Version 1.0, effective 7 September 2026. These documents were drawn up by the service operator, Risolveo, and apply from that date; the version accepted at registration is stored with the time of acceptance. Questions:
support@risolveo.com.
Privacy Policy
Version 1.0, effective 7 September 2026. The operator and controller for the website and accounts is Risolveo. Personal data requests: support@risolveo.com.
1. Who it covers
The policy applies to:
- visitors of risolveo.com;
- representatives of companies who request a demo;
- owners, admins and members of client companies who work in the cabinet;
- customers and other people who talk to a client company’s AI employee in its channels;
- anyone who writes to us about security, data or support.
It does not replace the client company’s own notice to its customers: the company must inform them about its processing.
2. Roles
- Controller — for the website, demo requests, accounts, contracts, invoices, security and abuse prevention the operator acts as an independent controller.
- Processor — the content of customer conversations, knowledge base materials, channel identifiers and actions on the company’s instructions the operator processes on behalf of the client company under the Data Processing Agreement (DPA).
- As a separate controller only where the law requires independent processing: fulfilling a legal obligation, fraud prevention, protecting rights.
3. What data is processed
Website visitors and demo requests. Name, work email, company and the text of the request if you provided them; the web server’s technical logs: IP address, time, requested address, browser type. The site uses no analytics, advertising pixels or external fonts; no request leaves the site’s pages for third parties.
Cabinet users. Email, name, role and company; the password only as a strong hash (scrypt); second-factor settings and hashes of recovery codes; the chosen language; actions in the cabinet (the log); sign-in address and time in the security logs.
Customers of client companies. Channel identifier (widget visitor key, Telegram id, email address or WhatsApp number depending on the channel), message text, time, language, reply and handover status, the handover review by staff. The service does not accept attachments from customers.
Company materials. Knowledge base pages (entered by hand, uploaded as files, gathered from the company’s website or from connected systems), the owners map, the rules for the bot, channel and connection settings. Connection secrets (Confluence, Jira, Slack, bot and mailbox tokens) are stored only encrypted and are never returned.
Security logs. Sign-in events, role and settings changes, actions of people and the bot, errors, rate-limit hits, incident details.
4. Data that must not be sent
Passwords, API keys, one-time codes, full payment card data, medical, biometric and other special categories of data, criminal records and children’s data are not passed through the service. The AI employee asks the customer not to send such data in its very first message. If such data nevertheless ended up in a conversation, the client company removes it with the cabinet’s tools (section 9), and the operator does so on its request.
5. Purposes and legal bases
| Purpose | Basis |
|---|
| Website, registration, cabinet, demo | Contract, or steps at your request before concluding it |
| Replying to a request and business correspondence | Legitimate interest in B2B communication |
| The AI employee working in the company’s channels | The client company’s documented instructions and the DPA |
| Security, logs, abuse limits | Legitimate interest in protecting the service, clients and customers |
| Invoices, accounting and tax records | Legal obligation |
| Protecting rights and resolving disputes | Legitimate interest; establishing, exercising and defending claims |
The client company itself determines the legal basis for processing its customers’ data.
6. How the AI works
In the first message the customer is told that they are talking to an AI employee, that it can make mistakes, that secrets should not be sent and that a person can be called. The company cannot switch this message off.
To draft an answer, the text of the conversation and excerpts from the company’s public materials are passed to the language model provider (see the subprocessor register). The provider processes them under commercial terms that exclude using the data to train models. The bot answers only with support from the company’s materials; without it, it asks a clarifying question or hands the conversation to a member of staff.
The service makes no decisions with legal or similarly significant effect for a person solely automatically. At any moment the customer can ask for a person; at the plan limit the conversation is not rejected but handed to the company’s staff.
7. Who receives data
- the client company and the staff it has authorised — everything relating to its channels and cabinet;
- the operator’s subprocessors — hosting and database (Hetzner Online GmbH, Germany), the language model provider (Anthropic, PBC, USA), service emails (Resend, Inc., processing in the EU region); the full register with data categories and transfer mechanisms is on the Subprocessors page;
- the channel platforms the company connected itself (Telegram, Meta for WhatsApp, the company’s mail server) and its systems (Confluence, Jira, Slack) — they operate under the company’s agreements with those platforms and are not the operator’s subprocessors;
- Stripe Payments Europe, Ltd. (Ireland) — once online payment is connected: card and payer data is processed by Stripe as an independent controller under its own terms; the operator receives the payment status, the amount and the last digits of the card;
- the operator’s professional advisers bound by confidentiality;
- public authorities — only where disclosure is required by law;
- a successor in a reorganisation or sale of the business, with these obligations preserved.
8. Where data is stored and international transfers
The server, the database and backups are in Germany (Hetzner, Falkenstein). The operator’s team in Ukraine has access to them. Service emails are sent through Resend’s infrastructure in the EU. Requests to the language model go to the provider in the USA.
