1. Introduction and Scope
This Privacy Policy ("Policy") describes how Trulay, Inc. ("Trulay," "we," "us," or "our") collects, uses, processes, discloses, stores, and protects information about our customers, website visitors, developers, and other individuals ("you" or "your") in connection with our communication platform services. This Policy applies to the websites, APIs, SDKs, dashboards, mobile applications, and other services provided by Trulay (collectively, the "Services") unless a separate privacy notice is provided to you.
This Policy is intended to comply with applicable data protection laws, including but not limited to the General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act ("CCPA") and its amendments ("CPRA"), the Personal Information Protection and Electronic Documents Act ("PIPEDA"), the Lei Geral de Protecção de Dados ("LGPD"), and other applicable national and regional data protection laws.
2. Information We Collect
2.1 Information You Provide to Us
We collect information that you provide directly to us, including:
- Account Registration Information: Your name, email address, company name, job title, phone number, billing address, and authentication credentials (such as username and password) when you create an account or place an order.
- Service Configuration Data: Sender IDs, messaging templates, routing preferences, webhook endpoints, API keys, and other technical configuration settings you specify to operate the Services.
- Communication Content: Messages, calls, emails, files, media, and other content that you upload, transmit, or receive through our Services, including SMS, MMS, WhatsApp Business API, RCS, email, voice, and video communications.
- Recipient Contact Information: Phone numbers, email addresses, and other contact details of individuals to whom you direct communications through our Services.
- Payment Information: Credit or debit card information, billing address, and other financial details. We process payments through third-party payment processors and do not store full payment card information on our servers.
- Support and Feedback Data: Information you provide when contacting our support team, submitting bug reports, or providing feedback, including correspondence, screenshots, and diagnostic information.
- Marketing and Communication Preferences: Information you provide when subscribing to newsletters, marketing communications, webinars, events, or when completing surveys.
2.2 Information Collected Automatically
When you access or use our Services, we automatically collect information and data, including:
- Device and Network Information: Internet Protocol ("IP") address, browser type and version, operating system, hardware model, device identifiers (e.g., IMEI, MAC address), mobile network information (including carrier name and signal strength), and device configuration data.
- Usage and Activity Data: Pages visited, features used, API endpoints accessed, actions taken within the dashboard or application, timestamps, session duration, clickstream data, and interaction patterns.
- Technical Performance Data: Response times, latency metrics, uptime statistics, error rates, delivery reports, and system performance indicators.
- Location Data: General geographic location derived from your IP address. We do not collect precise geolocation data unless explicitly consented to by you for specific features.
- Cookies and Tracking Technologies: Information collected through cookies, web beacons, pixel tags, embedded scripts, and similar tracking technologies as described in Section 6 of this Policy.
2.3 Information We Receive from Third Parties
We may receive information about you from third parties, including:
- Telecommunications Carriers and Networks: Delivery receipts, network status notifications, carrier identification data, line type information (mobile, landline, VoIP), SIM swap indicators, number porting status, and network quality metrics necessary to route and deliver communications.
- Business Partners and Service Providers: Data from partners with whom we jointly offer products or services, and from vendors who provide services on our behalf such as payment processing, analytics, authentication, and security.
- Identity Verification Services: Know Your Customer ("KYC") verification results, fraud risk scores, identity document validation data, and sanctions screening results from authorized verification partners.
- Publicly Available Sources: Business contact information, public social media profile data, and publicly available regulatory or compliance information.
- Referral Partners: Information provided by existing customers or referral partners who refer you to our Services.
3. Legal Basis for Processing
The legal basis for our processing of your information varies depending on the specific information and the context in which it is processed. Our legal bases for processing include:
- Contractual Necessity: Processing is necessary to perform a contract with you or to take steps at your request before entering into a contract (e.g., providing the Services you request, processing payments, responding to support requests).
- Legitimate Interests: Processing is necessary for our legitimate interests and interests of third parties, where such interests are not overridden by your interests or fundamental rights and freedoms (e.g., fraud prevention, security monitoring, service improvement, analytics, marketing communications).
- Legal Compliance: Processing is necessary to comply with our legal obligations, including tax, accounting, audit, and regulatory compliance requirements.
