This policy explains what PerseuBot does with personal data. It covers two very different sets of people: the businesses that subscribe to PerseuBot, and the customers of those businesses whose messages and bookings pass through it. Which part applies to you depends on which of the two you are — Section 2 says how to tell.
1. Introduction
PerseuBot is a service that answers a business's customers on WhatsApp and books appointments into its calendar. This policy describes how Vertice Studio, which operates PerseuBot, collects, uses, shares and protects personal data in connection with it.
We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Portuguese Law No. 58/2019. Please read this policy together with our Terms and Conditions.
2. Who we are, and our two roles
Vertice Studio […], registered office at […], Portugal, NIF 236 609 734.
Privacy contact: privacidade@perseubot.com
We have not appointed a statutory Data Protection Officer, as we are not required to. Send privacy questions to the address above.
Because PerseuBot is a platform businesses use to serve their own customers, our role under the GDPR depends on whose data is involved:
| Whose data | Our role | Where to read |
|---|---|---|
| Our business clients (account holders) and their Authorised Users | Controller — we decide why and how it is processed | Part A, Sections 4–8 |
| End Customers of those businesses — people who message a business or book with it | Processor — we act on the business's instructions; the business is the controller | Part C, Section 13 |
If you are an End Customer who messaged a business using PerseuBot, or booked an appointment through it, and you want to exercise your privacy rights: contact that business. They control your data. We help them answer. See Section 13.7.
3. Scope
This policy covers personal data processed through the PerseuBot management console and the PerseuBot mobile app for iPhone and Android; the WhatsApp assistant and the WhatsApp gateway that connects to it; the public booking pages; the reminder and campaign sender; and our website, support and billing.
It does not cover the separate privacy policies of the third parties listed in Section 9, nor what a business does with personal data outside PerseuBot.
Part A — Where Vertice Studio is the controller
_Applies to our business clients, their Authorised Users, and people who contact us._
4. What we collect about you
4.1. Account and identity. Your name, email address, a bcrypt hash of your password (never the password itself), your role, your account status and your timezone.
4.2. Business configuration. What you set up in order to run the Services: business name, booking-page address, contact details, the WhatsApp number you connect, the owner number that receives handover alerts, opening hours, breaks and holidays, services and prices, staff and resources, and your knowledge base. Where this includes personal data about your own staff, you are responsible for the legal basis on which you provide it — see Section 13.
4.3. WhatsApp connection data. The credentials your linked-device session produces when you scan the pairing code, the connected phone number, and the session's status and health. Session secrets are encrypted at rest. We do not receive or store your WhatsApp password, and we have no relationship with Meta — see Section 12.
4.4. Billing. Billing contact, VAT/NIF, plan, subscription status and transaction records, together with the identifiers Stripe issues for your customer and subscription. Card details go to Stripe's hosted pages and never reach our servers.
4.5. Usage, device and log data. IP address, browser and device information, which pages and features were used, timestamps and diagnostic logs. We also record operational metrics — message volume, latency, automation and escalation rates, and model token usage and cost. If you use the mobile app and allow notifications, we also keep that phone's push token, its platform (iOS or Android), the language it is set to and which alerts you chose, so we can send them; they are deleted when you sign out on that phone, change your password or sign out everywhere else, and after six months without use.
4.6. Audit trail. Significant administrative actions taken in your Account — who changed a plan, who deleted a customer, who paired a device — with the acting user and the time.
4.7. Communications. Your correspondence with us, including support requests.
4.8. Cookies. See Section 11.
5. Why, and on what legal basis
| Purpose | Legal basis (Article 6 GDPR) |
|---|---|
| Creating and administering your account; providing the Services | Contract — Art. 6(1)(b) |
| Authenticating users, encrypting secrets, keeping the Services secure | Contract and legitimate interests — Art. 6(1)(f) |
| Billing, invoicing and collecting payment | Contract and legal obligation — Art. 6(1)(c) |
| Support and answering your requests | Contract / legitimate interests |
| Monitoring, maintaining, debugging and improving the Services; aggregated analytics | Legitimate interests |
| Keeping an audit trail of administrative actions | Legitimate interests in accountability and security |
| Service and administrative messages | Contract / legitimate interests |
| Marketing our own Services to business contacts | Legitimate interests, or consent where required. You can opt out at any time |
| Accounting and tax obligations | Legal obligation |
| Establishing, exercising or defending legal claims; preventing fraud and abuse | Legitimate interests |
Where we rely on legitimate interests, we have weighed them against your rights. You may object — see Section 8.
