RRisolveo
Version 1.0, effective 7 September 2026. These documents were drawn up by the service operator, Risolveo, and apply from that date; the version accepted at registration is stored with the time of acceptance. Questions: support@risolveo.com.

Privacy Policy

Version 1.0, effective 7 September 2026. The operator and controller for the website and accounts is Risolveo. Personal data requests: support@risolveo.com.

1. Who it covers

The policy applies to:

  • visitors of risolveo.com;
  • representatives of companies who request a demo;
  • owners, admins and members of client companies who work in the cabinet;
  • customers and other people who talk to a client company’s AI employee in its channels;
  • anyone who writes to us about security, data or support.

It does not replace the client company’s own notice to its customers: the company must inform them about its processing.

2. Roles

  • Controller — for the website, demo requests, accounts, contracts, invoices, security and abuse prevention the operator acts as an independent controller.
  • Processor — the content of customer conversations, knowledge base materials, channel identifiers and actions on the company’s instructions the operator processes on behalf of the client company under the Data Processing Agreement (DPA).
  • As a separate controller only where the law requires independent processing: fulfilling a legal obligation, fraud prevention, protecting rights.

3. What data is processed

Website visitors and demo requests. Name, work email, company and the text of the request if you provided them; the web server’s technical logs: IP address, time, requested address, browser type. The site uses no analytics, advertising pixels or external fonts; no request leaves the site’s pages for third parties.

Cabinet users. Email, name, role and company; the password only as a strong hash (scrypt); second-factor settings and hashes of recovery codes; the chosen language; actions in the cabinet (the log); sign-in address and time in the security logs.

Customers of client companies. Channel identifier (widget visitor key, Telegram id, email address or WhatsApp number depending on the channel), message text, time, language, reply and handover status, the handover review by staff. The service does not accept attachments from customers.

Company materials. Knowledge base pages (entered by hand, uploaded as files, gathered from the company’s website or from connected systems), the owners map, the rules for the bot, channel and connection settings. Connection secrets (Confluence, Jira, Slack, bot and mailbox tokens) are stored only encrypted and are never returned.

Security logs. Sign-in events, role and settings changes, actions of people and the bot, errors, rate-limit hits, incident details.

4. Data that must not be sent

Passwords, API keys, one-time codes, full payment card data, medical, biometric and other special categories of data, criminal records and children’s data are not passed through the service. The AI employee asks the customer not to send such data in its very first message. If such data nevertheless ended up in a conversation, the client company removes it with the cabinet’s tools (section 9), and the operator does so on its request.

5. Purposes and legal bases

PurposeBasis
Website, registration, cabinet, demoContract, or steps at your request before concluding it
Replying to a request and business correspondenceLegitimate interest in B2B communication
The AI employee working in the company’s channelsThe client company’s documented instructions and the DPA
Security, logs, abuse limitsLegitimate interest in protecting the service, clients and customers
Invoices, accounting and tax recordsLegal obligation
Protecting rights and resolving disputesLegitimate interest; establishing, exercising and defending claims

The client company itself determines the legal basis for processing its customers’ data.

6. How the AI works

In the first message the customer is told that they are talking to an AI employee, that it can make mistakes, that secrets should not be sent and that a person can be called. The company cannot switch this message off.

To draft an answer, the text of the conversation and excerpts from the company’s public materials are passed to the language model provider (see the subprocessor register). The provider processes them under commercial terms that exclude using the data to train models. The bot answers only with support from the company’s materials; without it, it asks a clarifying question or hands the conversation to a member of staff.

The service makes no decisions with legal or similarly significant effect for a person solely automatically. At any moment the customer can ask for a person; at the plan limit the conversation is not rejected but handed to the company’s staff.

7. Who receives data

  • the client company and the staff it has authorised — everything relating to its channels and cabinet;
  • the operator’s subprocessors — hosting and database (Hetzner Online GmbH, Germany), the language model provider (Anthropic, PBC, USA), service emails (Resend, Inc., processing in the EU region); the full register with data categories and transfer mechanisms is on the Subprocessors page;
  • the channel platforms the company connected itself (Telegram, Meta for WhatsApp, the company’s mail server) and its systems (Confluence, Jira, Slack) — they operate under the company’s agreements with those platforms and are not the operator’s subprocessors;
  • Stripe Payments Europe, Ltd. (Ireland) — once online payment is connected: card and payer data is processed by Stripe as an independent controller under its own terms; the operator receives the payment status, the amount and the last digits of the card;
  • the operator’s professional advisers bound by confidentiality;
  • public authorities — only where disclosure is required by law;
  • a successor in a reorganisation or sale of the business, with these obligations preserved.

8. Where data is stored and international transfers

The server, the database and backups are in Germany (Hetzner, Falkenstein). The operator’s team in Ukraine has access to them. Service emails are sent through Resend’s infrastructure in the EU. Requests to the language model go to the provider in the USA.

For data from the EEA, the transfer to the operator in Ukraine and the onward transfer to subprocessors outside the EEA are covered by the European Commission’s Standard Contractual Clauses (Decision 2021/914, Modules 2 and 3) incorporated in the DPA, with additional measures: encryption in transit and of stored secrets, minimisation of the data sent to the model, and need-to-know access. For data from the United Kingdom the UK Addendum applies.

9. Retention periods

WhatHow long
A website request without a contract6 months after the last contact
Company account and knowledge base materialsThe contract term and 30 days after termination
Customer conversationsThe period the company sets in the cabinet: by default 30 days on Start, 90 on Operator, 365 on Business; zero means “never delete”. Counted from the last message, applied daily by a background job
Action logThe contract term; deleted together with the company’s data
Web server and container logsUp to 30 days, rotated by size
Security incident dataUp to 12 months, or longer where documented legal necessity requires
BackupsRolling 14-day window
Invoices, contracts, records of acceptance of the termsThe period set by tax and accounting law

Erasing a conversation at a person’s request replaces the message text with a marker and clears the identifiers; the counters (how many requests, how many handed to a person) remain as anonymised statistics. After a restore from backup the deletion jobs are applied again.

10. Your rights

You may request access to your data, rectification, erasure, restriction of processing, portability, object to processing based on legitimate interest, withdraw consent (without affecting processing that was already lawful), require human intervention in an automated decision and lodge a complaint with the supervisory authority where you live.

A customer’s request about a client company’s channel the operator passes to that company within three business days; the company has “show what we keep” and “erase” buttons in the cabinet and is responsible for the substantive reply. Requests to the operator as a controller go to support@risolveo.com; a reply within 30 days. A proportionate identity check may be required first.

11. Cookies and browser storage

The website, the cabinet and the widget set no cookies. The cabinet keeps in the browser’s localStorage the sign-in key, the chosen language and a mark that the onboarding video was shown; the widget keeps the conversation pass and the visitor id. Details are in the Cookie Policy.

12. Security

Company isolation at the database row level, roles and permissions, a second factor for sign-in, encryption of secrets with master key rotation, TLS, logging, rate limits, daily backups. In detail and verifiably — on the Security page.

Of a confirmed incident affecting a company’s data the operator notifies it without undue delay and no later than 48 hours after confirmation; notifying customers and regulators follows the rules of the DPA.

13. Children

The service is meant for businesses; accounts are created by adult authorised representatives of companies. If a company points its channel at minors, it is responsible for the legal basis, the notice and parental consent where required.

14. Changes

The version and date are shown at the top. Account owners are notified of material changes by email at least 15 days in advance. A new processing purpose is not applied to already collected data without a proper basis.

15. Contact

Risolveo Email for data and security matters: support@risolveo.com.