Version of 1 September 2026Русский

Privacy Policy

Finebot answers the customers of a business in messengers and keeps them in a CRM. This page explains what data is processed, why, where it is stored and what you can do about it.

1. Who we are

Finebot answers business customers in WhatsApp, Instagram and Telegram, books appointments, suggests products and runs deals in a CRM. The service belongs to Individual entrepreneur Kozhevnikov, Republic of Kazakhstan.

This policy follows the Law of the Republic of Kazakhstan on Personal Data and Its Protection of 21 May 2013 No. 94-V as currently in force, the Digital Code and the Law on Artificial Intelligence.

2. Key roles under Kazakhstan law

Kazakhstan law uses four figures. Here they are in plain words.

Below, «we» means Finebot. «You» depends on the section, because there are three groups of people and our role differs for each.

3. Three groups of people and our role for each

WhoWho decides why data is collectedFinebot role
Visitors of finebot.appFinebotOwner and operator
Platform clients: businesses and their staff with accounts in my.finebot.appFinebotOwner and operator
End customers of those businesses: people who message a businessThe businessThird party

Kazakhstan law has no concept of processing on instruction. So for end customer data the business acts as owner and operator, and Finebot acts as a third party under article 1, subparagraph 17 of the Law. «Third party» is a statutory role of Kazakhstan law and is functionally equivalent to a processor or service provider: we process the data on behalf of the business and at its direction, for its purposes, and we keep the data of each business in a separate workspace. For the purposes of the Meta Platform Terms, Finebot acts as a Tech Provider on behalf of its clients.

Statutory duties cannot be passed on by contract. We protect the data, delete it on request and answer for our own breaches, even where the business set the purposes. The business answers for obtaining consent and for setting lawful purposes.

4. Visitors of finebot.app

The site runs Yandex Metrica, counter number 112846702, with session replay, click map and link tracking enabled.

Session replay records on-page actions: mouse movement, scrolling and clicks. The site has no forms, so there is no form input to record.

What is collected

Purpose: to see which pages people read, where they leave and what to fix.

The processor is Yandex LLC, Russia. This is a transfer outside Kazakhstan, see section 10.

How to opt out

  1. Install the official Yandex opt-out add-on.
  2. Or block cookies for this site in your browser settings.
  3. Or use a script blocker.

5. Platform clients: businesses and their staff

Accounts in my.finebot.app are created by us during onboarding, there is no self-service sign-up. Staff records are added by the business itself.

What we store

Purpose: to give access to the dashboard, separate staff permissions, bill correctly and answer support requests.

Basis: the consent of the staff member, which the business secures, and the consent the business gives for itself when the contract is concluded. Payment records are also kept under the tax and accounting legislation of Kazakhstan.

Support access

A Finebot employee sees service information about a workspace: the company name, its contact phone and email, the name and email of the account owner, the plan, the subscription, the balance and the usage report. They can change the balance, grant, extend, switch or revoke a subscription, and create, edit or disable a workspace. Conversations and customer cards are closed to that access at the technical level.

Every access to service information and every such action is written to a log: who, when, which action, from which IP address and browser. The log is read only, and the application provides no way to alter its records.

6. End customers of businesses

These are people who message a business in WhatsApp, Instagram or Telegram. They have no Finebot account, and their data arrives from the messenger together with the message.

What arrives from the channels

ChannelWhat we receive
WhatsAppPhone number, wa_id, profile name, message text, files, images and voice messages, delivery and read statuses
InstagramIGSID and conversation text. Instagram attachments are not stored by the service
TelegramUser id, name and username, message text, files and voice messages

What the service creates

Purpose: to answer the customer on behalf of the business, book an appointment, suggest a product and close the deal.

The business sets the purposes. We do not use end customer conversations or contacts for our own purposes: not for advertising, not for research, not for model training.

8. Where the data is stored

The primary storage is a data centre in Astana, Republic of Kazakhstan, operated by Hoster.KZ. It holds the database and uploaded files: images, documents and voice messages.

