Privacy Policy
Last updated: July 2026
This Privacy Policy describes how Hablari (hereinafter, "Hablari," "we," or "the Controller") collects, uses, retains, and protects the personal data of those who visit our website, register on the platform, or interact with it, as well as of the end users whose data is processed on behalf of our business customers.
This document complies with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), the Spanish Organic Law 3/2018, of December 5, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD), the Spanish Law 34/2002, of July 11, on information society services and electronic commerce (LSSI-CE) and Regulation (EU) 2024/1689 on Artificial Intelligence (EU AI Act), in force since August 2026.
1. Identity of the Data Controller
- Name: Hablari.
- Contact email: contacto@hablari.com.
- Website: www.hablari.com.
Hablari is not legally required to appoint a Data Protection Officer (DPO), although any privacy-related inquiry may be directed to the email address indicated.
2. Two distinct roles: Controller and Processor
Hablari is a B2B business-to-business service. This means we process personal data in two distinct legal capacities that must be clearly distinguished:
2.1. As Data Controller
Hablari acts as Controller with respect to the data of the people who create an account on the platform, the members of their team (agents), and any person who interacts with our website or with us directly. In this capacity, we decide the purposes and means of the processing.
2.2. As Data Processor
Hablari acts as Data Processor (in accordance with article 28 of the GDPR) with respect to the personal data of end customers, contacts, and other individuals that the client company manages within the platform: conversations, phone numbers, email addresses, order history, notes, attachments, etc. The Controller of that data is the client company that uses Hablari; we process it exclusively to provide the agreed service and in accordance with that company's instructions. The terms of this arrangement are set out in full in the Data Processing Agreement (DPA) incorporated into the Terms and Conditions.
If you are an end user (a customer of a company that uses Hablari) and wish to exercise your rights over the data that company holds about you, please contact that company directly: it is the Controller and the one that must handle your request.
3. Data processed as Controller: categories, purposes, and legal bases
3.1. Registration and account data
Data: first name, last name, email address, password (stored hashed; Hablari never has access to the plain-text password), phone number (optional), profile photo or selected avatar, role within the organization (owner, manager, agent), interface preferences (visual theme), and time zone.
Purpose: creating and managing the account, authenticating the user, enabling collaboration within the same organization, and identifying who is responsible for each action on the platform.
Legal basis: performance of the subscription contract (art. 6.1.b GDPR). In the case of the phone number, when voluntarily provided, the data subject's consent (art. 6.1.a GDPR).
3.2. Organization data (client company)
Data: company name, description, logo, unique organization identifier (slug), contracted plan, and account settings (business hours, SLA, auto-replies).
Purpose: providing the multi-company service, customizing the interface, providing support, and managing the contractual relationship.
Legal basis: performance of the contract (art. 6.1.b GDPR).
3.3. Billing and subscription data
Data: contracted plan (Starter, Pro, or Max), subscription status, amount, billing dates, Stripe subscription and customer identifiers, invoice history. Hablari does not store the full credit card number or security data (CVV): payment is processed directly by Stripe, which holds PCI DSS certification.
Purpose: managing the subscription, issuing invoices, complying with tax and accounting obligations, detecting and preventing payment fraud.
Legal basis: performance of the contract (art. 6.1.b GDPR) and compliance with legal obligations in tax and commercial matters (art. 6.1.c GDPR).
3.4. Usage and technical data
Data: IP address, browser type and version, operating system, pages visited and actions performed within the application, access logs, system errors, and response times.
Purpose: ensuring the security and integrity of the platform, detecting and preventing unauthorized access, debugging technical errors, and improving service performance.
Legal basis: Hablari's legitimate interest in maintaining the security and quality of the service (art. 6.1.f GDPR), balanced against the rights of data subjects and proportionate to the purposes pursued.
3.5. Sign-up process and onboarding survey data
Data: during the registration and initial company setup process (onboarding), we voluntarily collect information about how you found out about Hablari (e.g., word of mouth, social media, internet search), the support channels currently in use, the approximate volume of conversations, the online store's status, and team size. We also collect, if present, UTM parameters found in the access URL (source, medium, campaign), the referring URL (referrer), and the type of device used for registration.
