Privacy Policy

Privacy Policy

What personal data Tephlo handles, why, for how long, who else sees it, and what you can ask us to do about it. Written to match what the software actually does.

Last updated 15 August 2026Revision Draft 1.0Effective [EFFECTIVE DATE]

In plain language

Tephlo is used by businesses to answer their customers. That means two very different sets of people, with two different answers.

  • If you messaged a business that uses Tephlo: your messages and the phone number, Telegram id or random web id you wrote from are stored so the business can answer you and keep the history. The business decides why — we handle it on their instructions, and they can export or delete your data.
  • If you run a workspace: we hold your name, work email, an encrypted password, your role and sign-in records, because that is what an account is.
  • Messages are sent to an AI provider to generate a reply. They are not used to train AI models, and they are never sold.
  • Some conversation context lives only in short-lived memory — the in-conversation working state expires after 30 minutes.
  • This site sets no tracking cookies at all. See the cookie notice.

1. Two different roles, and why it matters

[REGISTERED COMPANY NAME] operates Tephlo. Depending on whose data is involved, we act in one of two roles:

Processor — for the conversations businesses have with their customers
A business (our customer, called a “workspace” here) decides to run an assistant, decides what knowledge it answers from, and decides how long conversations are kept. They are the controller. We store and process that data on their instructions, under the Data Processing Agreement. If you are a customer of that business and want your data removed, the fastest route is to ask them — they hold the controls.
Controller — for the accounts of the people who run a workspace
When someone signs up, is invited to a workspace, signs in, contacts support, or visits our public sites, we decide why that data is handled. That is what sections 4, 5 and 6 of this policy describe.

2. What is collected from people who message a business

A workspace answers on WhatsApp, Telegram or a chat widget on the business’s own website. For each conversation the platform holds:

  • Your channel identifier. On WhatsApp this is the phone number the message came from; on Telegram, your Telegram user id; in the web widget, a random identifier the widget generates in your browser and reuses on that site — no name, no email, no account.
  • Message content. What you wrote and what was sent back, including replies written by a human agent, with timestamps and the provider’s message id (used to avoid processing the same message twice).
  • Conversation metadata. The channel, which business identity received the message, whether the assistant or a person is handling it, when it was last active, and — where a conversation was escalated — the reason and whether it was resolved.
  • Working state during a conversation. What you appear to be trying to do, the option you chose, details you already gave, and the question last asked, so nobody has to repeat themselves. This is held in fast temporary storage and expires 30 minutes after the last message.
  • Routing records, on shared numbers. Where a business is reached through a number the platform shares between businesses, a record of which business a conversation was routed to is kept using a salted one-way hash of your identifier rather than the identifier itself.
  • Captured requests. If you ask for a callback, make a complaint or request a refund, a ticket is created for the team with a short summary of what you asked for.
  • Remembered facts, where a workspace enables customer memory. Short statements you make about yourself — a name, a preference, a product you own — can be stored so you do not have to repeat them next time. Only statements you actually make are stored, and no more than a dozen are ever used in a reply.
  • Media you send, where those features are enabled. Voice notes can be transcribed to text; documents can be scanned for malware and read for the answer. Both are off unless the platform and the workspace turn them on. What a shared location contains is used at the moment it arrives to work out which of the business’s branches is nearest; a shared contact card is acknowledged and is never saved to an address book or contacted automatically.
  • Operational measurements. Counts and categories — how a turn ended, how many tokens a reply used, how long it took. These carry no message content and no identifier for you.

3. What the assistant refuses to collect

Some data is refused in code rather than discouraged in policy. The assistant will not ask you for, and will not store as conversation state, fields it recognises as payment instruments, credentials, bank details or government identity numbers — card and CVV numbers, PINs, passwords, one-time codes, IBAN and account numbers, passport and national identity numbers, dates of birth. The rule recognises these in English, French and Spanish, because the platform’s first market is francophone and a filter that only speaks English only protects English speakers.

Where text is stored for optional quality review, or extracted from a document you send, recognisable emails, phone numbers, long card-like numbers and labelled codes are replaced with markers before it is stored.

