بوسطجي
Home Pricing Blog Privacy Terms
العربية Log in Start free
  • Home
  • Pricing
  • Blog
  • Privacy
  • Terms
  • العربية
  • Start free
Bostagy legal

Privacy Policy

How Bostagy processes data for its customer-communications platform in Egypt and Saudi Arabia.

Version
1.0
Effective
27 September 2026
Last updated
27 September 2026
Review status

This is a compliance-oriented draft based on product behavior visible in the repository. It is not a legal certification. Marked items require business confirmation or professional legal review before commercial launch.

On this page
  1. 1. Who we are and this policy's scope
  2. 2. Information we process
  3. 3. Why we process personal data
  4. 4. Lawful grounds
  5. 5. Consent and direct marketing
  6. 6. Cookies and analytics
  7. 7. Who may receive data
  8. 8. International transfers
  9. 9. Retention and destruction
  10. 10. Individual rights
  11. 11. Children's data
  12. 12. Security
  13. 13. Personal-data breaches
  14. 14. Changes
  15. 15. Privacy contact

1. Who we are and this policy's scope

Bostagy is a multi-tenant software platform that brings a business's customer conversations into one shared inbox. The service operator is [LEGAL ENTITY INFORMATION REQUIRED]. Its registered address, commercial registration, tax details, and Saudi establishment details are [BUSINESS CONFIRMATION REQUIRED].

This policy covers business account administrators and agents, plus the end-customer data that reaches Bostagy through channels connected by a business customer. The code does not show Bostagy acting as a marketplace, seller, courier, or consumer ordering service.

Bostagy will usually be a controller for account, billing, security, and direct service data. A business customer will usually be the controller for its contacts and conversations, with Bostagy acting as its processor. The exact roles depend on the contract, purpose, and applicable law.

2. Information we process

Provided directly

  • Business-user name, email, hashed password, optional phone number, avatar, language, time zone, role, and preferences.
  • Account name, domain, support email, industry, company size, website, and administrator-defined fields.
  • Contact name, email, phone, channel identifiers, country, city, company, avatar, and custom attributes.
  • Messages, email, internal notes, optional audio transcripts, attachments, call records, and support communications.
  • Location sent in a message or location attachment. The code does not show continuous background GPS tracking.

Collected automatically

  • IP addresses, request/error/security logs, browser and device details, browser language, activity times, and session identifiers.
  • Cookies and local storage required for authentication, session continuity, interface preferences, and web push.
  • Marketing-site page views and CTA clicks when Amplitude is configured.

Received from others

  • Messages, files, and profile data from connected channels such as WhatsApp, Instagram, Messenger, email, SMS, and web chat.
  • Authentication and connection data from Google, Microsoft, or another selected sign-in provider.
  • Data from optional integrations such as Shopify, Slack, Telegram, TikTok, LINE, APIs, and webhooks.

Not requested by default

  • No default fields request identity documents or full card data. People can still place sensitive data in messages; business customers must restrict this unless necessary and lawful.
  • The live payment provider, billing flow, and whether any payment data passes through Bostagy are [BUSINESS CONFIRMATION REQUIRED].

3. Why we process personal data

  • Create business accounts; verify email; authenticate users; manage roles and permissions.
  • Receive, route, search, report on, and respond to customer conversations.
  • Operate customer-selected channels and integrations and deliver operational notifications.
  • Provide support, diagnose failures, secure accounts, and prevent fraud or misuse.
  • Run optional AI or transcription features when enabled; providers and data flows require deployment-specific confirmation.
  • Administer subscriptions, invoices, and payments if enabled and meet accounting or tax duties.
  • Measure and improve the marketing page when analytics is enabled and legally permitted.

4. Lawful grounds

Depending on the activity and country, processing may be necessary to perform a contract or take requested pre-contract steps, comply with law, protect a vital interest, pursue a documented legitimate interest where permitted after balancing impacts, or rely on valid consent. Consent is not treated as a blanket basis.

For Saudi Arabia, the framework includes the PDPL, its Implementing Regulations, and the Transfer Regulation. Where applicable, the PDPL also reaches processing concerning individuals in the Kingdom by an entity outside the Kingdom. For Egypt, it includes Personal Data Protection Law No. 151 of 2020 and Executive Regulations No. 816 of 2025. Final activity-by-activity grounds are [LEGAL REVIEW REQUIRED].

5. Consent and direct marketing

Where consent is used, it must be freely given, specific, demonstrable, and separate by purpose where required. It can be withdrawn through the method offered or the contact below without affecting earlier processing or processing supported by another lawful ground. Product consent records and versions are [BUSINESS CONFIRMATION REQUIRED].

Business customers can send campaigns through connected channels and are responsible for lawful lists, consent where required, suppression lists, and a clear opt-out. OTPs, password resets, security alerts, conversation updates, and billing notices are operational. The code does not evidence Bostagy's own direct marketing program; one must not launch without the required notice, consent, and opt-out controls.