For data from the EEA, the transfer to the operator in Ukraine and the onward transfer to subprocessors outside the EEA are covered by the European Commission’s Standard Contractual Clauses (Decision 2021/914, Modules 2 and 3) incorporated in the DPA, with additional measures: encryption in transit and of stored secrets, minimisation of the data sent to the model, and need-to-know access. For data from the United Kingdom the UK Addendum applies.
9. Retention periods
| What | How long |
|---|
| A website request without a contract | 6 months after the last contact |
| Company account and knowledge base materials | The contract term and 30 days after termination |
| Customer conversations | The period the company sets in the cabinet: by default 30 days on Start, 90 on Operator, 365 on Business; zero means “never delete”. Counted from the last message, applied daily by a background job |
| Action log | The contract term; deleted together with the company’s data |
| Web server and container logs | Up to 30 days, rotated by size |
| Security incident data | Up to 12 months, or longer where documented legal necessity requires |
| Backups | Rolling 14-day window |
| Invoices, contracts, records of acceptance of the terms | The period set by tax and accounting law |
Erasing a conversation at a person’s request replaces the message text with a marker and clears the identifiers; the counters (how many requests, how many handed to a person) remain as anonymised statistics. After a restore from backup the deletion jobs are applied again.
10. Your rights
You may request access to your data, rectification, erasure, restriction of processing, portability, object to processing based on legitimate interest, withdraw consent (without affecting processing that was already lawful), require human intervention in an automated decision and lodge a complaint with the supervisory authority where you live.
A customer’s request about a client company’s channel the operator passes to that company within three business days; the company has “show what we keep” and “erase” buttons in the cabinet and is responsible for the substantive reply. Requests to the operator as a controller go to support@risolveo.com; a reply within 30 days. A proportionate identity check may be required first.
11. Cookies and browser storage
The website, the cabinet and the widget set no cookies. The cabinet keeps in the browser’s localStorage the sign-in key, the chosen language and a mark that the onboarding video was shown; the widget keeps the conversation pass and the visitor id. Details are in the Cookie Policy.
12. Security
Company isolation at the database row level, roles and permissions, a second factor for sign-in, encryption of secrets with master key rotation, TLS, logging, rate limits, daily backups. In detail and verifiably — on the Security page.
Of a confirmed incident affecting a company’s data the operator notifies it without undue delay and no later than 48 hours after confirmation; notifying customers and regulators follows the rules of the DPA.
13. Children
The service is meant for businesses; accounts are created by adult authorised representatives of companies. If a company points its channel at minors, it is responsible for the legal basis, the notice and parental consent where required.
14. Changes
The version and date are shown at the top. Account owners are notified of material changes by email at least 15 days in advance. A new processing purpose is not applied to already collected data without a proper basis.
15. Contact
Risolveo Email for data and security matters: support@risolveo.com.
Cookies and Browser Storage
Version 1.0, effective 7 September 2026. Operator: Risolveo. Questions: support@risolveo.com.
1. In short
The risolveo.com website, the cabinet and the website widget set no cookies and use no analytics, advertising pixels, session recording, social buttons or external fonts. Not a single request leaves the site’s pages for a third party. That is why there is no cookie banner: there is nothing to consent to.
2. What is kept in the browser
The cabinet and the widget use the browser’s localStorage, and only for what is strictly necessary:
| Where | Entry | Purpose | Lifetime |
|---|
| Cabinet | Sign-in key | Keeps you signed in; removed by “Sign out” | Until sign-out; the sign-in itself lasts 12 hours |
| Cabinet | Cabinet language | Shows the chosen language before the first request to the server | Until changed |
| Cabinet | Mark that the onboarding video was shown | Not to open the video window on every sign-in | Until the storage is cleared |
| Widget on the company’s site | Conversation pass and visitor id | Continue the same conversation after a page reload; count limits per visitor | The pass lasts 60 minutes and is renewed during the conversation |
These entries leave the browser only in requests to the Risolveo server for the function they exist for, and are not used to track you across sites.
3. If anything is added
Before connecting any technology that sets cookies or sends data to third parties (analytics, a payment form, CAPTCHA, social sign-in), the operator will describe it in this policy with the cookie name, provider and lifetime; block non-essential technologies until consent, with equal “accept” and “decline” buttons; and add the provider to the subprocessor register if it receives personal data. A new version is published at least 15 days in advance.
4. Managing it
localStorage entries are removed through the browser settings (“clear site data”). After that you will need to sign in to the cabinet again, and a widget conversation starts with a new pass.
Terms of Use
Version 1.0, effective 7 September 2026. The service operator is Risolveo. Questions: support@risolveo.com.
1. What these terms cover
The terms govern access to the Risolveo service (the service): the risolveo.com website, the company cabinet, the API, the website widget and the channels a company connects to the service. The terms are concluded between the operator and the client company (the client) on whose behalf an account is created.
The Privacy Policy, the Data Processing Agreement (DPA), the Acceptable Use Policy, the Payments and Refunds Policy, the Service Level and Support document (SLA) and the subprocessor register form part of these terms. In case of conflict on personal data matters the DPA prevails, then an accepted Order Form, then these terms.
