Privacy Policy
Finebot answers the customers of a business in messengers and keeps them in a CRM. This page explains what data is processed, why, where it is stored and what you can do about it.
1. Who we are
Finebot answers business customers in WhatsApp, Instagram and Telegram, books appointments, suggests products and runs deals in a CRM. The service belongs to Individual entrepreneur Kozhevnikov, Republic of Kazakhstan.
- Legal name: Individual entrepreneur Kozhevnikov
- Owner: Kozhevnikov Dmitriy Sergeyevich
- Individual identification number: 020830551023
- Address: 121 Maylin street, Almaty, Kazakhstan
- Email: mail@finebot.app
- Person responsible for personal data processing: Kozhevnikov Dmitriy Sergeyevich
This policy follows the Law of the Republic of Kazakhstan on Personal Data and Its Protection of 21 May 2013 No. 94-V as currently in force, the Digital Code and the Law on Artificial Intelligence.
2. Key roles under Kazakhstan law
Kazakhstan law uses four figures. Here they are in plain words.
- Data subject is the person the data relates to.
- Owner holds the database or digital object with the data and decides on it.
- Operator collects, processes and protects the data.
- Third party is neither the subject nor the owner, but is connected to them by relations over collection, processing and protection of the data.
Below, «we» means Finebot. «You» depends on the section, because there are three groups of people and our role differs for each.
3. Three groups of people and our role for each
| Who | Who decides why data is collected | Finebot role |
|---|---|---|
| Visitors of finebot.app | Finebot | Owner and operator |
| Platform clients: businesses and their staff with accounts in my.finebot.app | Finebot | Owner and operator |
| End customers of those businesses: people who message a business | The business | Third party |
Kazakhstan law has no concept of processing on instruction. So for end customer data the business acts as owner and operator, and Finebot acts as a third party under article 1, subparagraph 17 of the Law. «Third party» is a statutory role of Kazakhstan law and is functionally equivalent to a processor or service provider: we process the data on behalf of the business and at its direction, for its purposes, and we keep the data of each business in a separate workspace. For the purposes of the Meta Platform Terms, Finebot acts as a Tech Provider on behalf of its clients.
Statutory duties cannot be passed on by contract. We protect the data, delete it on request and answer for our own breaches, even where the business set the purposes. The business answers for obtaining consent and for setting lawful purposes.
4. Visitors of finebot.app
The site runs Yandex Metrica, counter number 112846702, with session replay, click map and link tracking enabled.
Session replay records on-page actions: mouse movement, scrolling and clicks. The site has no forms, so there is no form input to record.
What is collected
- IP address and approximate location derived from it
- Visitor identifier stored in a cookie
- Device type, browser, operating system, screen resolution
- Pages viewed, time spent, links followed
- The page you arrived from
Purpose: to see which pages people read, where they leave and what to fix.
The processor is Yandex LLC, Russia. This is a transfer outside Kazakhstan, see section 10.
How to opt out
- Install the official Yandex opt-out add-on.
- Or block cookies for this site in your browser settings.
- Or use a script blocker.
5. Platform clients: businesses and their staff
Accounts in my.finebot.app are created by us during onboarding, there is no self-service sign-up. Staff records are added by the business itself.
What we store
- Name and work email of the staff member
- Password as a bcrypt hash. We neither store nor see the original password
- Role and permissions: owner, admin, staff
- Profile photo, if uploaded
- Company name and workspace settings
- Failed login attempts and lockout time on password guessing
- Balance, charges for AI work, plan and subscription history
- Tokens of connected channels and CRM systems, encrypted
- Contact phone and email of the organisation
- Telegram identifiers of staff who receive lead notifications
- Payment reference and subscription event history
- The dashboard session, which lives for 30 days
- Specialist cards used for booking: name, position, photo, working hours, days off and holidays
- Files the business uploaded into the knowledge base and the catalogue: documents, spreadsheets and images
- Playground sessions where a staff member tests the bot: messages, the system instruction and the full trace of tool calls
Purpose: to give access to the dashboard, separate staff permissions, bill correctly and answer support requests.
Basis: the consent of the staff member, which the business secures, and the consent the business gives for itself when the contract is concluded. Payment records are also kept under the tax and accounting legislation of Kazakhstan.
Support access
A Finebot employee sees service information about a workspace: the company name, its contact phone and email, the name and email of the account owner, the plan, the subscription, the balance and the usage report. They can change the balance, grant, extend, switch or revoke a subscription, and create, edit or disable a workspace. Conversations and customer cards are closed to that access at the technical level.
