Privacy Policy
Radd is published and operated by Volta (TRAAC), Cairo, Egypt ("we", "us"). Contact: [email protected].
This policy covers the Radd mobile application (iOS and Android, bundle
identifier com.radd.app), the Radd web console, and the service both
of them talk to.
Radd handles the content of messages between a business and its customers. That is the whole product, and it is the most sensitive thing in it.
Radd is bought by a business — a shop, a clinic, a brokerage. That business connects its own WhatsApp Business account, and Radd answers its customers on its behalf and hands the conversation to a human when the human is needed.
There are therefore two roles, and they matter:
If you are a customer of a business that uses Radd and you want your messages deleted, ask that business. It can delete them, and we act on its instruction — see section 10.
| What | Why | Kept |
|---|---|---|
| Business account: name, workspace code, and the address and database name of the business's ERP system if it connects one | To keep each business's data separate and to write leads and orders back into its own system | For the life of the subscription |
| Operator account: mobile number, a one-way hash of the password, role | To sign in the business's own staff and decide what each may do | While the account is active |
| Customer contact: mobile number, name if the customer gives one, language preference, and the matching customer number in the business's ERP | To hold a conversation with a person rather than with an anonymous number, and to attach the conversation to the right customer record | Until the business deletes it |
| Conversation: which channel and contact, whether it is open or closed, who it is assigned to, when the last message arrived, and when the messaging window expires | To route the conversation and to respect the messaging platform's own reply window | Until the business deletes it |
| Message content: the text of each message in and out, a link to any attached media, whether it came from the customer, from the automated reply or from a member of staff, the delivery state, and the cost of a paid send | The conversation history is the product. Staff need to read what was already said, and the business needs to see what its automation said in its name | Until the business deletes it, or 24 months by default |
| Understanding: the exact text received, its normalised form, the intent we matched it to, a confidence figure and the words that matched | Egyptian customers write in Arabic, in Latin-letter Franco-Arabic, and in mixtures of both. This record is what lets a wrong answer be traced to the phrase that caused it and corrected | 12 months |
| Automation state: which step of a reply flow a conversation reached and the values collected on the way | So a conversation resumes where it left off instead of starting again | With the conversation |
| Spend: the month's message cost, the cap the business set, and what is left | Paid messaging costs money per send. The cap exists so a runaway automation cannot spend a business's money, and it is enforced when a send is accepted | Seven years, as commercial records |
| Sign-in tokens and their rotation history | Security — so a stolen token can be detected and cut off | Until expiry, then 90 days |
Radd sends and receives through the business's own WhatsApp Business account on Meta's WhatsApp Business Platform. This means:
Under Egyptian Law 151 of 2018 on the Protection of Personal Data:
Data is held on servers we operate. Message content is kept for 24 months by default; a business can set a shorter period in its contract, and a shorter period wins. Understanding records are kept for 12 months. Billing records are kept for seven years because commercial law requires it.
If a breach affects message content we notify the affected business, and the Egyptian authority where the law requires it, without undue delay.
The messaging platform is operated by Meta outside Egypt, so a message you send or receive necessarily crosses a border on its way. Radd's own servers and database are operated by us; where a business requires them to stay in a particular country, that is agreed in writing before its account is created.
Radd is a business tool for adults. We do not knowingly create accounts for anyone under 18. A business using Radd is responsible for not messaging children unlawfully.
Questions about this policy, a request to see, correct, export or delete your data, or a complaint about how Radd handles it — write to [email protected] and put the word Radd in the subject line. We answer within thirty days.
Postal and in-person contact: Volta (TRAAC), Cairo, Egypt.
If you are not satisfied with our answer, you may complain to the Egyptian Personal Data Protection Centre established under Law 151 of 2018.
If we change what we collect, why we collect it, or who we share it with, we publish the new version at this address and change the effective date at the top. A change that materially widens what we collect is announced inside the app before it takes effect, and — where the law requires consent — asked for rather than assumed. This page is the whole policy; there is no second document.