime