Legal
Privacy Policy
Last updated: November 12, 2025
Introduction
Meridia Labs Ltd ("247Rep", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered business automation platform and related services (collectively, the "Services").
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your information as described herein.
Important: 247Rep is an official Meta Tech Provider. We process data on behalf of our customers, who maintain their own relationships with Meta and other third-party platforms.
1. Key Definitions
Personal Data: Any information relating to an identified or identifiable natural person.
Customer: The business or individual who creates an account and uses our Services.
End User: The customers or contacts of our Customers who interact with AI assistants powered by our Services.
Data Controller: The entity that determines the purposes and means of processing Personal Data. For Customer Data and End User Data, you (the Customer) are the Data Controller.
Data Processor: The entity that processes Personal Data on behalf of the Data Controller. 247Rep acts as a Data Processor for Customer Data and End User Data.
2. Information We Collect
2.1 Information You Provide Directly
Account Information:
- Name, email address, phone number
- Business name and details
- Payment information (processed by third-party payment processors)
- Login credentials
Platform Content:
- Product catalogs and pricing information
- Business knowledge base and training materials
- AI assistant configurations and settings
- Voice recordings, where you enable voice features, used to provide transcription and voice replies
- Web widget customization settings (colors, logos, text)
2.2 Information Collected Through Your Use of Services
Conversation Data:
- Messages exchanged between your AI assistants and End Users (via WhatsApp, Instagram, Telegram, Facebook, Web Widget, or voice)
- Messages you and your team members exchange with the Chief of Staff assistant (on the web dashboard, Telegram, or Slack)
- Conversation metadata (timestamps, delivery status, etc.)
- End User contact information (as provided through third-party platforms or web widget interactions)
- Web widget visitor information (browser data, session info, optional email/name if provided)
Usage Information:
- Credit consumption and transaction history
- Feature usage and interactions with the platform
- Analytics and performance metrics
Technical Information:
- IP addresses and device identifiers
- Browser type and version
- Operating system
- Referring URLs and pages visited
- Log data and cookies
2.3 Information from Third-Party Sources
- Connection tokens created when you authorize a channel — for WhatsApp and other supported Meta channels via Meta's Embedded Signup, which 247Rep manages as an official Meta Tech Provider — and any credentials you choose to provide for other optional integrations
- Data received from messaging platforms (Meta/WhatsApp, Telegram, etc.) based on the connections you authorize
- Payment and transaction information from our payment processors
2.4 Slack Integration Data
If you connect your Slack workspace to 247Rep (to use the Chief of Staff on Slack), we access and process the following through Slack's official APIs, only to provide the integration you enabled:
- Workspace & installation details: your Slack workspace (team) ID and name, the app installation, and the granted permission scopes.
- A bot access token issued by Slack during installation, which lets the Chief of Staff send and receive messages on your behalf. This token is encrypted at rest (AES-256-GCM) and is never shared with third parties.
- Messages directed to the assistant: the content of direct messages you (or team members you add) send to the Chief of Staff bot, and messages that @-mention the bot in a channel. We do not passively read general channel conversations that are not directed to the bot.
- Team member identity: the Slack user ID, display name, and email address of workspace members you add to your team, used solely to map them to their role and permissions.
- Interaction data: approvals/cancellations of proposed actions and slash-command inputs (e.g.
/cos) needed to carry out your requests.
We use Slack data only to operate the features you turned on (answering your questions, drafting and — with your approval — taking actions, assigning and tracking tasks, and posting the briefs/reminders you configured). We do not sell Slack data, use it for advertising, or use it to train generative AI/ML models. You can disconnect Slack at any time from the Chief of Staff panel, which deletes the stored installation and bot token; uninstalling the app from Slack has the same effect.
3. How We Use Your Information
We use the collected information for the following purposes:
3.1 To Provide and Maintain Services:
- Process AI-powered conversations between your business and End Users
- Maintain and improve platform functionality
- Process credit purchases and manage your account
- Provide customer support
3.2 To Improve and Develop Services:
- Analyze usage patterns and trends
- Improve platform reliability and features using aggregated, de-identified usage analytics. We do not use your business content, conversations, or your customers' personal data to train generative AI models, and the third-party AI providers that process your data to generate responses do not train their models on it.
