Privacy Policy
This page explains how MatnBot handles account, workspace, bot, conversation, and connected-channel data, including WhatsApp automation data.
Data controller and contact
MatnBot is operated by ITBeep in Saudi Arabia. ITBeep controls the account and service data needed to provide MatnBot, while each customer remains responsible for customer data and messaging activity submitted to its workspace. For access, export, correction, or deletion requests, contact privacy@matnbot.com.
Data categories
- Account and workspace information such as names, email addresses, roles, and audit events.
- Bot configuration, AI instructions, uploaded knowledge files, and generated answers.
- Conversation content from connected channels, including WhatsApp messages and metadata.
- Operational data such as webhook receipts, delivery status, errors, rate-limit events, and security logs.
- Billing records and payment status handled through the configured payment provider.
Purposes
- Provide the AI bot, inbox, ticketing, and human handoff requested by customers.
- Secure workspaces, enforce roles, investigate abuse, and maintain auditability.
- Operate WhatsApp automation, including webhook processing, template policy, and delivery tracking.
- Improve reliability through diagnostics, rate limiting, backup, and recovery.
Meta and WhatsApp data
When a customer connects a Meta or WhatsApp asset, MatnBot uses authorized account, phone-number, message, webhook, template, and delivery data only to provide the automation selected by that customer. MatnBot does not sell channel message data or use it for unrelated advertising profiles.
Meta deauthorization and data-deletion callbacks are processed through signed requests. Raw signed requests, access tokens, app secrets, and external user identifiers are not intentionally exposed in public pages, status pages, or ordinary support views.
Service providers and international processing
ITBeep uses Hetzner for production infrastructure and OpenAI for configured AI processing. Meta and WhatsApp process connected-channel data under their platform terms. Configured email, payment, monitoring, and backup services may process limited information when enabled for a customer and only for delivery, security, support, or billing.
Providers may process data outside the customer’s country. Where required, ITBeep uses contractual, access-control, and security measures intended to protect that processing.
Cookies and similar storage
The application uses authentication and session storage needed to keep users signed in and protect private dashboard routes. Cookie, analytics, and retention choices are minimized to what is needed for security, authentication, and service operation.
Installed app and device notifications
Device notifications are optional and enabled at your request for each device and selected inbox. We protect the stored device subscription and keys and retain notification preferences, event identifiers and delivery outcomes. Your browser's push provider delivers encrypted notifications and may process device and network metadata under its own policy. Notification previews contain no customer messages or names; opening the app checks your current account permissions.
You can disable a device in App & notifications or revoke permission in your browser. Delivery event metadata is removed thirty days after expiry, and inactive subscriptions are disabled after ninety days. Subscription keys are erased when a device is revoked or an expired/revoked session is cleaned up; this does not delete the conversation or account notification history.
The installed app retains a generic offline page, a public icon and a non-secret device binding. Its service worker does not store conversations or private files. Reply drafts stay in tab memory and can be lost when the tab closes; they are never sent automatically when connectivity returns.
Retention and deletion
Default WhatsApp retention is 7 days for raw webhook payloads, 30 days for normalized events, 365 days for messages, 30 days for media, 90 days for AI and tool artifacts, and 365 days for tickets and operator annotations. Workspace policy and legal obligations may adjust these periods within supported limits, and a valid legal hold may temporarily suspend deletion.
Deletion can be requested from the data deletion page. The flow creates an opaque case code and requires ownership verification before account or conversation data is deleted.
User rights
Depending on applicable law and the account relationship, users may request access, correction, export, restriction, objection, or deletion. MatnBot reviews requests, verifies ownership where needed, and responds through the provided contact channel.
Government and legal requests
ITBeep reviews the legal basis and scope of government requests, challenges requests that appear unlawful or excessive where permitted, limits disclosure to the minimum required, and documents the request and response. ITBeep may notify affected customers unless prohibited by law.