Privacy Policy
Last updated: September 16, 2026
This policy describes how WM Digital, LLC and WM Digital SpA (hereinafter "Hapee", "we" or "the platform") collect, use, store and protect the personal data of users who access the platform through the website hapee.ai, the iOS mobile app, the Android mobile app and the desktop app for Windows and macOS.
By using any of these channels, you accept the practices described in this document. If you do not agree, we ask that you not use the platform.
1. Data controller
Hapee.ai is operated by the WM Digital group. Two companies within the group act as joint controllers, each within its own scope:
WM Digital, LLC, a company incorporated under the laws of the State of Delaware, United States (Delaware file number 10365621; EIN: 38-4371956), operates the Hapee.ai platform, owns the technology, and is the controller of the data processed through the platform and its integrations with the third-party APIs the customer chooses to connect.
1908 Thomes Ave STE 12605, Cheyenne, WY 82001, US.
WM Digital SpA (Hapee), a company incorporated under the laws of Chile (Tax ID: 77.178.674-K), belongs to the same group, contracts with the platform's customers in Chile, and is the controller with respect to that commercial relationship.
Padre Mariano 82, office 502, Providencia, Santiago, Chile.
You may exercise your rights before either company, at the contact address indicated below.
General contact: info@hapee.ai
Privacy requests and data subject rights: info@hapee.ai
Privacy officer: Freddy Alejandro Castro Cuevas.
2. Data we collect
We collect the following types of data, either directly from the user or automatically when using the platform:
2.1. Account and contact data
- First and last name
- Email address
- Phone number (if you add it to your profile)
- Password (stored using a bcrypt hash)
- Profile picture or avatar (when you upload one voluntarily)
- Data about the organization you belong to (agency, client)
2.2. Identifiers
- Internal user identifier (associated with your session and audit records)
- Mobile device token for sending push notifications (Firebase Cloud Messaging)
2.3. User content
Any content you create, import or manage within the platform:
- Contacts, sales opportunities, tasks, notes, forms, workflows, reports, estimates, sites and funnels, blog posts, custom objects
- Messages and conversations (internal chat between team members, emails, SMS, WhatsApp, calls, direct messaging with customers in the unified inbox)
- Photos, videos, audio and files you upload (avatars, social media content in the social media management module, chat attachments, audio recorded when using the voice assistant)
2.4. Usage and interaction data
- Pages visited, clicks, session time, last login, audit events
- Search history within the platform and conversations with the AI assistant
- Error logs, performance and latency metrics for technical diagnostics
2.5. Approximate location
We infer approximate location (country and region) from the IP address when you interact with the platform. We do not collect or use exact GPS coordinates.
2.6. Third-party digital marketing data (agencies only)
If you connect advertising accounts via OAuth (Meta Ads, Google Ads, LinkedIn Ads, TikTok Ads, Google Analytics), we store the access tokens in encrypted form and query advertising metrics (impressions, clicks, spend, conversions) to generate reports.
2.7. Meta data (Facebook and Instagram)
If you connect a Facebook Page or an Instagram Business account, we receive the following data from Meta, always limited to the assets that the user performing the connection already administers and explicitly selects:
- Messages. Messenger conversations and Instagram direct messages that people start with your Page or account, along with the sender's public name and profile picture. We display them in your inbox so your team can read and reply to them. If the person unsends a message, we stop displaying its content.
- Page and Instagram account metrics. Reach, impressions, engagement, followers and post performance, for your account's reports.
- Advertising campaign metrics. Spend, impressions, clicks, conversions and other indicators from the advertising accounts you connect (see also 2.6).
- Identifiers. The identifier and name of the Page, the Instagram account and the selected advertising accounts.
This data is used solely to provide you with the service: it is not sold, not shared with third parties for advertising purposes, and not used to build audiences or target ads. We do not publish or modify campaigns or content on your Page without an action from you.
You can disconnect the Page or Instagram account at any time from Settings → Integrations in the platform. When you do, we unsubscribe from Meta's webhooks and stop receiving its data.
