Last updated: July 2026

GDPR & Data Protection

This page explains how Barrq, operated by BARRQ AI, handles personal data under the EU General Data Protection Regulation and the UK GDPR. It sits alongside our Privacy Policy, which covers how we handle data generally; this page covers the specific roles, rights and safeguards the GDPR defines.

1. Who is the controller, and who is the processor

The distinction matters because it decides who owes which duties, and the answer differs depending on whose data it is.

  • For your customers’ data — the people messaging your business on WhatsApp — you are the controller and Barrq is the processor. You decide why and how that data is used; we process it on your documented instructions to deliver the features you switch on.
  • For your own account data — your name, email, billing details and how your team uses the product — Barrq is the controller.

2. Lawful bases we rely on

  • Performance of a contract: providing the platform you subscribed to, processing your messages, orders and automations.
  • Legitimate interests: securing the service, preventing fraud and abuse, and improving reliability, balanced against your rights.
  • Consent: where you opt in, for example to marketing email. You can withdraw it at any time without affecting your account.
  • Legal obligation: retaining records we are required by law to keep, such as tax and accounting records.

3. Your responsibilities as a controller

Barrq gives you the tools; the lawful basis for messaging your own customers is yours to hold. Before you message someone through Barrq you must have a valid basis to do so, and you must honour opt-outs.

This is not only a legal point. WhatsApp enforce their own consent and quality rules, and messaging people who did not ask to hear from you puts the number your business depends on at risk.

4. Data subject rights

The GDPR gives individuals the rights below. Where Barrq is the controller, contact us and we will act on your request. Where you are the controller and we are your processor, send the request to the business that holds the relationship, and we will support them in answering it.

  • Access: a copy of the personal data held about you.
  • Rectification: correction of data that is inaccurate or incomplete.
  • Erasure: deletion, where there is no overriding basis to keep it.
  • Restriction: limiting how data is used while a dispute is resolved.
  • Portability: your data in a structured, machine-readable format.
  • Objection: to processing based on legitimate interests, and to direct marketing at any time.
  • Withdrawal of consent: at any point, where consent was the basis.

5. Responding to requests

We answer verified requests within one month, as the GDPR requires, and will tell you if a complex request needs longer. We may need to verify your identity first — we will not hand personal data to somebody who simply asks for it.

6. Sub-processors

We use a small number of vendors to run the service: cloud hosting and databases, the official Meta messaging APIs for WhatsApp, our AI model provider, an email delivery provider, and a payment provider. Each is bound by a written agreement with confidentiality and security obligations no weaker than ours.

A current list of sub-processors is available on request, and we will tell you before adding one that processes customer data so you have the chance to object.

7. International transfers

Some of these providers operate outside the EEA and the UK. Where personal data is transferred, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, together with technical measures such as encryption in transit and at rest.

8. Data Processing Agreement

If you need a signed Data Processing Agreement, including the Standard Contractual Clauses, contact us and we will put one in place. For business customers in the EEA and the UK we consider this routine, not an exception.

9. Retention

We keep personal data only as long as it is needed for the purpose it was collected for, or as long as the law requires. Conversation and messaging data is retained while your workspace is active; when you close your account we delete or anonymise the data we no longer need, other than records we must keep for legal or accounting reasons.

10. Security

  • Encryption in transit (TLS) and at rest, with platform secrets and API credentials encrypted with dedicated keys.
  • Strict tenant isolation, so one workspace can never read another’s data.
  • Role-based access within your workspace, and audit logging of administrative actions.
  • Least-privilege internal access, granted only where it is needed to operate or support the service.

11. Personal data breaches

If a breach affecting personal data occurs, we notify the relevant supervisory authority within 72 hours where the GDPR requires it, and we notify affected customers without undue delay, with what we know and what we are doing about it.

12. Automated decision-making

Barrq’s agent generates replies and can suggest products or times, but it does not make decisions producing legal or similarly significant effects about an individual. Conversations can be escalated to a human at any point, and your team can take over any conversation.

13. Contact and complaints

For any data protection question, or to exercise a right, contact us at hello@barrq.co and mark it for the attention of the data protection team. You also have the right to complain to your local supervisory authority.

A note on this page

This is a good-faith summary written to be genuinely useful, not a legal opinion, and it is not a substitute for advice from qualified counsel about your own obligations.