2. Business only
The service is intended for companies and professional use. The person who creates an account or accepts the documents confirms that they:
- are at least 18 years old;
- act within the company’s business, not as a consumer;
- are entitled to bind that company by contract;
- have provided accurate company details and contacts.
3. What the service does
Risolveo is an AI support employee. It answers the company’s customers on the basis of the materials the company itself has moved to the public part of its knowledge base, asks clarifying questions, hands conversations over to the company’s staff, creates tasks for owners and reminds them, keeps a log of its actions and shows metrics.
The set of functions depends on the plan (section 8) and the cabinet settings. A promise that is not in the cabinet or in these documents is not part of the contract.
4. Modes of operation
- Observe. The bot analyses and drafts replies; nothing goes out.
- Confirm. The bot drafts a reply; a member of staff sends, edits or rejects it in the cabinet; every decision stays in the log.
- Self. The bot replies and acts without confirmation within the thresholds and rules the company sets.
Self mode is not available on the Start plan. On the other plans only the account owner can switch it on, after acceptance cases, at least three business days in Confirm mode and an explicit confirmation in the cabinet; the confirmation is written to the log. The owner may switch it on earlier by accepting the risk with an explicit action, which is also recorded.
Self mode does not apply to decisions with legal or similarly significant effect: credit, insurance, hiring, education, health, public benefits, payments and transfers, changes of bank details, concluding or changing a contract. Such scenarios require separate written agreement and meaningful human oversight.
5. AI limitations
The bot’s answers may be inaccurate, incomplete or outdated. The bot answers only with support from the company’s public materials and does not invent prices, dates or conditions; otherwise it asks a clarifying question or calls a person. The client must:
- review the materials it moves outside and the rules for the bot;
- decide where human confirmation is required;
- not present the bot’s answer as legal, medical or financial advice;
- give customers an accessible way to reach a member of staff;
- monitor quality through the log and handover reviews.
The operator does not guarantee a particular commercial outcome, the absence of errors in the bot’s answers or uninterrupted operation of third-party channels.
6. Account and access
The client is responsible for:
- lawfully adding staff and assigning roles (owner, admin, member);
- protecting passwords, the second factor, recovery codes and access keys;
- promptly removing the access of staff who have left;
- immediately informing the operator of a suspected compromise.
The company access key carries all the owner’s powers and has no role: handing it over means handing over the owner’s powers. The account cannot be transferred to another company.
7. Client data and materials
The client retains the rights to its data and materials. The operator receives a limited right to process them only to provide, protect and support the service under the terms and the DPA. The operator does not use client data for advertising, does not sell it and does not train models on it.
The client warrants that it has the rights and a lawful basis for the materials and data it uploads and passes on; that it has informed its customers about the processing; and that its instructions and rules for the bot are lawful. The operator may refuse an instruction that clearly breaches the law, these terms, security or third-party rights.
Data category restrictions are set by the Acceptable Use Policy: passwords, keys, codes, full card data, special categories of data and children’s data are not passed through the service without separate written agreement.
8. Plans, activation and limits
The Start, Operator, Business and Managed plans: prices, included volumes and limits are published on the website and shown in the cabinet under “Personal data → Plan”. Registration is open; channels and the widget are switched on after the first invoice is paid or a promo code is entered (activation). Before activation the client can fill in the knowledge base, the owners map and the settings.
At 80, 90 and 100% of the included conversation volume the owner receives a notification. When the volume is used up the bot does not refuse customers but hands them over to the company’s staff; additional conversations are charged only if the client has itself enabled overage in the cabinet.
9. Confidentiality
Each party protects the other party’s non-public business, technical and personal information with no less care than its own, uses it only for the contract and discloses it only to those who need it and are bound by confidentiality. The duty does not cover information that has lawfully become public, was obtained without breach or must be disclosed by law; of the latter a party notifies the other in advance where permitted.
10. Intellectual property
The service, its technology, interfaces, documentation and brand remain the property of the operator and its licensors. The client receives a non-exclusive, non-transferable right to use the service during the paid or agreed period.
The rights to the client’s materials remain with the client. The client may use the bot’s answers in its business; responsibility for checking them before use lies with the client. Feedback and suggestions may be used to develop the service without disclosing confidential information.
11. Changes to the service
The operator develops the service and may change functions. The core paid functionality is not materially reduced without at least 15 days’ notice; if a change materially worsens an already paid period, the client may terminate the contract and receive a refund for unused full months (Payments Policy, section 7).
12. Payment
Payment is made against the operator’s invoice under the Payments and Refunds Policy. Prices exclude taxes unless the invoice says otherwise. A delay of more than 14 days after a reminder entitles the operator to limit access until payment; the client’s data is kept in accordance with section 15.
13. Support and availability
The availability level, maintenance windows, support hours and response targets, and downtime credits are described in the Service Level and Support document. Round-the-clock human support is not provided unless agreed in an Order Form for the Managed plan.
