ANYTIMEBOT

Política de privacidad

Última actualización: 29 de agosto de 2026 · Versión 2026-08

Esta Política de privacidad explica cómo ANYTIMEBOT trata los datos personales cuando creas una cuenta, agendas o diriges reuniones, utilizas el asistente de IA o conectas un servicio de mensajería o calendario.

1. Responsable y roles

ANYTIMEBOT is the controller for account, billing, security and platform-usage data. For data submitted by a business through its booking page, that business may be the controller and ANYTIMEBOT acts as its processor. The applicable controller/processor relationship and contact details must be confirmed in the customer agreement.

2. Datos que tratamos

  • Account data: name, email, username, profile image, timezone and authentication provider.
  • Scheduling data: booking pages, event types, availability, guest name, email, phone, booking and form data.
  • Communication data: WhatsApp/Twilio phone numbers, message content, delivery status and provider identifiers.
  • AI and knowledge-base data: bot instructions, uploaded documents, URLs and conversation context.
  • Technical data: IP address, user agent, cookies, logs and security events.
  • Consent records: purpose, policy version, date, withdrawal status and technical evidence.

3. Finalidades y bases jurídicas

  • Account and contract administration: performance of the service contract.
  • Bookings and notifications: performance of the requested service and, where required, consent.
  • AI responses and messaging: performance of the requested feature and the customer's instructions.
  • Security, fraud prevention and service reliability: legitimate interests, balanced against data-subject rights.
  • Optional recording or other optional processing: explicit consent, which can be withdrawn at any time.
  • Legal and tax obligations: compliance with applicable law.

4. Encargados y proveedores de servicios

We use the following providers for the purposes shown below. The exact region and applicable contractual safeguards must be confirmed in the current data-processing agreements and provider terms before relying on them for a particular customer.

ProviderPurposeLocation / transfer note
VercelHosting, serverless functions and deploymentRegion depends on project configuration; verify DPA and transfer mechanism.
Neon (AWS)PostgreSQL application databaseCurrent production connection observed in AWS us-east-1 (United States); extra-EEA transfer safeguards required.
ConvexBot conversations and event ingestionRegion and subprocessors depend on deployment; verify current DPA and transfer mechanism.
OpenAIAI response generation and embeddings where enabledMay involve processing outside the EEA; use DPA and applicable SCC/adequacy safeguard.
WhatsApp messaging serviceWhatsApp connection, QR pairing and message deliveryProvider infrastructure is outside the application; verify DPA, location and transfer safeguards.
TwilioOptional WhatsApp messaging integrationMay involve international processing; governed by Twilio DPA and applicable safeguards.
StripePayments, subscriptions and billing portalPayment processing and international transfer safeguards are governed by Stripe terms/DPA.
GoogleOptional sign-in and calendar synchronizationProcessing is governed by Google terms and applicable transfer safeguards.

5. Transferencias internacionales

Some providers may process data outside the European Economic Area. In particular, the current PostgreSQL production endpoint is hosted by Neon on AWS in us-east-1, United States. Where a transfer is not covered by an adequacy decision, it must be covered by an appropriate safeguard such as the EU Standard Contractual Clauses, together with a transfer-impact assessment where required. We do not represent that an international transfer is lawful solely because a provider is listed here; the controller must verify and maintain the applicable DPA and safeguards.

6. Retention

Operational data is removed under the configured retention policy. Unless a longer period is required by law or a documented customer instruction, cancelled bookings and WhatsApp messages are scheduled for deletion after 365 days, completed bookings after 730 days, and consent evidence after 1,825 days. Retention jobs run automatically and complete account erasure requests separately. These periods must be reviewed by the controller/DPO and adjusted where necessary.

7. Tus derechos conforme al RGPD

Subject to applicable law, you may request access, correction, erasure, restriction, objection, portability, or withdrawal of consent. Authenticated users can export their data from Settings and request account deletion there. Requests may also be sent to privacy@anytimebot.app. You may lodge a complaint with your local supervisory authority.

8. Security

We use access controls, authenticated endpoints, encrypted transport, hashed passwords and provider security controls. No online service can guarantee absolute security. Tenant isolation is currently logical within a shared PostgreSQL deployment; physical per-tenant databases are a planned architecture phase and are not represented as currently implemented.

9. Contacto

Questions or rights requests: privacy@anytimebot.app. The controller should designate and publish a data-protection contact or DPO where legally required.