- Develop new features and functionality
- Conduct research and development
3.3 For Security and Compliance:
- Detect and prevent fraud, spam, and abuse
- Monitor compliance with our Terms of Service (including the Acceptable Use provisions therein)
- Protect the security and integrity of our Services
- Comply with legal obligations
3.4 For Communication:
- Send service-related notifications and updates
- Respond to inquiries and provide support
- Send marketing communications (with your consent, where required)
4. Data Processing Roles and Responsibilities
4.1 247Rep as Data Processor:
For Customer Data and End User Data processed through the Services, you (the Customer) are the Data Controller, and we act as the Data Processor. This means:
- You determine the purposes and means of processing
- You are responsible for ensuring lawful processing and obtaining necessary consents
- We process data only on your instructions and as necessary to provide the Services
- We implement appropriate security measures to protect the data
4.2 247Rep as Data Controller:
For your account information and platform usage data, we act as the Data Controller and process this information for our legitimate business interests in providing and improving the Services.
4.3 Your Responsibilities as Data Controller:
- Obtain necessary consents from End Users before processing their data
- Ensure compliance with applicable privacy laws (NDPR, GDPR, etc.)
- Provide appropriate privacy notices to End Users
- Handle End User data rights requests (access, deletion, etc.)
- Maintain appropriate records of processing activities
4.4 Data Processing Agreement: If you require a separate data processing agreement (DPA) to meet your obligations under the GDPR, the NDPA, or similar laws, the data-processing terms in our Terms of Service govern our role as your processor, and a signable standalone DPA is available on request at dpo@247rep.app.
5. Data Sharing and Disclosure
We may share your information in the following circumstances:
5.1 Service Providers (Sub-processors): We engage third-party service providers to perform functions on our behalf. The main categories, and the providers we currently use, are:
- Cloud hosting & infrastructure: Vercel, Google Firebase, Neon (PostgreSQL), and Upstash.
- AI processing: OpenAI and Anthropic, used to generate and draft responses. Your data is sent to them to produce those responses; under their API terms they do not use it to train their models.
- Voice & telephony: Telnyx and Vapi, where you enable voice or calling features.
- Email delivery: Resend.
- Payment processing: Paystack and Flutterwave.
- Error monitoring & performance: Sentry.
These providers have access to Personal Data only as necessary to perform their functions and are obligated to maintain confidentiality. We keep this list current; if you need our full, up-to-date sub-processor list for your records, contact us at dpo@247rep.app.
5.2 Third-Party Platforms: When you connect third-party services (like Meta/WhatsApp, Telegram, or Slack) using your own credentials or by installing our app, data may be transmitted to these platforms as necessary to provide the Services. For Slack specifically, messages, task notifications, and briefs are delivered to your Slack workspace through Slack's APIs. Your use of these platforms is subject to their own terms and privacy policies.
5.3 Legal Requirements: We may disclose information if required by law or in response to:
- Legal process (subpoenas, court orders)
- Government or regulatory requests
- Protection of our rights, property, or safety
- Prevention of fraud or illegal activity
5.4 Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.
5.5 With Your Consent: We may share information with third parties when you provide explicit consent.
6. Data Retention
6.1 Retention Periods:
- Account information: Retained while your account is active and for a reasonable period thereafter
- Conversation data: Retained as necessary to provide analytics and support, or as required by law
- Payment records: Retained for tax and accounting purposes as required by law
- Technical logs: Typically retained for 90 days
6.2 Data Deletion: Upon account termination, we will delete or anonymize your data within 90 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, dispute resolution). Disconnecting Slack (or uninstalling the app from your Slack workspace) immediately deletes the stored Slack installation record and encrypted bot token.
6.3 Backup Retention: Data may persist in backup systems for up to 90 days after deletion from production systems.
7. Data Security
We implement appropriate technical and organizational security measures to protect your information:
- Encryption of data in transit (TLS/SSL) and at rest
- Access controls and authentication mechanisms
- Regular security assessments and monitoring
- Employee training on data protection
- Incident response procedures
7.1 Web Widget Security:
- All web widget communications encrypted via HTTPS/TLS
- Voice recordings (if enabled) processed securely and encrypted in transit and at rest
- Widget conversations isolated per visitor session
- No third-party tracking or cookies used by widget
- Visitor data processed only for conversation purposes
7.2 Data Breach Notification:
If we become aware of a personal data breach affecting data we process on your behalf, we will notify you (as the Customer and data controller) without undue delay after becoming aware of it and provide the information you reasonably need to meet your own notification obligations. Where we act as the data controller, we will notify the relevant supervisory authority and affected individuals as required by applicable law, including within any statutory timeframe (for example, within 72 hours under the GDPR where it applies).