Being exact about this. Pattern matching is a strong filter, not a guarantee. If you type a card number into a chat unprompted it may be stored as ordinary message text. Never send card details, passwords or one-time codes in a chat message — no legitimate business needs them that way.

4. What is collected from the people who run a workspace

  • Account details. Name, work email address, a hashed password, role, whether the account is active, and — if you choose to use them for password recovery — a phone number or linked Telegram chat.
  • Sign-in and security records. Session and refresh-token records, multi-factor authentication state (the secret itself is stored encrypted), failed sign-in counters and lockouts.
  • Signup details. For self-serve signup, the email address, company name and display name given, held against a verification link until it is used or expires.
  • Administrative audit records. Who changed a channel credential, who ran a privacy export or deletion and the reason they gave, who changed routing or platform configuration. These record the action, not the content.
  • Email delivery records. Verification, invitation, password reset and escalation-alert emails are recorded with the recipient and subject; the body is stored encrypted and cleared once delivery reaches a final state. Escalation alerts deliberately carry no customer message content — they say a conversation needs a person and link to the console.
  • Support correspondence. What you send us when you ask for help.

5. Website visitors

Our public sites — the marketing site, the documentation site and this legal site — run no analytics, no advertising scripts and no third-party tracking of any kind. Their content security policy blocks third-party scripts outright. The only browser storage involved is a currency preference you set yourself on the pricing page. The cookie notice lists everything, including the session cookies the signed-in consoles need.

Our hosting and infrastructure providers process connection data such as IP addresses in server logs for security and abuse prevention, as any web host does.

6. Why we handle this data, and on what basis

For customer conversations, the workspace you contacted decides the purpose and the lawful basis. We process on their documented instructions and tell them what the platform makes possible.

Where we are the controller, our purposes and bases are:

Processing where we are the controller
PurposeDataBasis
Providing accounts and the consolesAccount details, sign-in recordsPerformance of our contract with your business
Securing the platformAuthentication records, audit trails, lockout counters, error reportsLegitimate interests — keeping a multi-tenant platform safe
Operational emailEmail address, delivery recordsPerformance of the contract; consent for escalation alerts, which are confirmed by email first and can be stopped at any time
Support and correspondenceWhat you send usLegitimate interests — answering you
Meeting legal obligationsRecords we are required to keepLegal obligation

We do not use personal data for advertising, we do not sell it, and we do not use customer conversations to train AI models.

7. How long data is kept

These are the platform’s configured defaults. A workspace or the platform operator can set shorter periods, and an explicit deletion request takes effect immediately regardless of them.

WhatKept forThen
In-conversation working state30 minutes after the last messageExpires automatically; deleted immediately on erasure
Web chat widget session1 hour of inactivityExpires; the widget starts a new session
Conversations the assistant handled365 days after the last activity, by defaultDeleted by a scheduled sweep, with their messages and escalationsConversations waiting for a person, or being handled by one, are not age-deleted — they stay until resolved or explicitly deleted.
Delivery records for outbound messages7 days after publication, by defaultDeleted
Duplicate-delivery protection records30 days after completion, by defaultDeleted
Files you send to a workspaceDeleted as soon as the text has been extracted, by defaultExtracted text is stored encrypted for 7 days by default and can be configured to never be stored at all
Optional quality-review excerpts30 days by default, where a workspace enables themDeleted; sensitive values are masked before storage
Remembered customer factsUntil the workspace deletes them, or the workspace is deletedNo automatic expiry todayOnly statements a customer makes about themselves are stored. The data model supports expiring an entry the platform merely inferred; nothing currently writes one.
Staff accountsFor as long as the account existsDeleted with the account or the workspace
Administrative audit recordsKept as platform evidenceSurvive workspace deletion; contain no message content
Encrypted database backupsRolling schedule — hourly, daily and monthly copiesPruned as they age out; deleted data leaves backups then, not at the moment of deletion

8. Who else receives this data

The sub-processor page is the complete, current list, with what each provider is used for and where it operates. In outline:

  • An AI provider receives the conversation and the relevant passages of the workspace’s knowledge in order to generate a reply.
  • WhatsApp (Meta) and Telegram carry the messages themselves — they see everything sent over their own channel, under their own terms.
  • Hosting, database and storage providers hold the data at rest.
  • An email provider delivers verification, invitation, password reset and alert emails to staff addresses.
  • Optional providers — speech-to-text, image reading, web search and error monitoring — are off unless configured and are listed with their status.