This satisfies article 12 paragraph 2 of the Law: storage is in a database and, or, a digital object located in the territory of Kazakhstan. The same requirement is repeated by the Rules on personal data protection measures, which speak of a server room or a data centre located in Kazakhstan.

Files are stored on servers located in Kazakhstan. No external object storage is used at present.

9. Who we share data with

The service runs on third party channels and third party models, so some data goes to subprocessors. Here is the full list of categories and countries.

RecipientWhat is sharedPurposeCountry
Meta PlatformsMessages, phone number, account identifiersMessage delivery in WhatsApp and InstagramUSA, Ireland
SendPulseWhatsApp messages and phone numbersWhatsApp message delivery through a providerUnited States and Germany. The service is operated by SendPulse Inc., USA
TelegramMessages and chat identifiersTelegram message deliveryThe Netherlands for accounts registered in Kazakhstan. The group companies are registered in the British Virgin Islands and the UAE
AnthropicConversation text and the contact fields needed for a replyReply generation by the Claude modelUSA
OpenAIThe voice message as a fileVoice transcription by the Whisper modelUSA
amoCRMContacts and dealsSynchronisation, only if the business enabled the integrationThe business portal in the amocrm.ru or amocrm.com zone. The Russian portal is operated by JSC amoCRM and its servers are located in Russia
Bitrix24Contacts and dealsSynchronisation, only if the business enabled the integrationDepends on the zone of the business portal: bitrix24.kz is 1C-Bitrix Kazakhstan LLP with data centres in Kazakhstan, bitrix24.com is Alaio Inc., USA, bitrix24.ru is Russia
Hoster.KZEverything stored on the serverServer hostingKazakhstan
YandexVisit data for finebot.appWeb analyticsRussia

Every subprocessor is bound by written terms that allow processing only to provide the service to us and forbid use for their own purposes.

The processing country for a CRM is chosen by the business itself when it creates its portal: the portal address determines both the legal entity and the location of the servers. Subprocessors publish their own country lists and may change them, so we do not reproduce an exhaustive list on their behalf.

Where the business included in its consent a term about notifying the customer of transfers to a third party, that notice is sent within ten working days, article 19 paragraph 1 of the Law.

We disclose data to public authorities only where the law requires it and the request is properly issued. See section 17.

10. Transfers outside Kazakhstan

Meta, Anthropic, OpenAI, Telegram and Yandex are located outside Kazakhstan, so sending data to them is a cross-border transfer under article 16 of the Law.

Kazakhstan has no approved list of countries deemed to provide personal data protection. We therefore rely on the only dependable basis: the consent of the data subject under article 16 paragraph 3 subparagraph 1. For end customer data that consent is obtained by the business.

We send subprocessors only what the service needs. Data that is not required to answer the customer is not sent to the model.

11. Automated processing and AI replies

An AI answers in the conversation. It also creates a deal, moves its stage and books an appointment. This is automated processing within the meaning of article 19-1 of the Law.

Under the Law of the Republic of Kazakhstan on Artificial Intelligence, a person has the right to know that a service is provided using AI and the right to refuse interacting with it. We require businesses to disclose this in the conversation and to let the customer reach a human.

What the AI decides and what follows from it

The set of capabilities is configured by the business itself. Part of the list above may be switched off at a particular company, for example product search or online booking.

The consequences: the business treats an appointment and the arrangements made in the conversation as yours, and the AI notes shape what you are offered next. A model mistake can produce a wrong price, a wrong appointment time or a misread request, which is why the business must keep a way for you to check it with a human.

How to object and how to defend your rights

If you do not want decisions about you made by an AI, write to us or to the business you are messaging. An objection is considered within three working days, and we report the outcome. This period comes from article 19-1 paragraph 3 of the Law.

The ordinary rights from section 14 apply after that: correction, blocking, deletion and withdrawal of consent. If our answer does not satisfy you, you may address the authorised body or a court, see section 20.

