Core ChatPrivacy Policy

Effective date: 13 July 2026

1. Introduction

This Privacy Policy explains how White Rock ("White Rock", "we", "us" or "our"), a company incorporated under the laws of the United Arab Emirates with its registered office at [registered address], United Arab Emirates, collects, uses, discloses and protects personal data in connection with Core Chat, a corporate messaging application, including its mobile, desktop and web applications and related services (the "Service").

This Policy applies to individuals who use the Service ("Users"), visitors to our websites, and individuals who communicate with us. It should be read together with the Core Chat Terms & Conditions.

We process personal data in accordance with applicable data protection laws, including UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL") and, where applicable to Users in the European Economic Area or the United Kingdom, the General Data Protection Regulation ("GDPR") and the UK GDPR.

2. Our Role: Controller and Processor

Core Chat is designed for use by organisations ("Organisations" or "Customers"). Understanding who is responsible for your data depends on the type of data:

  • Customer Content (messages, files, voice/video communications and other content submitted within an Organisation’s workspace): the Organisation is the data controller, and White Rock processes this data as a data processor on the Organisation’s documented instructions and under a data processing agreement. Questions and requests regarding Customer Content should be directed to your Organisation in the first instance.
  • Account, billing, usage, diagnostic and support data needed to provide, secure and improve the Service, and data of website visitors: White Rock acts as the data controller.

Your Organisation’s own privacy policies and internal rules also govern its workspace. Your Organisation’s Admins may be able to access, export, restrict or delete Customer Content and manage your account in accordance with the Organisation’s policies.

3. Personal Data We Collect

Data you or your Organisation provide:

  • Account and profile data: name, business email address, phone number (if used for verification), job title, department, profile photo, workspace and team membership.
  • Customer Content: messages, files, images, links, voice and video communications, reactions, and message metadata (sender, recipients, timestamps, read status), processed on behalf of your Organisation.
  • Support and communications data: information you provide when you contact support, report a problem or respond to surveys.

Data collected automatically:

  • Usage data: features used, actions taken (e.g., login events, channels joined), session duration and interaction logs.
  • Device and technical data: device model, operating system and version, app version, language, time zone, IP address, network type, unique device or installation identifiers, and push notification tokens.
  • Diagnostics: crash reports, performance data and error logs.

Data from other sources:

  • Information provided by your Organisation when provisioning accounts (e.g., via corporate directory / SSO integration such as name, email, role).
  • Optional device permissions you grant, such as contacts, camera, microphone, photo library or notifications. These are used solely to deliver the relevant features (e.g., calls, file sharing), and you can revoke them in your device settings at any time.

We do not collect personal data for advertising purposes, and we do not sell personal data.

4. How We Use Personal Data

We use personal data to:

  • provide, operate and maintain the Service, including delivering messages, calls, notifications and file sharing;
  • set up and administer accounts and workspaces, and authenticate Users;
  • secure the Service, including detecting, preventing and investigating fraud, abuse, security incidents and violations of our Terms;
  • provide customer support and respond to requests;
  • monitor, analyse and improve the performance, reliability and usability of the Service, and develop new features;
  • comply with legal obligations, enforce our agreements and protect our rights, Users and the public; and
  • communicate with Users about service updates, security notices and administrative messages.

Where White Rock acts as a processor of Customer Content, we use such data only as instructed by the Organisation and as necessary to provide the Service.

5. Legal Bases for Processing

Where we act as controller, we rely on the following legal bases under the UAE PDPL and (where applicable) the GDPR:

  • Performance of a contract: to provide the Service under our Terms and agreements with Organisations.
  • Legitimate interests: to secure and improve the Service, prevent abuse, and communicate about service matters, balanced against your rights and interests.
  • Legal obligation: to comply with applicable laws, lawful requests and regulatory requirements.
  • Consent: where required, for example for certain optional device permissions or communications. You may withdraw consent at any time without affecting prior processing.

6. Access by Your Organisation

Because Core Chat is a workplace tool, your Organisation controls its workspace. Depending on the Organisation’s configuration and applicable law, its Admins may be able to: view workspace membership and usage information; access, export and delete Customer Content (including messages in channels and, in some configurations, direct messages); apply retention and legal-hold policies; and suspend or delete User accounts. White Rock is not responsible for how your Organisation collects, uses or discloses data under its control. Please review your Organisation’s policies for details.