Every access to service information and every such action is written to a log: who, when, which action, from which IP address and browser. The log is read only, and the application provides no way to alter its records.
6. End customers of businesses
These are people who message a business in WhatsApp, Instagram or Telegram. They have no Finebot account, and their data arrives from the messenger together with the message.
What arrives from the channels
| Channel | What we receive |
|---|---|
| Phone number, wa_id, profile name, message text, files, images and voice messages, delivery and read statuses | |
| IGSID and conversation text. Instagram attachments are not stored by the service | |
| Telegram | User id, name and username, message text, files and voice messages |
What the service creates
- A contact card: name, phone, email, company, position, language, profile photo and messenger username, custom fields of the business
- A deal with its stage, amount, products and an event log showing who changed what
- Delivery address, delivery method and payment method where the deal needs them
- An appointment: specialist, service, date and time, customer comment, staff note and cancellation reason
- AI notes on the conversation: facts about the customer and a readiness estimate
- Staff notes on the contact
- Reminders and tasks with their message text
- A campaign log: who was messaged, whether it was delivered and which error occurred
- A text transcript of voice messages
- Service records of scenario runs, including fragments of the step context. Kept for 60 days
- Identifiers of your messages on the messenger side and their delivery statuses
- Service flags: whether the bot is stopped on your conversation and why, when you last wrote, how many messages are unread
Purpose: to answer the customer on behalf of the business, book an appointment, suggest a product and close the deal.
The business sets the purposes. We do not use end customer conversations or contacts for our own purposes: not for advertising, not for research, not for model training.
7. Legal basis for processing
The basis is the consent of the data subject, article 7 paragraph 1 of the Law. The list of cases where consent is not required is closed in article 9, and Kazakhstan law has no «contract performance» or «legitimate interest» basis.
| Group | Who obtains consent |
|---|---|
| Site visitors | Finebot. Analytics starts when the site is opened, and the opt-out routes are listed in section 4 |
| Platform clients | Finebot when the contract is concluded. Consent of staff members is secured by the business that adds them to the account |
| End customers of businesses | The business, before it messages the customer or connects the bot to the conversation |
Article 8 paragraph 4 of the Law lists what consent must contain. Obtaining such consent from end customers is the duty of the business.
- Name or full name and identification number of the owner and the operator
- Full name of the data subject
- The term or period for which consent is given
- Whether the data is passed to third parties
- Whether there is a cross-border transfer
- Whether the data may be published in publicly available sources
- The list of data collected
- Any other details the operator decides to include
The business tells its customers that Finebot is connected and that data leaves Kazakhstan. Automated processing belongs in the consent separately: under article 19-1 paragraph 1 of the Law it is allowed where the data subject has consented. Proof of consent is kept by whoever obtained it, article 25 paragraph 2 subparagraph 5.
8. Where the data is stored
The primary storage is a data centre in Astana, Republic of Kazakhstan, operated by Hoster.KZ. It holds the database and uploaded files: images, documents and voice messages.
This satisfies article 12 paragraph 2 of the Law: storage is in a database and, or, a digital object located in the territory of Kazakhstan. The same requirement is repeated by the Rules on personal data protection measures, which speak of a server room or a data centre located in Kazakhstan.
Files are stored on servers located in Kazakhstan. No external object storage is used at present.
9. Who we share data with
The service runs on third party channels and third party models, so some data goes to subprocessors. Here is the full list of categories and countries.
| Recipient | What is shared | Purpose | Country |
|---|---|---|---|
| Meta Platforms | Messages, phone number, account identifiers | Message delivery in WhatsApp and Instagram | USA, Ireland |
| SendPulse | WhatsApp messages and phone numbers | WhatsApp message delivery through a provider | United States and Germany. The service is operated by SendPulse Inc., USA |
| Telegram | Messages and chat identifiers | Telegram message delivery | The Netherlands for accounts registered in Kazakhstan. The group companies are registered in the British Virgin Islands and the UAE |
| Anthropic | Conversation text and the contact fields needed for a reply | Reply generation by the Claude model | USA |
| OpenAI | The voice message as a file | Voice transcription by the Whisper model | USA |
| amoCRM | Contacts and deals | Synchronisation, only if the business enabled the integration | The business portal in the amocrm.ru or amocrm.com zone. The Russian portal is operated by JSC amoCRM and its servers are located in Russia |
| Bitrix24 | Contacts and deals | Synchronisation, only if the business enabled the integration | Depends on the zone of the business portal: bitrix24.kz is 1C-Bitrix Kazakhstan LLP with data centres in Kazakhstan, bitrix24.com is Alaio Inc., USA, bitrix24.ru is Russia |
| Hoster.KZ | Everything stored on the server | Server hosting | Kazakhstan |
| Yandex | Visit data for finebot.app | Web analytics | Russia |
Every subprocessor is bound by written terms that allow processing only to provide the service to us and forbid use for their own purposes.
