Legal

Privacy Policy

Last updated: May 2026

1. Who we are

Client Recovery ("we", "us", "our") is a SaaS platform that helps service businesses recover inactive clients through AI-generated outreach. Our registered contact email is daniel.tarasescu@gmail.com.

2. What data we collect

We collect and process the following categories of personal data:

  • Account data: your name, email address, and password (stored as a hash) when you register.
  • Business profile: business name, industry, description, address, and payment method preference you enter in Business Settings.
  • Client records: names, phone numbers, email addresses, visit dates, and service history you upload or enter. This data belongs to your clients and is processed on your behalf.
  • Message history: records of AI-generated messages and sends for audit and history purposes.
  • WhatsApp session: session credentials stored server-side to maintain your connection. These are never shared and are deleted when you disconnect.
  • Usage data: anonymous page views, feature usage counts, and error logs used to improve the platform.

3. How we use your data

  • To provide and operate the platform (contract performance).
  • To generate AI messages on your behalf using your client data as context.
  • To enforce plan quotas and billing (legitimate interest).
  • To send you transactional emails (password resets, confirmations).
  • To comply with legal obligations.

We do not use your client data to train AI models, sell data to third parties, or use it for advertising.

4. Data storage and security

All data is stored in Supabase (PostgreSQL) with row-level security policies that ensure each account can only access its own data. Data is encrypted at rest and in transit (TLS 1.2+). Access to production systems is restricted to authorised personnel only.

5. Third-party services

We use the following sub-processors:

  • Supabase — database and authentication (EU region available).
  • OpenAI / OpenRouter / Groq / Cerebras / Mistral — AI message generation. Your client data is sent as prompt context. These providers do not use API inputs to train models.
  • Stripe — payment processing (if applicable). We never store card numbers.
  • SMTP provider — transactional email delivery.

6. Your rights (GDPR)

If you are in the European Economic Area, you have the right to:

  • Access — request a copy of your personal data.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion of your account and all associated data.
  • Portability — export your client data as CSV at any time from the platform.
  • Objection — object to processing based on legitimate interest.

To exercise any of these rights, email us at daniel.tarasescu@gmail.com. We will respond within 30 days.

7. Cookies and local storage

We use browser localStorage to store your authentication session token (required for login) and your language preference. We do not use third-party tracking or advertising cookies. No cookie consent banner is required for strictly necessary storage.

8. Data retention

We retain your data for as long as your account is active. When you delete your account, all personal data is permanently deleted within 30 days. Message history exports and backup snapshots are purged on the same schedule.

9. Changes to this policy

We may update this policy as the platform evolves. Material changes will be communicated by email. The "Last updated" date at the top of this page reflects the most recent revision.

10. Contact

For privacy questions or data requests: daniel.tarasescu@gmail.com