Privacy Policy
Version 2026-10-08 · in effect from 8 October 2026
The short version
- For the people who use Teamline at our customers (account owners and team members), we collect what we need to run the account: name, email, sign-in and activity records, and billing details.
- The messages, contacts, leads and emails a business keeps in Teamline belong to that business. We only process them on its instructions. If you are one of its customers, that business is responsible for your data: contact it first.
- We don't sell personal data, we don't show ads, and we don't use advertising or analytics trackers.
- Our main providers are Google (hosting, database, sign-in, AI). Data may be processed in the United States, Qatar and other countries where they operate.
1. Who we are
Andybot (Dubai, United Arab Emirates) provides Teamline. For privacy questions or requests, write to info@andybot.net.
2. Two different roles
- We are the controller of the personal data described in section 3: data about our customers' account owners and team members, people who contact us, and visitors to our website. This policy explains how we use it.
- We are a processor for “Customer Data”: the WhatsApp chats, messages, contacts, leads, emails, files and AI conversations that our business customers keep in Teamline. Each customer decides why and how that data is used, and is the controller. We process it only to provide the service, under our Data Processing Agreement. If you are one of our customer's own customers or contacts, please read that business's privacy notice and contact it directly. If you contact us instead, we will pass your request to the business where we can identify it.
3. What we collect (as controller) and why
| Data | Why we use it | Legal basis |
|---|---|---|
| Account details: name, work email, company name, role and permissions, password (stored only in scrambled “hashed” form by our sign-in provider). | To create and run the account, sign you in, control who can do what. | Performance of our contract with the customer; our legitimate interest in running the service for the people the customer adds. |
| Activity records: which User sent which message, who opened which WhatsApp number, whether a User is active or away, last activity time, notification settings and device push subscriptions (a browser address and the browser type). | To show your team who did what, route notifications, keep the service working and secure. | Contract; legitimate interests (security, the team features the customer asked for). |
| Acceptance records: which version of our terms was accepted, when, by which account, and the IP address used. | To prove what was agreed. | Legitimate interest in proving our contracts; legal obligations. |
| Billing details: plan, prices, payments received, invoices, and the company's billing contact. | To charge for the service and keep accounts. | Contract; legal obligations (tax and accounting). |
| Support and messages to us: what you write to us and our replies. | To answer you and improve the service. | Legitimate interests; contract. |
| Technical data: IP address, browser and device type, time of requests, error logs. IP addresses are used briefly for limits that stop abuse (for example too many sign-ups); for those limits we store only a scrambled form. | To deliver pages, prevent abuse and fraud, and fix problems. | Legitimate interests (security, keeping the service working). |
| Usage statistics: counts such as messages sent, AI requests and storage used per company. | To apply plan limits, bill correctly and plan capacity. | Contract; legitimate interests. |
We do not use your personal data to make decisions about you by automated means that have legal or similarly significant effects. We do not sell or rent personal data, and we do not use it for advertising.
4. Who we share it with
- Our service providers, who process data for us under contract: see our list of sub-processors. The main one is Google (Google Cloud and Firebase for hosting, database, file storage, sign-in and server functions). AI features use a third-party AI provider.
- Browser push services (run by the maker of your browser, such as Google, Apple or Mozilla) deliver notifications you switch on. Notification content is encrypted end-to-end between our servers and your browser.
- Services you connect, such as WhatsApp (Meta) and your email provider, receive what is needed to send and receive your messages. They are not our providers; their own privacy policies apply.
- Professional advisers (lawyers, accountants, auditors) under confidentiality.
- Authorities when the law requires it, or to protect rights, safety and property. We check that requests are lawful and disclose no more than necessary.
- A buyer or successor if all or part of our business is sold or reorganised, under the same protections.
5. Where data is processed
Data is stored and processed on Google's infrastructure, in Qatar (Doha) (database, files and the WhatsApp connection server) and the United States (server functions), and may be handled in other countries where our providers operate. Where a law requires safeguards for transfers abroad, we rely on our providers' data processing terms and the other legal grounds the law allows.
6. How long we keep it
| Data | How long |
|---|---|
| Account details and activity records | While the account is active, then deleted within 30 days after the export period that follows the end of the contract. |
| Customer Data (processor role) | As the customer decides while the account is active; after the contract ends, as described in the Data Processing Agreement. |
| Billing and invoices | As long as tax and accounting laws require (in the UAE, generally 5 to 7 years). |
| Acceptance records | For the life of the contract plus the period in which claims can be made. |
| Support conversations | Up to 2 years after the last message, unless needed longer for a dispute. |
| Technical logs | Usually up to 30 days; abuse-prevention counters for up to a day. |
7. Security
We protect data with access controls that keep each company's data separate, encryption in transit (HTTPS/TLS) and at rest, least-privilege access for our staff, and security reviews and testing. Mailbox app passwords are kept in a separate store that no dashboard user can read. No system is perfectly secure; if a breach affects your personal data we will notify you and the authorities as the law requires. More detail is in Annex 2 of the Data Processing Agreement.
8. Your rights
Depending on the law that applies to you (for example UAE Federal Decree-Law No. 45 of 2021 or the Saudi Personal Data Protection Law), you may have the right to:
- know whether we process your data and get a copy;
- have inaccurate data corrected;
- have data deleted, or its use restricted;
- object to processing based on our legitimate interests;
- receive your data in a portable format;
- withdraw consent, where we rely on consent;
- not be discriminated against for using your rights;
- complain to a data protection authority (in the UAE, the UAE Data Office).
To use a right, write to info@andybot.net. We may need to confirm your identity. We answer within 30 days (or the shorter period the law sets), and tell you if we need more time. If your request concerns Customer Data, we will refer you to, or help, the business that controls it.
9. Cookies and storage in your browser
Teamline does not use advertising or analytics cookies, and loads no third-party trackers. The app stores only what it needs to work, in your browser:
| What | Purpose | How long |
|---|---|---|
| Sign-in session (stored by Firebase Authentication in your browser's storage) | Keeps you signed in so the app works. | Until you sign out. |
| Small preference settings (for example whether the menu is collapsed, recent emojis, notification prompt timing, writing-assistant preferences, whether you were signed in, to show the right loading screen) | Remember choices you made in the app. | Until you clear them or sign out. |
| Offline copy of the app (service worker cache) | Opens the app quickly and lets it install on your phone or computer. | Replaced on each update. |
| Push subscription (only if you turn notifications on) | Delivers notifications to this device. | Until you turn notifications off. |
These are strictly necessary for the service you asked for, so we do not ask for consent; you can clear them at any time in your browser settings, but the app will then sign you out. Our pages, code and fonts are served from our own website; we do not load fonts or scripts from third-party content networks.
10. Children
Teamline is for businesses and is not meant for anyone under 18. We do not knowingly collect children's data as controller. If you believe a child has given us data, tell us and we will delete it.
11. Changes
We may update this policy. We will post the new version here with its date and, for important changes, tell account owners by email or in the dashboard.
12. Contact
Andybot, Dubai, United Arab Emirates · info@andybot.net
Teamline