1. Kush jemi
chatstaff ("ne", "chatstaff") është një platformë softuerike që u mundëson bizneseve të përgjigjen në bisedat me klientët e tyre në WhatsApp, Instagram, Facebook Messenger dhe email, me ndihmën e një asistenti me inteligjencë artificiale dhe të stafit të tyre. Faqja jonë është chatstaff.tech. Për çdo pyetje rreth kësaj politike na shkruani te info@chatstaff.tech.
2. Për kë vlen kjo politikë
Kjo politikë përshkruan si trajtojmë të dhënat personale të tre grupeve:
- Bizneset klientë dhe stafi i tyre: personat që kanë llogari në panelin chatstaff.
- Klientët e bizneseve: personat që i shkruajnë një biznesi klient në WhatsApp, Instagram, Messenger ose email. Për këto të dhëna biznesi klient është kontrolluesi, ndërsa chatstaff është përpunuesi që vepron me udhëzimet e tij.
- Vizitorët e faqes chatstaff.tech: përfshirë ata që plotësojnë formularin e kërkesës për akses.
3. Çfarë të dhënash mbledhim
3.1 Bizneset klientë dhe stafi
- Emri, adresa e email-it, fjalëkalimi (i ruajtur vetëm si hash i pakthyeshëm), roli dhe gjuha e panelit.
- Të dhënat e biznesit: emri, profili i biznesit, katalogu i produkteve, baza e njohurive, orari i punës, cilësimet.
- Kredencialet e kanaleve që biznesi lidh (p.sh. token-a të WhatsApp Business, faqes së Facebook-ut, llogarisë së Instagram-it, kutisë së email-it). Ruhen të enkriptuara dhe përdoren vetëm për të dërguar dhe marrë mesazhe në emër të biznesit.
- Regjistri i veprimeve në panel (kush ndryshoi çfarë dhe kur), për siguri dhe llogaridhënie.
3.2 Klientët e bizneseve (mesazhet)
- Përmbajtja e mesazheve që klienti i dërgon biznesit dhe përgjigjet e biznesit ose të asistentit, përfshirë fotot e dërguara.
- Identifikuesit e kanalit: numri i WhatsApp-it, identifikuesi i Instagram-it ose i Messenger-it, adresa e email-it, emri i shfaqur.
- Të dhënat e porosive që klienti bën përmes bisedës (produkte, adresë dërgese, telefon).
- Një përmbledhje e shkurtër e bisedave të mëparshme, që biznesi t'i përgjigjet klientit me kontekst.
- Nëse klienti erdhi nga një reklamë e Meta-s: identifikuesi i reklamës që Meta e bashkëngjit mesazhit të parë.
3.3 Vizitorët e faqes
- Formulari i kërkesës për akses: emri, emri i biznesit, numri i WhatsApp-it, email-i (opsional), gjuha e zgjedhur.
- Preferenca e gjuhës, e ruajtur në shfletuesin tuaj. Nuk përdorim cookie gjurmimi apo reklamimi.
- Regjistra teknikë të serverit (adresa IP, koha, faqja e kërkuar) për siguri dhe për të parandaluar abuzimin.
Për statistikat e faqes publike mbajmë një numërim pa cookie. Ruajmë rrugën e faqes, hostin e referuesit, fushat UTM, gjuhën, llojin e pajisjes dhe një hash që ndërrohet çdo ditë dhe fshihet pas 48 orësh. Nuk ruajmë adresën IP dhe as shfletuesin. Këto të dhëna fshihen pas 13 muajsh. Nëse shfletuesi dërgon Do Not Track ose Global Privacy Control, nuk regjistrojmë asgjë. Kur dikush plotëson formularin e kërkesës, ruajmë faqen dhe referuesin e vizitës së parë të asaj dite, nëse ajo vizitë ekziston.
4. Si i marrim të dhënat nga Meta
Kur një biznes lidh numrin e WhatsApp-it, faqen e Facebook-ut ose llogarinë e Instagram-it, ai autorizon chatstaff përmes procedurës zyrtare të Meta-s (Facebook Login for Business / Embedded Signup). Meta na dërgon mesazhet hyrëse dhe ngjarjet e llogarisë përmes webhook-eve, dhe ne dërgojmë përgjigjet përmes API-ve të Meta-s. Ne i përdorim këto të dhëna vetëm për të ofruar shërbimin për atë biznes, në përputhje me Meta Platform Terms dhe politikat e WhatsApp Business. Nuk i shesim dhe nuk i përdorim për reklamim.
