Compliance

Data retention

What Callduck stores, retention considerations, and handling export/deletion requests.

Data retention

This page is practical guidance, not legal advice. It explains what Callduck stores and how to handle privacy obligations under laws like Saudi PDPL and GDPR-style regimes. Confirm specifics with your own counsel.

What Callduck stores

  • Messages — inbound and outbound message content and delivery status
  • Contacts — names, phone numbers, and CRM fields
  • Consent — opt-in/opt-out status with ConsentLog and OptOutLog history
  • Audit — who did what (campaigns sent, templates submitted, settings changed)

Retention considerations

  • Keep personal data only as long as you have a lawful basis and an operational need.
  • Consent and opt-out records are worth retaining longer — they are your proof you respected a customer's choice.
  • Define a retention period per data type and document it in your privacy policy.

Export & deletion requests

  • Export — Callduck can export a contact's data so you can fulfil an access request.
  • Deletion — handle "right to be forgotten" requests by removing the contact and their data; weigh this against records you must keep for legal/consent reasons.
  • Log how and when each request was handled.

Alignment with privacy law

> You are the data controller. Callduck provides the tools — consent tracking, audit logs, export and deletion — but compliance with Saudi PDPL, GDPR-style rules, and the WhatsApp Business Messaging Policy is your responsibility. This is guidance only.

تذكير: تبدأ كال داك في الوضع التجريبي الذي لا يرسل رسائل حقيقية. اربط بيانات اعتماد منصة واتساب للأعمال الرسمية الخاصة بك للانتقال إلى التشغيل الفعلي.

نبي نقيس أي الصفحات تفيد الناس. ما فيه كوكيز إعلانات، ولا بيع بيانات، ولا شي مربوط بهويتك. سياسة الخصوصية