HABEAS DATA
CitaChat LLC
Last updated: April 12, 2026
This Policy establishes the acceptable use conditions for the CitaChat Platform, the rights of personal data subjects (Habeas Data), and the User's commitments regarding the processing of their end customers' data. This Policy is an integral part of CitaChat's Terms and Conditions.
1. Acceptable Use
The User agrees to use the Platform lawfully, ethically, and in accordance with:
- CitaChat's Terms and Conditions.
- Meta Platforms Inc.'s WhatsApp Business Commerce Policy.
- Meta Platform Terms of Service.
- Applicable legislation regarding personal data protection, electronic communications, and commerce in the User's country of operation.
- Best practices for commercial communication with consumers.
2. Prohibitions
It is strictly prohibited to use CitaChat for:
2.1 Illegal or abusive communications:
- Sending spam, unsolicited mass messages, or communications without prior consent from the recipient in accordance with Meta's policies and applicable law.
- Harassing or intimidating message recipients.
- Using the AI Agent to impersonate a human person in contexts where the law requires disclosure of automation.
2.2 Prohibited content:
- Illegal, offensive, violent, discriminatory, defamatory content, or content that incites hatred.
- Sexually explicit material not authorized by law.
- Misinformation, fake news, or content designed to deceive recipients.
2.3 Goods and services prohibited by Meta:
- Firearms, ammunition, or weapon modifications.
- Controlled substances, illegal drugs, or prescription-free medications.
- Tobacco, alcohol, or vaporizers (except with specific authorization from Meta and local law).
- Unregulated financial services, pyramid schemes, or unauthorized investment schemes.
- Legally unauthorized gambling or betting.
- Surveillance or espionage services.
- Any product or service included in Meta Platforms Inc.'s prohibited content lists.
2.4 Illicit activities:
- Activities related to terrorism, organized crime, or money laundering.
- Unauthorized collection of third-party personal data through the Platform.
- Use of the Platform to access, extract, or reuse conversation data from other CitaChat clients.
2.5 Abusive technical use:
- Abusive use that may affect the stability, availability, or performance of the Platform.
- Attempts at reverse engineering, decompilation, or unauthorized access to CitaChat's infrastructure.
- Manipulation of the AI Agent to generate responses outside the purposes of legitimate commercial service.
3. Consent Obligations — WhatsApp Business API
The use of WhatsApp through CitaChat requires that the User complies with Meta Platforms Inc.'s consent requirements:
- 3.1 The User guarantees that all recipients of messages sent through the Platform have given their consent to receive communications from the User's company through WhatsApp, in accordance with Meta's policies.
- 3.2 The User will implement mechanisms for recipients to opt out of receiving further communications and will honor such requests immediately.
- 3.3 The User will not send marketing messages or commercial communications outside the 24-hour active conversation window without using Meta-approved templates and in accordance with Meta's pricing policies.
- 3.4 The User is responsible for obtaining and documenting consent from their end customers. CitaChat assumes no responsibility for non-compliance with this obligation.
4. Habeas Data — Data Subject Rights
4.1 User Declarations
The User declares that:
- They have express authorization or sufficient legal basis for the processing of personal data of their end customers through the Platform.
- They will adequately inform their customers about the use of automation and artificial intelligence in service, in accordance with applicable legislation.
- They guarantee their customers the rights of access, rectification, deletion, and objection in accordance with applicable law in their jurisdiction.
4.2 Recognized Rights
Data subjects whose personal data is processed through CitaChat have the right to:
- Access: Know what personal data of theirs is being processed.
- Rectification: Correct inaccurate or incomplete data.
- Deletion (Right to be Forgotten): Request the deletion of their data when there is no legal basis for its retention.
- Objection: Object to the processing of their data for specific purposes, including automated commercial communications.
- Portability: Receive their data in a structured format, when applicable.
- Information: Be clearly informed about the use of automated systems and artificial intelligence in the interaction.
4.3 Rights Exercise Channel
Data subjects may exercise their rights:
- Directly with the User (as Data Controller), through the business's service channels.
- With CitaChat, as Data Processor, by writing to: soporte@citachat.co.
CitaChat will forward requests to the corresponding User when applicable, and will respond directly when the processing is CitaChat's responsibility.
4.4 Applicable Legal Framework
This section complies with:
- Law 1581 of 2012 (Colombia) and Decree 1377 of 2013.
- Federal Law on Protection of Personal Data Held by Private Parties (Mexico).
- General Data Protection Regulation — GDPR (EU/EEA), applicable due to the international nature of the service.
- California Consumer Privacy Act — CCPA (USA).
5. Measures for Non-Compliance
CitaChat may, depending on the severity of the non-compliance:
- Send a formal warning to the User.
- Temporarily suspend access to the Platform or specific WhatsApp functionalities.
- Permanently cancel the account and service contract, without the right to proportional refund.
- Notify Meta Platforms Inc. of the non-compliance when required by the provider agreement conditions.
- Take corresponding legal action for damages caused to CitaChat, third parties, or data subjects.
6. Abuse Reporting
Any misuse of the Platform, or any communication that the User considers violates this Policy, may be reported to:
CitaChat will investigate reports received and take appropriate measures within a reasonable timeframe.
CitaChat LLC — soporte@citachat.co — citachat.co