6. How long we keep it
- Account and configuration data — for the life of your account, then for 30 days so it can be reactivated or exported, after which it is deleted or anonymised.
- Billing and tax records — for the period Portuguese law requires, generally 10 years.
- Logs and security data — typically 6 to 12 months.
- Audit trail — for the life of the account. The record of our own administrative actions on it — its creation, suspension, deletion and removal, with the business name and the owner's email address — is kept after the account is removed, as evidence of what was done and when.
- Encrypted backups — rotated on an approximately 30-day cycle, so deleted data can persist in a backup until that cycle completes.
- Marketing data — until you opt out, or after a period of inactivity.
We may keep data longer where a legal obligation requires it or to establish, exercise or defend a legal claim.
7. Who we share it with
The recipients in Section 9. We do not sell personal data, and we do not use it to train models.
8. Your rights
Subject to the conditions in the GDPR you have the right to access your data, to have it corrected, to have it erased, to restrict its processing, to portability, to object to processing based on legitimate interests or to direct marketing, and to withdraw consent where we rely on it, without affecting processing already carried out.
You can also delete your account yourself, in the mobile app: More → your account → Delete account. A staff login is deleted at once; if you are a business's only owner, the business is deleted with it and removed for good after 30 days (Section 6).
Write to privacidade@perseubot.com. We answer within one month, extendable by two further months for complex requests. We may need to verify your identity first.
You may also complain to the Portuguese supervisory authority:
Comissão Nacional de Proteção de Dados (CNPD) — Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa — cnpd.pt — geral@cnpd.pt
or to the authority in your own EU country of residence.
Part B — Applies to everyone
9. Recipients, sub-processors and international transfers
9.1. Sub-processors. We require each of these to protect personal data and to process it only as needed to provide their service to us.
| Recipient | What it does | Location | Safeguard |
|---|---|---|---|
| Ollama (Ollama Cloud) | Generates assistant replies | United States | SCCs; no training on submitted data |
| OpenRouter, where enabled | Alternative model routing | United States | SCCs; no-training and zero-retention settings where the routed model supports them |
| Stripe Payments Europe, Ltd. | Payments, invoicing, billing portal | Ireland (EEA), onward to Stripe, Inc. (US) | Stripe's intra-group SCCs; card data never reaches us |
| Our hosting provider | Application, database and WhatsApp gateway | Germany | Data stays in the EEA |
| Our object-storage provider | Encrypted off-site backups | European region | Encrypted before upload; SCCs if outside the EEA |
| Our email relay | Password resets and service notices | EEA | Data stays in the EEA |
| Expo (650 Industries, Inc.) | Delivers the mobile app's notifications | United States | SCCs in the provider's data processing terms |
| Apple and Google | Carry notifications to the phone (Apple Push Notification service, Firebase Cloud Messaging) | United States / EEA | SCCs in the provider's data processing terms |
"SCCs" means the European Commission's Standard Contractual Clauses — see 9.3.
What the model provider actually receives. To generate one reply, we send the text of the incoming message, the relevant part of the business's knowledge base, and the recent turns of that conversation. We do not send customer records, appointment history or billing data. Replies are not retained by the provider for training.
What a notification contains. The customer's name and, for a booking, the service and the time — never the text of a message. It goes only to the phones of people in the business who switched that alert on.
WhatsApp and Meta are deliberately absent from this table. PerseuBot does not use the WhatsApp Business Cloud API and we have no contractual relationship with Meta. Section 12 explains what that means for your data.
9.2. Other recipients. Professional advisers (legal, accounting), authorities where the law requires, and an acquirer in a merger or sale of assets, with continued protection.
9.3. Transfers outside the EEA. The model provider, Stripe's US affiliate and the notification services are outside the European Economic Area. For those transfers we rely on the European Commission's Standard Contractual Clauses, supplemented by technical measures including encryption in transit and at rest. You may request a copy of the relevant safeguards from privacidade@perseubot.com.
