Rudood by Calycks
Privacy Policy
Last updated: 25 July 2026
Who we are
Rudood is a business operations and customer-messaging platform by Calycks Websites Ltd. Its primary services are a shared business inbox, CRM, orders, bookings, and human-support workflows connected to WhatsApp, Facebook Messenger, and Instagram where available. Optional AI assistance is an ancillary feature; Rudood does not offer a general-purpose AI assistant through WhatsApp.
Rudood is operated by Calycks Websites Ltd (company number 17192351), 128 City Road, London, EC1V 2NX, United Kingdom. Email: info@calycks.co.uk. Phone: +447348954869.
Our roles and how data reaches Rudood
The connected business generally determines why and how its customer conversations are handled and is responsible for its customer notice, lawful basis, consent, and messaging permissions. Calycks Websites Ltd processes that data as the business's technology provider and service provider, only for that business's requested service. Calycks separately determines how Rudood account, billing, security, abuse-prevention, and legal compliance data is processed.
Data reaches Rudood when an authorised business user enters or uploads it, connects a business-owned channel through Meta OAuth or Embedded Signup, or when official Meta Graph APIs, the WhatsApp Cloud API, and signed webhook events deliver authorised messages and channel events. Rudood also creates service, security, and audit logs needed to operate and protect the platform.
Data we process
We process account details, business profile data, bot settings, connected channel identifiers, Meta Page IDs, Instagram business account IDs, scoped user IDs, access tokens, webhook subscription status, conversations, messages, attachments, media metadata, orders, bookings, payment status or references, notes, operational logs, and usage data needed to provide the service. Rudood does not require or store full payment-card or bank account numbers in customer conversations.
Rudood acts as a technology provider for business-owned Meta assets that the account owner chooses to connect. We do not request access to personal inboxes, and we only use connected business data to provide the inbox, AI reply, human handoff, order, booking, and CRM service for that business.
How we use data
We use data to operate Rudood, receive and display messages, send replies requested by the account owner, manage orders and bookings, provide support, prevent abuse, improve configuration, and comply with platform or legal requests.
We do not sell user data and we do not use Meta message data for advertising outside the service.
Depending on the context and applicable law, processing is based on performance of the service contract, the connected business's documented instructions, legitimate interests in operating and securing Rudood, consent where required, and compliance with legal obligations.
AI and subprocessors
When the bot is enabled, relevant conversation snippets, business settings, knowledge content, and CRM context may be sent to AI subprocessors such as OpenRouter and model providers available through it, including Google/Vertex AI, only to generate replies, summaries, classifications, or next-step suggestions. The data is processed to provide the service; it is not accurate to say no data is processed.
WhatsApp Business Solution Data is not used to create, train, or improve shared or general-purpose AI models. AI subprocessors receive it only as service providers acting on the connected business's instructions for the requested inference. Rudood restricts AI routing to providers that do not collect the request data.
Contracted infrastructure, hosting, database, authentication, storage, email, security, support, and AI providers may process only the data needed for their service. They must process it under written terms, protect it, and delete it when no longer required. A current service-provider list and supporting data-processing information can be requested from info@calycks.co.uk.
Meta channels and messaging rules
For Messenger and Instagram, Rudood is designed to send customer replies only inside the permitted response window. Rudood does not provide bulk or broadcast messaging for Meta channels and does not send marketing messages outside Meta rules. Connected channels can be disconnected from Settings.
At the start of an automated experience, after a significant lapse, or when a conversation returns from human handling to automation, a short message names Rudood and identifies it as the business's AI assistant. The message does not prompt the customer to request a human, but prompt human escalation remains available when requested and through the connected business's published support details.
WhatsApp status
Rudood's production WhatsApp integration uses the official WhatsApp Cloud API and Meta Embedded Signup. The business owns its WABA and phone number and adds its own payment method in Meta; Rudood receives only the permissions needed to operate the channel. The production connection does not depend on a QR session or an unofficial WhatsApp transport.
Free-form replies are sent only inside the permitted customer-service window. Approved templates are required where applicable outside that window, and opt-out requests are honored. Inbound WhatsApp media is retrieved from Meta on demand for display or processing and is not permanently written to the Rudood server filesystem merely to render it in the inbox.
WhatsApp automation is optional and supports the inbox, CRM, order, booking, and human-support service. It is not a general-purpose AI product. An automated reply is identified in the conversation, and the customer can request a human or stop automation at any time.
Security and international transfers
We use access controls, tenant-level data boundaries, encryption in transit, restricted production access, audit logging, and backups appropriate to the service. No method of transmission or storage is completely secure.
Some contracted providers may process data outside the United Kingdom. Where required, we use an adequacy decision, the UK International Data Transfer Agreement or Addendum, Standard Contractual Clauses, or another lawful transfer safeguard.
Retention and deletion
We retain account, conversation, CRM, order, and booking data while the relevant account or connected service is active and only as long as it remains necessary for the purposes described above. Access tokens are removed promptly when a channel is disconnected. Backup copies are isolated from normal use and removed under the applicable backup rotation schedule.
After a verified deletion request, we promptly disconnect applicable access and delete or place the relevant data into a documented review without undue delay, with completion no later than 30 days unless a longer legal, security, fraud-prevention, or accounting duty requires limited retention. Retained data is restricted to that purpose and deleted when the duty ends. Request deletion on the data deletion page or email info@calycks.co.uk.
Your rights and contact
Subject to applicable law, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. These rights are available to all Rudood users, including people whose messages are processed for a connected business. We may need to verify your identity or your authority over the relevant business asset before acting.
Email info@calycks.co.uk. You may also complain to the UK Information Commissioner's Office at ico.org.uk. General Calycks processing information is available in the Calycks Privacy Policy.