2.8. Data we do NOT collect
- Payment information: payments are processed through Stripe, which handles card data directly. Hapee never has access to card numbers or banking credentials
- Exact GPS coordinates or precise location
- The mobile phone's contact list
- Biometric, health or sensitive data
3. Purposes of processing
We use the data to:
- Authenticate users, manage accounts and control access
- Provide the platform's features (CRM, mailing, workflows, reports, sites, AI agents, etc.)
- Send push notifications, transactional emails and alerts related to your activity
- Provide customer support when you request help by email or within the platform
- Internal usage analysis (measure feature adoption, detect errors, improve the product)
- Hapee's own marketing communications (news, improvements, promotions), which you can unsubscribe from at any time
- Comply with applicable legal, tax and contractual obligations
We do not use the data for cross-app tracking, third-party advertising, or sale to data brokers.
4. Processors and external providers
To operate the platform we work with the following providers, who process data on our behalf under contractual confidentiality and security agreements:
- Amazon Web Services (AWS) — server and database hosting
- Anthropic — Claude models for the AI assistant, content generation and conversational agents. No identifiable personal data is stored in their systems beyond the time needed to process the response
- OpenAI — GPT models for conversational agents, when the customer selects one of those models in the agent editor, and for knowledge base indexing. The same conditions as the previous point apply: your data is not used to train models
- Voyage AI — computing vector representations (embeddings) of the documents you upload to an agent's knowledge base, so they can be searched. Same condition: they are not used to train models
- Mailgun — sending transactional and marketing emails
- Microsoft Corporation — email (Outlook / Microsoft 365) and calendar synchronization, only when you connect your account via OAuth. With your authorization we access message content to display it in the Hapee inbox and to send from your own address, and your calendar to read and create events. You can revoke access at any time from Hapee or from your Microsoft account
- Stripe — payment processing (subscriptions and purchases within forms)
- Twilio — sending and receiving SMS and voice calls
- Deepgram — speech-to-text conversion for AI agent calls and for the voice notes you receive via WhatsApp
- Groq — speech-to-text conversion (Whisper model) for voice notes, as an alternative to Deepgram. The audio is sent only to transcribe it and is not retained in their systems beyond that processing
- ElevenLabs — speech synthesis for AI agents and the voice assistant
- Meta (Facebook), Google and advertising platforms — only when you connect those accounts via OAuth to extract advertising metrics
- Meta Platforms (WhatsApp Business Platform) — sending and receiving WhatsApp messages when you connect a WhatsApp Business number to Hapee (see section 6)
- Google Firebase — social authentication (Google, Apple) and push notifications (FCM) in mobile applications
- Apple Inc. — Sign in with Apple in the iOS application
- Zoom Video Communications — creating and reading meetings, only when you connect your Zoom account so that appointments booked in Hapee generate their meeting link
- Cloudflare — publishing each customer's own domains. When a customer connects their own domain to Hapee, that domain is served through Cloudflare, which issues and renews its security certificate and acts as an intermediary between the site's visitors and our servers. For that reason Cloudflare processes those visitors' requests — including their IP address and the page content in transit — on our behalf. This is a different function from Cloudflare Turnstile, described below, which only takes part in forms
- Google reCAPTCHA, Cloudflare Turnstile and hCaptcha — protection against automated submissions in public forms, according to the provider the customer chooses for each form. They receive the IP address and browser signals of whoever completes the form, for the sole purpose of telling a person apart from an automated program
- Honeycomb — technical diagnostics of the automation engine (execution traces), only if that feature is enabled in the installation. Traces record which step ran and how long it took, not the content of messages
In addition, some pages load fonts and open-source libraries from content delivery networks (Google Fonts, jsDelivr and cdnjs). By the mere act of serving a file, those services receive the IP address of the browser requesting it. They do not process data on our behalf nor receive any data from your account, and for that reason they are not listed as processors; we state it because they are connections your browser makes.
We do not sell, rent or exchange personal data with third parties for advertising purposes.