Purpose: improving the product and onboarding process, analyzing the effectiveness of our marketing actions, and adapting the service to customers' needs. The data is analyzed in aggregate form.
Legal basis: Hablari's legitimate interest in improving the service (art. 6.1.f GDPR), given that the information is voluntary and does not affect how the account works.
3.6. Communications with support
Data: name, email address, and message content when you contact us through any channel.
Purpose: handling your inquiry or issue.
Legal basis: legitimate interest of both parties in resolving the communication (art. 6.1.f GDPR) or, when the inquiry arises from the contractual relationship, performance of the contract (art. 6.1.b GDPR).
4. Data processed as Data Processor
When a client company uses Hablari, it enters or receives through the platform data about its own customers and contacts. Hablari processes such data exclusively on behalf of that company (Controller) and in accordance with its instructions. This data may include:
- Identity and contact details of end customers: first name, last name, email address, phone number, social media username, postal address.
- Conversations and messages: the full content of exchanges via WhatsApp, Instagram Direct, email, and web chat, including text, images, documents, audio, and any other attached files.
- Internal notes: private team annotations about a customer or conversation, not visible to the end customer.
- Shopify order history: orders, products, amounts, statuses, and dates, when the client company connects its Shopify store.
- Tagging and classification data: tags, VIP status, assignments to agents and stores, priorities.
- Messages from web chatbot visitors: text sent to the chat widget embedded on the client's website (Max plan), associated with an anonymous or identified web session.
Hablari does not access this data except to provide the service, offer technical assistance, or comply with legal obligations. Hablari staff members who may access the data for support or moderation purposes do so under strict confidentiality and only when justified.
5. Artificial Intelligence: the AI Chatbot (Max plan)
The Max plan includes an AI-powered chatbot that client companies can embed on their own web pages. Below we describe the data processing associated with this feature:
5.1. How it works and what data is sent to OpenAI
When a visitor interacts with the chatbot of a Hablari client, the visitor's message and the client company's public description are sent to the OpenAI API (GPT-4o-mini model) to generate a response. No personally identifying data about the visitor is sent beyond the text they themselves type in the chat, nor any billing data or credentials of any kind.
5.2. Processing by OpenAI
Hablari uses the OpenAI API in no-training mode: under OpenAI's current API terms of use, data sent via the API is not used to train OpenAI's models. OpenAI acts as a subprocessor with respect to the end-user data of Hablari's clients.
5.3. EU AI Act compliance
In compliance with the Regulation (EU) 2024/1689 on Artificial Intelligence (EU AI Act), applicable from August 2026, the chatbot identifies itself to the visitor as an artificial intelligence system from the very first welcome message, with wording equivalent to: "I'm [company]'s AI assistant." This identification is automatic, permanent, and cannot be disabled by the client company. This AI system is classified as limited risk (conversational assistant) under article 50 of the EU AI Act, which specifically requires transparency toward the user.
5.4. Client's responsibility over the chatbot
The client company that activates the chatbot is responsible for the content it configures as the system prompt, of the context of use, and of ensuring that its deployment complies with the regulations applicable to its sector. Hablari provides the technical infrastructure; lawful use is the client's responsibility.
5.5. Rate limiting and abuse protection
The chatbot endpoint applies a limit of 10 requests per minute per IP address to protect the service against automated abuse. The visitor's IP address is processed solely for security purposes and is not stored persistently linked to the chat content.
6. Processors and subprocessors
To provide the service, Hablari relies on the following providers, which act as processors or subprocessors under contract and with adequate safeguards:
- Supabase, Inc. — PostgreSQL database, authentication, file storage (attachments, logos), and real-time communications. Data is hosted in the EU-Central (Frankfurt, Germany), region, within the European Economic Area. Supabase has a Data Processing Agreement (DPA) in place. More information: supabase.com/privacy.
- Vercel, Inc. — Hosting of the web application (serverless platform). Servers may be located inside or outside the EEA depending on the edge configuration. Vercel has a DPA in place and transfer safeguards via Standard Contractual Clauses (SCCs). More information: vercel.com/legal/privacy-policy.
