Privacy Policy
Last updated: June 30, 2026
1. Who we are (Data Controller)
AIgentBird, operated by Andrea Roques (Entrepreneur Individuel), is the data controller for the personal data described in this policy.
- Address: 5 rue de la source, 92370 Chaville, France
- Contact for privacy matters: [email protected]
- Supervisory authority: CNIL (France) — www.cnil.fr
2. What data we collect
| Category | Examples | Source |
|---|---|---|
| Identification & account | Name, business/salon name, email, phone, password (hashed) | You provide |
| Billing | Subscription plan, invoices, card data handled solely by Stripe (we never store card numbers) | You / Stripe |
| Usage & technical | Log data, actions in the app | Automatic |
| Support & communications | Messages, support tickets | You provide |
3. Why we use it & our legal basis (GDPR art. 6)
| Purpose | Legal basis |
|---|---|
| Create your account and provide the service | Performance of a contract (art. 6.1.b) |
| Billing, invoicing, accounting | Contract + legal obligation (art. 6.1.b / 6.1.c) |
| Security, fraud prevention, service improvement | Legitimate interest (art. 6.1.f) |
| Customer support | Contract / legitimate interest |
| Marketing emails to you | Consent (art. 6.1.a) — opt-in, with unsubscribe in every email |
| Complying with legal/tax obligations | Legal obligation (art. 6.1.c) |
4. Automated processing / AI features
AIgentBird operates an AI agent that can read and respond to messages exchanged through your connected WhatsApp Business account, your Telegram account, or our ready-to-use WhatsApp Business number and Telegram bot, in order to answer client questions, book or modify appointments, send reminders and ask for reviews.
- AI disclosure (EU AI Act, art. 50): from 2 August 2026, anyone interacting with the agent must be informed they are dealing with an AI system. The agent identifies itself as an AI at the start of the interaction.
- Automated decisions (GDPR art. 22): the agent does not make decisions producing legal or similarly significant effects on a person without human involvement.
- Message content is processed by OpenAI as a sub-processor under its data processing terms. OpenAI does not use data submitted via its API to train its models, and applies only limited retention for abuse monitoring.
5. Who we share data with (recipients & sub-processors)
We share data only with service providers that help us run AIgentBird, under contract:
- Stripe — payment processing (Stripe Privacy Policy applies)
- Cloudflare — storage (R2) of photos and WhatsApp-linked content
- Meta / WhatsApp — WhatsApp Business messaging, where you enable the WhatsApp AI agent
- OpenAI — powers the AI agent that processes WhatsApp messages
- Mailtrap — email delivery platform
All other data is hosted on our own server located in Europe. We do not sell your personal data.
6. International transfers
Where a provider processes data outside the EU/EEA, the transfer is covered by appropriate safeguards (European Commission Standard Contractual Clauses or an adequacy decision).
7. How long we keep it
| Data | Retention |
|---|---|
| Account data | For the life of your account + 30 days after closure |
| Invoices / accounting | 10 years (French legal obligation) |
| Marketing consent data | Until withdrawal, then deleted/anonymised |
8. Your rights
Under the GDPR you may: access your data, correct it, erase it, restrict or object to processing, request portability, and withdraw consent at any time. To exercise these, email [email protected]. We respond within one month.
You may also lodge a complaint with the CNIL (www.cnil.fr) or with the supervisory authority of your country.
9. Security
We take the security of your data seriously and apply appropriate technical and organisational measures to protect it against unauthorised access, loss, alteration or disclosure. These include:
- encryption of data in transit (TLS/HTTPS) for all connections to the Service and to our providers;
- access to your data restricted to AIgentBird’s founders;
- use of reputable infrastructure and sub-processors (such as Cloudflare, Stripe and OpenAI) that maintain their own recognised security standards, including encryption at rest on their platforms;
- core data hosted on our own server located in Europe.
No system can be guaranteed completely secure. If a personal data breach affects your data, we will act without undue delay to address it and will notify you and, where legally required, the competent supervisory authority (in France, the CNIL).
10. Changes
We may update this policy; the “last updated” date will change and material changes will be notified.