1. Who we are and this policy's scope
Bostagy is a multi-tenant software platform that brings a business's customer conversations into one shared inbox. The service operator is [LEGAL ENTITY INFORMATION REQUIRED]. Its registered address, commercial registration, tax details, and Saudi establishment details are [BUSINESS CONFIRMATION REQUIRED].
This policy covers business account administrators and agents, plus the end-customer data that reaches Bostagy through channels connected by a business customer. The code does not show Bostagy acting as a marketplace, seller, courier, or consumer ordering service.
Bostagy will usually be a controller for account, billing, security, and direct service data. A business customer will usually be the controller for its contacts and conversations, with Bostagy acting as its processor. The exact roles depend on the contract, purpose, and applicable law.
2. Information we process
Provided directly
- Business-user name, email, hashed password, optional phone number, avatar, language, time zone, role, and preferences.
- Account name, domain, support email, industry, company size, website, and administrator-defined fields.
- Contact name, email, phone, channel identifiers, country, city, company, avatar, and custom attributes.
- Messages, email, internal notes, optional audio transcripts, attachments, call records, and support communications.
- Location sent in a message or location attachment. The code does not show continuous background GPS tracking.
Collected automatically
- IP addresses, request/error/security logs, browser and device details, browser language, activity times, and session identifiers.
- Cookies and local storage required for authentication, session continuity, interface preferences, and web push.
- Marketing-site page views and CTA clicks when Amplitude is configured.
Received from others
- Messages, files, and profile data from connected channels such as WhatsApp, Instagram, Messenger, email, SMS, and web chat.
- Authentication and connection data from Google, Microsoft, or another selected sign-in provider.
- Data from optional integrations such as Shopify, Slack, Telegram, TikTok, LINE, APIs, and webhooks.
Not requested by default
- No default fields request identity documents or full card data. People can still place sensitive data in messages; business customers must restrict this unless necessary and lawful.
- The live payment provider, billing flow, and whether any payment data passes through Bostagy are [BUSINESS CONFIRMATION REQUIRED].
3. Why we process personal data
- Create business accounts; verify email; authenticate users; manage roles and permissions.
- Receive, route, search, report on, and respond to customer conversations.
- Operate customer-selected channels and integrations and deliver operational notifications.
- Provide support, diagnose failures, secure accounts, and prevent fraud or misuse.
- Run optional AI or transcription features when enabled; providers and data flows require deployment-specific confirmation.
- Administer subscriptions, invoices, and payments if enabled and meet accounting or tax duties.
- Measure and improve the marketing page when analytics is enabled and legally permitted.
4. Lawful grounds
Depending on the activity and country, processing may be necessary to perform a contract or take requested pre-contract steps, comply with law, protect a vital interest, pursue a documented legitimate interest where permitted after balancing impacts, or rely on valid consent. Consent is not treated as a blanket basis.
For Saudi Arabia, the framework includes the PDPL, its Implementing Regulations, and the Transfer Regulation. Where applicable, the PDPL also reaches processing concerning individuals in the Kingdom by an entity outside the Kingdom. For Egypt, it includes Personal Data Protection Law No. 151 of 2020 and Executive Regulations No. 816 of 2025. Final activity-by-activity grounds are [LEGAL REVIEW REQUIRED].
5. Consent and direct marketing
Where consent is used, it must be freely given, specific, demonstrable, and separate by purpose where required. It can be withdrawn through the method offered or the contact below without affecting earlier processing or processing supported by another lawful ground. Product consent records and versions are [BUSINESS CONFIRMATION REQUIRED].
Business customers can send campaigns through connected channels and are responsible for lawful lists, consent where required, suppression lists, and a clear opt-out. OTPs, password resets, security alerts, conversation updates, and billing notices are operational. The code does not evidence Bostagy's own direct marketing program; one must not launch without the required notice, consent, and opt-out controls.
8. International transfers
The application supports local or cloud hosting and international integrations, so data can technically be made available outside Egypt or Saudi Arabia. Actual server, database, backup, support, and vendor locations are [DATA HOSTING / INTERNATIONAL TRANSFER CONFIRMATION REQUIRED].
Saudi transfers require a defined purpose, destination, recipient, data-minimization review, an adequacy basis or appropriate safeguard such as approved standard clauses, and a transfer risk assessment where required. Egyptian transfers must follow Law 151/2020, its regulations, and any required permit or safeguard. Using the service is not blanket consent to every transfer.
9. Retention and destruction
We keep data only as long as reasonably needed for service delivery, security, accounting/legal duties, and disputes, then delete or anonymize it as required.
- Accounts and user profiles: [RETENTION PERIOD REQUIRES BUSINESS/LEGAL CONFIRMATION].
- Contacts, conversations, and attachments: contract/account settings apply; default schedule [RETENTION PERIOD REQUIRES BUSINESS/LEGAL CONFIRMATION].
- Invoices, payment, tax, security, backup, and analytics records: [RETENTION PERIOD REQUIRES BUSINESS/LEGAL CONFIRMATION].
10. Individual rights
Subject to country, role, lawful ground, and statutory exceptions, rights may include being informed, access and a copy, correction/completion, destruction or deletion, consent withdrawal, objection or restriction in applicable cases, disclosure information, and complaint. We verify identity and protect other people's data when responding.
Business users may contact Bostagy directly. End customers should normally start with the business they contacted; where Bostagy is its processor, we will assist that business. Saudi residents may complain to the competent Saudi data authority and Egyptian residents to Egypt's Personal Data Protection Center.
11. Children's data
The platform is business-facing, but a customer's conversations may contain children's data. No minimum age or guardian-consent flow is evident: [MINIMUM USER AGE REQUIRES BUSINESS/LEGAL CONFIRMATION]. Business customers must obtain guardian authorization or another ground and use added safeguards when required.
12. Security
The application supports hashed passwords, account-scoped permissions, revocable sessions, email verification, MFA, restricted administrative access, logging/monitoring, and encryption for configured application secrets. Deployment controls determine transport and storage protection; enforced HTTPS, encrypted backups, and key management are [BUSINESS CONFIRMATION REQUIRED]. No system is 100% secure.
13. Personal-data breaches
We will assess, contain, and document unauthorized access, disclosure, loss, or destruction and notify authorities, customers, or individuals when applicable law requires. Deadlines and recipients depend on the incident, jurisdiction, and role. The incident plan and notification ownership are [BUSINESS/LEGAL CONFIRMATION REQUIRED].
14. Changes
We will publish a new version and effective date and provide notice or seek new consent when a material change or a new consent-based purpose requires it. This is version 1.0; no earlier version is represented.
15. Privacy contact
Privacy requests: [PRIVACY CONTACT EMAIL REQUIRED].
Data Protection Officer details, if appointment is required: [DPO DETAILS REQUIRE LEGAL CONFIRMATION].
State your role, country, and relevant account/business without sending passwords or sensitive documents in the first message.