Privacy Policy
1. Scope
This policy explains how Nuevo Automations FZE LLC (licence no. 4431808.01, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates) handles personal data in connection with OrcaFlo: our website, the signup and payment process, the OrcaFlo dashboard, and the WhatsApp assistant service we provide to businesses.
It covers two roles. For our own customers (the businesses using OrcaFlo and their staff) we decide how data is used. For our customers’ customers (people who message a business that uses OrcaFlo) we process data on that business’s behalf and under its instructions, and that business is responsible for telling them how their data is used.
2. What we collect
- Signup and account data: name, business name, business type, email, phone number, login credentials (stored hashed), and staff user details.
- Billing data: payment status, amounts and a customer reference from Stripe. Card details are collected and stored by Stripe, not by us.
- Business configuration: assistant instructions, setup answers, product catalogues, prices, documents and settings you provide.
- Conversation data (processed for our customers): WhatsApp phone numbers, TikTok usernames and account identifiers, names customers share, message content including text, images, videos and voice notes, lead stages, appointments, and notes.
- Connected Meta account data (processed for our customers, only when a business connects its accounts): Instagram, Facebook Page and WhatsApp Business Platform identifiers, messages and comments, lead form answers, and the access tokens Meta issues to let OrcaFlo act for that business. See Instagram, Facebook and WhatsApp below.
- Connected calendar and spreadsheet data (processed for our customers, only when a business connects them): from Google Calendar, the connected account’s email address, its list of calendars, busy/free times, and the events OrcaFlo itself creates; from Google Sheets, only the spreadsheets the business picks or OrcaFlo creates for it; from Calendly or Cal.com, the business’s booking pages and the bookings made through them (the booker’s name, email, phone number, answers to booking questions, time and status). See Google, Calendly and Cal.com below.
- Connected CRM data (processed for our customers, only when a business connects a CRM): the IDs of the HubSpot, Salesforce, Zoho CRM or Pipedrive records OrcaFlo created or matched, the contact details the business chooses to sync back into OrcaFlo, and the access tokens (stored encrypted). See CRM integrations below.
- Connected TikTok accounts: when a business connects its TikTok Business Account or TikTok ad account, we receive access tokens (stored encrypted), the account’s username and ID, direct messages sent to that account by people who chose to message it, and, for conversations that start from a TikTok ad or TikTok.me link, the ad or link that started them. We never message anyone on TikTok who has not messaged the business first.
- Website chat, email and Telegram (processed for our customers, only when a business turns them on): messages and files sent through a business’s chat widget, email inbox or Telegram bot, and the contact details people choose to give. See Website chat, email and Telegram below.
- Technical and usage data: logs, device and browser information, and anonymous page-view counts on our website used to measure signups. The dashboard stores your login session and preferences in your browser’s local storage.
- Advertising data (marketing pages only): if you reach our signup page from an advert, we record the advert or campaign that brought you, your IP address and browser, and Meta’s own click identifier. If you then sign up, we share a hashed (one-way encrypted) copy of your email address, phone number and name with Meta so it can tell us that advert produced a customer. Meta cannot read the hashed values; it can only compare them with hashes it already holds. None of this happens inside the dashboard, and none of it involves your customers’ conversations.
3. How we use it
- to create and run your account and provide the Service, including generating AI replies;
- to take payments, prevent fraud and keep accurate records;
- to onboard and support you, and to send service, billing and security messages;
- to monitor, secure, debug and improve the Service;
- to comply with legal obligations and enforce our Terms.
We rely on performing our contract with you, our legitimate interests in running a secure and reliable service, compliance with law and, where required, consent. We do not sell personal data, and we do not use conversation data to advertise to anyone.
4. Instagram, Facebook and WhatsApp
A business using OrcaFlo can connect its own Instagram professional account, Facebook Page, WhatsApp Business account (through Meta’s WhatsApp Business Platform, also called the Cloud API) and Meta lead forms. It does this by signing in with Meta and approving the permissions shown on Meta’s own screen. We only receive what that business approves, and only for the accounts and Pages it selects. For this data we act on the business’s behalf, as its processor.