14. Suspension
The operator may immediately limit access to the extent necessary to remove a security threat, prevent unlawful or prohibited use, comply with a binding demand of a public authority or protect other clients. For a material breach of the terms — after notice, where prior notice is safe. The client is told the reason and given an opportunity to fix the breach.
15. Term, termination and data
The contract runs for as long as the client has an account. The client may terminate it at any time by email to support@risolveo.com; the operator with 30 days’ notice, or immediately for a material breach not remedied within 14 days of notice.
After termination the client may export its data through the cabinet and the API for 30 days. The company’s data is then deleted under the DPA: from the live systems within 30 days, from backups within the following 14 days. Mandatory records (invoices, contracts, records of acceptance of the terms) are kept for as long as the law requires.
16. Disclaimer of warranties
To the maximum extent permitted by law the service is provided “as is” and “as available”. No guarantee is given that AI answers are error-free, that the service is compatible with every system or that a particular result is achieved. Mandatory warranties that cannot be excluded by law remain.
17. Limitation of liability
To the maximum extent permitted by law neither party is liable for indirect losses, lost profit, loss of data caused by third parties or the cost of substitute services. The operator’s aggregate liability under the contract is limited to the amount paid by the client for the service in the 12 months preceding the event. The limitation does not apply to intent, gross negligence and liability that cannot be limited by law.
18. Third-party claims
The client defends the operator against third-party claims arising from the client’s unlawful data or instructions, a breach of the Acceptable Use Policy or the client’s lack of rights and notices, provided the operator gives timely notice and reasonable assistance. The operator defends the client against claims that the service infringes third-party intellectual property rights on the same conditions.
19. Governing law and disputes
The terms are governed by the laws of Ukraine. Disputes are resolved in the competent court at the operator’s registered location. For clients from the EEA and the United Kingdom the mandatory data protection rules apply regardless of the chosen law. Before going to court the parties try in good faith to settle a dispute in writing within 30 days.
20. Changes to the terms
The current version and date are published on this page; the version the client accepted is stored together with the time of acceptance. The operator notifies the account owner of material changes by email at least 15 days in advance. A client who disagrees may terminate the contract before the changes take effect without penalty; continued use after that date means acceptance of the new version.
21. Acceptance
The terms are accepted at registration by a separate explicit action with confirmation of authority. The service stores the company, the user, the versions of the accepted documents and the UTC time of acceptance.
22. Contact
Risolveo Email for all matters, including legal notices: support@risolveo.com.
Data Processing Agreement (DPA)
Version 1.0, effective 7 September 2026. Parties: the client company as controller and Risolveo as processor.
1. How it is concluded
The agreement is accepted together with the Terms of Use at company registration and applies without a separate signature. A client that needs a signed copy with both parties’ details writes to support@risolveo.com with the subject “DPA” and the company name; the operator returns the signed document within five business days.
2. Subject matter and precedence
The processor processes personal data on behalf of the controller solely to provide the Risolveo service and to carry out the controller’s documented instructions. The DPA is part of the Terms; on personal data matters the DPA prevails, then the Order Form, then the Terms, unless mandatory law requires otherwise.
3. Definitions
“Personal data”, “processing”, “controller”, “processor”, “subprocessor”, “data subject” and “personal data breach” have the meaning given by the applicable data protection law, including the GDPR and the UK GDPR. “Client data” means the personal data the processor receives from the controller, its staff and customers through the service and processes on the controller’s behalf.
4. Controller’s instructions
The processor:
- processes client data only on documented instructions: the Terms, the Order Form, the cabinet settings and the actions of authorised staff;
- informs the controller if, in its reasonable opinion, an instruction breaches applicable law, where such notice is not prohibited;
- does not sell client data, does not use it for advertising or model training and does not set new processing purposes;
- limits processing to what is necessary to provide and protect the service.
5. Controller’s obligations
The controller confirms that it has a lawful basis for collecting and transferring the data; that it has informed the data subjects about its processing and about the use of AI; that its instructions are lawful and documented; that it does not pass prohibited categories of data (Acceptable Use Policy); that it determines the public part of the knowledge base, the rules for the bot, the autonomy mode, staff roles and the conversation retention period; and that it is responsible for decisions taken on the basis of the bot’s answers.
6. Confidentiality and personnel
Access to client data is given only to persons who need it for their work and are bound by a duty of confidentiality. The processor applies least privilege, personal accounts, a second factor for privileged access, periodic review of rights and removal of the access of those who have left.
7. Security
The processor applies the measures listed in Annex 2; they are confirmed by the code and the configuration of the production installation (see Security). The controller is responsible for the security of its own side: devices, channels, staff, connected systems, access keys and settings.
8. Subprocessors
The controller gives general written authorisation to engage the subprocessors in the current register (the Subprocessors page, Annex 3). The processor imposes on each subprocessor data protection obligations no less protective than these in the applicable part, remains liable to the controller for their performance, notifies the account owner by email of a new or replaced subprocessor at least 15 days before it is given access to client data, and accepts reasoned objections on data protection grounds. If an objection cannot be resolved proportionately, the controller may terminate the contract for the affected function or entirely without penalty, with a refund for unused full months.
