Política de privacidad
Última actualización: 29 de agosto de 2026 · Versión 2026-08
Esta Política de privacidad explica cómo ANYTIMEBOT trata los datos personales cuando creas una cuenta, agendas o diriges reuniones, utilizas el asistente de IA o conectas un servicio de mensajería o calendario.
1. Responsable y roles
ANYTIMEBOT is the controller for account, billing, security and platform-usage data. For data submitted by a business through its booking page, that business may be the controller and ANYTIMEBOT acts as its processor. The applicable controller/processor relationship and contact details must be confirmed in the customer agreement.
2. Datos que tratamos
- Account data: name, email, username, profile image, timezone and authentication provider.
- Scheduling data: booking pages, event types, availability, guest name, email, phone, booking and form data.
- Communication data: WhatsApp/Twilio phone numbers, message content, delivery status and provider identifiers.
- AI and knowledge-base data: bot instructions, uploaded documents, URLs and conversation context.
- Technical data: IP address, user agent, cookies, logs and security events.
- Consent records: purpose, policy version, date, withdrawal status and technical evidence.
3. Finalidades y bases jurídicas
- Account and contract administration: performance of the service contract.
- Bookings and notifications: performance of the requested service and, where required, consent.
- AI responses and messaging: performance of the requested feature and the customer's instructions.
- Security, fraud prevention and service reliability: legitimate interests, balanced against data-subject rights.
- Optional recording or other optional processing: explicit consent, which can be withdrawn at any time.
- Legal and tax obligations: compliance with applicable law.
4. Encargados y proveedores de servicios
We use the following providers for the purposes shown below. The exact region and applicable contractual safeguards must be confirmed in the current data-processing agreements and provider terms before relying on them for a particular customer.
| Provider | Purpose | Location / transfer note |
|---|---|---|
| Vercel | Hosting, serverless functions and deployment | Region depends on project configuration; verify DPA and transfer mechanism. |
| Neon (AWS) | PostgreSQL application database | Current production connection observed in AWS us-east-1 (United States); extra-EEA transfer safeguards required. |
| Convex | Bot conversations and event ingestion | Region and subprocessors depend on deployment; verify current DPA and transfer mechanism. |
| OpenAI | AI response generation and embeddings where enabled | May involve processing outside the EEA; use DPA and applicable SCC/adequacy safeguard. |
| WhatsApp messaging service | WhatsApp connection, QR pairing and message delivery | Provider infrastructure is outside the application; verify DPA, location and transfer safeguards. |
| Twilio | Optional WhatsApp messaging integration | May involve international processing; governed by Twilio DPA and applicable safeguards. |
| Stripe | Payments, subscriptions and billing portal | Payment processing and international transfer safeguards are governed by Stripe terms/DPA. |
| Optional sign-in and calendar synchronization | Processing is governed by Google terms and applicable transfer safeguards. |
5. Transferencias internacionales
Some providers may process data outside the European Economic Area. In particular, the current PostgreSQL production endpoint is hosted by Neon on AWS in us-east-1, United States. Where a transfer is not covered by an adequacy decision, it must be covered by an appropriate safeguard such as the EU Standard Contractual Clauses, together with a transfer-impact assessment where required. We do not represent that an international transfer is lawful solely because a provider is listed here; the controller must verify and maintain the applicable DPA and safeguards.
6. Retention
Operational data is removed under the configured retention policy. Unless a longer period is required by law or a documented customer instruction, cancelled bookings and WhatsApp messages are scheduled for deletion after 365 days, completed bookings after 730 days, and consent evidence after 1,825 days. Retention jobs run automatically and complete account erasure requests separately. These periods must be reviewed by the controller/DPO and adjusted where necessary.
7. Tus derechos conforme al RGPD
Subject to applicable law, you may request access, correction, erasure, restriction, objection, portability, or withdrawal of consent. Authenticated users can export their data from Settings and request account deletion there. Requests may also be sent to privacy@anytimebot.app. You may lodge a complaint with your local supervisory authority.
8. Security
We use access controls, authenticated endpoints, encrypted transport, hashed passwords and provider security controls. No online service can guarantee absolute security. Tenant isolation is currently logical within a shared PostgreSQL deployment; physical per-tenant databases are a planned architecture phase and are not represented as currently implemented.
9. Contacto
Questions or rights requests: privacy@anytimebot.app. The controller should designate and publish a data-protection contact or DPO where legally required.

