Peekly
← BackVersion: 1.1
Effective Date: June 2025
Peekly is a sub-product of Tiltely LLC ("Peekly", "we", "us", or "our"), a company registered in Wyoming, USA. Peekly provides chatbot services to businesses, allowing them to integrate intelligent automated support and interaction on their websites and third-party messaging platforms, including WhatsApp. This Privacy Policy outlines how we collect, use, protect, and share personal data through Peekly's services, including how we comply with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable data protection laws.
Peekly collects personal data as described below, including data provided by End Users interacting with the chatbot and data collected for our own internal purposes (e.g., service improvement). By interacting with our service, you acknowledge and consent to the collection and processing of your personal data as described in this Privacy Policy.
Peekly provides the underlying infrastructure but does not control what data Clients choose to collect. Peekly disclaims responsibility for any data voluntarily provided by End Users in violation of applicable laws or Client's stated policies.
Peekly is committed to safeguarding personal data and ensuring transparency in our data processing practices. This policy applies to personal data processed by Peekly on behalf of business clients ("Clients") and, where applicable, directly from users who interact with Peekly ("End Users"), whether through website chat widgets or third-party messaging platforms such as WhatsApp.
Data Roles:
Peekly does not independently verify or monitor the legality, accuracy, or appropriateness of the data entered by End Users during interactions. All data collection is governed by the Client's configuration and intended use and therefore the Client's sole responsibility.
Peekly may process the following categories of data, including but not limited to:
From End Users (via Client websites and messaging platforms):
From Clients (business customers):
Peekly does not engage in automated decision-making that produces legal or similarly significant effects on individuals.
We process personal data:
When End Users interact with the Peekly chatbot, their input messages may be sent to third-party service providers, including OpenAI, for AI-powered response generation. When End Users interact via WhatsApp, messages are sent and received through Meta's WhatsApp Business Platform (WhatsApp Cloud API). This processing is necessary to provide, maintain, and optimize the chatbot service. We do not use End User data for marketing or unrelated profiling. Certain data, such as chatbot inputs, are necessary to provide the service. If you do not provide this data, we may be unable to fulfill your request.
We process personal data in accordance with Article 6 of the General Data Protection Regulation (GDPR), and we disclose the specific legal basis applicable to each processing purpose:
Contractual Necessity: We process personal data when it is necessary to perform our obligations under a contract. This includes:
Legitimate Interests: We process certain personal data to pursue our legitimate interests, provided that these interests are not overridden by your fundamental rights and freedoms. These legitimate interests include:
We do not rely on legitimate interests where data subjects would reasonably expect a different level of protection or where the processing involves sensitive data. To withdraw consent, End Users may contact us at contact@tiltely.com, or where applicable, use the chatbot interface or account portal to manage preferences.
Consent: Where required by law, we rely on your consent to process personal data. This applies to:
Consent is obtained explicitly and may be withdrawn at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Legal Obligation: In limited cases, we may process personal data as necessary to comply with our legal obligations, such as responding to lawful requests from public authorities or complying with applicable financial or regulatory requirements.
Where we act as a Data Processor on behalf of a Client, we rely on the Client to determine the appropriate lawful basis for processing End User data. As such, the Client remains responsible for ensuring that all data collected through their use of Peekly complies with the applicable legal bases under the GDPR or other relevant data protection laws.
Where Peekly is a Controller, we rely on:
As a Processor, we only process data on the documented instructions of our Clients.
Peekly has conducted a Legitimate Interests Assessment (LIA) for applicable processing activities and determined that such processing does not override the data subject's rights or reasonable expectations.
Peekly provides chatbot infrastructure as a Data Processor, but Clients are ultimately responsible for how personal data is collected and used on their websites and connected messaging platforms. When using Peekly, Clients must:
Clients are considered the Data Controllers for all data collected through their websites, messaging platform integrations, and chatbot experiences. Peekly processes data only under the Client's documented instructions. Peekly shall not be considered a Joint Controller for any data collected, stored, or processed through chatbot configurations defined solely by the Client.
Peekly disclaims any liability arising from a Client's failure to fulfill these responsibilities. In the event of a privacy dispute between a Client and an End User, the Client assumes full responsibility as the Data Controller.
Peekly may share personal data with third-party service providers strictly for operational and support purposes. These subprocessors act only on Peekly's documented instructions and do not use the data for their own purposes. The categories and purposes include:
All such subprocessors are bound by contractual safeguards as outlined in the Peekly Data Processing Addendum (DPA), which is incorporated by reference.
Peekly may also share data with:
We do not sell personal data. Peekly and Tiltely disclaim responsibility for the actions, security practices, or failures of third-party subprocessors beyond their contractual and legal obligations. Clients are responsible for reviewing and accepting the use of these subprocessors before engaging Peekly's services.