6. Cookies and analytics

Essential

  • Authentication, session, CSRF protection, interface/language settings, and storage required to operate the application.

Analytics

  • The marketing page loads Amplitude only when CLOUD_ANALYTICS_TOKEN is configured and skips it when Do Not Track is enabled.

Optional third parties

  • Google, Meta, hCaptcha, and connected-channel providers may set identifiers when their features are used.
The repository contains no cookie banner or preference center. Enabling Amplitude or other non-essential tracking in production without an appropriate consent mechanism is a compliance gap that must be assessed.

7. Who may receive data

The repository includes optional connectors for Meta services, Google, Microsoft, Twilio, Slack, Shopify, Telegram, LINE, TikTok, email and storage providers, Sentry/APM, and OpenAI or other models. Code support does not prove production use. The actual subprocessor list and contracts are [BUSINESS CONFIRMATION REQUIRED].

  • Authorized members of the business customer's account and the channel providers it elects to connect.
  • Hosting, database, storage, email, SMS, calling, push, security, and error-monitoring providers.
  • Amplitude when enabled, and AI or transcription providers when those features are enabled.
  • A payment or billing provider if payments are launched; provider and data scope [BUSINESS CONFIRMATION REQUIRED].
  • Professional advisers, regulators, courts, or public authorities when lawfully required or permitted.

8. International transfers

The application supports local or cloud hosting and international integrations, so data can technically be made available outside Egypt or Saudi Arabia. Actual server, database, backup, support, and vendor locations are [DATA HOSTING / INTERNATIONAL TRANSFER CONFIRMATION REQUIRED].

Saudi transfers require a defined purpose, destination, recipient, data-minimization review, an adequacy basis or appropriate safeguard such as approved standard clauses, and a transfer risk assessment where required. Egyptian transfers must follow Law 151/2020, its regulations, and any required permit or safeguard. Using the service is not blanket consent to every transfer.

9. Retention and destruction

We keep data only as long as reasonably needed for service delivery, security, accounting/legal duties, and disputes, then delete or anonymize it as required.

  • Accounts and user profiles: [RETENTION PERIOD REQUIRES BUSINESS/LEGAL CONFIRMATION].
  • Contacts, conversations, and attachments: contract/account settings apply; default schedule [RETENTION PERIOD REQUIRES BUSINESS/LEGAL CONFIRMATION].
  • Invoices, payment, tax, security, backup, and analytics records: [RETENTION PERIOD REQUIRES BUSINESS/LEGAL CONFIRMATION].

10. Individual rights

Subject to country, role, lawful ground, and statutory exceptions, rights may include being informed, access and a copy, correction/completion, destruction or deletion, consent withdrawal, objection or restriction in applicable cases, disclosure information, and complaint. We verify identity and protect other people's data when responding.

Business users may contact Bostagy directly. End customers should normally start with the business they contacted; where Bostagy is its processor, we will assist that business. Saudi residents may complain to the competent Saudi data authority and Egyptian residents to Egypt's Personal Data Protection Center.

11. Children's data

The platform is business-facing, but a customer's conversations may contain children's data. No minimum age or guardian-consent flow is evident: [MINIMUM USER AGE REQUIRES BUSINESS/LEGAL CONFIRMATION]. Business customers must obtain guardian authorization or another ground and use added safeguards when required.

12. Security

The application supports hashed passwords, account-scoped permissions, revocable sessions, email verification, MFA, restricted administrative access, logging/monitoring, and encryption for configured application secrets. Deployment controls determine transport and storage protection; enforced HTTPS, encrypted backups, and key management are [BUSINESS CONFIRMATION REQUIRED]. No system is 100% secure.

13. Personal-data breaches

We will assess, contain, and document unauthorized access, disclosure, loss, or destruction and notify authorities, customers, or individuals when applicable law requires. Deadlines and recipients depend on the incident, jurisdiction, and role. The incident plan and notification ownership are [BUSINESS/LEGAL CONFIRMATION REQUIRED].

14. Changes

We will publish a new version and effective date and provide notice or seek new consent when a material change or a new consent-based purpose requires it. This is version 1.0; no earlier version is represented.

15. Privacy contact

Privacy requests: [PRIVACY CONTACT EMAIL REQUIRED].

Data Protection Officer details, if appointment is required: [DPO DETAILS REQUIRE LEGAL CONFIRMATION].

State your role, country, and relevant account/business without sending passwords or sensitive documents in the first message.

بوسطجي

A unified customer inbox for teams in Egypt and the Gulf.

Product
  • Home
  • Pricing
  • Blog
  • Log in
Legal
  • Privacy Policy
  • Terms & Conditions
Contact
  • hello@bostagi.com
  • Privacy: confirmation required
bostagi.com — WUZZIFY.AI © 2026. All rights reserved.