However, no method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
8. Your Rights and Choices
Depending on your location, you may have the following rights:
8.1 Access and Portability: You may request access to your Personal Data and receive a copy in a structured, commonly used format.
8.2 Correction: You may request correction of inaccurate or incomplete Personal Data.
8.3 Deletion: You may request deletion of your Personal Data, subject to certain exceptions (e.g., legal obligations, legitimate interests).
8.4 Objection and Restriction: You may object to or request restriction of certain processing activities.
8.5 Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time.
8.6 Marketing Communications: You may opt out of marketing emails by clicking the unsubscribe link or contacting us.
8.7 Exercising Rights: To exercise these rights, contact us at hello@247rep.app. We will respond within 30 days.
8.8 End User Rights: If you are an End User seeking to exercise privacy rights regarding data processed through a Customer's use of our Services, please contact that Customer directly. We process End User Data on behalf of our Customers.
9. International Data Transfers
Our Services are operated from Nigeria, and your data may be processed in Nigeria and in other countries where we or our service providers (see Section 5) operate, including the United States and the European Union. Data protection laws in these countries may differ from those in your country of residence.
Where we transfer personal data internationally, we rely on appropriate safeguards. For transfers from the EEA or the UK, these may include the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum; for transfers subject to the Nigeria Data Protection Act, we rely on the transfer mechanisms it permits. You may request more information about these safeguards at dpo@247rep.app.
10. Children's Privacy
Our Services are not intended for individuals under 18 years of age. We do not knowingly collect Personal Data from children. If we learn that we have collected information from a child without parental consent, we will delete that information promptly.
11. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Maintain your session and remember your preferences
- Analyze usage patterns and improve our Services
- Provide personalized content and features
You can control cookies through your browser settings. However, disabling cookies may affect your ability to use certain features of our Services.
12. Nigeria Data Protection Act (NDPA) Compliance
As a Nigerian company, we comply with the Nigeria Data Protection Act, 2023 (NDPA) and applicable subsidiary regulations. We process Personal Data lawfully, fairly, and transparently, and collect only data that is adequate, relevant, and necessary for the specified purposes.
You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe we have violated your data protection rights.
13. Legal Bases for Processing (GDPR / UK GDPR)
Where the EU or UK GDPR applies to our processing of your personal data as a controller, we rely on the following legal bases:
- Performance of a contract: to create and administer your account, provide the Services, and process payments.
- Legitimate interests: to secure, maintain and improve the Services, prevent fraud and abuse, and communicate with you about your account — balanced against your rights and freedoms.
- Consent: for optional marketing communications and non-essential cookies, which you may withdraw at any time.
- Legal obligation: to comply with tax, accounting, and other legal requirements.
For personal data we process on behalf of our Customers (End User Data), the Customer is the controller and is responsible for establishing a lawful basis for that processing.
14. Automated Decision-Making and Profiling
The Services use AI to generate, draft, and suggest responses and actions. Customer-facing actions are designed to be reviewed and approved by the Customer or their authorized team before they take effect. We do not use your personal data to make solely automated decisions that produce legal or similarly significant effects about you without human involvement.
If you are an End User and have questions about automated processing in a conversation, please contact the Customer (the business) you were interacting with, who is the controller of that data.
15. Your U.S. State Privacy Rights (California and others)
If you are a resident of California or another U.S. state with a comprehensive privacy law, you may have rights to know, access, correct, delete, and port your personal information, and to opt out of the "sale" or "sharing" of personal information and of certain targeted advertising.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information beyond the purposes permitted by law. To exercise any of these rights, contact us at dpo@247rep.app. We will not discriminate against you for exercising your rights, and you may use an authorized agent where the law permits.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last Updated" date. Your continued use of the Services after changes constitutes acceptance of the updated Privacy Policy.
17. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Meridia Labs Ltd
Email: hello@247rep.app
Address: Lagos, Nigeria
Data Protection Officer: dpo@247rep.app
