HUANG’S

HUANG’S · auto CS

Privacy Policy — auto CS

Last updated: 1 October 2026

auto CS is the internal customer service and conversation archive application of HUANG’S LUA CINTILANTE. This policy explains how we process personal data through the application and its connection to WhatsApp Business and Meta business services.

1. Who is responsible

The controller is Lua Cintilante Unipessoal Lda, trading as HUANG’S LUA CINTILANTE, at Rua da Rotunda 20, 4480-619 Árvore, Portugal. For privacy questions or requests concerning your data, email huangssuporte@outlook.com.

This policy covers customers, prospective customers, business contacts and authorised staff or administrators whose data is processed in auto CS. It supplements our general website privacy policy. The external ordering store and Meta/WhatsApp also have their own privacy information for their services.

2. Data we collect and where it comes from

We receive data from your communications with our business, records made by our staff and the Meta interfaces connected to our business accounts. Depending on the communication and features available, this includes:

  • Contact details: your WhatsApp name and telephone number, and the name, company, shop, email address or other contact details you provide.
  • Conversation content: messages exchanged with our staff, images, voice messages, documents and other attachments made available by the integration.
  • Message metadata: message identifiers, business number, sender and recipient, dates, times, message type and delivery or read status where available.
  • Customer service records: product enquiries, order-related information, commercial follow-up notes and associated question-and-answer records used internally to consult conversations.
  • Business integration data: authorised account and administrator identifiers, WhatsApp Business Account and business phone identifiers, permissions, access credentials and technical events needed to connect and maintain the service.
  • Technical information: server and access logs, which may include IP addresses, timestamps, browser information and error details needed to operate and secure the service.

3. Existing conversations and connected numbers

When an authorised administrator connects an existing business number and enables history sharing, auto CS may receive earlier customer conversations and subsequent messages made available by Meta. The amount and types of history received depend on the platform, account eligibility and the choices made during connection. We do not obtain unrestricted access to a customer’s other WhatsApp conversations or device.

Our staff can continue handling conversations in WhatsApp Business where coexistence is enabled. Messages made available through that connection can be stored in our internal archive. Permission to connect a business account does not itself constitute consent from every conversation participant to any further use of their data.

4. Purposes and legal grounds

We use data to respond to enquiries, support orders, follow up commercial relationships, let authorised colleagues continue customer service and consult relevant previous communications. We also process data to manage the integration, maintain security and meet applicable legal obligations.

Where processing is necessary for a contract with you or steps you request before entering one, we rely on that contract or those steps. For business representatives, continuity of customer service, relevant commercial records and service security, we rely on our legitimate interests, balanced against individuals’ rights and expectations. Specific legal obligations provide a basis only for the data and purposes to which they apply. Where consent is required, we request it separately.

Providing contact and enquiry information is necessary for us to handle the corresponding request through this channel. You can choose another contact method. This application does not sell conversations or use them for targeted advertising.

5. AI and automated decisions

The current service archives conversations and supports human customer service. We do not currently send customer conversations to external AI providers through auto CS or use it to send AI-generated replies automatically. Internal organisation of messages or question-and-answer pairs is not model training.

We do not use auto CS to make decisions based solely on automated processing that produce legal or similarly significant effects on you. Before introducing a materially different AI use involving personal data, we will assess its legal basis and providers, update this notice and obtain consent where required. This policy does not authorise unrestricted reuse of conversations to train AI models.

6. Who receives data

Access to archived conversations is limited to authorised staff and technical support acting for the business as needed for their work. Recipient categories include Meta/WhatsApp for the messaging integration, hosting and infrastructure providers for storage and operation, and email providers for requests sent by email. This public website uses Cloudflare, and our published support mailbox uses Microsoft/Outlook.

Providers acting on our behalf are required to process data under the applicable instructions and data protection arrangements. Meta/WhatsApp may also process information under its own responsibilities and privacy terms. We may disclose relevant information to authorities where legally required or to professional advisers where necessary to establish, exercise or defend legal claims.

7. International processing

The use of international communications, infrastructure and email providers may involve processing outside the European Economic Area. For transfers for which we are responsible, an applicable GDPR transfer mechanism is required, such as an adequacy decision or the European Commission’s standard contractual clauses, together with additional measures where necessary. Contact us for information about relevant recipients and safeguards, or to request a copy of the applicable safeguards.

8. How long we retain data

Our conversation archive has a maximum retention period of ten years from collection, including associated media and conversation records. This is an upper limit for maintaining relevant commercial history, not a statutory requirement to keep every chat for ten years. Data should be deleted or irreversibly anonymised earlier when it is no longer necessary, following a valid erasure request or where the legal basis no longer applies.

We assess the need for retention by reference to the ongoing customer relationship, unresolved enquiries or orders, complaints and applicable claim periods. Specific records needed for a legal obligation or a dispute may be retained for the corresponding period with access limited to that purpose.

Access credentials are retained only while needed for the authorised integration. Technical logs and request records are kept for the time needed to investigate incidents, operate the service or demonstrate how a request was handled. Backups must follow the relevant retention and deletion rules; restoration must not reintroduce data that has been validly erased.

9. Your rights

Subject to the applicable conditions, you may request access, correction, erasure, restriction or portability of your personal data, and object to processing based on legitimate interests. If processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing. You may complain to the Portuguese Data Protection Authority (CNPD), including through www.cnpd.pt.

We normally respond within one month of receiving a rights request. Where legally permitted, a complex request may require an extension of up to two further months; we will explain the reason within the first month. We may request proportionate information to verify identity, without collecting more than necessary.

Portuguese Data Protection Authority (CNPD)

10. How to request data deletion

You do not need an auto CS login to make a request. Our business handles requests received through the following email process:

  1. Email huangssuporte@outlook.com with the subject “auto CS — Data deletion request”.
  2. Identify your WhatsApp number with its international country code and explain whether you want all relevant data deleted or only particular conversations. For an administrator account request, identify the account concerned. Do not include passwords or identity documents in the initial email.
  3. We will verify the request as necessary, review the corresponding conversations, attachments and related records, and communicate the outcome. If specific information must be retained on legal grounds, we will explain what is retained and why.
  4. Deletion in our archive does not automatically delete copies on participants’ devices or information held by Meta/WhatsApp under its own responsibilities. Disconnecting a business integration does not by itself delete data previously archived; you can request its deletion through this process.
Email a data deletion request

11. Security and policy updates

We use technical and organisational measures appropriate to the risks, including access restrictions and protected connections, to help prevent unauthorised access, loss and disclosure. No system can guarantee absolute security.

We publish changes on this page with an updated date and provide additional notice where a significant change in processing requires it. The English and European Portuguese versions describe the same practices. Questions can be sent to huangssuporte@outlook.com.