9.4. Changes. We will tell business clients in advance of any new sub-processor that will handle End-Customer data, as described in Section 13.6.
10. How we protect personal data
We apply technical and organisational measures appropriate to the risk:
- passwords hashed with bcrypt, never stored or logged in the clear;
- session and integration secrets encrypted at rest, with key rotation supported;
- TLS for all traffic, with HTTP Strict Transport Security;
- multi-tenant isolation: every record is scoped to one business and every query is filtered by it, so one business cannot reach another's data;
- role-based access, separating business roles from platform administration, with an audit trail of administrative actions;
- short-lived access tokens with separate, revocable refresh tokens;
- anti-abuse controls on public booking pages — rate limiting, a honeypot field and booking caps;
- rate limiting on authentication and signup;
- least-privilege access for our own personnel, and encrypted off-site backups.
No system is perfectly secure. If a personal-data breach is likely to result in a risk to individuals, we will notify the supervisory authority and, where required, the affected individuals or the business client concerned, within the timescales the GDPR sets.
11. Cookies
The console and our websites use cookies and similar storage that are strictly necessary for the Services to work — keeping you signed in, securing sessions, and remembering your chosen language. These do not require consent. If we ever deploy non-essential cookies such as analytics, we will ask for your consent through a banner first, in line with the ePrivacy rules and Portuguese law.
The marketing site you are reading sets no cookies at all.
12. WhatsApp: what our connection means for data
PerseuBot does not use the WhatsApp Business Cloud API. It connects to a business's existing WhatsApp account as a linked device, using an independent implementation of the WhatsApp multi-device protocol — the same mechanism as WhatsApp Web. Three consequences follow, and we would rather state them than leave them to be discovered:
- Meta is not our sub-processor, and we cannot make it one. Messages between an End Customer and a business travel over WhatsApp's own infrastructure and are subject to Meta's privacy policy, over which we have no influence and no contract.
- We do hold message content. Once a message reaches the linked device, PerseuBot stores its text so the assistant can answer, so the business can read its conversations, and so bookings can be traced back to what was agreed. Retention is described in Section 13.8.
- The connection can be ended by Meta. A number may be restricted or banned without notice. That is a service risk rather than a privacy risk, and it is described in Section 6 of the Terms.
Part C — Where Vertice Studio is the processor
13. Data processing terms (DPA)
This Section 13 is the Data Processing Agreement between Vertice Studio ("Processor") and each business client ("Controller") under Article 28 GDPR, governing End-Customer personal data. It is incorporated into the Terms and Conditions.
13.1. Subject matter and duration. The Processor processes End-Customer personal data in order to provide the Services, for as long as the Controller's subscription lasts and as set out in 13.8.
13.2. Nature and purpose. Receiving, storing and routing WhatsApp messages; generating assistant replies; managing conversations and human handover; creating, changing and cancelling appointments; sending appointment reminders and, where the Controller uses them, promotional campaigns; maintaining the Controller's customer records; and producing analytics for the Controller.
13.3. Categories of data subject. The Controller's End Customers — people who contact it on WhatsApp or book an appointment — and anyone named inside a conversation or a booking field.
13.4. Types of personal data, as configured by the Controller:
- Identifiers and contact data — WhatsApp ID and phone number, display name, and email where the Controller collects it as a booking field;
- Message content — the text of messages exchanged with the assistant or with a human, plus metadata: direction, timestamps, delivery status and gateway message ID;
- Customer record — tags, free-text notes written by the Controller's staff, marketing-consent status, first and last seen, and the timestamp at which the End Customer was told the assistant is automated;
- Booking data — service, staff member, date, time, status, source and the answers to any custom booking fields the Controller defines;
- Technical data — the IP address recorded against a public booking, for anti-abuse purposes only.
The Controller must not configure custom fields, or otherwise route special-category data (Article 9 GDPR) through the Services, unless it has a valid legal basis and has told the Processor. The Services are not specifically designed to safeguard such data.
