1. About this document
VybeFlow is operated by PT Horizon Vyber Nusantara (formerly PT Vyber Asia Cloud) (“we”), at Plosokuning 5 RT 25, RW 10, Kel. Minomartani, Kec. Ngaglik, Sleman, Special Region of Yogyakarta 55581, Indonesia. The service is reached at vybeflow.vyber.id.
This policy covers the VybeFlow console, the website chatbot you install through our SDK, and every channel integration you connect through the service. It does not cover third-party sites, apps or services you connect yourself — including WhatsApp, Instagram and Telegram, each of which has its own privacy policy.
Read it alongside the Terms & Conditions and the WhatsApp Data Policy.
2. Our two roles over your data
This distinction decides almost everything else in this document, so it comes first.
As data controller
For your business account data — name, email address, phone number, team members and their roles, subscription history and payments — we are the controller. We decide what that data is used for, and you can exercise the rights in section 10 directly with us.
As data processor
For the contents of conversations with your customers — messages, phone numbers, account names, attachments, tickets and notes — we are a processor acting on your instructions. You are the controller. You decide which customers are contacted, what is sent, and how long it stays in your account.
The consequence is real: if one of your customers asks for their data to be deleted, that request is addressed to you, not to us. We provide the tools and will help if asked, but the duty to answer is yours. Section 11 explains how.
3. What we collect
| Category | Contents | Our role |
|---|---|---|
| Account identity | Name, email, profile photo from Google or Facebook at sign-up, phone number | Controller |
| Team members | Email and role (Admin or Operational) of everyone you invite | Controller |
| Subscription data | Plan, quota used, top-up history, payment status | Controller |
| Channel configuration | WhatsApp Business number identity, Instagram Business account, Telegram bot token, website chatbot domain | Controller |
| Conversation contents | Inbound and outbound messages, customer display names and numbers, image and document attachments, ticket status, ticket conclusions | Processor |
| Contact database | Contacts and customers you upload or import | Processor |
| Agent configuration | System prompt, skills, product catalogue, API connectors and their parameters | Controller |
| Technical logs | IP address, access time, browser type, application errors, Manager AI activity records | Controller |
What we do not collect. We never ask for or store credit card numbers or other card details. Payments are handled by a payment provider (see section 7) and we receive only the transaction status. We do not store your password either: sign-in goes through Google or Facebook.
Masked parameters. When you mark an API connector parameter as sensitive — an OTP or a password, say — its value is passed to your target API but is never shown in the console and never written to the conversation transcript.
4. Where the data comes from
- From you, when you sign up, invite a team, connect channels, upload contacts and configure agents.
- From the WhatsApp Business Platform (Meta), when a customer messages your business number. Details in the WhatsApp Data Policy.
- From the Instagram Graph API (Meta), when a customer sends a direct message to your Instagram Business account.
- From the Telegram Bot API, when a customer messages the bot you connected.
- From your website chatbot, when a visitor starts a conversation through the SDK you installed.
- From the payment provider, as a transaction status when you buy quota or a subscription.
5. What the data is used for
| Purpose | Basis |
|---|---|
| Running the service: receiving messages, generating AI replies, managing tickets, running campaigns | Performance of our contract with you |
| Billing and counting quota | Performance of the contract |
| Security, and preventing abuse and spam | Our and your legitimate interests |
| Technical support when you ask for help | Performance of the contract |
| Meeting legal obligations and Meta platform policy | Legal and contractual obligation |
| Telling you about material changes to the service | Legitimate interest |
We do not sell your data or your customers' data, and we do not share it with advertisers.
6. How AI processes conversations
To generate a reply, the relevant conversation content is sent to the third-party AI model providers we use as subprocessors. What is sent is the context needed to answer: recent messages in that conversation, the system prompt you wrote, and data from the skills you enabled — your product catalogue, for instance.
We choose providers who are contractually barred from using your data to train their models. The list of providers in use can change over time; the current list is available on request through the contact in section 15.
