Privacy Policy
This policy explains what data Osnovatel LLC ("we", "the Company") processes when operating the POTOK platform and the AI messaging agents connected to it, why we process it, and what you can demand from us.
1. Roles
Our users are businesses. The conversations are held with their customers.
- The client business is the controller of its customers' data. It decides which messaging channels to connect, what information to load into the platform and how long to keep it.
- Osnovatel LLC is the processor. We store and transmit data on the client business's instruction and under a contract with it. We do not use its customers' conversations for our own purposes.
If you messaged a business that uses POTOK and want to know what happened to your data, contact that business directly or write to [email protected] and we will pass your request to the controller.
2. Data we process
2.1. Staff of the client business (platform users)
- Name, email address, role in the company, password hash.
- Telegram identifier, if the person enabled notifications.
- Activity log inside the platform: sign-in, changes to deals, messages sent — so the owner can see the team's work and so incidents can be investigated.
2.2. Conversation data
- Phone number or messenger identifier, profile name.
- Message content: text, images, documents, voice messages, plus metadata — timestamp, direction, delivery status.
- Contact names from the address book of the connected WhatsApp Business number, if the client business chose to run the app and the platform side by side; the names exist so that the platform shows people rather than raw numbers.
- Message history of up to 180 days prior to onboarding, delivered by the WhatsApp Business Platform on the explicit instruction of the number's owner at the moment of connection.
2.3. Technical data
- IP address and device type when the platform is accessed, error records and server request logs.
- We use no advertising or tracking cookies. Cookies and local storage are used only to keep you signed in and to remember the colour theme.
3. Why we process it
- Deliver a customer's message to the responsible member of staff and store the reply.
- Produce the AI agent's reply from information the client business itself supplied.
- Show the owner the numbers: first response time, workload, state of deals.
- Keep the service secure and investigate failures and abuse.
- Invoice the subscription and meet the requirements of Kyrgyz law.
Our legal bases are the contract with the client business, its instruction as controller, our legitimate interest in the security of the service, and — for messages outside the 24-hour customer service window — the recipient's opt-in collected by the client business.
4. What we never do
- We do not sell or rent data to third parties.
- We do not use customer conversations to target advertising.
- We do not provide data for training artificial intelligence models. The providers we use to generate replies process the text through their API and do not train on it.
- We do not message people who never contacted the business and never opted in.
- We do not use unofficial methods of connecting to messaging services.
5. Who we share data with
Only with providers the service cannot run without, and only to the extent their function requires.
| Provider | Purpose | Data received |
|---|---|---|
| Meta Platforms Ireland Ltd. | Message delivery on WhatsApp and Instagram | Phone number, message content, metadata |
| Telegram Messenger Inc. | Messaging channel and staff notifications | Chat identifier, message content |
| Supabase Inc. | Database and file storage, server-side code execution | All platform data, in encrypted storage |
| Anthropic PBC | Generation of the AI agent's reply | Conversation text and the business facts included in the request |
| Cloudflare Inc. | Protection against automated sign-ups and network abuse | IP address, technical headers |
We comply with the Meta Platform Terms and the WhatsApp Business Solution Terms in how we handle data obtained through the WhatsApp Business Platform.
Data may also be disclosed on a lawful demand from a state authority of the Kyrgyz Republic. Where the law permits, we notify the client business.
6. Storage and retention
- Data is stored with our infrastructure provider in data centres outside the Kyrgyz Republic. Access is restricted by role and encrypted in transit.
- Data is retained while the client business's subscription is active.
- After the contract ends, data is kept for 30 days and then deleted irreversibly. A client business may request earlier deletion.
- Security logs are kept for up to 12 months.
- Accounting records are kept for the period required by Kyrgyz law.
7. Security
- All data in transit travels over TLS.
- Staff access follows least privilege and is logged.
- Channel access tokens are stored apart from the publicly served application and are never exposed to the browser.
- The database is backed up daily.
- We notify affected client businesses of a confirmed personal data breach within 72 hours of discovery.
8. Your rights
- Ask what data of yours we process.
- Have inaccurate data corrected.
- Request deletion — the procedure is on the Data deletion page.
- Withdraw consent to receive messages: reply "stop" in the same chat.
- Complain to [email protected]. We answer within 30 calendar days.
9. Children
The platform is built for organisations and their staff. We do not knowingly collect data about anyone under 16. If such data reached us, write to us and we will delete it.
10. Changes
A new version is published on this page with its date. We notify client businesses of material changes by email at least 14 days before they take effect.
11. Contact
Osnovatel LLC (ОсОО «Основатель»)
58 Baytik Baatyr street, Bishkek, Kyrgyz Republic
Tax ID (INN) 01805202210036 · registration number 205956-3301-ООО
Data questions: [email protected]
General enquiries: [email protected]