9. Data subject rights
A data subject request relating to client data the processor forwards to the controller without undue delay and no later than three business days, and does not answer on the merits except where mandatory law requires. The processor provides tools in the cabinet (“Personal data” section) to export and erase a customer’s data and gives reasonable assistance with the other rights. The controller is responsible for the decision on the request, the identity check and meeting the deadline.
10. Impact assessments and consultations
The processor provides the available information the controller needs for a data protection impact assessment and consultations with a supervisory authority: the description of processing (Annex 1), the measures (Annex 2), the subprocessor register and the Security page. Work beyond the standard documentation may be charged by agreement, except assistance that mandatory law does not allow to be made conditional on payment.
11. Security breaches
Of a confirmed breach affecting client data the processor notifies the account owner by email without undue delay and no later than 48 hours after confirmation. The notice, as far as the information is available, states the nature of the incident, the categories and approximate number of affected data subjects and records, the likely consequences, the measures taken and planned and a contact for coordination; it is supplemented as the investigation proceeds and does not constitute an admission of fault. Notifying data subjects and regulators is the controller’s responsibility; the processor gives reasonable assistance.
12. Deletion and return
Within 30 days after the end of the service the controller exports its data through the cabinet and the API; after that period the processor deletes the client data from the live systems, and within the following 14 days it leaves the backup window. Backups are protected and used only for recovery; after a restore the deletion jobs are applied again. Anonymised counters may be kept only if irreversibly anonymised.
13. Audits
First, the processor provides documentation, the results of automated checks and answers to a reasonable security questionnaire. An additional audit takes place no more than once in 12 months (except after a confirmed incident or on a regulator’s demand), with 30 days’ notice, by a qualified auditor bound by confidentiality, in a scope that does not expose other clients’ data and does not disrupt the service; the controller bears the costs unless the audit reveals a material breach by the processor.
14. International transfers
Data is stored in Germany (EEA). The processor is located in Ukraine; its team’s access to data from the EEA and the transfer to subprocessors in the USA are covered by the European Commission’s Standard Contractual Clauses (Decision 2021/914): Module 2 between the controller in the EEA and the processor, Module 3 between the processor and the subprocessors. The Clauses are incorporated into this DPA in the version published by the Commission; Clause 7 (docking) applies; Clause 9 — option 2 (general authorisation, 15 days); Clause 11 — without the optional language; Clauses 17 and 18 — the law and courts of Ireland; Annex I — Annex 1 of this DPA; Annex II — Annex 2; the competent supervisory authority is that of the controller’s country. For data from the United Kingdom the UK International Data Transfer Addendum to the same Clauses applies. Additional measures: TLS in transit, encryption of secrets, minimisation of the data sent to the model, need-to-know access.
15. Liability
Liability under the DPA is governed by the Terms, except liability that cannot be limited by law. The DPA does not create separate unlimited liability.
16. Term
The DPA applies for as long as the processor processes client data and continues to apply to retained data after the end of the service.
Annex 1. Description of processing
| Element | Description |
|---|
| Subject matter | AI support employee: answers to customers from the client’s materials, clarifications, handover to staff, tasks and reminders, log and metrics |
| Duration | The contract term and 30 days of deletion after termination |
| Nature | Receipt, storage, retrieval, transfer to the model provider to draft an answer, sending into the channel, logging, export, erasure |
| Purpose | Operation of the channels and functions of the service configured by the client |
| Data subjects | The client’s customers and contacts; the client’s staff; other persons whose data the client lawfully provided |
| Data | Channel identifiers, message text, time, language, statuses, knowledge base materials, the owners map, actions and settings |
| Special categories | Not permitted |
| Frequency | Continuous while the service is used |
| Retention | The period set by the client in the cabinet; the rules of the Privacy Policy |
Annex 2. Technical and organisational measures
- company isolation at the database row level (Row-Level Security enforced) and no access without a company context;
- TLS for all connections; certificates renew automatically;
- connection and channel secrets under envelope encryption with the company key and master key rotation;
- passwords only as hashes; second factor (TOTP) and recovery codes; owner / admin / member roles;
- rate limits on sign-in and registration;
- an append-only log of the actions of people and the bot, without message bodies;
- daily backups with a 14-day window and tested restoration;
- automatic security updates of the server; a firewall open only on 22, 80 and 443; server sign-in by keys only;
- availability monitoring with alerts to the operator;
- the conversation retention period applied by a background job from the last message; export and erasure of a customer’s data from the cabinet;
- minimisation of the data sent to the model provider; the provider’s commercial terms without training on data;
- review of the team’s access and removal of those who have left.
Annex 3. Subprocessors
The current register is published on the Subprocessors page and forms part of the DPA.
Acceptable Use
Version 1.0, effective 7 September 2026. Part of the Terms of Use. A breach of this policy is a material breach of the Terms.