The agent's web search feature sends the search query — not the whole conversation — to a third-party search provider.
A limit you should know about. AI model output is probabilistic and can be wrong. You are responsible for what your agent says to your customers; the AI Lab exists so you can test it before that happens. Do not put data that must not reach a third party into a system prompt or a skill.
7. Who the data is shared with
We share data only with the subprocessors needed to run the service, and only as far as they need it:
| Party | For what |
|---|---|
| Meta Platforms, Inc. | Sending and receiving WhatsApp and Instagram messages |
| Telegram FZ-LLC | Sending and receiving Telegram messages |
| AI model providers | Generating agent replies (see section 6) |
| Payment gateway provider | Processing subscription and quota top-up payments |
| Infrastructure and database providers | Running and storing the service |
Beyond that, we may disclose data where required by law or a valid court order, or where necessary to protect the rights, safety and security of ourselves or our users. In a merger, acquisition or asset sale, data may pass to the successor, and you will be told before that takes effect.
8. How long data is kept
- Account data is kept while your account is active.
- Conversation contents and tickets are kept while your account is active, because that history is what lets an agent recognise a returning customer. You can delete them sooner — see section 11.
- Payment records are kept for as long as tax and accounting rules require.
- Technical logs are kept briefly, for diagnosis and security.
- After an account is closed, data is deleted or anonymised within 90 days, except what we are legally required to keep.
9. Security
Access to the console requires authentication through Google or Facebook; we do not store your password. Data in transit is protected by TLS. Internal access is limited to staff who need it for operations and support. Within your own account, the Admin and Operational roles limit who can connect or disconnect a channel.
No system is completely safe. If a security incident affects personal data, we will notify you and the competent authority as the applicable rules require.
10. Your rights
Under Law No. 27 of 2022 on Personal Data Protection, you have the right to: know what data we process and why; obtain a copy; correct inaccurate data; have data deleted; restrict or object to certain processing; withdraw consent you previously gave; and lodge a complaint with the competent authority.
Make a request through the contact in section 15. We will respond within a reasonable time, generally no more than 30 days, and may ask you to verify your identity before acting on a request involving personal data.
If you are a customer of a business that uses VybeFlow, your request must go to that business. They are the controller of those conversations; we only process on their instructions.
11. Data deletion
There are three routes, depending on what you want removed.
Deleting one conversation or one contact
Do it directly in the console, in the Inbox or the Database. Deletion applies to your account and cannot be undone.
Deleting all of your account data
Send a request from the email address registered on your account to admin@vyber.id with the subject “Data Deletion”. Once your identity is verified we delete the account data and every conversation in it within 30 days, and from system backups within 90 days.
Revoking app access from Facebook or Instagram
Open Settings & privacy → Settings → Apps and websites in your Facebook account and remove VybeFlow. Revoking access stops new data from flowing; to remove data already stored, send the deletion request above as well.
Data we are legally required to keep — payment records for tax purposes, for instance — is retained until that period ends and is not used for anything else.
12. Processing outside Indonesia
Some of our subprocessors — particularly the messaging platforms and the AI model providers — process data outside Indonesia. Where that happens, we ensure there is an adequate basis and adequate safeguards as required by the applicable personal data protection rules, including contractual obligations of confidentiality and security.
13. Children
VybeFlow is a service for businesses and is not directed at anyone under 18. We do not knowingly collect children's personal data. If you become aware of such data in our service, contact us and it will be deleted.
14. Changes to this policy
We may update this policy. The version and effective date appear at the top of the page. For changes that materially affect you, we will give notice by email to your registered address or in the console before they take effect.
15. Contacting us
For questions, rights requests, or data deletion:
PT Horizon Vyber NusantaraPlosokuning 5 RT 25, RW 10
Kel. Minomartani, Kec. Ngaglik
Sleman, Special Region of Yogyakarta 55581
Indonesia
Email: admin@vyber.id