Legal

Privacy policy

1. Who is responsible

Chaggu (formerly TieComs) is operated by CERTILABOR S.A.S., a Colombian company with tax ID (NIT) 900849607, domiciled in Bogotá D.C., Colombia ("Chaggu", "we"), which acts as the controller of account data. When a company uses Chaggu to communicate with its team and with other companies, that company is responsible for the content its people share, and Chaggu processes it as a processor on its instructions.

Privacy contact: [email protected].

2. Data we process

DataSourcePurpose
Name, email, job title, department and photoYou, or your Google or Microsoft accountCreating your account and identifying you to other people and companies
Company and email domainYou, and domain verification (DNS or identity provider)Showing other companies that your organization is real and verified
Google account identifier (sub) or Microsoft identifiers (tid and oid), and the Google Workspace domain or Microsoft directoryGoogle or Microsoft, when you sign inSigning in without a password and linking you to your company
Messages, photos, videos, files (including audio files), issues, reminders and eventsWhat you and others postProviding the conversation service
WhatsApp account number and name, contact names and numbers or identifiers, groups, and chat text or descriptions of media contentThe WhatsApp account you choose to link using a QR code or pairing code; this connection is optionalDisplaying and organizing your chats, identifying participants, and forwarding messages to a Chaggu conversation when you link that chat
Terms you enter when searching WhatsApp chatsYour optional use of search for the linked accountFinding the chats you request
Notification tokens, device platform and languageThe app, if you allow notificationsDelivering message, mention, reminder and meeting alerts to your sessions
Voice transcripts, summaries and suggested issuesVoice notes and sidechats processed with AI featuresDisplaying audio as text, suggesting tasks and preparing a summary you can review before posting it in the thread
Sessions, devices, IP address and security logsYour use of the appSecurity, fraud prevention, auditing and support

We don't use advertising cookies or third-party trackers. We only use the cookies and local storage strictly needed to keep you signed in.

We only upload photos and files you select for your profile or to share in Chaggu, including audio files you choose. The apps do not request access to your device's entire address book: WhatsApp contacts, if you enable that feature, come from the linked account. Synced chats are private to their owner, except for messages you choose to forward or link to a shared conversation. You can disconnect WhatsApp in the app; the server deletes that connection and its synced private contacts and chats, while messages already shared in Chaggu remain subject to the conversation's retention rules.

When you search WhatsApp chats, the search terms are sent to the server. HTTP requests, including those queries, are stored in technical logs for diagnostics and security and may remain there after the results are displayed.

If you link a WhatsApp chat to a Chaggu conversation, new messages and reactions from that chat arrive in the conversation with the display name the person uses on WhatsApp, visible to everyone with access to that conversation. Unlinking stops it.

If you allow notifications, the app registers a token for each session, together with the platform and language. When remote notifications are enabled, Apple Push Notification service (APNs) or Google Firebase Cloud Messaging (FCM) process the token and the content needed to deliver the alert: for example, the chat name, sender, a message preview and conversation identifiers. You can turn off notifications in your device settings. We delete the token when you sign out, the session is revoked, or the provider reports that the token is invalid.

Voice and AI features are optional. Before transferring data to Inworld or DeepSeek, the app explains what will be sent and asks for permission for that note or summary. Declining still lets you send and play the note and write the summary manually, without AI. To transcribe a voice note, Inworld receives the audio and language. To summarize it or suggest an issue, DeepSeek receives the transcript, the names of the author and participants, and the conversation name. If you request a sidechat summary to bring back to the thread, DeepSeek receives the messages used for the summary, their authors’ names, the original message, the group name and the name of the person posting the result. Transcripts and summaries are stored in Chaggu and shown to people with access to the conversation; the sidechat summary is posted in the original thread when you confirm sending it. These features require the corresponding services to be enabled.

Shared links. When someone shares a link in a conversation, the Chaggu server visits that address to build the preview; the linked site sees the server's IP address, not yours. We store the title, description, author or channel and a thumbnail (the thumbnail in Amazon S3), and show them in the conversation and in the link library to those who have access to it. Marking a link as seen or "Watch later" is visible only to you.

The AI summary of a link is optional and requested manually: DeepSeek receives the link's address, title and description and, for a public page with text, up to 14,000 characters of that text; it does not receive messages, names or conversation data. The summary is stored and reused for anyone who asks for the same link. The weekly link digest by email is also optional: you turn it on in your profile, it is sent through Brevo, and you can turn it off there at any time.

3. Sign in with Google and Microsoft

If you choose "Continue with Google" or "Continue with Microsoft", we only request basic identity scopes: openid, email and profile. We don't request access to Gmail, Google Drive, Calendar, Outlook, OneDrive, Teams or any other content in your account.

Chaggu' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use this data only to sign you in and show your profile; we don't transfer it to third parties except as needed to provide the service or comply with the law; we don't use it for advertising; and no human reads it except with your consent, for security, or as required by law. We don't use Google or Microsoft data to train artificial intelligence models.

You can revoke access at any time from your Google Account or Microsoft My Apps.

4. Company verification

To protect people who talk across companies, we verify that an organization controls the email domain it claims: through a DNS TXT record added by its administrator (with the prefix chaggu-verification=; records created with tiecoms-verification= are still accepted), or through the information Google Workspace or Microsoft Entra ID provide at sign-in. We store the domain, the method and the verification date, and we show other companies the name, domain and verification badge. Public email domains (such as gmail.com or outlook.com) can't be claimed as a company.

5. Who we share data with

We don't sell or rent personal data.

6. International transfers

Our servers are in the United States (AWS, us-east-1). By using Chaggu, your data is transferred to and stored there, with security measures equivalent to those required by Colombian law.

7. How long we keep data

8. Security

We encrypt traffic with TLS, store passwords with a strong algorithm (scrypt), rotate session tokens, detect their reuse and log sensitive events. No system is perfect; if an incident affects your data, we will notify you and the authorities where required.

9. Your rights

Under Colombian Law 1581 of 2012 and Decree 1377 of 2013 (and, where applicable, other laws such as the EU GDPR), you can access, update, correct and delete your data, request proof of consent, withdraw it, and file complaints with the Superintendencia de Industria y Comercio. Email [email protected]. We answer requests within 10 business days and complaints within 15 business days.

You can use Delete account in the app settings or email us from your account address. Read the deletion instructions, including which data is deleted or anonymized and the retention exceptions.

10. Children

Chaggu is a work tool. It is not intended for anyone under 18 and we don't knowingly collect their data.

11. Changes

If we make material changes to this policy, we will notify you in the app or by email before they take effect.