7. How We Share Personal Data

We do not sell personal data. We share personal data only:

  • with the Organisation that manages your workspace, as described in this Policy;
  • with service providers (sub-processors) who support the Service, such as cloud hosting, content delivery, push notification delivery, analytics and crash reporting, and customer support tooling, under contracts that restrict their use of the data;
  • with other Users within your workspace, as an inherent part of the messaging functionality (e.g., your profile and messages are visible to intended recipients);
  • with competent authorities, courts or regulators where required by applicable law or a valid legal process, or where necessary to protect the rights, property or safety of White Rock, our Users or the public;
  • in connection with a merger, acquisition, financing or sale of assets, subject to appropriate confidentiality safeguards and notice where required; and
  • with your consent or at your direction.

8. International Data Transfers

Personal data may be stored and processed in the United Arab Emirates and in other countries where we or our service providers operate. Where personal data is transferred outside the jurisdiction in which it was collected, we implement safeguards required by applicable law, such as transfers to jurisdictions with an adequate level of protection, appropriate contractual protections (including standard contractual clauses where applicable), and, where required, consent. Details of the safeguards applied are available on request.

9. Data Retention and Deletion

We retain personal data only for as long as necessary for the purposes described in this Policy, and as follows:

  • Customer Content is retained in accordance with the retention settings and instructions of your Organisation, and is deleted or returned upon termination of the Organisation’s agreement, in accordance with the applicable data processing terms.
  • Account data is retained for the life of the account and deleted or anonymised within a reasonable period after account deletion, subject to legal retention obligations.
  • Usage, diagnostic and log data is retained for limited periods appropriate to security, troubleshooting and service-improvement purposes.
  • We may retain certain data longer where required by law, to resolve disputes or to enforce our agreements.

Account deletion: you may request deletion of your account at any time from within the application (Settings → Account → Delete account) or by contacting privacy@white-rock.ae. If your account is managed by an Organisation, deletion requests may be routed to, or actioned by, that Organisation as controller.

10. Security

We apply appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. These measures include encryption of data in transit and at rest, access controls and authentication requirements, logging and monitoring, network security controls, personnel confidentiality obligations, and regular security assessments. No method of transmission or storage is completely secure; if we become aware of a personal data breach affecting you, we will notify you and/or the relevant Organisation and the competent authorities where required by applicable law.

11. Your Rights

Subject to applicable law (including the UAE PDPL and, where applicable, the GDPR), you may have the right to:

  • request access to the personal data we hold about you and receive information about its processing;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of your personal data;
  • request restriction of processing, or object to processing (including processing based on legitimate interests);
  • request portability of personal data you provided to us, in a structured, commonly used machine-readable format;
  • withdraw consent at any time, where processing is based on consent; and
  • lodge a complaint with a competent data protection authority, including the UAE Data Office or, where the GDPR applies, your local supervisory authority.

To exercise these rights, contact us at privacy@white-rock.ae. We may need to verify your identity before acting on a request. Where your request concerns Customer Content controlled by your Organisation, we will refer the request to the Organisation and support its response as processor.

12. Children

The Service is intended for business use by adults and is not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided personal data through the Service, please contact us at privacy@white-rock.ae and we will take appropriate steps to delete it.

13. Third-Party Services

The Service may contain links to, or integrations with, third-party services enabled by you or your Organisation. This Policy does not apply to third-party services, and we encourage you to review their privacy policies before use.

14. Changes to this Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by other reasonable means before the changes take effect, and update the effective date above. Your continued use of the Service after the effective date constitutes acknowledgement of the updated Policy.

15. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact:

  • Data Protection contact: privacy@white-rock.ae
  • White Rock, [registered address], United Arab Emirates
  • Website: https://white-rock.ae

Contacts

Ready to move forward with clarity and impact?

Let's talk about how we can deliver measurable value for your business.

White Rock logo

Location:

Abu Dhabi, UAE

Support:

Get help

© 2025 White Rock LTD. All Rights Reserved.