5. Për çfarë i përdorim të dhënat
- Për t'u përgjigjur klientëve në emër të biznesit, me asistentin AI ose me stafin e biznesit.
- Për të mbajtur historikun e bisedave dhe porositë, që biznesi t'i menaxhojë nga paneli.
- Për njoftime drejt biznesit (p.sh. kur një bisedë kërkon një njeri, statusi i porosisë).
- Për statistika të agreguara që i shohin vetëm bizneset për punën e tyre.
- Për sigurinë e platformës dhe për të përmbushur detyrime ligjore.
6. Inteligjenca artificiale
Për të gjeneruar përgjigje, përmbajtja e bisedës (së bashku me katalogun dhe bazën e njohurive të biznesit) i dërgohet ofruesit tonë të modeleve gjuhësore, Anthropic, përmes API-së së tij, i cili i përpunon të dhënat si nën-përpunues dhe nuk i përdor për të trajnuar modelet e veta. Asistenti nuk merr vendime ligjërisht të detyrueshme: porositë regjistrohen si drafte dhe konfirmohen nga stafi i biznesit.
7. Me kë i ndajmë
Nuk i shesim të dhënat personale. I ndajmë vetëm me:
- Meta Platforms (WhatsApp, Instagram, Messenger) dhe Microsoft / Google (kur biznesi lidh kutinë e email-it), për të dërguar dhe marrë mesazhe.
- Anthropic, për gjenerimin e përgjigjeve (pika 6).
- Ofruesin e infrastrukturës ku hostohet platforma (server dhe bazë të dhënash në Bashkimin Evropian).
- Autoritetet, kur na e kërkon ligji.
8. Sa kohë i ruajmë
- Mesazhet, klientët dhe porositë e një biznesi: sa kohë biznesi është klient i chatstaff, dhe deri në 30 ditë pas mbylljes së llogarisë.
- Kredencialet e kanaleve: derisa biznesi e shkëput kanalin; fshihen menjëherë me shkëputjen.
- Formulari i kërkesës për akses: deri në 12 muaj, ose më herët me kërkesën tuaj.
- Regjistrat teknikë: deri në 90 ditë.
9. Siguria
Të gjitha lidhjet janë të enkriptuara (HTTPS). Token-at e kanaleve ruhen të enkriptuar në bazën e të dhënave, fjalëkalimet vetëm si hash. Aksesi në panel bëhet me llogari personale dhe çdo veprim regjistrohet. Pavarësisht masave, asnjë sistem nuk është 100% i sigurt; nëse ndodh një incident që prek të dhënat tuaja, do t'ju njoftojmë siç e kërkon ligji.
10. Të drejtat tuaja
Keni të drejtë të kërkoni akses, korrigjim, fshirje ose kufizim të përpunimit të të dhënave tuaja, si dhe të ankoheni pranë autoritetit mbikëqyrës (në Shqipëri: Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale). Nëse jeni klient i një biznesi që përdor chatstaff, kërkesën mund t'ia drejtoni biznesit ose neve; ne do ta ndihmojmë biznesin ta përmbushë. Për fshirjen shihni faqen Fshirja e të dhënave.
11. Ligji i zbatueshëm
Përpunojmë të dhënat në përputhje me Ligjin nr. 124/2024 "Për mbrojtjen e të dhënave personale" të Republikës së Shqipërisë dhe, për personat në Bashkimin Evropian, me Rregulloren e Përgjithshme për Mbrojtjen e të Dhënave (GDPR).
12. Ndryshimet
Nëse e ndryshojmë këtë politikë, publikojmë versionin e ri këtu me datën e përditësimit. Për ndryshime thelbësore njoftojmë bizneset klientë me email.
1. Who we are
chatstaff ("we", "chatstaff") is a software platform that lets businesses answer their customers' conversations on WhatsApp, Instagram, Facebook Messenger and email, with the help of an AI assistant and their own staff. Our website is chatstaff.tech. For any question about this policy write to info@chatstaff.tech.
