Privacy Policy
- Effective from
- Last updated
- Version
- 2.0
This policy explains what personal data we process when you use meruma, what for, who we share it with, and what you can ask us about it. It is written to be understood: if anything is unclear, write to us and we will explain it.
Who we are
meruma is a conversational CRM operated by HIPER DEVS LLC, a company incorporated in the state of Florida, United States, with offices at 2226 N Cypress Bend Dr Apt 505, Pompano Beach, FL 33069 (“meruma”, “we”).
For anything privacy-related, including exercising your rights: info@meruma.app, with “Privacy” as the subject.
Two different roles
This is the most important distinction in this document, because everything else follows from it.
For your account data — name, email, organization, billing, usage records — we act as the data controller: we decide what it is used for and we answer for it.
For the data your organization uploads to or receives inside meruma — your customers’ contacts, conversations, files, recordings, signed documents — we act as the data processor. This means that data belongs to your organization, that we process it solely on its instructions, and that we never use it for any purpose of our own. The terms of that processing are in the data processing agreement.
If you wrote to a business that uses meruma and want to know what that business does with your data, the business is the one who answers, not us. We can still help you route the request.
What data we process
If you write to us through the contact form. We collect your name, your email, and — if you fill them in — your company and your phone number, along with your message and the reason you are writing. We use them for one thing: to reply to you. The basis is taking steps at your request before entering into a contract. If you also tick the newsletter box, those emails go on your consent and you can withdraw it whenever you want. We keep the message for up to 24 months and it is then deleted automatically.
Your account and your organization. Each user’s name and email, the organization name, language and preferences, a profile picture if you upload one, and billing details. Passwords are handled by Amazon Cognito: we neither see nor store them.
Technical and usage data. Access and activity logs, IP address, browser type and application events, needed to run the service, understand failures and protect it from abuse.
The data your organization processes with the tool, which depends on how it uses it: contacts and their details, custom fields the organization defines itself, messages from every connected channel and their attachments, voice notes, call recordings when the organization turns them on, appointments and attendees, form responses with their files, signed documents with their audit trail, and the lists behind its email campaigns.
That last group can contain almost anything, because those are free-form fields and messages. We do not inspect or classify it: each organization is responsible for deciding what it puts into the tool and on what grounds.
What we use it for, and on what legal basis
As a controller, we process your account data for these purposes:
| Purpose | Legal basis |
|---|---|
| Providing the service you signed up for, and supporting you | Performance of the contract |
| Billing you and keeping our accounts | Performance of the contract and legal obligation |
| Telling you about the service: invitations, changes, security | Performance of the contract |
| Protecting the platform from abuse, fraud and unauthorized access | Legitimate interest in keeping the service secure |
| Improving the product from aggregated usage data | Legitimate interest in improving what we offer |
| Sending you commercial news, if you subscribed | Consent, which you can withdraw at any time |
| Responding to requests from competent authorities | Legal obligation |
As a processor, we handle your organization’s data for one purpose only: running the service on your instructions. Nothing else.
We do not sell personal data, we do not share it with third parties for advertising, and we do not use it for advertising of our own. Text message originator opt-in data and consent are never sold or shared with any third party.
Who we share it with
Only with the providers meruma needs in order to work, each under contract and with access limited to what its function requires. The full list, with each provider’s country and what data it sees, is on the subprocessors page, which we keep current and where we announce changes before they happen.
We may also share data where a legal obligation or an order from a competent authority requires it, and in the event of a merger or sale of the company — in which case we will give notice in advance and this policy will keep applying until it is replaced.
International transfers
meruma is a United States company and its infrastructure is hosted in the United States
(Amazon Web Services region us-east-1). If you are in the European Union, the United
Kingdom or Switzerland, your data is transferred there.
Those transfers rely on the Standard Contractual Clauses approved by the European Commission (Implementing Decision 2021/914), which we sign with our providers and which form part of our data processing agreement. Write to us and we will send you a copy of the clauses that apply.
