Privacy Policy

Last updated: 6 July 2026

Your privacy and your customers privacy matter to us. This policy explains in detail what data AIdesk collects, how it is used, stored and protected, who it may be shared with, and what rights you have over it.

01Introduction and scope

This policy applies to the entire AIdesk platform: the tenant dashboard, the AI chatbot across WhatsApp, Instagram, Telegram and the website widget, and the admin panel. It is important to clarify AIdesk dual role regarding data: AIdesk acts as a data controller for the tenant own account data (business owner and billing contact details), while it acts as a data processor for the end-customer conversation data it handles on behalf of the tenant under the service agreement. This policy is designed to align with internationally recognized principles such as the EU General Data Protection Regulation (GDPR) and the Saudi Personal Data Protection Law (PDPL), without this constituting a claim of formal certification or a completed regulatory audit.

02Definitions

For clarity, this policy uses the following terms:

  • "Tenant" or "business client": the business subscribed to the platform, responsible for its account and channels.
  • "End-customer": the person who messages a tenant bot through WhatsApp, Instagram, Telegram, or the website widget.
  • "Personal data": any information that can identify a natural person, directly or indirectly.
  • "Channel": the communication method linked to a tenant account (a WhatsApp number, an Instagram account, a Telegram bot, the website widget).
  • "Sub-processor": any third party AIdesk relies on to operate part of the service on its behalf.

03Data we collect

We collect the following categories of data, only as needed to run the service:

  • Account and tenant data: business name, account admin details, billing and contact information.
  • Conversation content: end-customer messages and bot replies across every channel linked to the account.
  • Channel secrets and credentials: such as access tokens, WhatsApp phone number IDs, and webhook secrets, stored encrypted with AES-256-GCM.
  • Analytics platform data: aggregated performance metrics from Google Analytics 4, Meta Ads, Google Ads, TikTok, Snapchat and Google Business, without identifying individual end-users of those platforms.
  • Usage and log data: IP address, device type, timestamps, and API call logs for security and troubleshooting purposes.
  • Cookies: to run the session and remember display preferences.

04How we use your data

Collected data is used strictly for the following purposes: running the chatbot and generating automated replies, displaying analytics and aggregating ad performance, managing subscription and billing, providing technical support, keeping the platform secure and preventing abuse, and complying with legal obligations where required. Tenant or end-customer data is never sold to any third party for marketing purposes.

05Legal basis for processing

Data processing relies on one or more of the following bases depending on the specific activity: performance of the contract with the tenant to deliver the service, legitimate interest in keeping the platform secure and improving its quality, explicit consent for any optional marketing communication, and legal obligation where applicable.

06AI processing disclosure

The chatbot relies on AI language models to understand end-customer messages and draft replies. This is done through the LLM routing provider OpenRouter, which forwards requests to models such as Google Gemini. Only the message text necessary to generate a reply is sent, and this data is not used to train general-purpose models accessible to parties outside the scope of delivering your service.

07Sub-processors

AIdesk relies on a limited set of trusted service providers to operate specific platform features, strictly within what is needed to deliver the service and under contractual commitments that protect your data:

  • AI model provider (OpenRouter and the language models it routes to) for generating automated replies.
  • Hosting and infrastructure provider for running servers and databases.
  • Cloud database (Supabase) for securely storing account and conversation data.
  • Advertising and analytics platforms (Google, Meta, TikTok, Snapchat) that a tenant optionally connects via OAuth authorization, for read-only access to performance metrics.
  • Queue and cache service (Redis) for efficiently processing messages and background jobs.

08Data sharing and disclosure

We only share your data in the following cases: with the tenant itself regarding its own end-customer data collected through its channels, with the sub-processors listed above strictly within the scope of delivering the service, when required by a valid legal request from a competent authority, or in the event of a business transfer such as a merger or acquisition, with prior notice where feasible.

09International data transfers

Because some service providers and infrastructure are hosted outside Saudi Arabia and the Gulf, your data may be processed in other locations. In these cases we work to ensure appropriate contractual and technical safeguards with each provider, such as encryption and data protection clauses in agreements, consistent with good international practice.

10Data retention

Account data and conversation content are retained for the duration of your contractual relationship with AIdesk, and are deleted or anonymized within a defined period after account closure, except where retention is required for security or legal purposes for a limited additional period. On account closure you may request data export or deletion before final removal.

11Security measures

Channel secrets and sensitive keys are encrypted at rest with AES-256-GCM, and data is transmitted over encrypted connections (TLS). Access to production systems is restricted through a limited permissions model for the operations team, and every tenant is logically isolated from other tenants own data at the database level.

12Your data rights

You may request to access, correct, delete, or port your data, object to its processing, or withdraw consent at any time, by contacting us through the support channels listed below. If you are an end-customer messaging a tenant bot, please direct any request about your own data to that tenant directly, since it is the party originally responsible for collecting it; AIdesk will provide the tenant the support needed to fulfill your request.

13Children privacy

AIdesk is a business-to-business (B2B) platform and is not directed at children. We do not knowingly collect personal data of individuals under the legal age of majority through the dashboard or admin panel.

14Cookies

Essential cookies are used to maintain your login session and remember display preferences such as dark mode, alongside optional analytics cookies to understand and improve site usage. You can manage your browser settings to control these cookies.

15Data breach notification

In the event of a security incident materially affecting your data, we are committed to notifying affected tenants without undue delay, and notifying relevant authorities where applicable law requires it.

16Tenant responsibilities as data controller

The tenant remains responsible for ensuring it has a sufficient legal basis and appropriate consent or notice from its own end-customers before enabling the AIdesk bot to communicate with them through its channels, as it is the party originally responsible for collecting its customers data.

17Changes to this policy

We may update this policy from time to time to reflect service or legal developments. The last-updated date will be shown at the top of this page, and account admins will be notified of material changes by email or an in-dashboard notice.

18Privacy contact

For any question or request related to this policy, you may contact the AIdesk support team through the contact channels listed on the site, and your inquiry will be routed to the team member responsible for privacy matters.