Privacy Policy

Last updated: 16 July 2026

Clientora ("Clientora", "we", "us") provides an AI customer-assistant platform that lets a business connect its messaging channels (Facebook Messenger, Instagram, WhatsApp, Viber) so that an AI assistant can automatically reply to that business's customers. This policy explains what we collect and how we use it.

Clientora is operated by Ideal Dev SH.P.K., a company registered in Kosovo (business number 812388933), with its registered office at 2 Nëntori, Prishtinë, Kosovo.

Who is responsible for your data

When you message a business that uses Clientora, that business is the controller of your personal data; Clientora processes it on the business's behalf to generate replies.

Information we process

  • Messages & conversation content exchanged between a customer and the connected business page/number, plus the channel and the channel-specific user id (e.g. a Page-scoped ID, phone number, or Viber id) needed to deliver the reply.
  • Channel connection data a business provides to connect a channel — e.g. Facebook/Instagram Page access tokens, WhatsApp tokens, or Viber tokens. These are stored encrypted and used only to receive and send messages on that channel.
  • Knowledge base contenta business adds (offers, FAQs, uploaded documents, or text imported from the business's own website) used to ground the assistant's answers.
  • Account data for business users of the dashboard: name, email, password (hashed).
  • Usage metrics such as message counts and token/cost totals.

How we use information

  • To receive inbound messages and generate and send automated replies.
  • To retrieve the relevant knowledge-base entries that inform each reply.
  • To operate, secure, and support the service and enforce per-business usage limits.

Meta platform data we access

When a business connects its Facebook Page or Instagram account, Clientora accesses the following through the Meta permissions it has been granted, solely to power that business's assistant:

  • The list of Pages you manage (pages_show_list) — so you can choose which Facebook Page to connect.
  • Messages and conversations on the connected Page (pages_messaging) — to read the customer's message and send the assistant's reply, within Meta's messaging policies (including the 24-hour window).
  • Page settings & message webhooks (pages_manage_metadata) — to subscribe the Page to message notifications so new messages reach the assistant.
  • Business assets you grant (business_management) — to connect the Pages and assets you authorise on your behalf.
  • Instagram professional account basic profile (instagram_business_basic) — the connected Instagram account's id, username and profile picture, to identify and display the account you connected, and to show the name and profile picture of a customer who messages you so the business can recognise them in its inbox.
  • Instagram direct messages (instagram_business_manage_messages) — to receive messages customers send to the connected Instagram account and send the assistant's reply back, within Instagram's messaging policies (including the 24-hour window).
  • WhatsApp messages (whatsapp_business_messaging) and WhatsApp account setup (whatsapp_business_management) — to receive and reply to messages on a connected WhatsApp Business number, and to subscribe that number's account to message notifications.

We request only the permissions needed to receive and answer messages. We do not request or use permissions for advertising, publishing content, or reading anything beyond the conversations a customer sends to the connected business.

We use this data only to receive and answer messages for that business. We do not use it for advertising, do not sell it, and do not share it except with the sub-processors listed below.

Sub-processors & sharing

To generate replies we send the conversation context and the relevant knowledge-base text to OpenAI(our AI model provider). Under OpenAI's API data-usage policy, data submitted through the API is not used to train or improve its models and is retained for at most 30 days for abuse monitoring before deletion. We exchange messages with the platforms a business connects (Meta — Messenger, Instagram and WhatsApp — and Viber). Our infrastructure runs on Amazon Web Services. We do not sell personal data, and data obtained through Meta permissions is used only to receive and answer that business's messages.

How we protect data

Channel access tokens and other credentials are encrypted at rest using AES-256; dashboard passwords are hashed (bcrypt). All data is transmitted over encrypted connections (TLS / HTTPS). Our systems run on Amazon Web Services in the EU region eu-central-1 (Frankfurt), with administrative access restricted to authorised personnel.

Legal basis & international transfers

For personal data Clientora processes on behalf of a connected business, that business is the data controller and Clientora is its processor; the lawful basis is the controller's — typically its legitimate interest in answering its own customers, or performance of a contract (GDPR Art. 6(1)(b)/(f)). Personal data is stored within the EU (AWS eu-central-1, Frankfurt). Where a sub-processor processes data outside the EU (e.g. OpenAI in the United States), the transfer is covered by appropriate safeguards such as the EU Standard Contractual Clauses.

Retention

Messages and knowledge-base content are retained while the business's account is active and deleted on request or when the account/channel is removed. Encrypted channel credentials are deleted when a channel is disconnected. Data created by Meta App Review test users is deleted within 48 hours of the review's completion.

Your rights & data deletion

You can request access to or deletion of your data at any time. To delete your data, visit https://clientora.tech/data-deletion and follow the instructions, or email us at the address below.

Deletion requests submitted through Facebook are handled by our data deletion callback at https://api.clientora.tech/api/data-deletion-callback and processed promptly (within 30 days at the latest).

Contact

For any privacy request, email info@clientora.tech.