Legal
Privacy policy
Last updated: September 26, 2026
In short: we use your data only so you can talk and work with other companies on Chaggu. We don't sell data, we don't show ads, and we don't read your Google or Microsoft email, calendar or files. When you sign in with Google or Microsoft we only receive your name, email, profile picture and an account identifier.
1. Who is responsible
Chaggu (formerly TieComs) is operated by CERTILABOR S.A.S., a Colombian company with tax ID (NIT) 900849607, domiciled in Bogotá D.C., Colombia ("Chaggu", "we"), which acts as the controller of account data. When a company uses Chaggu to communicate with its team and with other companies, that company is responsible for the content its people share, and Chaggu processes it as a processor on its instructions.
Privacy contact: [email protected].
2. Data we process
| Data | Source | Purpose |
|---|---|---|
| Name, email, job title, department and photo | You, or your Google or Microsoft account | Creating your account and identifying you to other people and companies |
| Company and email domain | You, and domain verification (DNS or identity provider) | Showing other companies that your organization is real and verified |
Google account identifier (sub) or Microsoft identifiers (tid and oid), and the Google Workspace domain or Microsoft directory | Google or Microsoft, when you sign in | Signing in without a password and linking you to your company |
| Messages, photos, videos, files (including audio files), issues, reminders and events | What you and others post | Providing the conversation service |
| WhatsApp account number and name, contact names and numbers or identifiers, groups, and chat text or descriptions of media content | The WhatsApp account you choose to link using a QR code or pairing code; this connection is optional | Displaying and organizing your chats, identifying participants, and forwarding messages to a Chaggu conversation when you link that chat |
| Terms you enter when searching WhatsApp chats | Your optional use of search for the linked account | Finding the chats you request |
| Notification tokens, device platform and language | The app, if you allow notifications | Delivering message, mention, reminder and meeting alerts to your sessions |
| Voice transcripts, summaries and suggested issues | Voice notes and sidechats processed with AI features | Displaying audio as text, suggesting tasks and preparing a summary you can review before posting it in the thread |
| Sessions, devices, IP address and security logs | Your use of the app | Security, fraud prevention, auditing and support |
We don't use advertising cookies or third-party trackers. We only use the cookies and local storage strictly needed to keep you signed in.
We only upload photos and files you select for your profile or to share in Chaggu, including audio files you choose. The apps do not request access to your device's entire address book: WhatsApp contacts, if you enable that feature, come from the linked account. Synced chats are private to their owner, except for messages you choose to forward or link to a shared conversation. You can disconnect WhatsApp in the app; the server deletes that connection and its synced private contacts and chats, while messages already shared in Chaggu remain subject to the conversation's retention rules.
When you search WhatsApp chats, the search terms are sent to the server. HTTP requests, including those queries, are stored in technical logs for diagnostics and security and may remain there after the results are displayed.
If you link a WhatsApp chat to a Chaggu conversation, new messages and reactions from that chat arrive in the conversation with the display name the person uses on WhatsApp, visible to everyone with access to that conversation. Unlinking stops it.
If you allow notifications, the app registers a token for each session, together with the platform and language. When remote notifications are enabled, Apple Push Notification service (APNs) or Google Firebase Cloud Messaging (FCM) process the token and the content needed to deliver the alert: for example, the chat name, sender, a message preview and conversation identifiers. You can turn off notifications in your device settings. We delete the token when you sign out, the session is revoked, or the provider reports that the token is invalid.
Voice and AI features are optional. Before transferring data to Inworld or DeepSeek, the app explains what will be sent and asks for permission for that note or summary. Declining still lets you send and play the note and write the summary manually, without AI. To transcribe a voice note, Inworld receives the audio and language. To summarize it or suggest an issue, DeepSeek receives the transcript, the names of the author and participants, and the conversation name. If you request a sidechat summary to bring back to the thread, DeepSeek receives the messages used for the summary, their authors’ names, the original message, the group name and the name of the person posting the result. Transcripts and summaries are stored in Chaggu and shown to people with access to the conversation; the sidechat summary is posted in the original thread when you confirm sending it. These features require the corresponding services to be enabled.
