Privacy Policy

Version v2.0-2026-08 ยท Last updated 12 August 2026

1. Introduction

This Privacy Policy explains how Geret AI Connect, operated by Geret AI Connect ("we", "us"), collects, uses, stores, and protects information when you use our AI customer-conversation platform. It also explains the rights you and your customers have. For personal data belonging to your own customers, you are the controller and we act as your processor under your instructions.

2. Information we collect

Account information: your name, email address, password hash or federated sign-in identifier, role, and workspace membership. Business information: business name, type, description, offers, services, products, policies, promotions, business hours, FAQs, and AI instructions you add. Conversation data: customer messages and assistant replies from connected channels, including Facebook Messenger messages, conversation status, and handoff events. Lead and customer records: names, contact details such as phone or email, interest, status, temperature, and notes you or your channels provide. Channel and integration data: connected Page identifiers, page names, and access credentials stored in encrypted form. Usage and analytics data: feature usage, AI request counts, plan and trial status, rate-limit counters, and aggregate dashboard metrics. Technical and security data: IP address, device and browser information, timestamps, error reports, and audit-log entries for administrative actions.

3. How we use information

We use information to: create and secure your account and workspace; generate AI replies grounded in your knowledge base; deliver, receive, and store messages on your connected channels; capture and organise leads; show dashboards and analytics; enforce plan limits, trial eligibility, rate limits, and monthly caps; detect, investigate, and prevent abuse, fraud, and security incidents; provide support and respond to your requests; keep audit records for accountability; and comply with legal obligations. We do not sell your data, and we do not use your conversations or knowledge base to train our own or public AI models.

4. Legal bases

Where data-protection law requires a legal basis, we rely on: performance of our contract with you; our legitimate interests in operating, securing, and improving the Service; your consent where you give it, for example when you connect a Facebook Page; and compliance with legal obligations.

5. AI processing

Message content, relevant knowledge-base entries, recent conversation history, and your AI instructions are sent to an AI model provider through our server-side gateway so a reply can be generated. Requests are made from our backend using server-side credentials; your browser never holds AI provider keys. Providers process the data to return a response and under our arrangements do not use it to train public models. Automated replies are not used to make decisions with legal effect about individuals, and a conversation can always be handed to a human.

6. Facebook and Messenger integration

If you connect a Facebook Page, we use Meta's official OAuth flow with a signed state parameter and request only the permissions needed to read and send Page messages. We store your Page identifier, Page name, and an encrypted Page access token. Messenger events reach us through a signed webhook that we verify before processing; unsigned or invalid requests are rejected. We use this access solely to receive your customers' messages, generate replies, and send responses on your behalf. You can disconnect a Page at any time in the app, or remove our app from your Facebook Business settings; disconnecting stops further message processing.

7. Third-party services

We rely on trusted processors to run the Service: cloud hosting and edge compute, a managed PostgreSQL database and authentication provider, an AI model gateway and model providers, Meta platform APIs for messaging, email delivery for transactional messages, and video-meeting tools where you use webinar features. Processors are bound by contract to protect data and to process it only on our instructions. Some may process data outside your country; where that happens we rely on appropriate safeguards.

8. Cookies and analytics

We use strictly necessary cookies and local browser storage to keep you signed in, remember your active workspace or Page, and protect against abuse. We also keep first-party counters inside your workspace, such as AI request counts and plan usage, which are part of running the Service. We do not use third-party analytics, advertising, or cross-site tracking cookies, so no non-essential cookie consent is required. You can clear or block cookies in your browser, but sign-in will not work without the necessary ones.

9. How we store and protect information

Data is stored in managed cloud infrastructure and encrypted in transit with TLS and at rest by our provider. Each business workspace is isolated at the database level with row-level security, so a workspace can only read and write its own records. Access to production data is limited to the smallest number of people who need it, secrets and API keys are held server-side only and never exposed to the browser, channel access tokens are stored encrypted, administrative actions are written to an audit log, and we run automated security, rate-limit, and self-healing diagnostics. No system can be guaranteed perfectly secure; if a breach affects your data we will notify you and any regulator as required by law.

10. Data retention

We keep workspace data while your account is active. If you delete your workspace or request deletion, we remove or irreversibly anonymise your business data, conversations, leads, and customer records within 30 days, except where we must keep limited records longer for legal, tax, security, or abuse-prevention reasons. Backups are rotated and expire within 30 days. Audit and security logs are retained for up to 12 months. Aggregate, non-identifying statistics may be kept indefinitely.

11. Who can access your data

You and the staff or agents you invite to your workspace. Our administrators may access limited account, subscription, and diagnostic information to provide support, handle billing, and investigate abuse or security incidents; such access is recorded in the audit log. We disclose data to authorities only where legally required and, where permitted, we will tell you first.

12. Your rights

Subject to applicable law, you may request access to your data, correction of inaccurate data, a copy of your data in a portable format, deletion of your data, restriction of or objection to certain processing, and withdrawal of consent for optional processing. To exercise these rights, use the deletion and export page in the app or email privacy@geretaiconnect.com. We respond within 30 days and may need to verify your identity. In the Philippines you may also complain to the National Privacy Commission; elsewhere you may complain to your local supervisory authority.

13. Your customers' rights

If one of your customers asks you to delete their messages or contact details, you can remove the conversation, lead, and customer record from your workspace. If a customer contacts us directly, we will refer them to you as the controller and, where required, support you in fulfilling the request. Customers may also request removal of data linked to their Messenger conversations by emailing privacy@geretaiconnect.com or using our data deletion request page.

14. Account and data deletion

You can request deletion of your account, workspace, or a specific customer's data at any time from our data deletion request page, which is linked in the app and website footer. We confirm the request by email, delete or anonymise the data within 30 days, and disconnect any linked Facebook Pages so no further messages are processed.

15. Children

The Service is for businesses and is not directed at children under 18. We do not knowingly collect data from children. If you believe a child's data reached us, contact us and we will delete it.

16. Changes to this Policy

We may update this Policy. Material changes will be announced in the app or by email, and the version and date on this page will change. Current version: v2.0-2026-08.

17. Contact us

Privacy questions and requests: privacy@geretaiconnect.com. General support: support@geretaiconnect.com. Operator: Geret AI Connect. Our registered business details are available on request by emailing privacy@geretaiconnect.com.