← Back to relayplus.app

Privacy policy

1. Who we are

RelayPlus (“RelayPlus”, “we”, “us”, or “our”) is a product operated by LETSGATHER APP SOLUTIONS LIMITED. The company builds software that businesses use to talk to their customers on WhatsApp, Instagram and Messenger. Our registered office is 2202-823 Carnarvon Street, New Westminster, British Columbia V3M 0N5, Canada.

Two different relationships are covered by this policy, and it matters which one you are in. If you signed up for RelayPlus, we are the data controller for your account. If you are a customer who messaged a business that uses RelayPlus, that business is the controller of your conversation and we are its processor — we handle your data on their instructions, and they decide how long to keep it.

2. What we collect

We collect three categories of data and nothing outside them.

3. What we never do

We do not sell personal data. We do not share it with advertisers or data brokers. We do not use your conversations to train general-purpose AI models — the AI features in RelayPlus run on models we license, and your messages are passed through for inference only, never retained by the model provider for training. We do not read your conversations except when you ask support for help with a specific thread and grant temporary access, which is logged and expires after 72 hours.

4. Why we process it

Under GDPR terms, our lawful bases are:

5. Who we share it with

We use three subprocessors, each under a data processing agreement. The full list, with what each one receives, is at relayplus.app/subprocessors, and we give 30 days notice before adding one.

6. Where your data lives

Your data is held in a single region on our hosting provider’s infrastructure. We do not currently offer a choice of data region, and we will tell you here before that changes. Transfers out of the EEA and the UK rely on the European Commission’s Standard Contractual Clauses.

7. How long we keep it

Retention is set by the workspace owner in Settings, within these limits:

8. Your rights

Wherever you live, you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop processing it, object to processing based on legitimate interest, and withdraw consent. Californian residents additionally have the CCPA rights to know, delete, correct, and to opt out of sale or sharing — which is easy for us, because we do neither.

Account holders can do most of this without asking: Settings → Data controls has one-click export in JSON and CSV, and a delete-workspace button. For anything else, or if you are an end customer rather than an account holder, use the data deletion page or write to [email protected]. We answer within 30 days, usually within 2 business days, and we do not charge for it.

9. Security

TLS 1.3 in transit, AES-256 at rest. Two-factor authentication available on every plan and enforceable workspace-wide. Role-based access control, with every permission change written to an audit log you can read. Annual third-party penetration test, summary available under NDA. SOC 2 Type II report available on request. If a breach affects your data we will tell you within 72 hours of becoming aware, with what happened and what we are doing about it — no waiting for the legal team to soften it.

10. Children

RelayPlus is a business tool and is not directed at anyone under 16. We do not knowingly collect their data. If a business using RelayPlus has messaged a child and you tell us, we will delete the record and notify the business of their obligation.

11. Changes and contact

We will email every workspace owner at least 30 days before a material change to this policy, and keep previous versions available at relayplus.app/legal/history. Continued use after the effective date means acceptance.

Data protection contact: [email protected]. Our EU representative is Ravenholm Data Services BV, Prinsengracht 263, Amsterdam. You can complain to your local supervisory authority at any time, but we would rather you gave us a chance to fix it first.