We may also disclose data where the law requires it, or to establish or defend legal claims. If our business is transferred, data moves with it and this policy continues to apply until it is replaced.

9. International transfers

The providers above operate internationally, and the AI provider may route a request to a model provider in another country. We cannot promise that data stays inside one country or region, and this policy will not pretend otherwise.

Where personal data protected by the law of [APPLICABLE DATA PROTECTION LAW] leaves that jurisdiction, the transfer mechanism relied on is [TRANSFER MECHANISM] — this must be confirmed by counsel for each provider before this policy is published as final.

10. Your rights, and how they work here

Depending on where you are, you may have rights to access your data, correct it, delete it, restrict or object to its use, receive a portable copy, and withdraw consent you gave.

If you messaged a business that uses Tephlo, ask that business: they are the controller, and their administrators have two tools built into the console.

  • Export produces a structured copy of one customer’s data with that business: every conversation, the full transcript, escalations, shared-number sessions, routing records and memberships.
  • Deletion permanently removes conversations and their messages, escalations, transcripts of media in them, shared-number sessions, routing records, memberships, queued outbound messages and in-flight processing records, and clears the short-lived working state. Work already accepted before the deletion is suppressed rather than delivered afterwards, so a reply cannot arrive after someone asked to be forgotten. Both actions are recorded in an audit trail that identifies the subject only by a salted hash.
What deletion covers. One request removes the conversations and their messages, the escalations raised from them, the routing and session records, any queued deliveries, the facts remembered about that person by the customer-memory feature, and the tickets captured for the team (callbacks, complaints, refund requests) with their summaries. What remains is an audit record of the deletion itself, which identifies the person only by a salted hash and exists so the erasure can be proven to have happened.

If you run a workspace, write to us using the contact details below. We will verify who you are before acting — usually by using an address already on the account — and answer within one month, or tell you why we need longer.

11. How the data is protected

The Security Overview is the detailed answer. The short version: each workspace’s data is separated and every request is scoped to the account making it; connections are encrypted; channel credentials, authentication secrets, email bodies and extracted document text are encrypted at rest; passwords are hashed; sensitive values are stripped from logs; administrative actions are recorded in audit trails, two of which the database itself refuses to let anyone alter.

What we do not claim. There is no SOC 2 report, no ISO 27001 certificate, and message content is not end-to-end encrypted — the platform has to read a message to answer it.

12. Children

Tephlo is a business tool and is not directed at children. Workspaces must not configure an assistant to collect personal data from children below the age of consent in their jurisdiction, and must not use the platform for services aimed at children without a lawful basis and appropriate safeguards. If you believe a child’s data has reached the platform, tell us and we will work with the workspace to remove it.

13. Automated processing

Replies are generated automatically, and the platform decides automatically when to bring in a person — for example when it is not confident, when a topic is sensitive, when someone asks for a human, or when a customer is visibly frustrated. These decisions affect how a conversation is handled; they do not by themselves produce legal or similarly significant effects about a person, and workspaces are required by the Acceptable Use Policy not to use the assistant to make such decisions. A human is always reachable through escalation.

14. Changes to this policy

The date at the top of this page is the date this text last changed. Material changes are notified to workspace administrators by email before they take effect. New sub-processors appear on the sub-processor page before they begin processing.

15. Contact and complaints

Write to support@tephlo.com, or to the data protection contact at [DATA PROTECTION CONTACT]. Postal address: [REGISTERED COMPANY NAME], [REGISTERED ADDRESS].

If you are not satisfied with our answer, you can complain to the supervisory authority in your country. In [OPERATING JURISDICTION] that authority is [SUPERVISORY AUTHORITY]. We would rather hear from you first, but you are not required to come to us before going to them.