The processing country for a CRM is chosen by the business itself when it creates its portal: the portal address determines both the legal entity and the location of the servers. Subprocessors publish their own country lists and may change them, so we do not reproduce an exhaustive list on their behalf.
Where the business included in its consent a term about notifying the customer of transfers to a third party, that notice is sent within ten working days, article 19 paragraph 1 of the Law.
We disclose data to public authorities only where the law requires it and the request is properly issued. See section 17.
10. Transfers outside Kazakhstan
Meta, Anthropic, OpenAI, Telegram and Yandex are located outside Kazakhstan, so sending data to them is a cross-border transfer under article 16 of the Law.
Kazakhstan has no approved list of countries deemed to provide personal data protection. We therefore rely on the only dependable basis: the consent of the data subject under article 16 paragraph 3 subparagraph 1. For end customer data that consent is obtained by the business.
We send subprocessors only what the service needs. Data that is not required to answer the customer is not sent to the model.
11. Automated processing and AI replies
An AI answers in the conversation. It also creates a deal, moves its stage and books an appointment. This is automated processing within the meaning of article 19-1 of the Law.
Under the Law of the Republic of Kazakhstan on Artificial Intelligence, a person has the right to know that a service is provided using AI and the right to refuse interacting with it. We require businesses to disclose this in the conversation and to let the customer reach a human.
What the AI decides and what follows from it
- Answers a message on behalf of the business, suggests a product and states its price and availability
- Creates a deal, moves its stage, adds products and services to it
- Updates your contact card: name, email and the custom fields of the business. It cannot change your phone number
- Collects the delivery address, the payment method and the delivery method from the conversation
- Books an appointment with a specialist for a specific date and time, reschedules and cancels it
- Comes back to the conversation later when the conversation is put on hold
- Writes notes on the conversation: facts about you and an estimate of your readiness to buy
- Hands the conversation over to a human and stops itself when it sees that a person is needed
- Calls a staff member of the business in Telegram, and details of your request then go into that chat
The set of capabilities is configured by the business itself. Part of the list above may be switched off at a particular company, for example product search or online booking.
The consequences: the business treats an appointment and the arrangements made in the conversation as yours, and the AI notes shape what you are offered next. A model mistake can produce a wrong price, a wrong appointment time or a misread request, which is why the business must keep a way for you to check it with a human.
How to object and how to defend your rights
If you do not want decisions about you made by an AI, write to us or to the business you are messaging. An objection is considered within three working days, and we report the outcome. This period comes from article 19-1 paragraph 3 of the Law.
The ordinary rights from section 14 apply after that: correction, blocking, deletion and withdrawal of consent. If our answer does not satisfy you, you may address the authorised body or a court, see section 20.
In addition, article 43 of the Digital Code gives the right to learn that an algorithmic system was applied, to receive an explanation of the key factors behind a decision and to demand a review of that decision with human involvement.
12. What we never do
- We do not train models on your data. Messages, contacts and deals are not used to create, develop, train or improve any machine learning models, ours or anyone else.
- We do not sell, rent or license data.
- We do not build advertising profiles and do not pass data to ad networks.
- AI notes and estimates are built only from the content of the conversation inside the workspace of one business. We do not use service data received from Meta for them, we do not combine information about a person across different businesses, and we do not apply them for any purpose other than answering that same customer. Their basis is the same as for the rest of the processing: the consent obtained by the business.
- We do not use data for credit scoring, hiring, insurance or similar decisions.
- We do not attempt to re-identify people from anonymised data.
- We do not share the conversations of one business with another business.
- We do not scrape public sources to enlarge our databases.