2. Who this policy covers
- Client businesses and their staff: people with an account in the chatstaff dashboard.
- The businesses' customers: people who message a client business on WhatsApp, Instagram, Messenger or email. For this data the client business is the controller and chatstaff is the processor acting on its instructions.
- Visitors of chatstaff.tech, including those who fill in the access request form.
3. What data we collect
3.1 Client businesses and staff
- Name, email address, password (stored only as an irreversible hash), role and dashboard language.
- Business data: name, business profile, product catalogue, knowledge base, business hours, settings.
- Credentials of the channels the business connects (e.g. WhatsApp Business, Facebook Page, Instagram account or mailbox tokens). They are stored encrypted and used only to send and receive messages on the business's behalf.
- The dashboard activity log (who changed what and when), for security and accountability.
3.2 The businesses' customers (messages)
- The content of messages the customer sends to the business and the replies of the business or the assistant, including photos sent.
- Channel identifiers: WhatsApp number, Instagram or Messenger identifier, email address, display name.
- Order details placed through the conversation (products, delivery address, phone).
- A short summary of earlier conversations so the business can reply with context.
- If the customer came from a Meta ad: the ad identifier Meta attaches to the first message.
3.3 Website visitors
- Access request form: name, business name, WhatsApp number, email (optional), chosen language.
- Language preference, stored in your browser. We use no tracking or advertising cookies.
- Technical server logs (IP address, time, requested page) for security and abuse prevention.
For the public site we keep cookieless counts. We store the page path, the referrer host, the UTM fields, the language, the device type and a hash that rotates every day and is deleted after 48 hours. We do not store the IP address or the browser. These rows are deleted after 13 months. If the browser sends Do Not Track or Global Privacy Control, we record nothing. When someone submits the access form, we store the page and the referrer of that day's first visit, when that visit exists.
4. How we receive data from Meta
When a business connects its WhatsApp number, Facebook Page or Instagram account, it authorises chatstaff through Meta's official flow (Facebook Login for Business / Embedded Signup). Meta delivers incoming messages and account events to us via webhooks, and we send replies through Meta's APIs. We use this data solely to provide the service to that business, in line with the Meta Platform Terms and the WhatsApp Business policies. We do not sell it and do not use it for advertising.
5. What we use the data for
- To reply to customers on the business's behalf, with the AI assistant or the business's staff.
- To keep the conversation history and orders so the business can manage them from the dashboard.
- For notifications to the business (e.g. a conversation needs a human, order status).
- For aggregated statistics that only the business sees about its own work.
- For platform security and to meet legal obligations.
6. Artificial intelligence
To generate replies, the conversation content (together with the business's catalogue and knowledge base) is sent to our language-model provider, Anthropic, through its API; it processes the data as a sub-processor and does not use it to train its models. The assistant makes no legally binding decisions: orders are recorded as drafts and confirmed by the business's staff.
7. Who we share it with
- Meta Platforms (WhatsApp, Instagram, Messenger) and Microsoft / Google (when a business connects a mailbox), to send and receive messages.
- Anthropic, for reply generation (section 6).
- The infrastructure provider hosting the platform (server and database in the European Union).
- Authorities, where the law requires it.
8. How long we keep it
- A business's messages, customers and orders: while the business is a chatstaff client, and up to 30 days after the account is closed.
- Channel credentials: until the business disconnects the channel; deleted immediately on disconnection.
- Access request form: up to 12 months, or earlier on request.
- Technical logs: up to 90 days.
9. Security
All connections are encrypted (HTTPS). Channel tokens are stored encrypted in the database, passwords only as hashes. Dashboard access uses personal accounts and every action is logged. No system is 100% secure; if an incident affects your data we will notify you as the law requires.
10. Your rights
You may request access, correction, deletion or restriction of processing of your data, and lodge a complaint with the supervisory authority (in Albania: the Commissioner for the Right to Information and Personal Data Protection). If you are a customer of a business using chatstaff, you can address your request to the business or to us; we will help the business fulfil it. For deletion see Data deletion.
11. Applicable law
We process data in accordance with Law no. 124/2024 "On the protection of personal data" of the Republic of Albania and, for people in the European Union, the General Data Protection Regulation (GDPR).
12. Changes
If we change this policy we publish the new version here with the update date. For material changes we notify client businesses by email.