- Stripe, Inc. — Payment processing and subscription management. Stripe is PCI DSS certified and has a DPA in place. Payment data (card number, CVV) is processed directly by Stripe; Hablari only stores subscription and customer identifiers. More information: stripe.com/es/privacy.
- OpenAI, LLC — AI engine for the chatbot (Max plan). Acts as a subprocessor with respect to visitor messages sent to the chatbot. OpenAI's servers are located primarily in the United States. Transfers are covered by Standard Contractual Clauses. API data is not used to train models. More information: openai.com/policies/privacy-policy.
- Meta Platforms, Inc. (WhatsApp Business API / Instagram Graph API) — Optional messaging channels that the client company can connect. Meta acts as the provider of the communication channel; Hablari receives inbound messages via webhooks verified with an HMAC signature and sends outbound messages through the Meta API. Meta's processing of data on its own platforms is governed by its own privacy policies.
- Shopify International Limited — E-commerce platform. When the client company connects its Shopify store, Hablari accesses order and customer data via the Shopify Admin API. Processing by Shopify is governed by its own policies.
- Resend, Inc. — Email sending and receiving service. Hablari uses a single Resend account to manage the email channel for all its clients: each client company provides its own domain, which is verified within Hablari's Resend account. Inbound emails are received via webhook with signature verification. Resend has a DPA in place.
- Klaviyo, Inc. — Email marketing platform. Optional connector that the client company can enable to sync contacts or automations. Klaviyo acts as a processor with respect to the data the client company provides to it. More information: klaviyo.com/legal/privacy-notice.
7. International data transfers
The main database (Supabase) is located in the European Union. However, some providers listed in the previous section — in particular Vercel (US), Stripe (US), OpenAI (US), Resend (US), and Klaviyo (USA)— may process data outside the European Economic Area.
These transfers are backed by one or more of the following mechanisms:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Implementing Decision 2021/914), which require the provider to offer a level of protection equivalent to that of the GDPR.
- Adequacy decision from the European Commission, where one exists for the destination country.
You can request a copy of the safeguards applicable to each transfer by writing to contacto@hablari.com.
8. Retention periods
- Account and organization data: for the duration of the subscription contract and, after its termination, a maximum of 3 years to address legal claims, unless the data subject exercises their right to erasure beforehand.
- Billing data: for 7 years from the date of each transaction, in compliance with the tax and accounting obligations set out in the General Tax Law (Ley General Tributaria) and the Commercial Code (Código de Comercio).
- Technical and security logs: a maximum of 12 months from their generation, unless they are needed to investigate a security incident, in which case they will be retained until it is resolved.
- Data processed as processor (end-customer data): for the duration of the contract with the client company. After the account is canceled, the data is retained in an inaccessible state for a maximum period of 90 days to allow recovery in the event of accidental cancellations or export requests. Once that period has elapsed, the data is permanently deleted unless otherwise instructed by the Controller. If the client company requests immediate erasure, Hablari will carry it out without undue delay.
- Chatbot visitor messages: retained for the duration of the client's account. Deleted in the same purge operation as the rest of the company's data.
- Support communications: 2 years from the resolution of the case.
9. Rights of data subjects
In accordance with the GDPR and the LOPDGDD, you have the right to:
- Access (art. 15 GDPR): obtain confirmation of whether we process your personal data and, if so, receive a copy of it.
- Rectification (art. 16 GDPR): request the correction of inaccurate or incomplete data. Many of your details can be corrected directly from Settings → Profile within the platform itself.
- Erasure or "right to be forgotten" (art. 17 GDPR): request the deletion of your data when, among other reasons, it is no longer necessary for the purposes for which it was collected.
- Restriction of processing (art. 18 GDPR): request that the processing of your data be restricted under certain circumstances, for example while a rectification request is being verified.
- Portability (art. 20 GDPR): receive your data in a structured, commonly used, machine-readable format, and transmit it to another controller when the processing is based on consent or on the performance of a contract and is carried out by automated means.
- Objection (art. 21 GDPR): object to the processing of your data when it is based on legitimate interest, unless we demonstrate compelling legitimate grounds that override your interests.
- Withdrawal of consent: when the processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out prior to its withdrawal.
- Not to be subject to automated decision-making (art. 22 GDPR): not to be subject to a decision based solely on automated processing that produces legal effects significantly affecting you.