5. LinkedIn integration (Community Management API)
This section specifically describes how Hapee uses LinkedIn's Community Management API when you link a LinkedIn company page or your personal LinkedIn profile to your Hapee account through the OAuth 2.0 authorization flow. Each integration is independent, optional, and is activated only when you — as an authorized administrator of the page, or as the owner of the personal profile — decide to connect it.
The Hapee integration enables two distinct scenarios: (a) managing the publication and performance of organic content on a company page (covered in sections 5.1 and 5.2), and (b) managing the publication of organic content on your personal profile (covered in section 5.3). The purposes, revocation and compliance guarantees in sections 5.4, 5.5 and 5.6 apply to both scenarios.
5.1 Data we access from your LinkedIn page
When you connect a LinkedIn company page, we access the following data from that page (not from your followers' personal profiles):
- Page information — name, identifier (URN), logo, description, industry, company size, website URL and total number of followers
- Existing posts — content, publication date, format (text, image, video, article, document, poll)
- Organic performance metrics — impressions, reach, clicks, reactions (likes, celebrate, support, love, insightful, funny), comments, shares and engagement rate for each post
- Aggregated demographics of followers and of the audience reached per post (industry, function, seniority, location, company size) — always in aggregated and anonymized form, never at an individual level
We do not access individual profiles of your followers, their personal contact data, the page's private messages (InMail), or the personal connections of the administrator who authorizes the integration.
5.2 Actions we perform on behalf of your page
The OAuth authorization allows us to perform the following actions, always initiated by you or an authorized member of your Hapee account:
- Publish organic content on behalf of the page: text posts, images, videos, articles, documents and polls. Each post is executed only when you schedule or approve it from Hapee's social media management module
- Schedule posts for specific dates and times
- Edit or delete posts created from Hapee
- Read organic statistics to show you the performance of your posts in the Reporting module
5.3 Connecting and posting to your personal LinkedIn profile
Additionally, Hapee allows you to connect your personal profile on LinkedIn via OAuth 2.0 to manage posts from the social media management module. This integration is independent from the company page connection: you may have one, the other, or both active.
Data we access from your personal profile:
- Basic information from your profile: name, identifier (URN), profile picture, professional headline and public profile URL
- Existing posts and metrics for posts created from Hapee: impressions, reactions, comments, shares and engagement rate
Actions we perform on your personal profile, always initiated by you:
- Publish organic content only on your own personal profile (that of the user authenticated via OAuth): text posts, images, videos, articles, documents and polls. Each post is executed only when you schedule or approve it from the social media management module
- Schedule posts for specific dates and times
- Edit or delete posts created from Hapee
- Read organic statistics for the posts you have created from Hapee
Explicit restrictions for personal profiles:
- We only publish on the personal profile of the user who authenticated via OAuth. We never publish, comment or react on third-party profiles under any circumstances
- We do not access your network of connections (1st, 2nd or 3rd degree), nor their personal data, nor do we send them messages
- We do not read private messages (InMail) or your inbox
- We do not perform automatic actions without your approval: Hapee never triggers posts, comments, reactions or connection requests autonomously. Each action requires an explicit operation initiated by you in the social media management module's interface
- We do not use your profile for engagement automation (automatic likes, automatic follows, profile scraping, mass cold messaging): these practices violate LinkedIn's terms and are not part of Hapee
5.4 Purpose of processing
Data obtained from LinkedIn is used exclusively to:
- Enable centralized management of organic content from the social media management module
- Generate organic performance reports for you and your team
- Schedule planned posts
We do not use this data to train artificial intelligence models, for advertising resale, for third-party profiling, or for any purpose unrelated to the direct operation of your account.
