Be Digital AI e.U. ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our workspace-scoped Customer Relationship Management (CRM) platform, including our messaging integrations.
1. Introduction
Be Digital AI e.U. is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our workspace-scoped CRM platform, including our messaging integrations.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, workspace details
- Contact & Customer Data: Names, phone numbers, email addresses, messaging handles (WhatsApp, Instagram, Facebook, TikTok)
- Conversation Data: Messages, attachments, and conversation history across integrated channels
- Business Data: Sales pipeline information, opportunities, custom fields, and automation rules
2.2 Information Collected Automatically
- Usage Data: Login times, features used, interactions with the platform
- Device Information: Device type, browser type, IP address
- Cookies: Authentication tokens and session data for security and functionality
3. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve our CRM platform
- Process and manage multi-channel conversations (WhatsApp, Instagram, Facebook, TikTok)
- Enable AI-powered automation and intelligent responses
- Perform background jobs and scheduled tasks
- Provide real-time messaging and notifications
- Ensure security and detect fraud
- Comply with legal obligations
- Send service announcements and updates
4. Third-Party Integrations & Data Sharing
We distinguish between service providers we use for every workspace, and optional integrations that only receive data if and when you connect them using your own account or credentials. See our Data Processing Agreement for the full, current list.
4.1 Meta Platforms (WhatsApp, Instagram, Facebook)
We integrate with Meta's messaging APIs to enable you to manage conversations across WhatsApp, Instagram, and Facebook. When you connect these channels, your conversation data is shared with Meta according to their terms. Meta's Privacy Policy governs their data handling: https://www.facebook.com/privacy/policy
4.2 TikTok Integration (Coming Soon)
TikTok messaging is a planned channel integration and is not yet available on the Platform. Once live, your TikTok conversation data will be processed according to TikTok's Privacy Policy: https://www.tiktok.com/legal/page/us/privacy-policy
4.3 Core Service Providers
- Hosting: IONOS for our application and database servers (EU-based)
- File Storage: DigitalOcean Spaces (Frankfurt, EU) for attachments and media
- Payment Processing: Stripe (billing data, transaction records)
- Email: Hostinger for transactional email delivery
- Push Notifications: Expo for mobile push delivery
- AI processing: OpenAI — powers the AI features for workspaces that have not connected their own AI provider. It acts as our processor under a data processing agreement, receives only the data an AI feature needs, and does not use it to train its models
- Our database, cache, and background job runner are self-hosted on our own servers and are not shared with any external company
4.4 Optional Integrations You Control
The following only receive data if and when you, as Workspace Administrator, choose to connect them using your own account, tenant, or API key. Your use of them is governed by your own agreement with that provider:
- Your own AI provider (OpenAI, Anthropic/Claude, Google Gemini, Azure OpenAI, or a self-hosted/custom endpoint) — replaces our AI processor when you supply your own API key
- Tavily — AI web-search tool, using your own API key
- Microsoft Outlook — email channel connected via your own Microsoft account
- Calendly — calendar/booking integration connected via your own Calendly account
- Magicline — gym/studio management sync connected via your own Magicline tenant
5. AI Features and the Data They Send
Convelly includes AI features: drafting and improving replies, translating and summarizing conversations, transcribing voice dictation, scheduled AI follow-ups, automations that run on triggers and conditions, and a workspace assistant that answers questions about your own data. Nothing is sent to an AI service unless you or your workspace administrator start one of these features.
5.1 What is sent
- The text you type into an AI feature, and voice recordings you dictate — the recording itself is sent to be converted to text
- The messages of the conversation you ask the AI to reply to, translate or summarize
- The workspace records needed to answer you — for example a contact's name and phone number, bookings, deals, notes, and any files you attach
5.2 Who receives it
For workspaces that have not connected their own AI provider, the data is sent to OpenAI, which processes it on our behalf as our processor under a data processing agreement. If your workspace has connected its own AI provider — OpenAI, Anthropic/Claude, Google Gemini, Azure OpenAI, or a self-hosted endpoint — the data goes to that provider instead, under your own agreement with them.
5.3 How it is used
The data is used only to produce the result you asked for. Our AI processor does not use it to train its models, and we never sell it or share it for advertising. AI processing is clearly labelled in the product, and AI output is a suggestion you review — not an automated decision made about you.
5.4 Your permission
In our mobile app we ask for your permission before any data is sent to an AI service for the first time, and you can withdraw it at any time under You → AI features. If you decline, the AI features stay switched off and the rest of the platform keeps working. In the web app, a workspace administrator decides whether AI features are enabled for the workspace.
6. Data Security
We implement security measures including:
- JWT-based authentication with secure token storage
- End-to-end encryption for sensitive data
- Role-based access control (ADMIN, MEMBER)
- Rate limiting to prevent unauthorized access
- Regular security updates and monitoring
- Secure integration encryption for third-party tokens
7. Data Retention
- Active Data: Retained while your workspace is active
- Deleted Data: Conversations and messages can be deleted by workspace administrators
- Backups: May be retained for disaster recovery purposes
- Compliance: Data retained as required by law
8. Your Rights
Depending on your location, you may have the right to:
- Access your personal information
- Correct inaccurate data
- Request deletion of your data
- Opt-out of certain data processing
- Data portability
9. Children's Privacy
Convelly is not intended for users under 16 years old. We do not knowingly collect information from children under 16.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, which may have different privacy laws.
11. Changes to This Privacy Policy
We may update this Privacy Policy periodically. Continued use of the platform after changes constitutes acceptance of the updated policy.
12. Contact Us
For privacy inquiries or concerns:
- Support form: www.convelly.com/support
- Address: Be Digital AI e.U., Pressgasse 24/18, 1040 Wien, Austria
Your privacy is important to us.