This Privacy Policy describes how CHAARI SARL ("Chaari", "we", "us", or "our"), collects, processes, stores, shares, and protects personal data in connection with its cloud-based messaging infrastructure platform accessible at https://chaari.app (the "Platform").
Chaari operates as a Business-to-Business (B2B) and Business-to-Developer (B2D) cloud communication platform providing SMS routing, transactional messaging, and related services (collectively, "Services"). Our direct customers are companies and individuals ("Clients") who integrate our API to send SMS messages to their own end-users ("End Recipients").
This Policy applies to: (i) all Clients and their authorised users who register on the Platform; (ii) End Recipients whose phone numbers are processed through the Platform; (iii) visitors to our website.
1. DEFINITIONS
For the purposes of this Privacy Policy, the following terms shall have the meanings ascribed to them:
"Personal Data" means any information relating to an identified or identifiable natural person, including name, phone number, email address, IP address, identification documents, and billing information.
"Processing" means any operation or set of operations performed on Personal Data, whether automated or not, including collection, recording, organisation, storage, adaptation, use, transmission, and deletion.
"Data Controller" means CHAARI SARL, which determines the purposes and means of processing Personal Data of Clients and their authorised users.
"Data Processor" means CHAARI SARL acting on behalf of Clients when routing SMS messages to End Recipients.
"Client" means any legal entity or individual who creates an account on the Platform and uses the Chaari API to send messages.
"End Recipient" means the natural person who receives an SMS message transmitted through the Platform on behalf of a Client.
"Sub-processor" means any third-party service provider engaged by Chaari to process Personal Data in connection with the Services.
2. CATEGORIES OF PERSONAL DATA COLLECTED
2.1 Data Collected from Clients and Authorised Users
When a Client registers and uses the Platform, Chaari collects and processes the following categories of data:
Identity and Account Data
- Full name, job title, and function
- National Identity Card (NID) or Passport number and copy (for KYC compliance)
- For corporate entities: registration number and/or Tax Identification Number (TIN)
- Email address and phone number
Financial and Billing Data
- Billing address and payment method details
- Transaction records, invoices, and credit balance history
- Payment instrument data processed via our payment sub-processors
Technical and Usage Data
- API access keys and authentication tokens
- IP addresses and device information at login
- Connection logs, session timestamps, and access records
- API call logs, SMS delivery reports, and throughput statistics
- Dashboard activity and configuration settings
Communications Data
- Support tickets, correspondence, and chat messages submitted to Chaari
2.2 Data Processed on Behalf of Clients (End Recipients)
When Clients use the API to send SMS messages, Chaari processes as a Data Processor:
- Destination phone numbers of End Recipients
- SMS message content (OTP codes, alerts, promotional messages, transactional notifications)
- Message delivery status, timestamps, and routing metadata
Chaari does not own or control End Recipient data. Clients are responsible for ensuring they have the legal basis and consents required to process End Recipient data and to send messages to them. Chaari does not use End Recipient data for any purpose beyond the technical routing of the message.
2.3 Data Collected Automatically (Website and Dashboard)
- Cookies and session identifiers (see Section 7)
- Browser type, operating system, and referral URLs
- Analytics data (anonymised where possible)
3. LEGAL BASIS FOR PROCESSING
Chaari processes Personal Data on the following legal bases:
- Contract Performance: Processing is necessary to execute the subscription agreement and to provide the Services to Clients.
- Legal Obligation: Processing is required to comply with applicable Chadian law, telecom regulations, and financial regulations including KYC/AML obligations.
- Legitimate Interests: Processing for fraud prevention, security monitoring, and platform improvement, where Chaari's interests are not overridden by the data subject's rights and freedoms.
- Consent: For non-essential cookies and analytics tracking, where explicit consent is obtained via our cookie banner.
4. PURPOSES OF PROCESSING
Chaari processes Personal Data for the following specific, explicit, and legitimate purposes:
- Account creation, identity verification (KYC), and Client onboarding
- Authentication, access control, and API key management
- SMS message routing, delivery, and delivery status reporting
- Billing, invoicing, payment processing, and credit management
- Technical support and customer relationship management
- Fraud detection, abuse prevention, and platform security
- Service performance monitoring and improvement
- Legal defence and dispute resolution
- Sending service-related communications (not marketing without consent)
Personal Data will not be processed for purposes incompatible with those listed above without prior notification and, where required, consent.
5. DATA RETENTION
Personal Data shall not be retained beyond the period necessary for the purposes for which they were collected. Chaari applies the following retention schedule:
- SMS routing logs and delivery reports: 12 months from the date of transmission
- Client account data and KYC documents: Duration of the contract plus 3 years following termination
- Connection and API access logs: 12 months
- Support communications: 2 years from the date of resolution
- Cookie data: Duration as specified in the Cookie Policy (Section 7)
Upon expiry of the applicable retention period, Personal Data shall be securely deleted, anonymised, or archived in accordance with applicable legal requirements. Where retention is required for legal proceedings or regulatory investigations, data may be retained until the matter is resolved.