13.5. Processor obligations. The Processor will:
- (a) process End-Customer personal data only on the Controller's documented instructions — these terms and the Controller's configuration of the Services being those instructions — unless EU or Member-State law requires otherwise, in which case it will say so unless prohibited;
- (b) ensure that people authorised to process the data are bound by confidentiality;
- (c) implement the technical and organisational measures described in Section 10;
- (d) observe the conditions for engaging sub-processors in 13.6;
- (e) assist the Controller, taking into account the nature of the processing, with data-subject requests (13.7) and with its obligations under Articles 32–36 GDPR;
- (f) notify the Controller without undue delay after becoming aware of a personal-data breach affecting End-Customer data;
- (g) delete or return End-Customer personal data at the end of the Services, as described in 13.8;
- (h) make available the information needed to demonstrate compliance with Article 28 and allow for audits by the Controller or an auditor it mandates, on reasonable notice, subject to confidentiality and to reasonable limits on frequency.
13.6. Sub-processors. The Controller gives general authorisation for the Processor to engage the sub-processors listed in Section 9.1 — in particular the model provider, the hosting provider and Stripe. The Processor imposes data-protection obligations on each that are no less protective than this DPA, and remains liable for their performance. The Processor will give the Controller reasonable notice of any intended addition or replacement, and the Controller may object on reasonable data-protection grounds.
13.7. Data-subject requests. The Processor will assist the Controller, so far as possible and by appropriate measures, in responding to End Customers exercising their rights of access, rectification, erasure, restriction, portability and objection. The console provides the Controller with the tools to do this directly: a per-customer export and a per-customer erasure. If the Processor receives a request straight from an End Customer, it will, where lawful, refer it to the Controller rather than answer it itself.
13.8. Retention, minimisation, erasure and return.
- Message content is minimised after approximately 18 months. As a technical measure, and unless the Controller instructs otherwise in writing, the readable text of a message and the raw payload behind it are removed after that period. The record itself survives so that counts, timestamps and the link to an appointment remain intact.
- Customer records and appointment history are kept until the Controller deletes them, or until it exercises erasure on an End Customer's behalf. They are not swept automatically, because they are the business records the Controller relies on.
- On erasure of an End Customer, that person's conversations and message content are deleted, and their appointments are anonymised and kept only as non-identifying business records.
- On termination of the Services, End-Customer personal data is available for export for 30 days, after which the Processor deletes it and instructs its sub-processors to do the same, unless EU or Member-State law requires it to be kept. Encrypted backups are deleted on the standard rotation cycle of approximately 30 days.
13.9. International transfers. The Processor may transfer End-Customer personal data outside the EEA to the sub-processors in Section 9.1 — in practice, the message text and knowledge base sent to the model provider, and a customer's name and a booking's service and time in notifications to the business's own team — under the safeguards in Section 9.3. The Controller authorises those transfers.
13.10. Controller responsibilities. The Controller warrants that it has a valid legal basis for the processing it instructs, that it has given its End Customers the privacy notices the law requires, and that its configuration and instructions comply with applicable law. In particular:
- the Controller is responsible for the lawfulness of any promotional campaign it sends. PerseuBot does not obtain marketing consent on the Controller's behalf, and a customer record created from an ordinary conversation carries no consent;
- the Controller must not enter into the knowledge base, or into customer notes, personal data it has no basis to hold.
13.11. Automated interaction is disclosed. The Services tell each End Customer, on first contact, that they are speaking with an automated assistant and may ask for a person, as Article 50 of Regulation (EU) 2024/1689 requires. The Controller must not defeat that disclosure.
13.12. Liability. Liability under this DPA is subject to the limits in the Terms and Conditions, to the extent the GDPR permits.
Part D
14. Children
The Services are business tools and are not directed at children. We do not knowingly collect personal data from children. Business clients are responsible for not using the Services to collect data from children without an appropriate legal basis.
15. Changes to this policy
We may update this policy. If we make a material change we will tell business clients by email or in the Services, and update the date at the top. Continuing to use the Services after the change takes effect constitutes acknowledgement of the updated policy.
16. Contact
Vertice Studio — privacidade@perseubot.com — […], Portugal
Questions about this document? privacidade@perseubot.com