VybeFlowby vyber.id

Legal

VybeFlow Privacy Policy

This document explains what personal data we collect, what it is used for, who it is shared with, how long it is kept, and what rights you have over it.

Effective 6 September 2026 Version 1.0 PT Horizon Vyber Nusantara
Contents

Contents

  1. About this document
  2. Our two roles over your data
  3. What we collect
  4. Where the data comes from
  5. What the data is used for
  6. How AI processes conversations
  7. Who the data is shared with
  8. How long data is kept
  9. Security
  10. Your rights
  11. Data deletion
  12. Processing outside Indonesia
  13. Children
  14. Changes to this policy
  15. Contacting us

1. About this document

VybeFlow is operated by PT Horizon Vyber Nusantara (formerly PT Vyber Asia Cloud) (“we”), at Plosokuning 5 RT 25, RW 10, Kel. Minomartani, Kec. Ngaglik, Sleman, Special Region of Yogyakarta 55581, Indonesia. The service is reached at vybeflow.vyber.id.

This policy covers the VybeFlow console, the website chatbot you install through our SDK, and every channel integration you connect through the service. It does not cover third-party sites, apps or services you connect yourself — including WhatsApp, Instagram and Telegram, each of which has its own privacy policy.

Read it alongside the Terms & Conditions and the WhatsApp Data Policy.

2. Our two roles over your data

This distinction decides almost everything else in this document, so it comes first.

As data controller

For your business account data — name, email address, phone number, team members and their roles, subscription history and payments — we are the controller. We decide what that data is used for, and you can exercise the rights in section 10 directly with us.

As data processor

For the contents of conversations with your customers — messages, phone numbers, account names, attachments, tickets and notes — we are a processor acting on your instructions. You are the controller. You decide which customers are contacted, what is sent, and how long it stays in your account.

The consequence is real: if one of your customers asks for their data to be deleted, that request is addressed to you, not to us. We provide the tools and will help if asked, but the duty to answer is yours. Section 11 explains how.

3. What we collect

CategoryContentsOur role
Account identityName, email, profile photo from Google or Facebook at sign-up, phone numberController
Team membersEmail and role (Admin or Operational) of everyone you inviteController
Subscription dataPlan, quota used, top-up history, payment statusController
Channel configurationWhatsApp Business number identity, Instagram Business account, Telegram bot token, website chatbot domainController
Conversation contentsInbound and outbound messages, customer display names and numbers, image and document attachments, ticket status, ticket conclusionsProcessor
Contact databaseContacts and customers you upload or importProcessor
Agent configurationSystem prompt, skills, product catalogue, API connectors and their parametersController
Technical logsIP address, access time, browser type, application errors, Manager AI activity recordsController

What we do not collect. We never ask for or store credit card numbers or other card details. Payments are handled by a payment provider (see section 7) and we receive only the transaction status. We do not store your password either: sign-in goes through Google or Facebook.

Masked parameters. When you mark an API connector parameter as sensitive — an OTP or a password, say — its value is passed to your target API but is never shown in the console and never written to the conversation transcript.

4. Where the data comes from

5. What the data is used for

PurposeBasis
Running the service: receiving messages, generating AI replies, managing tickets, running campaignsPerformance of our contract with you
Billing and counting quotaPerformance of the contract
Security, and preventing abuse and spamOur and your legitimate interests
Technical support when you ask for helpPerformance of the contract
Meeting legal obligations and Meta platform policyLegal and contractual obligation
Telling you about material changes to the serviceLegitimate interest

We do not sell your data or your customers' data, and we do not share it with advertisers.

6. How AI processes conversations

To generate a reply, the relevant conversation content is sent to the third-party AI model providers we use as subprocessors. What is sent is the context needed to answer: recent messages in that conversation, the system prompt you wrote, and data from the skills you enabled — your product catalogue, for instance.

We choose providers who are contractually barred from using your data to train their models. The list of providers in use can change over time; the current list is available on request through the contact in section 15.

The agent's web search feature sends the search query — not the whole conversation — to a third-party search provider.

A limit you should know about. AI model output is probabilistic and can be wrong. You are responsible for what your agent says to your customers; the AI Lab exists so you can test it before that happens. Do not put data that must not reach a third party into a system prompt or a skill.

7. Who the data is shared with

We share data only with the subprocessors needed to run the service, and only as far as they need it:

PartyFor what
Meta Platforms, Inc.Sending and receiving WhatsApp and Instagram messages
Telegram FZ-LLCSending and receiving Telegram messages
AI model providersGenerating agent replies (see section 6)
Payment gateway providerProcessing subscription and quota top-up payments
Infrastructure and database providersRunning and storing the service

Beyond that, we may disclose data where required by law or a valid court order, or where necessary to protect the rights, safety and security of ourselves or our users. In a merger, acquisition or asset sale, data may pass to the successor, and you will be told before that takes effect.

8. How long data is kept

9. Security

Access to the console requires authentication through Google or Facebook; we do not store your password. Data in transit is protected by TLS. Internal access is limited to staff who need it for operations and support. Within your own account, the Admin and Operational roles limit who can connect or disconnect a channel.

No system is completely safe. If a security incident affects personal data, we will notify you and the competent authority as the applicable rules require.

10. Your rights

Under Law No. 27 of 2022 on Personal Data Protection, you have the right to: know what data we process and why; obtain a copy; correct inaccurate data; have data deleted; restrict or object to certain processing; withdraw consent you previously gave; and lodge a complaint with the competent authority.

Make a request through the contact in section 15. We will respond within a reasonable time, generally no more than 30 days, and may ask you to verify your identity before acting on a request involving personal data.

If you are a customer of a business that uses VybeFlow, your request must go to that business. They are the controller of those conversations; we only process on their instructions.

11. Data deletion

There are three routes, depending on what you want removed.

Deleting one conversation or one contact

Do it directly in the console, in the Inbox or the Database. Deletion applies to your account and cannot be undone.

Deleting all of your account data

Send a request from the email address registered on your account to admin@vyber.id with the subject “Data Deletion”. Once your identity is verified we delete the account data and every conversation in it within 30 days, and from system backups within 90 days.

Revoking app access from Facebook or Instagram

Open Settings & privacy → Settings → Apps and websites in your Facebook account and remove VybeFlow. Revoking access stops new data from flowing; to remove data already stored, send the deletion request above as well.

Data we are legally required to keep — payment records for tax purposes, for instance — is retained until that period ends and is not used for anything else.

12. Processing outside Indonesia

Some of our subprocessors — particularly the messaging platforms and the AI model providers — process data outside Indonesia. Where that happens, we ensure there is an adequate basis and adequate safeguards as required by the applicable personal data protection rules, including contractual obligations of confidentiality and security.

13. Children

VybeFlow is a service for businesses and is not directed at anyone under 18. We do not knowingly collect children's personal data. If you become aware of such data in our service, contact us and it will be deleted.

14. Changes to this policy

We may update this policy. The version and effective date appear at the top of the page. For changes that materially affect you, we will give notice by email to your registered address or in the console before they take effect.

15. Contacting us

For questions, rights requests, or data deletion:

PT Horizon Vyber Nusantara
Plosokuning 5 RT 25, RW 10
Kel. Minomartani, Kec. Ngaglik
Sleman, Special Region of Yogyakarta 55581
Indonesia
Email: admin@vyber.id