What we receive and why:
- Account and Page details: the connected Instagram account’s ID, username and profile picture; the Facebook Page’s ID and name; the WhatsApp Business account ID, phone number and display name. We use these to show the business which accounts are connected and to route messages to the right place.
- Direct messages: messages that people send to the business on Instagram, Messenger or WhatsApp, including names or usernames, profile pictures Meta shares, text, images, voice notes and other attachments. We use them to show the conversation in the business’s inbox, to generate the AI replies the business has configured, and to send the business’s replies back.
- Comments: comments on the business’s own Instagram posts and reels and Facebook Page posts, and the commenter’s username. We use them so the business can reply, or have OrcaFlo send the commenter one private reply that the business has configured. We only act on comments on the business’s own content.
- Lead form answers: when someone submits a Meta lead form on the business’s advert, we receive the answers they gave (for example name, phone number, email and any custom questions), plus the advert and form it came from. We add them as a lead in the business’s OrcaFlo account so the business can contact them.
- Advert referral data: when someone starts a chat from a click-to-message advert, Meta tells us which advert it was (for example the ad ID and a click identifier). We use it so the business can see which adverts produce conversations and sales.
- Access tokens: the tokens Meta issues so OrcaFlo can act for the business. They are encrypted at rest and never shown in the dashboard.
Conversions API (per business). If a business chooses to connect its own Meta pixel or dataset, OrcaFlo can report outcomes from its chats (for example “became a lead” or “made a purchase”, with the value) to that business’s own Meta dataset, so the business can measure its adverts. Contact details sent this way (phone number, email, name) are hashed (one-way encrypted) before they leave our systems, together with the advert click identifier where one exists. This is off unless the business turns it on, it only ever goes to the business’s own dataset, and the business is responsible for telling its customers about it and having a lawful basis for it.
What we don’t do. We do not sell Meta platform data, use it to build profiles for advertising, share it with data brokers, or use it for any purpose other than providing OrcaFlo to the business that connected the account. We do not use it to train general-purpose AI models. We use it in line with Meta’s Platform Terms and Developer Policies.
Disconnecting. A business can disconnect an account at any time from OrcaFlo’s settings, or from Meta itself (Facebook: Settings & privacy → Settings → Business integrations; Instagram: Settings → Website permissions → Apps and websites). When that happens we stop receiving data and delete the stored access token. See Data deletion for how to have the data itself deleted.
5. Google, Calendly and Cal.com
A business using OrcaFlo can connect its own Google Calendar, Google Sheets, Calendly or Cal.com account so its assistant can book appointments into the business’s real diary and record leads where the business wants them. It does this by signing in on Google’s, Calendly’s or Cal.com’s own screen and approving the access shown there (or, for a self-hosted Cal.com server, by pasting an API key it creates there). We only receive what the business approves.
Google Calendar. With the business’s permission OrcaFlo:
- reads the list of the business’s calendars, so it can choose which ones count as “busy” and which one new bookings go into;
- reads free/busy times only (start and end times, never event titles, descriptions or guests) so the assistant only offers times when the business is actually free;
- creates, updates and cancels calendar events for appointments booked through OrcaFlo, with the customer’s name, phone number and the service booked;
- reads events OrcaFlo created, so the business can see a customer’s upcoming meetings next to their chat.
Google Sheets. OrcaFlo only has access to spreadsheets the business picks or that OrcaFlo creates for it, and uses that access to add a row for each new lead or order the business chose to record. It cannot see any other file in the business’s Google Drive.
Calendly and Cal.com. OrcaFlo reads the business’s booking pages so the assistant can send the right booking link, and receives a notification whenever someone books, reschedules or cancels through them. It uses the booking details (name, email, phone number, answers, time, status) to match the booking to the customer’s chat, update their lead stage and show the appointment in OrcaFlo.