5.5 How to revoke LinkedIn access
You can revoke Hapee's access to your company page or your personal LinkedIn profile at any time, independently. These are the two ways:
- From Hapee: go to Settings → Integrations → LinkedIn and click "Disconnect" on the page or personal profile you want to unlink. Revocation is immediate
- From LinkedIn: go to Settings & Privacy → Data Privacy → Permitted Services at linkedin.com and remove Hapee's authorization
When you revoke access, we delete the session's OAuth tokens (page or personal profile) within a maximum of 24 hours and the cached data (metrics, aggregated demographics for pages, basic profile data and unpublished drafts) within a maximum of 90 days. Posts already sent to LinkedIn remain in your Hapee account as an audit record, associated with your history, but they can no longer be edited nor can updated statistics be read until you reconnect that page or profile.
5.6 Compliance with LinkedIn's policies
This integration complies with the LinkedIn API Terms of Use and the LinkedIn Privacy Policy. We do not retain, copy or distribute data derived from LinkedIn beyond what is strictly necessary to operate the service. We do not share data obtained from LinkedIn with third parties, not even in aggregated or anonymized form for commercial purposes.
6. WhatsApp Business integration (Meta Cloud API)
When you connect a WhatsApp Business number to Hapee, we process — on your behalf and on behalf of your sub-accounts, through the WhatsApp Business Platform (Meta Cloud API) — the data needed to manage your conversations. This integration is optional and is activated only when you, as an authorized administrator, connect the number.
6.1 Data we process
- Phone numbers of the contacts who write to you or whom you write to
- Profile name of the contact on WhatsApp
- Message content (text, images, audio, video, documents) sent and received, and its delivery status (sent, delivered, read)
6.2 Purpose of processing
- Manage and reply to conversations from Hapee's unified inbox
- Send message templates (previously approved by Meta) and notifications
- Automate workflows and, when you enable it, allow artificial intelligence agents to reply to messages
Messages may be processed by Anthropic (Claude) or OpenAI (GPT) — depending on the model you choose for your agent — to generate replies or analysis, and voice notes by Deepgram to transcribe them. We do not use the content of your WhatsApp messages to train artificial intelligence models, for advertising, or for any purpose unrelated to the direct operation of your account.
6.3 Storage, retention and deletion
WhatsApp messages are stored encrypted on AWS servers while the conversation is active and according to the retention period agreed with each customer. You can request their deletion by writing to info@hapee.ai or from hapee.ai/eliminacion-datos.
6.4 Compliance with Meta's policies
WhatsApp data is exchanged with Meta Platforms, Inc., provider of the WhatsApp Business Platform, for sending and receiving messages. We comply with the WhatsApp Business Platform Policies and we neither sell nor use this data for advertising purposes.
7. Integration with your mailbox and calendar (Google and Microsoft)
When you connect your Google account to Hapee, we process — on your behalf — the data needed for you to reply to emails and manage meetings from the platform. This integration is optional, is initiated by each user from their own profile, and you can revoke it at any time from Hapee or from your Google account's permissions page.
7.1 Permissions we request and what for
gmail.send— send emails from your mailbox when you reply to a contact from Hapee, so the recipient receives the message from your real address and can reply to you.calendar.events— create, update and cancel in your calendar the appointments booked from Hapee, including the Google Meet link, and detect the changes you make in Google so they are reflected in Hapee.calendar.readonly— list your calendars so you can choose which one Hapee writes to, and read your busy times so the booking page does not offer an already taken slot.openidandemail— identify the account that was connected and show which address emails are sent from.
We request the most restricted permission that enables each function. When a narrower alternative exists, we use it: that is why we request gmail.send, which only allows sending and does not grant access to read your email; and we do not request /auth/calendar, which would grant full control over all your calendars.
7.2 Limited Use of Google data
Hapee's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- We use Gmail and Calendar data solely to provide you with the functions described in 7.1, visible within the platform.
- We do not transfer this data to third parties, except (i) when necessary to provide and improve those functions, (ii) for security reasons, (iii) to comply with a legal obligation, or (iv) as part of a merger or acquisition, with prior notice and your consent.
- We do not use this data for advertising, for advertising profiling, nor do we sell or transfer it to data brokers.
- We do not use the content of your emails to train generalized or third-party artificial intelligence models.