End User data is retained for up to 12 months after last interaction, unless configured differently by the Client. The default is 90 days. Peekly retains certain logs, such as access and modification, including chatbot interaction timestamps, API access events, and administrative actions, for up to 5 years for auditing and regulatory compliance. Logs are stored securely and accessible only by authorized personnel.
Clients may request deletion of data at any time by contacting us at contact@tiltely.com.
The following table summarizes the key data retention periods applied by Peekly in accordance with Article 5(1)(e) of the GDPR:
| Data Type | Retention Duration | Deletion or Expiry Criteria |
|---|---|---|
| Consent Records | 5 years | Consent withdrawn or expired |
| Chat History | Up to 12 months | After 1 year, or earlier upon user request |
| Backups with user data | Up to 6 months | Auto-deleted on schedule (rolling purge) |
| Access Logs | 5 years | Policy-based removal |
| Processing Logs | 2 years | Retained for accountability; not auto-deleted |
| Subprocessor Contracts | Contract duration + 5 years | Deleted after contract end |
| Erasure Request Logs | 5 years (meta only) | Never (no personal data stored) |
| Export Copies | 1 year | Deleted after access is fulfilled |
As a U.S.-based company, Peekly may transfer personal data to the United States and other countries where we or our subprocessors operate. Peekly uses the European Commission's Standard Contractual Clauses (SCCs) 2021/914/EU as the basis for data transfers to subprocessors outside the EEA. Peekly and Tiltely shall not be held liable for data protection failures caused by foreign subprocessors acting beyond our oversight or control, provided such subprocessors were properly vetted and disclosed.
If Peekly is acting as a Processor, please contact the website or business (the Controller) to exercise your rights.
If we are the Controller, you have the right to:
You can contact us at contact@tiltely.com to exercise your rights.
Peekly retains anonymized metadata (e.g., timestamps, request type) of user rights requests for up to 5 years to demonstrate compliance under GDPR Article 30.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority. EU users may lodge complaints through https://edpb.europa.eu/about-edpb/board/members_en
Residents of certain U.S. states, including California, may have rights regarding their personal data under state-specific privacy laws such as the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and similar laws in other jurisdictions.
These rights may include:
If Peekly is acting as a Data Processor, End Users must contact the business or website where they interacted with the Peekly chatbot (the Data Controller) to exercise these rights.
If Peekly is acting as the Data Controller, you may contact us at contact@tiltely.com. We will verify your identity before fulfilling any requests.
Peekly follows industry-standard security practices. However, by using Peekly, Clients and End Users acknowledge that no platform can guarantee absolute security and agree not to hold Peekly or Tiltely liable for security breaches beyond Peekly's direct control. Peekly and Tiltely shall not be held liable for any unauthorized access, data loss, or data breach resulting from external cyberattacks, hacking attempts, or other malicious actions beyond our reasonable control. Peekly's obligation is limited to notifying the Client. The Client remains responsible for fulfilling any End User notifications or regulatory filings required under applicable laws.
In the event of a personal data breach, we will notify affected individuals and relevant authorities in accordance with applicable data protection laws, where Peekly acts as the Controller.
Peekly uses trusted third parties to process data securely on our behalf. A full list of subprocessors is included in the Peekly Data Processing Addendum (DPA) and is updated regularly.
Peekly does not knowingly collect data from children under 13. It is the Client's responsibility to ensure Peekly is not deployed on websites or messaging platforms targeting children or collecting data from minors in violation of applicable laws.
Clients are responsible for reviewing this Privacy Policy regularly. Continued use of Peekly services constitutes acceptance of any updates or changes. Peekly disclaims liability for Clients failing to inform their End Users of such changes. Peekly will provide advance notice of material changes to this Privacy Policy either through its website or directly to Clients where required by law. Clients are responsible for ensuring their End Users are informed of any such updates.
For any questions or privacy-related concerns, please contact:
Email: contact@tiltely.com
Data Controller Contact (for GDPR-related inquiries): Tiltely LLC, acting as Peekly's legal entity
Email: contact@tiltely.com
Peekly complies with the General Data Protection Regulation (GDPR) in the European Union, the California Consumer Privacy Act (CCPA), and other applicable privacy laws globally, including data protection laws in the United States, Canada, Brazil (LGPD), and Australia (Privacy Act).
We have tailored our practices to ensure that End Users and Clients worldwide are informed of their rights and have control over their data. If you reside in a jurisdiction with specific data protection laws, you may have rights such as access, correction, deletion, or restriction of processing, as described in this Privacy Policy.
Peekly makes no guarantees regarding uninterrupted service, real-time data availability, or error-free operation. To the maximum extent permitted by applicable law, Peekly and Tiltely shall not be held liable for damages, data loss, or system unavailability caused by unforeseen outages, force majeure events, or third-party service failures beyond their reasonable control.
Peekly shall not be held liable for any direct or indirect damages resulting from Client misconfiguration, unlawful chatbot deployment, or failure to comply with regional data privacy laws.