Shared links. When someone shares a link in a conversation, the Chaggu server visits that address to build the preview; the linked site sees the server's IP address, not yours. We store the title, description, author or channel and a thumbnail (the thumbnail in Amazon S3), and show them in the conversation and in the link library to those who have access to it. Marking a link as seen or "Watch later" is visible only to you.
The AI summary of a link is optional and requested manually: DeepSeek receives the link's address, title and description and, for a public page with text, up to 14,000 characters of that text; it does not receive messages, names or conversation data. The summary is stored and reused for anyone who asks for the same link. The weekly link digest by email is also optional: you turn it on in your profile, it is sent through Brevo, and you can turn it off there at any time.
3. Sign in with Google and Microsoft
If you choose "Continue with Google" or "Continue with Microsoft", we only request basic identity scopes: openid, email and profile. We don't request access to Gmail, Google Drive, Calendar, Outlook, OneDrive, Teams or any other content in your account.
Chaggu' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use this data only to sign you in and show your profile; we don't transfer it to third parties except as needed to provide the service or comply with the law; we don't use it for advertising; and no human reads it except with your consent, for security, or as required by law. We don't use Google or Microsoft data to train artificial intelligence models.
You can revoke access at any time from your Google Account or Microsoft My Apps.
4. Company verification
To protect people who talk across companies, we verify that an organization controls the email domain it claims: through a DNS TXT record added by its administrator (with the prefix chaggu-verification=; records created with tiecoms-verification= are still accepted), or through the information Google Workspace or Microsoft Entra ID provide at sign-in. We store the domain, the method and the verification date, and we show other companies the name, domain and verification badge. Public email domains (such as gmail.com or outlook.com) can't be claimed as a company.
5. Who we share data with
- The people and companies you talk with: they see your name, title, company and what you post in the spaces you take part in.
- Your company's administrator: they can manage your membership, require corporate sign-in and remove your access.
- Providers that help us operate: Amazon Web Services (servers, database and file storage), Cloudflare (network and protection), Google and Microsoft (sign-in), and Brevo (transactional email); Apple APNs and Google FCM (remote notifications); Inworld (voice note transcription) and DeepSeek (summaries and suggestions), using the data described above for each feature. If you link a WhatsApp account, a connection to WhatsApp synchronizes the data described above. These services support the features you choose to use.
- When required by law: in response to a valid order from a competent authority.
We don't sell or rent personal data.
6. International transfers
Our servers are in the United States (AWS, us-east-1). By using Chaggu, your data is transferred to and stored there, with security measures equivalent to those required by Colombian law.
7. How long we keep data
- Account data: for as long as the account exists.
- Messages and files: according to the company's or shared space's settings, or until deleted.
- Security and audit logs: up to 24 months.
- When you close your account we delete or anonymize your data within 30 days, except what the law requires us to keep or what is part of a company's conversations, which remains under that company's control.
8. Security
We encrypt traffic with TLS, store passwords with a strong algorithm (scrypt), rotate session tokens, detect their reuse and log sensitive events. No system is perfect; if an incident affects your data, we will notify you and the authorities where required.
9. Your rights
Under Colombian Law 1581 of 2012 and Decree 1377 of 2013 (and, where applicable, other laws such as the EU GDPR), you can access, update, correct and delete your data, request proof of consent, withdraw it, and file complaints with the Superintendencia de Industria y Comercio. Email [email protected]. We answer requests within 10 business days and complaints within 15 business days.
You can use Delete account in the app settings or email us from your account address. Read the deletion instructions, including which data is deleted or anonymized and the retention exceptions.
10. Children
Chaggu is a work tool. It is not intended for anyone under 18 and we don't knowingly collect their data.
11. Changes
If we make material changes to this policy, we will notify you in the app or by email before they take effect.