Privacy policy

Last updated: 3 September 2026

This policy explains what personal data AlexDev processes when you use the AI Business Assistant (the “Service”), why we process it, and what you and your customers can ask us to do with it.

1.Who we are

AlexDev (alex-dev.pro) operates the Service. For data you upload and for messages exchanged with your customers, you are the data controller and we act as your processor. For your own account data (your name, email, billing details) we are the controller.

2.What we process

  • Account data: name, work email, company name, workspace name, role, authentication metadata.
  • Configuration data: your knowledge base entries, prompts, rules, business hours and channel settings.
  • Channel credentials: WhatsApp / Meta access tokens, Telegram bot tokens, CRM keys — encrypted at rest and used only to send and receive messages on your behalf.
  • Conversation data: messages exchanged between your customers and the assistant or your operators, along with the channel identifier (phone number, Telegram chat id, visitor id), display name and timestamps.
  • Technical data: request logs, error traces, delivery statuses and audit records of administrative actions.

3.Why we process it

  • To provide the Service: receive, route, answer and deliver messages, and show them in your inbox.
  • To keep the Service secure and reliable: abuse prevention, rate limiting, debugging, audit trails.
  • To bill you and to communicate about your account.
  • To improve the Service using aggregated, non-identifying usage statistics.

We do not sell personal data, and we do not use your conversations or knowledge base to train our own or any third party’s models.

4.Sub-processors

The Service runs on a small, fixed set of providers:

  • Hosting and edge delivery (application servers and logs).
  • Managed PostgreSQL database and authentication (workspace data, conversations, credentials).
  • AI model providers — Anthropic, OpenAI or DeepSeek, selected per workspace — which receive the conversation text and the relevant knowledge-base snippets under terms that prohibit training on API data.
  • Messaging platforms you connect: Meta (WhatsApp, Instagram, Messenger) and Telegram, each governed by their own terms.
  • CRM systems you connect: Bitrix24, Kommo, amoCRM, HubSpot or your own endpoints.

An up-to-date list with locations is available on request at info@alex-dev.pro.

5.Storage, isolation and retention

Every record is scoped to a workspace and filtered by workspace identifier on every query; workspaces do not share conversation, knowledge or credential data. Credentials are encrypted at rest with a key held outside the database.

Conversations and knowledge entries are retained for as long as your workspace is active, and deleted within 30 days of workspace deletion or of a written deletion request. Backups roll off on their own cycle, at most 35 days. Audit records may be kept longer where required for security or accounting purposes.

6.Your customers’ rights

Where GDPR or an equivalent regime applies, data subjects may request access, correction, deletion, restriction, portability, or object to processing. Because we act as your processor for conversation data, route such requests to us at info@alex-dev.pro and we will assist you within the statutory deadline.

7.Security

  • Transport encryption (TLS) for all traffic, including webhooks.
  • Channel credentials encrypted at rest; the panel only ever displays masked hints.
  • Signature verification on inbound webhooks from Meta and secret-token checks for Telegram.
  • Role-based access inside a workspace, with an audit log of administrative actions.
  • Least-privilege service credentials; no production data on developer machines.

8.International transfers

Data may be processed outside your country — in particular by AI model providers and messaging platforms based in the EU or the United States. Where required we rely on the European Commission’s standard contractual clauses or an adequacy decision.

9.Cookies

The web application uses strictly necessary cookies for authentication and session integrity. The embeddable chat widget stores a random visitor identifier in the visitor’s browser so a conversation survives a page reload; it sets no advertising or analytics cookies.

10.Changes

We will post any material change on this page and, where the change affects how we process personal data, give notice by email to workspace owners at least 14 days before it takes effect.

Contact

The Service is operated by AlexDev (alex-dev.pro). Contact: info@alex-dev.pro.
Email: info@alex-dev.pro · https://www.alex-dev.pro

This document is a plain-language template. Have it reviewed by counsel in your jurisdiction before relying on it commercially.