← Back to Home

Privacy Policy and Personal Data Processing

How StrongerBrandAI handles platform data and end-user data

Last updated: September 8, 2026

1. Scope of this policy

This policy describes processing by StrongerBrandAI S.A.S. in the declared Colombia operation using WhatsApp, when a business uses the receptionist agent. This launch does not enable Telegram, Instagram, Messenger or CRM as active operations. CRM is mentioned only as an informational or future capability: it is not currently a tool for marketing, campaigns, segmentation or promotional messages. Each future channel, country or feature requires review and, where appropriate, a new version. This policy covers data under StrongerBrandAI's control; WhatsApp, Meta, the Owner and other providers may apply their own policies.

2. Who is involved and who is responsible

StrongerBrandAI operates the platform and acts as a processor when it handles end-user data following the Owner's instructions. It is also an independent controller of account, operation, security, support and compliance data. The Owner defines the purposes of the service, configures the business, informs end users and obtains the required authorizations. One account may manage one or more tenants; each tenant has its own data, channels and responsibilities. The end user is the person who messages the business on WhatsApp or interacts with the agent.

3. Legal framework and authorization

The Colombia operation considers Statutory Law 1581 of 2012, Decree 1074 of 2015 and instructions from the Superintendence of Industry and Commerce. Before automated service begins, the agent shows the processing notice, links this policy and requests an explicit answer. The authorization is recorded with the tenant, channel, identifier, country, notice version, displayed text, response and date. If the end user does not authorize, automated service ends. Authorization is limited to the stated purposes and does not by itself authorize incompatible marketing, campaigns or later messages.

4. End-user data

Depending on what the person shares, we may handle their WhatsApp identifier and phone number, name, email, messages, files or voice notes, information needed for an appointment, confirmations, cancellations, no-contact requests, notice responses and technical conversation identifiers. The contact profile may retain name, phone and email for future appointments. The agent is not designed to request cards, passwords, PINs, banking credentials, complete identity documents or other unnecessary sensitive data. If a person voluntarily shares sensitive information, it may pass through as part of the message, but it is not a requested or enabled category in this launch.

5. Owner and business data

We may handle the account name and email, country, business data, services, hours, prices, instructions, knowledge content and agent configuration. We may also handle WhatsApp technical identifiers and credentials, connection status, configuration dates and consumption or billing data when the corresponding feature is enabled.

6. Technical and security data

We may record IP address, browser, device, dates, session status, errors, technical identifiers, consent events, authentication attempts and activity needed to separate tenants, prevent fraud, investigate errors and protect the platform. Some technical identifiers, such as a conversation identifier, may locate an operation and therefore have restricted access.

7. Where data comes from

Data may come from the end user, the Owner, WhatsApp and Meta through channel events, the Owner's browser or device, and technical systems for authentication, hosting, database, artificial intelligence, email, security and monitoring.

8. What we use data for

We use data to manage accounts and tenants, authenticate access, operate WhatsApp, receive messages, generate replies, retain context, manage appointments, send authorized reminders, handle no-contact, correction or deletion requests, activate human support when available, separate tenants, protect the platform, measure consumption and performance, comply with legal duties and defend rights or claims. We do not sell data, use one tenant's conversations for another, or authorize campaigns or marketing without an applicable purpose and authorization.

9. Artificial intelligence and message processing

The agent uses artificial intelligence to interpret requests and generate replies. When the relevant feature is used, the necessary turn context, relevant messages, business instructions, audio for transcription, knowledge files or text, and mathematical representations for search may be sent to those services. StrongerBrandAI limits information to what is needed to provide the service and does not use content to publicly train its own model.

10. Providers and international transfers

We may use Meta and WhatsApp for the channel; Supabase for authentication and database; OpenAI for replies, transcription or knowledge processing; Railway for hosting and backend; Google Firebase Cloud Messaging for panel notifications if the Owner enables them; email providers and Supabase Auth for confirmation, recovery and verification; and Vercel to host this website. Sentry is not enabled in this operation. Some providers may process data outside Colombia; transfers are limited to what is necessary and subject to applicable protection obligations. Meta and WhatsApp may handle data under their own terms.

11. Owner panel technologies

The panel uses an HttpOnly session cookie and does not store the session token in localStorage. localStorage stores visual preferences such as the theme. sessionStorage temporarily stores navigation and technical notices, including the notice associated with deleting an agent, and is cleared when no longer needed. The service worker supports web functions and Firebase Cloud Messaging registers a technical device identifier if the Owner enables notifications. These technologies do not store a local copy of the end user's chat history.

12. Retention and deletion

We retain data while needed to provide the service, maintain context, manage appointments, handle rights, comply with legal duties, investigate incidents, prevent fraud or defend claims. The agent's self-service deletes the end user's contact profile —name, phone and email for future appointments— but does not automatically delete conversations or appointments. Consent evidence, minimal logs and backups may remain restricted during the applicable cycle. When an agent is deleted, the platform purges that tenant's data and logs within its scope; an aggregated usage summary without end-user personal data may remain.

13. Logs, support, security and incidents

Technical logs are not the history repository. The code avoids sending messages, phones, emails, names, addresses, tokens and credentials to the logger, and applies global redaction to application, Uvicorn, backend access and library-error logs. Support may retain tenant, conversation identifier, dates, channel, status, errors, model, tools and metrics. Railway, Supabase, Meta and other providers may have their own records. If we confirm an incident affecting data under our control, we will assess scope, contain the risk and communicate what is required. The service may be interrupted by our failures, maintenance or external providers; we will make reasonable efforts to restore it but do not guarantee continuous availability.

14. Rights and how to exercise them

End users may learn what data is processed, correct it, request proof of authorization, revoke it or request deletion where appropriate. To request evidence of the notice and recorded response, or review specific data under StrongerBrandAI's control, write to contacto@strongerbrandai.com with the business, the WhatsApp number used and the scope of the request. The agent and panel do not automatically display this evidence. Data held by the Owner, Meta, WhatsApp or another provider must be requested from the relevant controller.

15. Changes and contact

We may update this policy because of legal, technical, provider, channel or feature changes. Material changes will be published as a new version and, where appropriate, require new acceptance before the affected feature is enabled. This version does not automatically expand processing to Telegram, Instagram, Messenger, other countries, CRM, marketing or future modules. For questions or requests: contacto@strongerbrandai.com.

StrongerBrandAI — Ley 1581 de 2012 — República de Colombia

StrongerBrandAI — AI Chatbot for B2B