6. RIGHTS OF DATA SUBJECTS
Individuals whose Personal Data is processed by Chaari as Data Controller (i.e., Clients and their authorised users) have the following rights:
- Right of Access: The right to obtain confirmation of whether Personal Data about you is being processed and to receive a copy of that data.
- Right of Rectification: The right to request correction of inaccurate, incomplete, or outdated Personal Data.
- Right of Erasure/Deletion: The right to request deletion of Personal Data where it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.
- Right of Opposition: The right to object, on legitimate grounds, to the processing of Personal Data concerning you.
- Right to Information: The right to be informed of the characteristics of the processing at the time of data collection.
To exercise any of these rights, please send a written request to:
Email: aymar.a@chaari.app
Subject line: "[Data Subject Rights Request] – [Your Name]"
Chaari will respond to verified requests within one (1) month of receipt, in accordance with applicable law.
Note: Chaari acts as a Data Processor for End Recipient data. End Recipients wishing to exercise their rights regarding messages sent to them should contact the Client (sender) directly. Chaari will provide reasonable cooperation to assist Clients in fulfilling such requests.
7. COOKIES AND TRACKING TECHNOLOGIES
The Chaari Platform (https://chaari.app) uses cookies and similar tracking technologies. By using the Platform, you agree to our use of cookies as described below.
7.1 Types of Cookies Used
- Strictly Necessary Cookies: Essential for authentication, session management, API token handling, and security. These cannot be disabled and do not require consent.
- Analytics Cookies: Used to measure website and dashboard traffic, user behaviour, and feature usage. These are deployed with your consent and data is anonymised where possible.
7.2 Cookie Consent and Control
Upon first accessing the Platform, a cookie consent banner will be displayed. You may accept or decline analytics cookies. You can manage or withdraw your consent at any time through your account settings or browser settings. Withdrawing consent will not affect the lawfulness of processing based on consent before withdrawal.
7.3 Retention of Cookie Data
- Session cookies: Deleted when you close your browser
- Persistent authentication cookies: Up to 30 days
- Google Analytics cookies: Up to 26 months (subject to Google's retention policy)
8. DATA SECURITY
Chaari implements appropriate technical and organisational security measures to protect Personal Data against unauthorised access, accidental loss, destruction, or disclosure. These measures include:
- End-to-end encryption of data in transit using SSL/TLS protocols
- Encryption of data at rest using AES-256 on PostgreSQL databases
- Password hashing using industry-standard algorithms
- API access secured by unique, rotatable access tokens
- Optional two-factor authentication (2FA) for Client accounts
- Web Application Firewall (WAF) and DDoS protection
- Daily encrypted backups with restricted access
- Access control based on least-privilege principles, restricted to authorised personnel
- Signed confidentiality agreements with all personnel and sub-processors having access to Personal Data
In the event of a personal data breach, Chaari will notify affected Clients without undue delay, and no later than within a reasonable timeframe consistent with applicable law.
9. MINIMUM AGE AND DATA OF MINORS
The Chaari Platform is strictly intended for persons aged 18 years or older. By registering on the Platform, Clients represent and warrant that they are at least 18 years of age. Chaari does not knowingly collect Personal Data from individuals under 18 years of age for the purpose of account registration.
Clients may use the Chaari API to send SMS messages to End Recipients who are minors (e.g., school notification systems), provided that: (i) they have obtained all necessary parental or guardian consents required by applicable law; (ii) the content complies with Chaari's Acceptable Use Policy; and (iii) such use complies with all applicable laws protecting minors. Clients remain solely responsible for compliance when messaging minors.
If Chaari becomes aware that it has inadvertently collected Personal Data from a person under 18 for account registration purposes without parental consent, it will take immediate steps to delete such data.
10. CLIENTS AS INDEPENDENT DATA CONTROLLERS
When Clients use the Chaari API to send SMS messages to End Recipients, the Client is the Data Controller for the Personal Data of those End Recipients. Chaari acts solely as a Data Processor in this context, processing data only on the documented instructions of the Client.
Clients are solely responsible for:
- Obtaining valid consents or establishing a legal basis for processing End Recipient data
- Providing adequate privacy notices to End Recipients
- Ensuring that the content of messages complies with applicable law and Chaari's Acceptable Use Policy
- Responding to End Recipients' data subject rights requests
- Complying with local data protection laws applicable to the jurisdictions in which they operate
Chaari is not responsible for the compliance of its Clients with applicable data protection laws in their respective jurisdictions.
11. CHANGES TO THIS PRIVACY POLICY
Chaari reserves the right to update or modify this Privacy Policy at any time. In the event of material changes, Chaari will notify registered Clients by email and/or by a prominent notice on the Platform at least thirty (30) days before the changes take effect. The "Effective Date" at the top of this document will be updated accordingly.
Continued use of the Platform after the effective date of the revised Policy constitutes acceptance of the changes. If you do not agree with the revised Policy, you must cease using the Platform and request account deletion.