- Vital Interests: Processing is necessary to protect your vital interests or the vital interests of another individual (e.g., in emergency situations).
- Consent: Processing is based on your explicit consent, which you may withdraw at any time without affecting the lawfulness of processing based on consent before withdrawal.
4. How We Use Your Information
We use the information we collect for the following purposes:
4.1 Service Delivery and Operation
- To create, maintain, and manage your account and billing relationship.
- To authenticate your identity and authorize access to the Services.
- To route, transmit, deliver, and track communications across global telecommunications networks.
- To provide customer support, respond to inquiries, and resolve technical issues.
- To process payments, issue invoices, and manage billing relationships.
- To monitor system performance, uptime, and service availability.
4.2 Platform Security and Integrity
- To detect, prevent, and mitigate fraud, abuse, spam, and unauthorized access attempts.
- To verify sender identities and validate the integrity of messages and communications.
- To monitor and enforce rate limits, usage caps, and acceptable use policies.
- To identify and block malicious traffic, phishing attempts, and other security threats.
- To conduct security audits, vulnerability assessments, and penetration testing.
- To investigate and respond to security incidents and potential policy violations.
4.3 Platform Improvement and Development
- To analyze aggregated usage patterns and performance metrics to optimize delivery routes and reduce latency.
- To develop, test, and improve our algorithms, features, and services.
- To train machine learning models for fraud detection, spam filtering, and delivery optimization.
- To conduct research and analysis to enhance the quality, effectiveness, and user experience of the Services.
4.4 Communications
- To send you service-related notifications, account alerts, and security updates.
- To provide technical support and respond to your inquiries.
- To send marketing communications, product updates, and promotional offers, with your consent where required by law.
4.5 Legal and Regulatory Compliance
- To comply with applicable laws, regulations, and legal processes.
- To respond to requests from government authorities, law enforcement, and regulatory bodies.
- To enforce our rights, investigate potential violations, and protect our legal interests.
- To investigate and prevent potentially prohibited, illegal, or harmful activities.
5. Data Sharing and Disclosure
We do not sell your personal information to third parties. We may share your information with third parties only in the following circumstances:
5.1 Service Providers and Vendors
We share information with trusted third-party service providers who assist us in operating our platform, conducting business, or providing services to you. These service providers are bound by confidentiality obligations and include:
- Cloud Infrastructure Providers: Third-party data centers and cloud service providers that host our infrastructure and store data on our behalf.
- Payment Processors: Financial institutions and payment service providers that process billing and payment transactions.
- Analytics Providers: Third-party analytics services that help us understand usage patterns and improve our Services.
- Support and Communication Tools: Customer support platforms, ticketing systems, and communication tools that facilitate our customer service operations.
- Marketing and Advertising Partners: Service providers that help us deliver marketing communications and measure advertising effectiveness, subject to appropriate restrictions.
- Security and Fraud Prevention: Third-party security services that help us detect and prevent fraud, abuse, and security threats.
- Professional Services: Auditors, consultants, and legal advisors who assist us in managing our legal, financial, and compliance obligations.
These service providers are contractually obligated to use your information only as necessary to provide their services to us and to maintain appropriate security and confidentiality measures.
5.2 Telecommunications Carriers and Network Providers
To deliver communications through our Services, we transmit necessary information to telecommunications carriers, messaging aggregators, and network operators. This transmission is essential to fulfill your communication requests.
5.3 Legal Requirements
We may disclose your information if required to do so by law, regulation, or legal process, or if we reasonably believe that such disclosure is necessary to:
- Comply with applicable laws, regulations, subpoenas, court orders, or governmental requests.
- Investigate, prevent, or take action regarding potential violations of our terms, fraud, or security issues.
- Protect and defend our rights, property, safety, or interests, or those of our users and customers.
- Establish, exercise, or defend against legal claims.
- Protect against imminent harm to the rights, property, or safety of Trulay, our users, customers, or the public.
5.4 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a substantial portion of our assets, your information may be transferred to the acquiring entity or successor in interest. We will use reasonable efforts to require the successor entity to honor our commitments under this Policy, and we will provide notice of such transfers where required by law.
