Privacy Policy
Last updated: July 8, 2026
ProtoHQ ("ProtoHQ", "we", "us") provides an operations-automation platform that helps businesses turn their WhatsApp conversations into tracked work. This Privacy Policy explains what information the ProtoHQ application collects, how we use it, how we protect it, and the choices you have. It applies to the ProtoHQ web application at app.protohq.co.in and this website.
Who this applies to
ProtoHQ is a business-to-business product used by organisations ("customers") that operate their own ProtoHQ workspace. If you interact with a business that uses ProtoHQ, that business is the controller of your data; please refer to that business's own privacy notice for details about how they handle it.
Information we process
- Account information — the email address and name used to sign in to a workspace, and authentication session data.
- Conversation content — messages and related metadata from a customer's connected business WhatsApp number, which the customer chooses to process through ProtoHQ.
- Operational data — the tasks, priorities, assignments, and approvals generated from those conversations.
- Integration data — information retrieved from third-party services a customer connects (see "Google user data" and "Other integrations" below).
- Technical data — logs and diagnostic information needed to operate the service securely and reliably.
Google user data
If a customer chooses to connect a Google account, ProtoHQ requests read-only access to the following, and only to provide features the customer has asked for:
- Google Contacts (
contacts.readonly) — to identify and enrich the people in WhatsApp conversations, so a conversation shows a real name rather than only a phone number. - Google Calendar (
calendar.readonly) — to provide scheduling and availability context when interpreting requests and deadlines.
ProtoHQ requests read-only scopes only; it does not create, modify, or delete anything in your Google Contacts or Calendar. The OAuth authorization (refresh token) is stored encrypted at rest and is used solely to keep the connected features working. You can disconnect Google at any time from within ProtoHQ, or revoke access from your Google Account at myaccount.google.com/permissions.
Limited Use disclosure. ProtoHQ's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not transfer or use it for purposes other than providing or improving the user-facing features described above, except as required for security or to comply with applicable law. We do not allow humans to read Google user data except with your consent for support, when required for security, or to comply with law.
How we use information
- To provide the service — capturing conversations, extracting tasks, routing and tracking work, and enabling connected integrations.
- To secure and maintain the service — authentication, abuse prevention, backups, and troubleshooting.
- To comply with legal obligations.
We do not sell personal information, and we do not use your content or Google user data to train foundation models.
AI processing
ProtoHQ uses language models to interpret conversations and propose tasks. Relevant conversation text is sent to a model provider strictly to generate those results for your workspace. Proposed actions are shown for human review and are not written to any connected system of record until approved.
Storage and security
Each workspace's business data is stored separately and isolated from other workspaces. Secrets such as integration credentials are encrypted at rest. Access to the service is protected by authentication and least-privilege internal controls. Backups are encrypted in transit and at rest.
Data retention
We retain workspace data for as long as the workspace is active and as needed to provide the service. Raw message payloads are minimised on a rolling basis, and completed operational records are pruned over time. When a workspace is closed, its data is deleted or anonymised within a reasonable period, subject to legal retention requirements.
Other integrations
Customers may connect additional systems (for example, an ERP such as ERPNext) using credentials they provide. ProtoHQ uses those credentials only to perform the integration the customer configured, and stores any secrets encrypted at rest.
Sub-processors
We use a small set of infrastructure and service providers to run ProtoHQ (hosting, storage/backups, and an AI model gateway). These providers process data only on our behalf and under appropriate confidentiality and security obligations.
Your choices
- Disconnect any integration (including Google) from within ProtoHQ at any time.
- Revoke Google access directly at myaccount.google.com/permissions.
- Request access to, correction of, or deletion of your data by contacting us (requests from end users may be routed to the relevant customer, who is the data controller).
International transfers
Data may be processed in countries other than where you are located. Where required, we rely on appropriate safeguards for such transfers.
Children
ProtoHQ is a business product and is not directed to children, and we do not knowingly collect data from children.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Contact
Questions about this policy or your data can be sent to privacy@protohq.co.in.