1. Lawful use
The service must not be used for:
- fraud, deception, extortion or obtaining money unlawfully;
- violating privacy, intellectual property or confidentiality rights;
- discrimination, harassment, threats, exploitation or causing harm;
- circumventing sanctions, export restrictions or mandatory requirements;
- passing AI off as a human: the disclosure in the first message cannot be switched off, and the rules for the bot may not instruct it to hide its nature;
- fake reviews, impersonation or misleading messages.
2. Prohibited data
Without separate written agreement with the operator, the following must not be passed through the service:
- passwords, private keys, API keys, one-time codes and recovery codes;
- full payment card data and other payment authentication data;
- medical, genetic, biometric and other special categories of personal data;
- criminal records;
- children’s data;
- high-risk government identifiers (passports, tax numbers);
- data obtained without a lawful basis or the required notice.
If a customer sent such data on their own, the company removes it with the cabinet’s tools.
3. Automated decisions
The bot may not be the sole basis for a decision with legal or similarly significant effect: creditworthiness and insurance; hiring, dismissal and employee evaluation; admission to education; medical diagnosis and treatment; public benefits and essential services; concluding or changing a contract; payments, transfers and changes of bank details. Such scenarios require documented human review and separate agreement.
4. Communications
The service is not used for spam, unlawful mailings, contact lists without a proper basis or circumventing opt-outs. The bot answers customer requests; outbound marketing messages are not sent through it.
5. Security
It is prohibited to:
- search for or exploit vulnerabilities of the service or of other clients outside the vulnerability disclosure rules (the Security page);
- bypass company isolation, rate limits, permissions and protective mechanisms;
- upload malicious code or use the service to control it;
- guess credentials, run phishing or collect other people’s sign-in data;
- create disproportionate load or interfere with the service;
- hand account access or company keys to unauthorised persons.
6. Materials and rules for the bot
The company is responsible for its knowledge base, the rules for the bot and the connected systems. The bot may not be instructed to violate rights, state knowingly false information, bypass agreed limits or collect customer data beyond what an answer needs.
7. Response
On a reasonable suspicion of a breach the operator limits the function or the account to the minimum necessary extent and, where safe and lawful, states the reason and gives an opportunity to fix the breach. A serious or repeated breach leads to termination of access under section 15 of the Terms. Report a breach: support@risolveo.com.
Payments, Subscriptions and Refunds
Version 1.0, effective 7 September 2026. The operator and payee is Risolveo. Invoice questions: support@risolveo.com.
1. Business only
The service is sold to companies and professional users. The price, period, included volume and renewal terms are determined by the plan chosen at registration or in the cabinet and by the invoice; for the Managed plan, by an Order Form.
2. Plans
| Start | Operator | Business | Managed |
|---|
| Per month | $99 | $199 | $399 | from $699 |
| Per year (ten monthly fees) | $990 | $1,990 | $3,990 | from $6,990 |
| Setup, one-off | $149 | $249 | $499 | $900 |
| Conversations per month | 300 | 1,000 | 3,000 | by agreement |
| Beyond the volume, per conversation | $0.35 | $0.25 | $0.18 | $0.15 |
| Channels | 1 (no WhatsApp) | 2 | 4 | by agreement |
| Staff | 3 | 10 | 30 | by agreement |
| Knowledge base pages | 200 | 1,500 | 5,000 | by agreement |
| Connections to your systems | 0 | 1 | 5 | by agreement |
| Self mode | no | after acceptance | after acceptance | after acceptance |
| Default conversation retention | 30 days | 90 days | 365 days | by agreement |
Prices are in US dollars excluding taxes. Taxes, where they apply to a transaction, are shown separately on the invoice; when paying from another country the client provides the details needed for correct taxation.
3. How payment works
Registration is free. After registration the operator issues an invoice for setup and the first period to the account owner’s email; channels and the widget are switched on once payment is received (activation) or with a promo code. Payment is by bank transfer to the details on the invoice. Online card payment goes through Stripe (Stripe Payments Europe, Ltd., Ireland) once it is connected; clients are notified of the date through the subprocessor register at least 15 days in advance. Card data is processed by Stripe and never reaches the operator.
Invoices are due within 14 days. A delay after a reminder entitles the operator to limit access until payment; the company’s data is kept in accordance with the Terms.
4. Promo codes and pilots
A promo code activates a plan for the period stated in it without payment. Pilot terms, discounts and credits are fixed in an Order Form or by email; credits have no monetary value and are neither transferable nor refundable.
5. Renewal and cancellation
The subscription renews against an invoice for the next period; there are no automatic charges until the client explicitly enables them after a payment provider is connected. The subscription can be cancelled at any time by email to support@risolveo.com: access continues until the end of the paid period and no further invoice is issued.
6. Exceeding the volume
At 80, 90 and 100% of the included conversations the owner receives a notification. When the volume is used up the bot hands new requests to the company’s staff; conversations beyond the volume are charged at the plan rate only if the client has enabled overage in the cabinet. Overage is billed on the next invoice with a breakdown.