5.5 Consent
We may share your information for any other purpose with your explicit consent.
6. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to collect information about your interactions with our website and Services. For detailed information about the cookies we use and your choices regarding cookies, please see our Cookie Policy.
7. Data Retention
We retain your information for as long as necessary to provide our Services, comply with legal obligations, resolve disputes, and enforce our agreements. The specific retention periods are as follows:
- Account Data: Retained for the duration of your account relationship and for 365 days after account deletion, unless a longer retention period is required by law.
- Message Content: Retained for up to 72 hours after successful delivery for quality assurance and dispute resolution purposes, then securely deleted.
- Delivery Records and Integrity Proofs: Retained for 12 months or as required by applicable telecommunications regulations.
- Payment and Billing Records: Retained for 7 years to comply with tax, accounting, and financial reporting requirements.
- Usage Logs and Analytics: Retained for 90 days in identifiable form and indefinitely in aggregated, anonymized form.
- Audit Logs: Retained for 365 days to maintain an audit trail for security and compliance purposes.
- Support Records: Retained for 24 months after case resolution for quality assurance and training purposes.
- Marketing Preferences: Retained until you opt out or your preferences change, plus a reasonable period thereafter.
In the event of a legal hold or ongoing litigation, we may retain information for longer than these periods as required by law or for the establishment, exercise, or defense of legal claims.
8. Data Security
We implement and maintain appropriate technical and organizational measures to protect your information, including:
- Encryption in Transit: All data transmitted between your applications and our Services is encrypted using TLS 1.3 or equivalent standards.
- Encryption at Rest: Data stored on our servers is encrypted using AES-256 or equivalent standards.
- Access Controls: Strict role-based access controls and least-privilege principles limit who can access your data.
- Security Monitoring: Continuous monitoring for security events, anomalies, and potential threats.
- Regular Testing: Penetration testing, vulnerability assessments, and security audits are conducted regularly.
- Incident Response: Formal incident response plan to detect, respond to, and recover from security incidents.
- Employee Training: Regular security and privacy training for all employees with access to customer data.
We maintain SOC 2 Type II certification and comply with ISO 27001 standards for information security management.
9. Your Rights and Choices
Depending on your location and applicable law, you may have certain rights regarding your personal information, including:
9.1 Right to Access
You may request confirmation as to whether or not we are processing your personal information, and where we are, access to that information and certain other details.
9.2 Right to Rectification
You may request that we correct, update, or complete your personal information that we hold about you.
9.3 Right to Erasure (Right to be Forgotten)
You may request that we delete your personal information, subject to certain legal exceptions and data retention requirements.
9.4 Right to Restrict Processing
You may request that we restrict or suspend our processing of your personal information under certain circumstances.
9.5 Right to Data Portability
You may request that we provide you with your personal information in a structured, commonly used, and machine-readable format, and that we transmit it to another controller.
9.6 Right to Object
You may object to our processing of your personal information based on our legitimate interests, and we will cease such processing unless we can demonstrate compelling legitimate grounds.
9.7 Right to Withdraw Consent
Where we process your information based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal.
9.8 Right to Non-Discrimination
We will not discriminate against you for exercising any of your privacy rights.
9.9 Exercising Your Rights
To exercise any of these rights, contact us using the details in Section 11. We will respond to your request within 30 days, though complex requests may take up to 60 days. We may need to verify your identity before fulfilling your request.
10. International Data Transfers
Our Services operate globally. Your information may be transferred to, stored, and processed in countries other than your country of residence, including countries that may have different data protection laws than your jurisdiction. When we transfer your personal information, we implement appropriate safeguards to ensure a comparable level of protection.
11. Children's Privacy
The Services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children under the age of 16. If we become aware that we have collected personal information from a child, we will take steps to delete such information promptly.
12. Contact Us
If you have any questions, concerns, requests, or complaints regarding this Privacy Policy, your personal information, or our privacy practices, please contact us:
If you are a resident of the European Economic Area, United Kingdom, or Switzerland and believe we have infringed your data protection rights, you have the right to lodge a complaint with your local data protection supervisory authority.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (if you have an account) or by posting a prominent notice on our website, and update the "Last Updated" date. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated policy.