How this data is stored and shared. Access tokens and API keys are encrypted at rest and never shown in the dashboard. Appointment details are stored in the business’s OrcaFlo account like any other appointment. Busy/free times are used on the spot to work out open slots and kept for no more than a few minutes. We never send Google Calendar event content, Google Sheets content, or any other Google user data to an AI model; the assistant only ever sees the list of open slots OrcaFlo worked out. We do not sell this data, use it for advertising, or use it to build, train or improve generalised AI or machine-learning models, and people at Nuevo Automations do not read it except with the business’s permission for support, for security, or where the law requires.
Google API Services User Data Policy. OrcaFlo’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting. A business can disconnect Google, Calendly or Cal.com at any time from OrcaFlo’s Integrations page, which deletes the stored token or key straight away and stops all access. Google access can also be removed at myaccount.google.com/permissions, and Calendly access under Calendly → Integrations & apps. Events OrcaFlo already created stay in the business’s own calendar unless it deletes them.
6. CRM integrations (HubSpot, Salesforce, Zoho CRM, Pipedrive)
A business using OrcaFlo can connect its own HubSpot, Salesforce, Zoho CRM or Pipedrive account so its leads and conversations appear there without anyone typing them twice. It does this by signing in on the CRM’s own screen and approving the access shown there. (Google Sheets is covered in the section above.)
What OrcaFlo sends to the CRM. For each of that business’s customers: name, email address and address when known, the phone number for WhatsApp contacts, the lead stage, temperature and source, a link to the chat in OrcaFlo, any custom fields the business chose to map, a short summary of each conversation (as a note, or a completed task in Salesforce), and a deal or opportunity, with the order amount and currency, when a lead is qualified or an order is paid. Each row OrcaFlo adds to a connected Google Sheet holds the same kind of lead details (date, name, phone number, email address, source, stage, temperature and a chat link) or order details (order ID, status, amount, currency and items).
What OrcaFlo reads from the CRM. Only the records it created, or found by searching the customer’s phone number or email address, so it can keep them up to date and avoid duplicates, plus the business’s own pipeline stages and lead statuses (settings, not personal data). Where the business chooses two-way sync (HubSpot and Salesforce), OrcaFlo reads back the name, email address and address of those records, and in Salesforce also the mapped custom fields. To show a CRM card next to a chat, OrcaFlo reads the linked record’s owner, stage or status and company (in HubSpot, also up to 10 properties the business chooses) when the card is opened; it displays them and doesn’t store them. OrcaFlo never imports any other records from the CRM.
How this data is stored and shared. Access tokens are encrypted at rest and never shown in the dashboard. Record IDs and synced fields are stored in the business’s OrcaFlo account like its other contact data. We do not sell this data, use it for advertising, or use it to train AI models.
Disconnecting. A business can disconnect a CRM at any time from OrcaFlo’s Integrations page, which deletes the stored tokens straight away, revokes OrcaFlo’s access at the CRM and cancels any syncs still waiting. It can also remove OrcaFlo from inside the CRM (for example under Connected apps in HubSpot). Records OrcaFlo already created stay in the business’s CRM unless it deletes them there.
7. Website chat, email and Telegram
Website chat. When a visitor uses a business’s OrcaFlo chat widget, we process their messages, any files they upload, and any name, email address or phone number they choose to give. We recognise the browser with a random visitor ID stored in its local storage. The widget uses no cookies and no third-party trackers. Uploaded files are stored on our servers and are available only to that business and that visitor.
Email. When a business connects its inbox (IMAP/SMTP), we read new incoming emails so its assistant can answer them, and store those messages and their attachments in the business’s conversation history. We don’t import older mail, and we skip newsletters, automatic replies and bounces. The mailbox password is stored encrypted.
Telegram. When a business connects a Telegram bot, we receive the messages people send to that bot, with their Telegram name and username (and a phone number only if they choose to share their contact), and send the business’s replies through Telegram.
Tracked chat links and QR codes. When someone opens a business’s tracked link or scans its QR code, we record the time, the type of device (mobile or desktop) and the host name of the website they came from. We don’t store their IP address or browser details.