7. Refunds
A refund is given:
- for unused full months of a paid period — on termination for the operator’s material breach, on a material reduction of paid functionality (Terms, section 11) and on a reasoned objection to a new subprocessor (DPA, section 8);
- for an erroneous or double charge — in full;
- on cancelling an annual plan within the first 30 days — for unused full months;
- in other cases where the law requires it.
The setup fee is not refunded once setup has been carried out. Dissatisfaction with the bot’s answers is not in itself a ground for a refund: answers require the client’s oversight, and the remedies for a breach of contract are described in the Terms. Refunds are made within 14 days to the details the payment came from.
8. Invoice disputes
A question about an invoice is first sent to support@risolveo.com with the invoice number; the operator replies within five business days. The right to contact the bank remains, but a knowingly false chargeback is a breach of the Terms.
Service Level and Support
Version 1.0, effective 7 September 2026. Part of the Terms of Use. Questions: support@risolveo.com.
1. Availability
The operator keeps the service (cabinet, API, widget, processing of messages in channels) available at least 99.5% of the time in a calendar month. Availability is measured by the operator’s own monitoring, which checks the server’s health every minute.
Excluded from the calculation:
- planned maintenance announced to the account owner by email at least 24 hours in advance, no more than four hours per month in total, at night Kyiv time where possible;
- outages of channel platforms and company systems (Telegram, Meta, the company’s mail server, Confluence, Jira, Slack) and of the client’s network;
- circumstances beyond the operator’s reasonable control;
- access limits under the Terms (overdue payment, policy breach).
Outages of the operator’s own subprocessors (hosting, model provider, email) count: they are the operator’s choice, not the client’s.
2. Downtime credits
If availability in a month fell below the target, the client may request a credit by email to support@risolveo.com within 30 days after the end of that month:
| Availability in the month | Credit |
|---|
| below 99.5% but not below 99.0% | 10% of the monthly fee |
| below 99.0% | 25% of the monthly fee |
The credit is applied to the next invoice and is the sole remedy for downtime, apart from the right to terminate for a breach lasting more than 30 consecutive days.
3. Support
Support works by email at support@risolveo.com on business days from 9:00 to 18:00 Kyiv time. First-response targets:
| Plan | First response |
|---|
| Start | 2 business days |
| Operator | 1 business day |
| Business | 8 business hours |
| Managed | 4 business hours; a named contact; out-of-hours handling per the Order Form |
A report of service unavailability or a security incident on any plan is taken up immediately during business hours and within four hours outside them. Round-the-clock human support is not provided unless agreed in an Order Form.
4. Onboarding
Channels (Telegram, email, WhatsApp) and the company’s systems are connected together with the client under the onboarding procedure after activation; the operator completes its part within two business days of receiving the access details from the client. The onboarding video and in-app hints are available in the cabinet right after registration.
5. Incidents
The operator informs the account owner by email about an outage affecting the client as the facts become clear and, after the fix, with a short description of the cause and the measures taken. Security incidents follow section 11 of the DPA.
6. Data and recovery
Database backups are made daily and kept for 14 days; restoration is tested. The recovery objective after losing the server is at most 24 hours (RTO) and the data-loss objective at most one day (RPO). The client can export its data from the cabinet and via the API at any time.
Security
Version 1.0, effective 7 September 2026. A description of what exists in the product and on the production installation. The operator holds no ISO 27001, SOC 2 or PCI DSS certification and claims none.
1. Company isolation
Each company’s data is separated at the database row level: the access policy is enforced on every table, the application connects to the database with a role that cannot bypass it, and a query without a company context returns nothing. Background jobs read shared tables only through separate reviewed functions. Isolation is covered by automated checks that try to read and change other companies’ data and fail if they succeed.
2. Access and accounts
- sign-in by email and password; the password is stored only as a hash (scrypt);
- second factor — an authenticator app (TOTP) and recovery codes; recommended for owners and admins;
- owner, admin and member roles; permissions are checked on the server for every action;
- a sign-in lasts 12 hours; company access keys are issued and revoked by the owner, shown once and stored as hashes;
- rate limits: sign-in — at most 20 attempts per address and 10 per email in 15 minutes; registration — 5 per address per hour;
- removing a departed employee’s access takes effect immediately.
3. Encryption and secrets
- TLS for all connections to the website, cabinet, API and widget; certificates are issued and renewed automatically;
- connection and channel tokens (Confluence, Jira, Slack, bots, mailboxes) are stored under envelope encryption with the company key; the master key lives only in the server configuration and is rotated by a procedure that never exposes secrets;
- logs contain no message bodies, passwords, codes or tokens; secrets are not stored in the repository.