- No human reads your emails, except (i) with your express consent for a specific case, (ii) for security reasons — for example, investigating abuse —, (iii) to comply with the law, or (iv) on aggregated and anonymized data for internal operations.
7.3 Artificial intelligence processing
If you enable the AI assistance features, the text of the email you are drafting or replying to may be processed by Anthropic (Claude) or OpenAI (GPT), depending on the model you choose, for the sole purpose of generating or improving that reply. These providers act as processors and do not use that content to train their models under the commercial terms we have with them. This feature is optional and is enabled per account.
7.4 Storage, retention and deletion
Access tokens are stored encrypted and are used only for the calls described. Emails displayed in a conversation are stored encrypted on AWS servers while the conversation is active and according to the retention period agreed with each customer. When you disconnect the account from your profile, we revoke the token and stop accessing your mailbox. You can request the deletion of data already stored by writing to info@hapee.ai or from hapee.ai/eliminacion-datos.
7.5 Microsoft integration (Outlook and Microsoft 365)
The Microsoft connection works the same way as Google's and with the same guarantees: it is optional, is initiated by each user from their own profile, and you can revoke it at any time from Hapee or from your Microsoft account's permissions page. The permissions we request are delegated — we always act on your behalf and with your authorization, never over the entire organization:
Mail.Send— send emails from your mailbox when you reply to a contact from Hapee, so the recipient receives the message from your real address and can reply to you.Mail.Read— read the emails in your mailbox to display your contacts' replies within the conversation in Hapee. Without this permission, replies would remain only in Outlook and the conversation history would be incomplete.Calendars.ReadWrite— create, update and cancel in your calendar the appointments booked from Hapee, and read your availability so busy slots are not offered. When you mark an appointment as an online meeting, this same permission generates the Microsoft Teams link.User.Read— identify the account that was connected and show which address emails are sent from.offline_access— keep the connection active without asking you to sign in on every synchronization.
We do not request administrator permissions nor access to the data of other people in your organization. Everything stated in sections 7.2, 7.3 and 7.4 — limited use, optional AI processing, encrypted storage, retention and deletion — applies in the same way to the data we receive from Microsoft: we do not use it for advertising or to train models, and no human reads your emails except in the cases listed there.
8. TikTok integration (business account and advertising)
When you connect a TikTok account to Hapee, we process — on your behalf and on behalf of your sub-accounts, through the official TikTok for Business APIs — the data needed to measure your presence, manage your comments and handle your messages. This integration is optional and is activated only when you, as the owner or authorized administrator of the account, connect it through TikTok's authorization (OAuth) flow. We only access the accounts that expressly authorize us, and only their own content.
8.1 Data we access from your TikTok account
- Profile of the connected account: identifier, display name, username, profile picture and aggregated follower and audience metrics
- Account posts (videos and photos): identifier, description, date, link and performance metrics — views, reach, likes, comments, shares and watch time
- Comments on the account's posts: comment text, date, status (visible or hidden) and, for the author, their unique TikTok identifier, username, display name and profile picture
- Direct messages of the business account, when the feature is enabled: content of messages sent and received (text and images), date and, for the participants, their unique identifier, display name and profile picture
- Advertising accounts, if you connect TikTok Ads: campaign metrics — impressions, clicks, spend and conversions — for your reports
We store the TikTok identifier of whoever comments or writes in order to recognize them as a single person: without it, someone who comments and later messages you privately would appear in your CRM as two separate contacts.
8.2 Actions we perform on behalf of your account
Always initiated or configured by you:
- Publish and schedule organic content on your own account
- Reply publicly to comments on your posts, including the automatic replies you configure by keyword
- Hide, unhide, delete or "like" comments on your own posts
- Send and receive direct messages from Hapee's unified inbox, replying to conversations the person started
We do not publish, comment or send messages on third-party accounts, nor do we perform any action you have not configured or requested.