How long we keep it
| What | How long |
|---|---|
| Account and organization data | While the account is active |
| Contacts, conversations, files and documents | While the organization keeps them, or until it deletes them |
| Call recordings | While the organization keeps them; deleted with the organization |
| Access and activity logs | Up to 12 months |
| Billing records | As long as applicable tax law requires |
| Backups | Up to 90 days, by rotation |
When an account or an organization is deleted, active data is erased within 30 days and backups roll off within 90. The details are in the data deletion policy.
Your rights
Over the data we control, you can exercise:
- Access: find out what data of yours we process, and get a copy.
- Rectification: correct anything wrong or incomplete.
- Erasure: ask us to delete it, where no obligation requires us to keep it.
- Restriction: ask us to keep it but stop using it while a dispute about it is resolved.
- Objection: object to processing based on our legitimate interest.
- Portability: receive your data in a structured, commonly used format.
- Withdrawing consent at any time, where consent is the basis. Withdrawing it does not affect what was done before.
- Not being subject to automated decisions with legal effects. meruma makes no such decisions about people today.
Write to info@meruma.app and we will answer as soon as we can, always within the period applicable law sets. We may ask you to prove your identity before we hand over information about personal data.
If you believe we mishandled your request, you can lodge a complaint with the data protection authority of your country.
If your data sits in the account of an organization that uses meruma, go to that organization first: it is the one that decides about it. We assist them in answering you.
Security and incidents
We encrypt data in transit and at rest, isolate each organization at the database level, authenticate through Amazon Cognito and offer two-factor authentication. The measures are detailed on the security page.
If a security breach affecting personal data were to occur, we will notify the affected organizations without undue delay and, in any case, with the information and within the deadlines applicable law requires, so that they can meet their own notification duties.
Data from the platforms you connect
When your organization connects WhatsApp, Instagram, Messenger, Google or Microsoft, we receive data from those platforms so the channel can work, and we process it for that alone.
Google data. meruma’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use your mail and calendar data only for the features you can see in the application, we do not transfer it to third parties other than to provide those features, we do not use it for advertising, and we do not use it to train artificial intelligence models.
Meta data. Data we receive from Meta platforms is kept separate per organization, is never shared between customers, and is deleted when the organization asks or stops using the channel.
Artificial intelligence
If your organization turns on bots, its messages and the knowledge documents it uploads are sent to the model provider (today, OpenAI) to generate the answer, using the organization’s own key.
Customer data is not used to train artificial intelligence models, ours or anyone else’s. That is a commitment of our own, and also an obligation WhatsApp and Google impose on us.
When a bot handles a conversation, the person can see they are talking to an automated assistant from the first message.
Cookies
This site uses no analytics or advertising cookies, and loads no third-party resources that follow you. The application does store information in your browser to keep your session. The details are in the cookie policy.
Minors
meruma is a work tool and is not directed at people under 18; we do not knowingly create accounts for them. If we find one, we delete it. If a minor writes to a business that uses meruma, the business is the one answering for that processing.
Regional information
European Union, United Kingdom and Switzerland. The General Data Protection Regulation applies to us because we offer services to people in those territories. The rights listed above are those of its articles 15 to 22, and the legal basis for each purpose is in the table above.
Brazil. The General Data Protection Law applies to us. meruma’s appointed data protection officer is Leandro Sebastián Lardaro, reachable at info@meruma.app with “Privacy” as the subject.
United States. We do not sell or share personal information within the meaning of state privacy laws, nor do we use it for cross-context behavioral advertising. If you live in a state with its own privacy law, the rights above reach you all the same.
Changes to this policy
If this policy changes substantively, we publish the new version here with its date and version number, and we notify active organizations before it takes effect. We keep previous versions: ask us if you need one.
Language
This policy is published in English, Spanish and Portuguese. If the versions differ, the English version prevails and is the binding one.