In addition, article 43 of the Digital Code gives the right to learn that an algorithmic system was applied, to receive an explanation of the key factors behind a decision and to demand a review of that decision with human involvement.

12. What we never do

13. How long we keep data

The general rule from article 12 paragraph 2 of the Law: data is kept until the purposes of collection are met. The specifics follow.

WhatHow long
Conversations, contacts, deals, appointmentsWhile the contract with the business is in force. The business deletes the contact card itself in the dashboard, conversations and appointments are deleted by us on request
Data after the contract with the business ends30 calendar days to collect the data, then deletion. The export is prepared on request. Only deals and payment records stay longer, because accounting needs them
Files and voice messagesTogether with the conversation they belong to
AI usage records365 days, then deleted automatically
Service records of scenario runs, including fragments of the step context60 days, then deleted automatically
Dashboard session30 days
Support access log and security logs12 months
Backups{{to confirm with the owner: whether backups are made, where they are kept and how long they live}}
Payment recordsFor the periods set by the tax and accounting legislation of Kazakhstan
Yandex Metrica dataPer Yandex retention periods as the analytics operator

Article 18 of the Law names the end of the relationship between the subject and the operator as a separate ground for deletion. Termination of the contract therefore triggers deletion, not merely loss of access.

14. Your rights and our response times

Article 24 of the Law gives the data subject rights that can be used at any time.

RequestResponse timeBasis
Correct or complete data on supporting documents1 working dayArt. 25 (2)(8)
Block data where a breach is indicated1 working dayArt. 25 (2)(8)
Delete data where unlawful collection is confirmed1 working dayArt. 25 (2)(8)
Objection to automated processing3 working daysArt. 19-1 (3)
Withdrawal of consent: we stop processing or give a reasoned refusal15 working daysArt. 8 (7)
Deletion of data on your request, or a reasoned refusal15 working daysOur own commitment: the Law sets no period for deletion
Request for information about your data, and a reasoned refusal of it3 working daysParagraph 16 of the Rules on collection and processing of personal data, order of 21 October 2020 No. 395

How to reach us: email mail@finebot.app. State the phone number or account you messaged from and what you need. Deletion is described separately on the Data Deletion page.

If a business collected data about you and we hold it as a third party, you may address either the business or us. We accept the request, pass it to the business, because the content of the contact card is decided by the business, and delete the data on our side.

15. How we protect data

The list covers the measures in place today. It will grow as the service develops, and we will update this section.

16. What happens after a breach

On a personal data security breach we notify the authorised body for personal data protection within one working day of discovery. This is required by article 25 paragraph 2 subparagraph 8 of the Law.

The notice includes the details that identify the affected people and the contacts of the responsible person. What follows is set by the Rules on notification of a personal data security breach: the authorised body passes the information to the operator of the electronic government infrastructure, which notifies people through their portal account or by a message to their mobile number.

We notify the affected business client without delay so that it can meet its own duties and warn its customers through its own channels.

17. Government requests

We disclose data to a public authority only where the request is issued in accordance with the law, comes from a body with the relevant powers and identifies specific data.

18. Data about children

The service is built for businesses and we do not collect data about children deliberately. Where an end customer is a minor, consent is given by a legal representative, and this is the responsibility of the business.

If you believe we hold data of a child without such consent, write to us and we will delete it.

19. Changes to this policy

The policy changes when the service or the law changes. The current version always sits at this address, and the version date is shown at the top of the page.

We notify business clients about material changes by email to the account address in advance.

This policy is governed by the law of the Republic of Kazakhstan. The dispute procedure is set out in the Terms of Service.

20. Contacts

For any question about data write to mail@finebot.app. We reply to the address the request came from.

If our answer does not satisfy you, you may address the authorised body for personal data protection of the Republic of Kazakhstan. These functions are currently performed by the Ministry of Artificial Intelligence and Digital Development. The right to defend your rights and to claim compensation for moral and material damage, including in court, comes from article 24 paragraph 1 subparagraph 7 of the Law. Deletion and anonymisation can also be required under article 41 of the Digital Code.