8.3 Purpose of processing
- Display the performance of your account and your posts in Hapee's reports
- Centralize comments and direct messages in a single support inbox
- Run the automations you define — for example, replying to whoever comments a given word
- Record in your CRM the people who interact with your account, so your team can follow up with them
Comments and messages may be processed by Anthropic (Claude) or OpenAI (GPT) — depending on the model you choose for your agent — to generate replies or analysis. We do not use TikTok data to train artificial intelligence models, we do not sell it, we do not use it for our own advertising purposes, and we do not share it with third parties unrelated to providing the service.
8.4 Storage, retention and deletion
TikTok data is stored encrypted on AWS servers in the United States, together with the rest of your account's data, while the connection remains active and according to the retention period agreed with each customer. Access tokens are stored encrypted and are never exposed to the browser.
When you disconnect the account from Hapee, or revoke access from your TikTok account settings, we immediately stop accessing your data and delete the tokens. You can request the deletion of data already stored by writing to info@hapee.ai or from hapee.ai/eliminacion-datos.
8.5 Compliance with TikTok's policies
Data is exchanged with TikTok Pte. Ltd. and its affiliates, providers of the TikTok for Business APIs, solely for the purposes described. We comply with the TikTok Terms of Service, with the TikTok for Business developer terms and with their data use policies. We do not sell data obtained from TikTok nor use it for advertising unrelated to your own account.
9. Mobile applications (iOS and Android)
Hapee's mobile app is an integrated experience that loads the web platform inside a native container. It uses the following operating system permissions, when you authorize them:
- Push notifications — to notify you of new messages, assignments and relevant events
- Camera and photo gallery — only when you upload a profile picture, chat attachments or social media posts
- Microphone — only when you activate the assistant's hands-free voice mode
You can revoke any of these permissions at any time from your device's system settings.
10. Storage, security and retention
- Data is stored on AWS servers located primarily in United States regions. It may be transferred internationally in transit to the processors listed in section 4.
- Passwords are stored with a one-way bcrypt hash (never in plain text)
- OAuth tokens from advertising platforms are stored encrypted in the database
- Internal chat messages are stored with symmetric Fernet (AES-128 + HMAC) encryption
- Sessions are managed with secure cookies (HTTPS-only, SameSite Lax) and expire after 8 hours
- AI agent call recordings are automatically deleted after 90 days
- We keep your data while your account is active. After deletion, your identifiable personal data is anonymized or deleted within a maximum of 90 days, except when we must retain it due to a legal obligation (for example, tax records)
11. Your rights
As a data subject, you may exercise at any time the rights of:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Deletion — request the erasure of your account and associated data
- Objection — object to processing for marketing purposes
- Portability — receive your data in a structured, commonly used format
To exercise any of these rights, write to us at info@hapee.ai. We will respond within a maximum of 30 days. The application has a dedicated option to request the deletion of your account at hapee.ai/eliminacion-datos.
12. Minors
The platform is aimed at professionals and companies. We do not intentionally collect personal data from children under 13. If we become aware that a child under 13 has provided us with data without verifiable parental consent, we will delete that information. If you suspect this may have happened, contact us at info@hapee.ai.
13. Cookies and similar technologies
We use strictly necessary cookies to keep your session authenticated and remember preferences (language, theme). We do not use third-party advertising cookies or cross-site tracking networks.
14. Changes to this policy
We may update this policy to reflect legal, operational or functional changes. When changes are significant, we will notify you by email or through a prominent notice within the platform. The date at the top indicates the last revision.
15. Governing law
This policy is governed by Law 19.628 on the Protection of Private Life of the Republic of Chile, currently in force, and by Law 21.719 on the protection of personal data, which replaces it and comes fully into force in December 2026. From that date, and with respect to the data our customers entrust to us, Hapee acts as a processor and the customer as controller. All other relevant Chilean regulations also apply. Where applicable, we also respect the requirements of the European Union's General Data Protection Regulation (GDPR) for users residing in that territory.
16. Contact
For any query or complaint related to your privacy, you can write to us at info@hapee.ai or by postal mail to the address indicated in section 1.