Skip to content

Privacy Policy

Effective Date: 2026-07-10
Last Updated: 2026-07-10

1. Who we are

MADEBYJJ, LLC (“we,” “us,” “our”) is a Delaware limited liability company operating the back-office automation service available at deskwiz.app (the “Service”). The Service helps small business clients automate customer responses across WhatsApp and, when enabled, SMS, as well as appointment booking.

Legal entity: MADEBYJJ, LLC
Registered address: 254 Chapman Rd, Ste 208 #14797, Newark, DE 19702
Operating from: Lakewood, NJ
Contact: privacy@madebyjj.com

This Privacy Policy explains how we collect, use, share, and protect information when you use the Service.

2. Who this policy applies to

This policy applies to three groups:

  1. Clients — small businesses that subscribe to the Service to automate their customer communications
  2. End-customers — individuals who message our clients via WhatsApp or SMS and whose messages DeskWiz processes
  3. Visitors — anyone visiting deskwiz.app

We have different obligations to each group, explained in the relevant sections below.

3. Information we collect

3.1 From Clients (businesses subscribing to the Service)

When you sign up as a client, we collect:

3.2 Google Calendar data

If a client connects Google Calendar, DeskWiz requests access only to check calendar availability and manage booking events that DeskWiz creates or updates on the client’s behalf.

We may collect or process the following Google user data:

DeskWiz does not request full calendar management access, does not read unrelated calendar event details for marketing, and does not use Google Calendar data to train generalized AI or machine-learning models. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

3.3 WhatsApp Business Platform Data

This section describes data we receive from Meta’s WhatsApp Business Platform and is provided specifically for transparency to Meta and to end-customers whose messages our clients process.

When an end-customer sends a WhatsApp message to one of our clients’ business numbers, Meta delivers that message to our webhook endpoint. We receive and process:

We use this data solely to:

We do not:

3.4 SMS customer-care data

When a client enables DeskWiz SMS customer care and an end-customer voluntarily texts that client’s business number, the messaging provider delivers the conversation to our systems. We receive and process:

We use SMS data to provide the requested customer care, maintain the conversation for the client’s review, help with a requested appointment, prevent abuse, and operate the messaging feature. We do not use SMS data to create advertising audiences, send promotional campaigns, or market unrelated products or services.

SMS message frequency varies with an end-customer’s conversation and request; DeskWiz does not use this customer-care flow for recurring promotional messages. Message and data rates may apply.

Mobile information sharing: No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. We may share mobile information with service providers, including Twilio, only as needed to provide and secure the Service, comply with law, or protect against fraud and abuse. Those providers may not use it for their own marketing or promotional purposes.

3.5 From Visitors to deskwiz.app

When you visit our website, we automatically collect:

4. How we use information

We use information for the following purposes:

PurposeInformation usedLegal basis (GDPR)
Provide the ServiceClient account data, WABA credentials, end-customer messagesContract performance
Respond to end-customer messages on a client’s behalfWhatsApp or SMS message content, conversation historyContract performance (with our client) and legitimate interest
Book appointments in third-party tools on a client’s behalfClient booking system credentials, end-customer name and contact infoContract performance
Check availability and manage confirmed Google Calendar bookingsGoogle OAuth tokens, free/busy availability, and DeskWiz-managed event detailsContract performance and client consent
Bill clientsAccount and payment informationContract performance
Improve the ServiceAggregated, anonymized usage dataLegitimate interest
Detect fraud and abuseAll categories as neededLegitimate interest
Comply with legal obligationsAny data as legally requiredLegal obligation
Communicate with clientsAccount email, business contact infoContract performance

We do not use automated processing to make any decision that produces legal or similarly significant effects on end-customers without human review.

5. Sharing and third parties (subprocessors)

We share information with the following categories of recipients:

5.1 Subprocessors

A current, complete subprocessor list is maintained at deskwiz.app/subprocessors and updated when changes occur.

5.2 Legal disclosures

We may disclose information if required by law, court order, or to:

We notify clients of any government data request unless legally prohibited.

5.3 Google user data sharing

We do not sell, rent, or transfer Google user data to advertising networks, data brokers, or information resellers. We disclose Google user data only to subprocessors that help us provide or secure the Service, to the connected Google services as needed to perform the requested Calendar actions, or when legally required.

5.4 Business transfers

If we are acquired or merge with another entity, your information may be transferred. We will notify clients before any such transfer.

6. We do NOT sell your data

We do not sell personal information as defined under CCPA, GDPR, or any other privacy law. We do not share data with advertising networks. We do not use Google user data or end-customer data for marketing of any kind.

Google Calendar data is used only to provide or improve the user-facing booking features the client authorizes: availability checks, confirmed event creation, confirmed event updates, confirmed event cancellation, and related support.

7. Data security

We implement industry-standard security measures including:

No security system is perfect. If we discover a breach affecting your data, we will notify affected clients without undue delay.

8. Data retention

Data categoryRetention period
Client account dataDuration of subscription + 90 days after termination
WhatsApp and SMS end-customer messages90 days from receipt, then deleted unless client opts to retain longer
Booking system credentialsUntil client revokes or cancels Service
Google Calendar OAuth tokensUntil client disconnects Google Calendar or cancels Service
DeskWiz-managed Google Calendar event IDs and booking metadataDuration of subscription + 90 days after termination unless deleted earlier
Billing records7 years (for tax compliance)
Webhook delivery logs30 days
Aggregated, anonymized analyticsIndefinite

Clients can request earlier deletion of end-customer message data at any time via the dashboard or by emailing privacy@madebyjj.com.

9. Your rights

9.1 Rights for individuals in the EU/UK/EEA (GDPR)

You have the right to:

To exercise these rights, email privacy@madebyjj.com. We respond within 30 days.

9.2 Rights for California residents (CCPA / CPRA)

You have the right to:

To exercise these rights, email privacy@madebyjj.com.

9.3 End-customers messaging our clients

If you are an end-customer who sent a WhatsApp message or SMS to a business using our Service and want your data deleted, please:

  1. Contact the business you messaged directly (they are the data controller for that conversation), OR
  2. Email us at privacy@madebyjj.com with the phone number you used and the business name

We will delete your data within 30 days, subject to legal retention requirements.

10. International data transfers

We are based in the United States. If you are located outside the US, your information will be transferred to and processed in the US. We rely on:

11. Cookies and tracking

deskwiz.app uses:

We do not use advertising cookies, retargeting pixels, or cross-site tracking.

12. Children’s privacy

The Service is intended for businesses. We do not knowingly collect personal information from individuals under 18. If you believe we have collected data from a minor, contact privacy@madebyjj.com and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Continued use of the Service after changes constitutes acceptance.

14. Contact us

For any questions about this Privacy Policy or to exercise your rights:

MADEBYJJ, LLC
254 Chapman Rd, Ste 208 #14797, Newark, DE 19702

Email: privacy@madebyjj.com
General inquiries: hello@madebyjj.com


Privacy Policy v1.1