Privacy Policy
Last updated: 28 July 2026
This policy explains what personal data Tola collects, why we collect it, who we share it with, and the choices and rights you have. It covers both the data we decide the purposes of, and the data we handle on behalf of our customers.
1. Introduction and scope
This Privacy Policy explains how Tola, Inc. (“Tola”, “we”, “us”) handles personal data. It covers our website, our marketing activities, and the Tola platform (the “Service”).
Tola is an AI-powered customer communication platform. Our customers — typically businesses — connect channels such as WhatsApp and email, and use Tola to receive, assign, automate and reply to conversations with the people who contact them.
This policy does not cover the privacy practices of our customers. If you contacted a business that uses Tola and want to know how that business handles your data, contact the business directly.
2. Our role: controller and processor
We act in two different capacities, and your rights differ depending on which applies.
- As a controller, for data we decide the purposes of: website visitors, marketing contacts, prospects, and the account and billing data of our customers' administrators and users.
- As a processor, for data our customers place in the Service: the content of conversations, contact records, attachments and related metadata. Our customer is the controller of that data, and we process it on their documented instructions under a Data Processing Addendum.
Where we act as a processor and you are an individual whose data was uploaded by a customer, please direct requests to that customer. We will assist them in responding.
3. Personal data we collect
Data you provide directly:
- Account data: name, work email, password hash, job title, company name, and profile photo where supplied.
- Billing data: billing contact, address, tax identifiers, and the last four digits and expiry of a payment card. Full card numbers are handled by our payment processor and are not stored by Tola.
- Support and sales data: the content of enquiries, demo requests, newsletter sign-ups, and correspondence with our team.
Data generated by use of the Service:
- Conversation data: message content, attachments, timestamps, sender and recipient identifiers, assignment and status history, internal notes, tags, and templates.
- Usage data: features used, actions taken, pages viewed, session duration, and performance and error telemetry.
- Device and connection data: IP address, browser and operating system, device type, approximate location derived from IP, and cookie identifiers.
Data from third parties:
- Channel providers, such as the WhatsApp Business Platform and email providers, which pass us the messages and metadata required to deliver the Service.
- Integration partners you connect, limited to the scopes you authorise.
- Identity providers where you sign in via single sign-on.
- Publicly available business sources used for prospecting, where permitted by law.
4. How and why we use personal data
Where we act as a controller, we rely on the following purposes and legal bases under the UK GDPR and EU GDPR:
- To provide, operate and support the Service — performance of a contract.
- To bill for the Service and collect payment — performance of a contract.
- To secure the Service, detect abuse and prevent fraud — legitimate interests in protecting our platform and users.
- To improve and develop features, including through aggregated and de-identified analysis — legitimate interests in improving our product.
- To send service announcements and operational notices — performance of a contract or legitimate interests.
- To send marketing communications about Tola — consent, or legitimate interests in the case of existing business customers, with an opt-out in every message.
- To comply with legal obligations, respond to lawful requests and establish or defend legal claims — legal obligation or legitimate interests.
Where we act as a processor, we use conversation data only to deliver the Service to our customer, to keep it secure, and as otherwise instructed by them in writing.
5. AI processing
Some features use machine learning to summarise threads, suggest replies, classify intent, route conversations and draft content.
We do not use customer conversation data to train foundation models that are made available to other customers. Where we use third-party model providers to deliver AI features, we contract for equivalent restrictions, including that data submitted through our account is not used to train their general models.
Model providers may retain input and output for a limited period for abuse monitoring, as set out in our sub-processor list.
AI output is generated probabilistically and may be inaccurate. Customers are responsible for human review before relying on or sending output, and for not using AI features to make decisions with legal or similarly significant effects without meaningful human oversight.
6. Sharing and disclosure
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
We disclose personal data to:
- Sub-processors that host, secure, analyse or support the Service, under written contracts imposing equivalent protection. Our current list is at [link to sub-processor list].
- Channel and integration providers, to the extent needed to deliver messages you have chosen to send.
- Professional advisers, auditors and insurers, under duties of confidentiality.
- Authorities and other parties where required by law, or where necessary to establish, exercise or defend legal claims. Where lawful, we will notify the affected customer before disclosing their data.
- An acquirer, in connection with a merger, acquisition, financing or sale of assets, subject to this policy continuing to apply.
7. International transfers
We are based in [country] and use sub-processors in other countries, including the United States. Transfers out of the UK and the EEA are made under an approved transfer mechanism — typically the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer risk assessment and, where appropriate, supplementary technical measures such as encryption in transit and at rest.
Customers on eligible plans may request data residency in [region]. Contact us for the current options.
8. Retention
Where we act as a processor, we retain conversation data for as long as the customer's subscription is active and for [30] days after termination, after which it is deleted in the ordinary course. Customers can configure shorter retention for message content in-product.
Where we act as a controller, we retain:
- account and billing records for the life of the account and then for [7] years, to meet tax and accounting obligations;
- marketing contact data until you opt out, or after [24] months of inactivity;
- security and audit logs for [12] months;
- support correspondence for [24] months.
Backups are held on a rolling cycle and are overwritten within [35] days. Data may persist in backups for a short period after deletion from live systems.
9. Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2 or above) and at rest, role-based access control, least-privilege administrative access, multi-factor authentication for staff, network segregation, centralised logging, dependency and vulnerability scanning, and periodic penetration testing.
We operate an incident response process and will notify affected customers without undue delay after becoming aware of a personal data breach affecting their data, with the information they need to meet their own notification obligations.
No system is completely secure. You are responsible for keeping credentials confidential and for configuring access within your own account appropriately.
10. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and receive a copy;
- have inaccurate data corrected;
- have data erased in certain circumstances;
- restrict or object to processing, including objecting to direct marketing at any time;
- receive data in a portable format, and have it transmitted to another controller where technically feasible;
- withdraw consent, without affecting processing already carried out;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
If you are a California resident, you may also request disclosure of the categories and specific pieces of personal information collected, request deletion or correction, and opt out of sale or sharing — we do not sell or share as those terms are defined. We will not discriminate against you for exercising these rights, and you may use an authorised agent.
To exercise a right, contact [privacy@tola.example]. We will verify your identity and respond within the period required by law — generally one month under the GDPR and 45 days under the CCPA. You also have the right to complain to your local supervisory authority; in the UK this is the Information Commissioner's Office.
11. Cookies and similar technologies
Our website uses cookies that are strictly necessary for it to function, and — with your consent where required — analytics cookies that help us understand how the site is used.
The Service itself uses strictly necessary cookies for authentication, session management and security. These cannot be disabled without preventing the Service from working.
You can manage non-essential cookies through our cookie banner or your browser settings. Blocking cookies may affect site functionality.
12. Children
The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact [privacy@tola.example] and we will delete it.
13. Changes to this policy
We may update this policy to reflect changes to the Service, our practices, or the law. We will update the “last updated” date above, and for material changes we will give notice by email or in-product before they take effect.
Previous versions are available on request.
14. Contact us
For privacy questions or to exercise a right, contact [privacy@tola.example], or write to Tola, Inc., [registered address], marked for the attention of the Data Protection Officer.
Our EU/UK representative under Article 27, where applicable, is [representative name and address].