9.1. How to exercise your rights
To exercise any of these rights, send an email to contacto@hablari.com indicating: (i) the right you wish to exercise, (ii) your full name, (iii) the email address associated with your account, and (iv) a copy of a document proving your identity. We will handle your request within a maximum period of one month (extendable by two additional months in particularly complex cases).
If the data for which you are requesting the exercise of rights belongs to end customers of a company using Hablari, you must contact that company (the data Controller), not Hablari.
9.2. Complaint to the AEPD
If you believe we have infringed your rights or have not properly handled your request, you may file a complaint with the Spanish Data Protection Agency (AEPD) (www.aepd.es), the competent supervisory authority in Spain.
10. Cookies and similar technologies
Hablari uses technical or strictly necessary cookies for the platform to function and, only with your consent, cookies for analytics (Google Analytics) to measure aggregate site usage and improve it. We do not use behavioral advertising or retargeting cookies. Full details are available in our Cookie Policy.
- Session cookie: stores the user's authentication token to keep the session active across requests. It is deleted upon logout or when the token expires. It is essential for the application to function.
- Preferences cookie: stores the visual theme (light/dark) chosen by the user to avoid a "flash" when the page loads. It does not contain identifying personal data.
Technical cookies do not require prior consent under article 22.2 of the LSSI-CE, as they are necessary to provide the service. Cookies for analytics do require your consent: they are disabled by default via consent mode (Google Consent Mode) and are only activated if you accept them in the cookie banner that appears on your first visit, where you can choose "Essential only" or "Accept."
11. Technical and organizational security measures
Hablari applies appropriate security measures in line with the state of the art and the risk of each processing activity, including:
- Encryption in transit: all communications between the user's browser and the application take place over HTTPS/TLS. Meta and Resend webhooks are validated with an HMAC signature before being processed.
- Multi-tenant isolation: each company's data is logically separated using Row-Level Security (RLS) in the PostgreSQL database. All tables include an
org_idcolumn, and access policies prevent one company from seeing another company's data. - Secure authentication: passwords stored with secure hashing (managed by Supabase Auth); authentication with Google OAuth available; no email magic links (due to the risk of sending limits and phishing).
- Principle of least privilege: the different roles (agent, manager, owner) have differentiated permissions. Access to the super-admin panel is restricted to a list of authorized Hablari staff emails via a server environment variable.
- Rate limiting: public endpoints (in particular the chatbot) are rate-limited by IP address to prevent abuse.
- Audit logs: actions taken by Hablari staff on client accounts are logged in an audit table recording who, what, when, and why.
- Integration credentials: connector credentials (API tokens for Meta, Shopify, Klaviyo, Resend) are stored encrypted in the database and are never exposed to the client.
No system is infallible. Should a security breach occur affecting your personal data with a risk to your rights and freedoms, we will notify you without undue delay and within the maximum period required by the GDPR, and we will notify the AEPD where applicable.
12. Data of minors
The Hablari service is intended exclusively for businesses and professionals. We do not knowingly process personal data of minors under 14 years of age. By registering, the user declares that they are of legal age and are acting on behalf of a company or professional activity. If we became aware that we had collected a minor's data without appropriate consent, we would delete it immediately.
13. Commercial communications
Hablari may send communications about service news, important updates, or changes to the terms to the email address associated with the account. These communications are informational in nature and are linked to the contractual relationship. To the extent that they constitute commercial communications as such, we will offer you the option to unsubscribe at any time via the link provided in the email itself or by writing to contacto@hablari.com.
14. Updates to this policy
Hablari may update this Privacy Policy to reflect regulatory changes, new service features, or new subprocessors. We will publish the current version on this same page with the date of the last update. When changes are substantial, we will actively inform you (via a notice on the platform or by email) with reasonable advance notice. Continued use of the platform after the new version takes effect implies acceptance of it.
15. Privacy contact
For any query, rights request, or issue related to the processing of personal data, you can contact us at:
- Email: contacto@hablari.com
- Recommended subject line: "Data protection — [reason for the query]"
If your request does not receive a response within one month, or you are not satisfied with the response received, you may file a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan, 6, 28001 Madrid, Spain.