9. How long we keep it
We keep account and configuration data while your account is active. Conversation data is kept while your account is active so the assistant can remember context and you can review history. After an account closes we delete or anonymise its data within a reasonable period, except records we must keep for legal, tax or accounting reasons, and backups that are overwritten on their normal cycle.
When a business disconnects an Instagram, Facebook or WhatsApp account, we delete its access token straight away. Messages, comments and leads already received stay in that business’s OrcaFlo account (they are its records) until the business deletes them, closes its account, or a deletion request is made as described in Data deletion.
When a business disconnects Google, Calendly or Cal.com, we delete its stored token or API key straight away and remove the notification subscriptions we created in that account. Appointments already booked stay in the business’s OrcaFlo account until it deletes them or closes its account.
When a business disconnects a CRM, we delete its tokens straight away, revoke our access there and stop syncing. Record IDs are kept on the business’s contacts in OrcaFlo, so reconnecting doesn’t create duplicates, until it deletes them or closes its account.
When a business’s team uses AI Assist in a conversation it has taken over, photos the customer sends in that conversation are kept for up to 7 days (at most the last 3) so the assistant can read them, then deleted automatically.
If a business disconnects TikTok or revokes OrcaFlo’s access, we delete its TikTok access tokens immediately and its TikTok conversation data within 30 days.
10. Security
We protect data with measures including encrypted connections, access controls with role-based permissions, hashed passwords and restricted administrative access. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you and the relevant authorities as required by law.
11. Your rights
Subject to applicable law, including the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), you may ask to access, correct, delete or restrict the processing of your personal data, object to certain processing, or receive a copy of your data. Contact us at support@orcaflo-panel.com.
If you messaged a business that uses OrcaFlo, please contact that business first, because it controls your conversation data. We will help it respond.
To have your data deleted, see Data deletion below.
12. Data deletion
You can ask us to delete your personal data at any time. There are three ways to do it:
- By email. Use the button below, or write to support@orcaflo-panel.com with the subject “Data deletion request”. Tell us your name, and the email address, phone number, Instagram username or Facebook name you used, and which business you dealt with if you know it.
- If you connected OrcaFlo with Facebook or Instagram (for example as a business owner connecting a Page or Instagram account): remove OrcaFlo in Facebook under Settings & privacy → Settings → Business integrations (or Apps and websites), then choose to delete the data OrcaFlo holds; on Instagram, go to Settings → Website permissions → Apps and websites and remove OrcaFlo. Meta then sends us a deletion request automatically, and you receive a confirmation code and a link where you can check its status.
- If you are a business using OrcaFlo: disconnect the account in OrcaFlo’s settings and email us to delete the related messages, comments and leads, or close your account and we delete all of its data.
What gets deleted. For a request that comes through Facebook or Instagram, we immediately disconnect every Page, Instagram account and WhatsApp account that Meta account connected to OrcaFlo, delete the stored access tokens, and delete the profile details we hold about that Meta account. Messages, comments and leads those connected accounts received are the business’s own customer records; we delete them when the business asks us to or closes its account. If you are a person who messaged a business (not the business itself), email us and we delete the messages, comments and lead answers linked to your Instagram, Facebook or WhatsApp identity across every business account on OrcaFlo within 30 days. Encrypted backups are kept for up to 35 days, with one monthly copy kept for about 3 months; deleted data disappears from them as they expire, and we never restore it into our live systems except to recover from a disaster.
We reply to email requests within 30 days. We may need to confirm it’s you before deleting anything, and we keep records we are legally required to keep (for example invoices). If a business that uses OrcaFlo holds your data as its own customer record, we will also tell that business about your request.
14. Children
OrcaFlo is a business service for people aged 18 and over; we don’t knowingly collect personal data from children. Businesses using OrcaFlo must not use it to collect children’s data unlawfully, and must obtain a parent’s or guardian’s consent where the law requires it.
If you believe a child’s data has reached us, use the deletion request above and we’ll remove it.
15. Changes
We may update this policy and will post the new version here with a new date. Material changes will be notified to account holders by email or in the dashboard.
16. Contact
Nuevo Automations FZE LLC
Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
Email: support@orcaflo-panel.com
orca.flo