13. How long we keep data
The general rule from article 12 paragraph 2 of the Law: data is kept until the purposes of collection are met. The specifics follow.
| What | How long |
|---|---|
| Conversations, contacts, deals, appointments | While the contract with the business is in force. The business deletes the contact card itself in the dashboard, conversations and appointments are deleted by us on request |
| Data after the contract with the business ends | 30 calendar days to collect the data, then deletion. The export is prepared on request. Only deals and payment records stay longer, because accounting needs them |
| Files and voice messages | Together with the conversation they belong to |
| AI usage records | 365 days, then deleted automatically |
| Service records of scenario runs, including fragments of the step context | 60 days, then deleted automatically |
| Dashboard session | 30 days |
| Support access log and security logs | 12 months |
| Backups | {{to confirm with the owner: whether backups are made, where they are kept and how long they live}} |
| Payment records | For the periods set by the tax and accounting legislation of Kazakhstan |
| Yandex Metrica data | Per Yandex retention periods as the analytics operator |
Article 18 of the Law names the end of the relationship between the subject and the operator as a separate ground for deletion. Termination of the contract therefore triggers deletion, not merely loss of access.
14. Your rights and our response times
Article 24 of the Law gives the data subject rights that can be used at any time.
- Find out whether we hold your data, where it came from, why it is processed and how long it is kept
- Require correction or completion of inaccurate data
- Require blocking of the data where there are signs of unlawful collection
- Require destruction or deletion of the data
- Withdraw consent
- Object to automated processing
- Claim compensation for moral and material damage
| Request | Response time | Basis |
|---|---|---|
| Correct or complete data on supporting documents | 1 working day | Art. 25 (2)(8) |
| Block data where a breach is indicated | 1 working day | Art. 25 (2)(8) |
| Delete data where unlawful collection is confirmed | 1 working day | Art. 25 (2)(8) |
| Objection to automated processing | 3 working days | Art. 19-1 (3) |
| Withdrawal of consent: we stop processing or give a reasoned refusal | 15 working days | Art. 8 (7) |
| Deletion of data on your request, or a reasoned refusal | 15 working days | Our own commitment: the Law sets no period for deletion |
| Request for information about your data, and a reasoned refusal of it | 3 working days | Paragraph 16 of the Rules on collection and processing of personal data, order of 21 October 2020 No. 395 |
How to reach us: email mail@finebot.app. State the phone number or account you messaged from and what you need. Deletion is described separately on the Data Deletion page.
If a business collected data about you and we hold it as a third party, you may address either the business or us. We accept the request, pass it to the business, because the content of the contact card is decided by the business, and delete the data on our side.
15. How we protect data
- Connections to the site and the dashboard use HTTPS with TLS.
- Passwords are stored as bcrypt hashes. The original password cannot be recovered from the hash.
- Channel and CRM tokens are encrypted with AES-256-GCM. The encryption key is kept outside the database and supports rotation.
- Access is separated by roles: owner, admin, staff. Data of one workspace is not reachable from another.
- Login is locked after a series of failed password attempts.
- Finebot support cannot reach conversations or customer cards, and every access to service information is written to a read only log.
- The server is located in a data centre in Astana.
The list covers the measures in place today. It will grow as the service develops, and we will update this section.
16. What happens after a breach
On a personal data security breach we notify the authorised body for personal data protection within one working day of discovery. This is required by article 25 paragraph 2 subparagraph 8 of the Law.
The notice includes the details that identify the affected people and the contacts of the responsible person. What follows is set by the Rules on notification of a personal data security breach: the authorised body passes the information to the operator of the electronic government infrastructure, which notifies people through their portal account or by a message to their mobile number.
We notify the affected business client without delay so that it can meet its own duties and warn its customers through its own channels.
18. Data about children
The service is built for businesses and we do not collect data about children deliberately. Where an end customer is a minor, consent is given by a legal representative, and this is the responsibility of the business.
If you believe we hold data of a child without such consent, write to us and we will delete it.
19. Changes to this policy
The policy changes when the service or the law changes. The current version always sits at this address, and the version date is shown at the top of the page.
We notify business clients about material changes by email to the account address in advance.
This policy is governed by the law of the Republic of Kazakhstan. The dispute procedure is set out in the Terms of Service.
20. Contacts
For any question about data write to mail@finebot.app. We reply to the address the request came from.
If our answer does not satisfy you, you may address the authorised body for personal data protection of the Republic of Kazakhstan. These functions are currently performed by the Ministry of Artificial Intelligence and Digital Development. The right to defend your rights and to claim compensation for moral and material damage, including in court, comes from article 24 paragraph 1 subparagraph 7 of the Law. Deletion and anonymisation can also be required under article 41 of the Digital Code.