DRAFT — pending legal review. This document is a placeholder draft and is not legally binding.
Version 2026-07-03-draft1 · Effective 2026-07-03
# Privacy Policy
_Effective date: 2026-07-03_
This Privacy Policy explains how AZINTECO ("we") handles personal data.
## Data we process
- **Account data**: name, email, workspace membership.
- **Contact data**: phone numbers, names and messaging opt-out status you import
or that your customers provide by messaging you.
- **Conversation data**: message content and delivery metadata.
- **Usage/technical data**: request identifiers, logs (secrets and raw payloads
are redacted before storage) and billing status.
## How we use data
To provide the Service, route and store messages, apply automation and AI
replies you configure, secure the platform, and comply with law.
## Legal bases
Performance of contract, legitimate interests in operating and securing the
Service, and consent where required (e.g. marketing messages to contacts).
## Sharing
We use processors such as messaging providers (Meta), infrastructure, and
payment (Stripe). We do not sell personal data.
## Your rights
Subject to law, you (and, via you as controller, your contacts) may request
access, export, correction and deletion. Workspace owners can export or request
deletion of workspace data from within the product.
## Retention
Workspace data is retained for the life of the workspace and deleted on request
per the Data Processing Addendum. The self-service erasure tooling removes
workspace content — contacts, conversations, messages, templates, flows,
analytics and integration credentials.
### Records retained or minimized after an erasure request
A limited, minimized set of records may be retained after an erasure request
where we have a legal basis to keep it. These records contain no message
content and are redacted or minimized:
- **Proof of Terms/Privacy acceptance.** When an account is created we record
that the Terms and Privacy Policy were accepted, together with the account user
identifier, the timestamp, the document versions accepted, and the IP address
and user-agent of the acceptance. This is retained as evidence that the account
holder agreed to the Terms — legal bases: performance of / entry into the
contract, compliance with our record-keeping obligations, and our legitimate
interest in establishing, exercising or defending legal claims. It is kept for
the applicable limitation period after the account relationship ends.
- **Redacted diagnostic / bug reports.** Reports submitted through the product
are passed through automated redaction (secrets and personal data are stripped)
before storage. Depending on the deletion mode and legal basis, workspace-scoped
reports may be deleted with workspace content or a redacted record and masked
submitter reference may be kept for a limited period to investigate and fix
defects and abuse — legal basis: our legitimate interest in the security and
integrity of the Service.
- **Security audit records.** Minimal, redacted records of security-sensitive
actions (e.g. sign-in, consent changes, webhook rejections) may be deleted with
workspace content or kept for a limited period where needed for security,
abuse-prevention, legal claims or compliance with law — legal bases: our
legitimate interest in securing the platform and compliance with law.
You may contact us at privacy@azinteco.com to ask about, or object to, any retained
record, subject to the legal bases above.
## Contact
Data protection contact: privacy@azinteco.com