4. AI controls
- AI disclosure in the first message in the customer’s language; the company cannot switch it off;
- the bot answers only with support from the company’s public materials; without it, it asks a clarifying question or calls a person;
- the Observe, Confirm and Self modes are a property of the bot’s toolset, not a request to the model: in Observe mode it physically has no tools that change the world;
- Self — only after acceptance, three business days in Confirm and the owner’s explicit confirmation, written to the log;
- customer stop phrases, lack of support and the plan limit hand the conversation to a person; limits on messages per conversation and per visitor per day protect against exhaustion;
- the model provider receives the conversation text and excerpts of the materials — without staff names or connection secrets;
- isolation checks for knowledge base search across companies are part of the automated suite.
5. Infrastructure
- one server in a Hetzner data centre in Germany; sign-in by SSH keys only, passwords and root sign-in disabled; the firewall allows only 22, 80 and 443;
- security updates of the system are installed automatically;
- the service runs in containers; the database and the queue are not reachable from outside;
- monitoring checks the health every minute and alerts the operator on failure;
- container logs are size-limited and rotated.
6. Backups and recovery
A database backup is made daily at 03:00 UTC and kept for 14 days; restoration from a backup has been tested on a staging server and is repeated on every significant schema change. Backups are kept on the operator’s server in a separate directory; off-site backup storage in the EEA will be introduced with notice through the subprocessor register.
7. Log
The log of the actions of people and the bot is append-only: the application cannot change or delete an entry. An entry holds the company, who acted, the type of action, the UTC time and a safe object identifier. The company’s staff can see the log in the cabinet.
8. Development
Code passes automated checks before release: types and a suite of more than six hundred tests, including checks of isolation, permissions, modes and data erasure. Dependencies are updated on a schedule; only a committed version of the repository reaches the production server.
9. Incidents
A security incident is confirmed unauthorised access to, change, loss or disclosure of data. The procedure: containment, preserving evidence, assessing the affected companies and records, recovery, notifying the owners of affected accounts no later than 48 hours after confirmation, a review of causes and measures. Contact for incident reports: support@risolveo.com with the subject “security”.
10. Vulnerability disclosure
The operator accepts vulnerability reports from good-faith researchers at support@risolveo.com with the subject “security” and at /.well-known/security.txt. The rules:
- in scope: risolveo.com, the cabinet, the API, the widget;
- out of scope: availability attacks, social engineering, physical access, third-party platforms;
- do not read or change other people’s data beyond what is needed for a proof; on reaching other people’s data — stop and report;
- acknowledgement of receipt within two business days, assessment and a fix plan within five; critical vulnerabilities are fixed first;
- the operator does not pursue researchers who follow these rules and does not pass their data to third parties; no bounty is paid; public thanks at the researcher’s wish after the fix.
Subprocessors
Version 1.0, effective 7 September 2026. The register is part of the Data Processing Agreement. Account owners are notified of changes by email at least 15 days in advance.
1. Current subprocessors
| Provider | Service in Risolveo | Data | Where it processes | Transfer mechanism |
|---|
| Hetzner Online GmbH, Germany | Server, database, backups, TLS termination | All service data: accounts, materials, conversations, logs | Falkenstein, Germany (EEA) | Processing inside the EEA; the provider’s data processing agreement |
| Anthropic, PBC, USA | Language model: understanding the question and drafting the answer | Text of the current conversation, excerpts from the company’s public materials, the rules for the bot; no staff names or secrets | USA | Standard Contractual Clauses (Module 3) and the Data Privacy Framework under the provider’s terms; commercial terms with no training on data |
| Resend, Inc., USA | Service emails: staff invitations, password recovery codes, operator alerts about plans and outages | Recipient address, subject, code or link; no customer conversations | EU region (Ireland) | Processing in the EU; Standard Contractual Clauses under the provider’s terms |
The operator, Risolveo, is located in Ukraine; the team’s access to the data in Germany is covered by the Standard Contractual Clauses (Module 2) under section 14 of the DPA.
2. What is not a subprocessor
The channel platforms and systems that the company connects itself — Telegram, Meta (WhatsApp), the company’s mail server, Confluence, Jira, Slack — operate under the company’s own agreements with those platforms. The operator passes them only what a channel needs to work (messages into the channel, tasks into Jira, notifications into Slack), on the company’s instructions, and is not responsible for their terms.
The domain registrar and DNS do not process the service’s personal data.
3. Planned changes
| Provider | For what | When |
|---|
| Stripe Payments Europe, Ltd., Ireland | Online card payments and invoicing; card data is processed by Stripe, the operator receives only the status, the amount and the last digits | Being connected; access to data no earlier than 15 days after notice. Until then payment is by invoice and no payment data reaches the operator |
| Off-site backup storage (EEA) | Backups outside the main server | No earlier than 15 days after notice |
4. Objections
A reasoned objection on data protection grounds is sent to support@risolveo.com within 15 days of the notice. The parties look for a proportionate solution; if there is none, the company may terminate the contract for the affected function or entirely without penalty (DPA, section 8).
5. Change history
| Date | Change |
|---|
| 5 September 2026 | Hetzner Online GmbH — production server; Resend, Inc. — service emails |
| 7 September 2026 | Anthropic, PBC — language model provider; register published |