Kikoach
English Español Français Italiano Português
Features Pricing
English Español Français Italiano Português

Privacy Policy

Last updated: June 30, 2026

1. Who we are (Data Controller)

AIgentBird, operated by Andrea Roques (Entrepreneur Individuel), is the data controller for the personal data described in this policy.

  • Address: 5 rue de la source, 92370 Chaville, France
  • Contact for privacy matters: [email protected]
  • Supervisory authority: CNIL (France) — www.cnil.fr

2. What data we collect

CategoryExamplesSource
Identification & accountName, business/salon name, email, phone, password (hashed)You provide
BillingSubscription plan, invoices, card data handled solely by Stripe (we never store card numbers)You / Stripe
Usage & technicalLog data, actions in the appAutomatic
Support & communicationsMessages, support ticketsYou provide

3. Why we use it & our legal basis (GDPR art. 6)

PurposeLegal basis
Create your account and provide the servicePerformance of a contract (art. 6.1.b)
Billing, invoicing, accountingContract + legal obligation (art. 6.1.b / 6.1.c)
Security, fraud prevention, service improvementLegitimate interest (art. 6.1.f)
Customer supportContract / legitimate interest
Marketing emails to youConsent (art. 6.1.a) — opt-in, with unsubscribe in every email
Complying with legal/tax obligationsLegal obligation (art. 6.1.c)

4. Automated processing / AI features

AIgentBird operates an AI agent that can read and respond to messages exchanged through your connected WhatsApp Business account, your Telegram account, or our ready-to-use WhatsApp Business number and Telegram bot, in order to answer client questions, book or modify appointments, send reminders and ask for reviews.

  • AI disclosure (EU AI Act, art. 50): from 2 August 2026, anyone interacting with the agent must be informed they are dealing with an AI system. The agent identifies itself as an AI at the start of the interaction.
  • Automated decisions (GDPR art. 22): the agent does not make decisions producing legal or similarly significant effects on a person without human involvement.
  • Message content is processed by OpenAI as a sub-processor under its data processing terms. OpenAI does not use data submitted via its API to train its models, and applies only limited retention for abuse monitoring.

5. Who we share data with (recipients & sub-processors)

We share data only with service providers that help us run AIgentBird, under contract:

  • Stripe — payment processing (Stripe Privacy Policy applies)
  • Cloudflare — storage (R2) of photos and WhatsApp-linked content
  • Meta / WhatsApp — WhatsApp Business messaging, where you enable the WhatsApp AI agent
  • OpenAI — powers the AI agent that processes WhatsApp messages
  • Mailtrap — email delivery platform

All other data is hosted on our own server located in Europe. We do not sell your personal data.

6. International transfers

Where a provider processes data outside the EU/EEA, the transfer is covered by appropriate safeguards (European Commission Standard Contractual Clauses or an adequacy decision).

7. How long we keep it

DataRetention
Account dataFor the life of your account + 30 days after closure
Invoices / accounting10 years (French legal obligation)
Marketing consent dataUntil withdrawal, then deleted/anonymised

8. Your rights

Under the GDPR you may: access your data, correct it, erase it, restrict or object to processing, request portability, and withdraw consent at any time. To exercise these, email [email protected]. We respond within one month.

You may also lodge a complaint with the CNIL (www.cnil.fr) or with the supervisory authority of your country.

9. Security

We take the security of your data seriously and apply appropriate technical and organisational measures to protect it against unauthorised access, loss, alteration or disclosure. These include:

  • encryption of data in transit (TLS/HTTPS) for all connections to the Service and to our providers;
  • access to your data restricted to AIgentBird’s founders;
  • use of reputable infrastructure and sub-processors (such as Cloudflare, Stripe and OpenAI) that maintain their own recognised security standards, including encryption at rest on their platforms;
  • core data hosted on our own server located in Europe.

No system can be guaranteed completely secure. If a personal data breach affects your data, we will act without undue delay to address it and will notify you and, where legally required, the competent supervisory authority (in France, the CNIL).

10. Changes

We may update this policy; the “last updated” date will change and material changes will be notified.

Kikoach
Features Pricing
Legal notice · Privacy policy · Terms & conditions

© 2026 Kikoach, powered by AIgentBird. Built with love, exclusively for coaches.