What personal data Tephlo handles, why, for how long, who else sees it, and what you can ask us to do about it. Written to match what the software actually does.
Tephlo is used by businesses to answer their customers. That means two very different sets of people, with two different answers.
[REGISTERED COMPANY NAME] operates Tephlo. Depending on whose data is involved, we act in one of two roles:
A workspace answers on WhatsApp, Telegram or a chat widget on the business’s own website. For each conversation the platform holds:
Some data is refused in code rather than discouraged in policy. The assistant will not ask you for, and will not store as conversation state, fields it recognises as payment instruments, credentials, bank details or government identity numbers — card and CVV numbers, PINs, passwords, one-time codes, IBAN and account numbers, passport and national identity numbers, dates of birth. The rule recognises these in English, French and Spanish, because the platform’s first market is francophone and a filter that only speaks English only protects English speakers.
Where text is stored for optional quality review, or extracted from a document you send, recognisable emails, phone numbers, long card-like numbers and labelled codes are replaced with markers before it is stored.
Our public sites — the marketing site, the documentation site and this legal site — run no analytics, no advertising scripts and no third-party tracking of any kind. Their content security policy blocks third-party scripts outright. The only browser storage involved is a currency preference you set yourself on the pricing page. The cookie notice lists everything, including the session cookies the signed-in consoles need.
Our hosting and infrastructure providers process connection data such as IP addresses in server logs for security and abuse prevention, as any web host does.
For customer conversations, the workspace you contacted decides the purpose and the lawful basis. We process on their documented instructions and tell them what the platform makes possible.
Where we are the controller, our purposes and bases are:
| Purpose | Data | Basis |
|---|---|---|
| Providing accounts and the consoles | Account details, sign-in records | Performance of our contract with your business |
| Securing the platform | Authentication records, audit trails, lockout counters, error reports | Legitimate interests — keeping a multi-tenant platform safe |
| Operational email | Email address, delivery records | Performance of the contract; consent for escalation alerts, which are confirmed by email first and can be stopped at any time |
| Support and correspondence | What you send us | Legitimate interests — answering you |
| Meeting legal obligations | Records we are required to keep | Legal obligation |
We do not use personal data for advertising, we do not sell it, and we do not use customer conversations to train AI models.
These are the platform’s configured defaults. A workspace or the platform operator can set shorter periods, and an explicit deletion request takes effect immediately regardless of them.
| What | Kept for | Then |
|---|---|---|
| In-conversation working state | 30 minutes after the last message | Expires automatically; deleted immediately on erasure |
| Web chat widget session | 1 hour of inactivity | Expires; the widget starts a new session |
| Conversations the assistant handled | 365 days after the last activity, by default | Deleted by a scheduled sweep, with their messages and escalationsConversations waiting for a person, or being handled by one, are not age-deleted — they stay until resolved or explicitly deleted. |
| Delivery records for outbound messages | 7 days after publication, by default | Deleted |
| Duplicate-delivery protection records | 30 days after completion, by default | Deleted |
| Files you send to a workspace | Deleted as soon as the text has been extracted, by default | Extracted text is stored encrypted for 7 days by default and can be configured to never be stored at all |
| Optional quality-review excerpts | 30 days by default, where a workspace enables them | Deleted; sensitive values are masked before storage |
| Remembered customer facts | Until the workspace deletes them, or the workspace is deleted | No automatic expiry todayOnly statements a customer makes about themselves are stored. The data model supports expiring an entry the platform merely inferred; nothing currently writes one. |
| Staff accounts | For as long as the account exists | Deleted with the account or the workspace |
| Administrative audit records | Kept as platform evidence | Survive workspace deletion; contain no message content |
| Encrypted database backups | Rolling schedule — hourly, daily and monthly copies | Pruned as they age out; deleted data leaves backups then, not at the moment of deletion |
The sub-processor page is the complete, current list, with what each provider is used for and where it operates. In outline:
We may also disclose data where the law requires it, or to establish or defend legal claims. If our business is transferred, data moves with it and this policy continues to apply until it is replaced.
The providers above operate internationally, and the AI provider may route a request to a model provider in another country. We cannot promise that data stays inside one country or region, and this policy will not pretend otherwise.
Where personal data protected by the law of [APPLICABLE DATA PROTECTION LAW] leaves that jurisdiction, the transfer mechanism relied on is [TRANSFER MECHANISM] — this must be confirmed by counsel for each provider before this policy is published as final.
Depending on where you are, you may have rights to access your data, correct it, delete it, restrict or object to its use, receive a portable copy, and withdraw consent you gave.
If you messaged a business that uses Tephlo, ask that business: they are the controller, and their administrators have two tools built into the console.
If you run a workspace, write to us using the contact details below. We will verify who you are before acting — usually by using an address already on the account — and answer within one month, or tell you why we need longer.
The Security Overview is the detailed answer. The short version: each workspace’s data is separated and every request is scoped to the account making it; connections are encrypted; channel credentials, authentication secrets, email bodies and extracted document text are encrypted at rest; passwords are hashed; sensitive values are stripped from logs; administrative actions are recorded in audit trails, two of which the database itself refuses to let anyone alter.
Tephlo is a business tool and is not directed at children. Workspaces must not configure an assistant to collect personal data from children below the age of consent in their jurisdiction, and must not use the platform for services aimed at children without a lawful basis and appropriate safeguards. If you believe a child’s data has reached the platform, tell us and we will work with the workspace to remove it.
Replies are generated automatically, and the platform decides automatically when to bring in a person — for example when it is not confident, when a topic is sensitive, when someone asks for a human, or when a customer is visibly frustrated. These decisions affect how a conversation is handled; they do not by themselves produce legal or similarly significant effects about a person, and workspaces are required by the Acceptable Use Policy not to use the assistant to make such decisions. A human is always reachable through escalation.
The date at the top of this page is the date this text last changed. Material changes are notified to workspace administrators by email before they take effect. New sub-processors appear on the sub-processor page before they begin processing.
Write to support@tephlo.com, or to the data protection contact at [DATA PROTECTION CONTACT]. Postal address: [REGISTERED COMPANY NAME], [REGISTERED ADDRESS].
If you are not satisfied with our answer, you can complain to the supervisory authority in your country. In [OPERATING JURISDICTION] that authority is [SUPERVISORY AUTHORITY]. We would rather hear from you first, but you are not required to come to us before going to them.