1. Introduction
Arutai ("we", "us", "our platform") is a business-communication analytics platform that connects to WhatsApp Business and Instagram Direct accounts to help companies manage, analyse and improve their customer correspondence. This policy describes what personal data we collect, why, how we process it, who we share it with, and what rights you have.
This policy applies to:
- Users of the Arutai web platform and mobile app — employees of our business customers
- End customers of businesses using Arutai, whose correspondence may be processed through our platform
By using Arutai you agree to the practices described here.
2. Who controls the data
The business using Arutai is the controller of its correspondence data: it is a party to the conversation and the holder of the records. Arutai LLC acts as a processor, operating on that business's instructions under a contract or public offer. We do not access correspondence on our own initiative and we are not an independent party to it.
For any question about this policy, contact [email protected].
3. What data we collect
3.1 Platform user data (business accounts)
- Full name and email, for registration and sign-in
- Organisation name and business details
- Role within the organisation
- Sign-in times and session activity
- Subscription and payment status — we never store full card details
3.2 End-customer data (contacts of businesses using Arutai)
- Phone numbers (WhatsApp) and Instagram handles — displayed in masked form inside the platform, for example +996 70x xxx 567. Unmasked identifiers are stored in the database but are never shown in the interface.
- Display names as provided by the messenger
- Correspondence content — text messages, voice-message transcripts where processed, image descriptions, and timestamps from WhatsApp and Instagram conversations
- Conversation metadata: read status, delivery status, message direction
3.3 Data produced by AI analysis
- Conversation risk scoring
- Intent and sentiment classification
- Session outcome prediction, for example whether a sale closed
- AI-generated insight summaries
- Reply drafts — shown only to the business's own staff, never sent automatically
3.4 Technical and usage data
- IP addresses and device identifiers
- Browser type and operating system
- In-app navigation and feature usage, to improve the platform
- API request logs and error logs
4. How we use data
| Purpose | Legal basis |
|---|---|
| Providing the platform and its features | Performance of a contract |
| Authentication and account security | Legitimate interest / contract |
| AI analysis of correspondence and insight generation | Legitimate interest (business analytics) |
| Generating reply drafts for human review | Legitimate interest |
| Detecting churn risk and conversation-health signals | Legitimate interest |
| Improving the platform and fixing defects | Legitimate interest |
| Sending transactional email (account, billing) | Contract |
| Meeting legal obligations | Legal obligation |
Important: AI-generated drafts are suggestions only. Arutai never sends a message to an end customer automatically or without explicit confirmation by the business's own staff. This is a foundational product principle with no exceptions.
5. Third-party services and sub-processors
We use the following sub-processors. Each handles data only to the extent needed to provide its service and is bound by a data-processing agreement.
| Service | Purpose | Privacy policy |
|---|---|---|
| Supabase | Database storage, authentication | supabase.com/privacy |
| OpenAI | AI analysis of correspondence content | openai.com/policies/privacy-policy |
| Google Gemini (Google LLC) | AI analysis of correspondence content | policies.google.com/privacy |
| Trigger.dev | Background job processing (imports, sweeps) | trigger.dev/legal/privacy |
| Expo / EAS (650 Industries, Inc.) | Mobile app build and delivery | expo.dev/privacy |
| Meta Platforms | Message delivery via WhatsApp Business API | facebook.com/privacy/policy |
| Meta Platforms | Message delivery via Instagram Graph API | facebook.com/privacy/policy |
| Vercel | Web application hosting | vercel.com/legal/privacy-policy |
Personal data is pseudonymised before it is sent to any external language model. Phone numbers, handles and names are replaced at a single enforcement point in our code before any content leaves our systems. This is a legal requirement under the Digital Code of the Kyrgyz Republic, and it is covered by automated tests.
We never sell personal data to third parties.
6. Data retention
| Data type | Retention period |
|---|---|
| Account and organisation data | Until account deletion, then 30 days |
| Correspondence messages and metadata | Until deleted by the organisation or the account closes |
| AI analysis and insights | Matches the retention of the related correspondence |
| Audit and security logs | 12 months |
| Billing records | 7 years (statutory requirement) |
Once a retention period ends, data is irreversibly deleted from all systems, including backups, within 90 days.
7. Data security
- All data in transit is encrypted with TLS 1.2 or higher (HTTPS)
- All data at rest is encrypted in the PostgreSQL database managed by Supabase
- Tenant isolation: each organisation can access only its own data, enforced at the database level by row-level security policies
- Least-privilege support access: Arutai staff can access an organisation's data only with that organisation's explicit, time-limited grant, and every access is audited
- Phone numbers and contact identifiers are masked in the interface to minimise exposure of personal data to platform users
8. International data transfers
Arutai runs on infrastructure located primarily in the European Union and the United States. Where personal data is transferred outside your country of residence, we apply appropriate safeguards — standard contractual clauses or equivalent mechanisms under applicable law.
9. Your rights
Depending on your jurisdiction, you may have the following rights:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your data (the "right to be forgotten")
- Restriction — request that we limit how we use your data
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interest
- Withdrawal of consent — where processing relies on consent, withdraw it at any time
To exercise these rights, contact [email protected]. We respond within 30 days. If you are an end customer of a business that uses Arutai, we recommend contacting that business directly — it is the controller of your correspondence data and we process it on its behalf.
10. Cookies
The Arutai web platform uses cookies for authentication session management (strictly necessary) and security (CSRF protection). We do not use advertising or tracking cookies and we do not participate in cross-site tracking. See the cookie notice for detail on this marketing site.
11. Children
Arutai is a business-to-business platform. It is not intended for, and not directed at, anyone under 18. We do not knowingly collect data about minors.
12. Changes to this policy
We may update this policy from time to time. For material changes we will notify users by email and update the "last updated" date at the top. Continuing to use the platform after changes take effect constitutes acceptance of the updated policy.
13. Contact
For anything related to data privacy:
Email: [email protected]
Phone / WhatsApp: +996 999 147 741
Entity: Arutai LLC (ОсОО «Арутай»), Bishkek, Kyrgyz Republic
Full registration details — registration number, tax ID and registered address — are available on request for a data-processing agreement, procurement, or a supervisory authority request. Email [email protected].