Privacy Policy
Ainomiq B.V. · Amsterdam, the Netherlands · KvK 42032616 · Last updated 13 July 2026
Who we are
Ainomiq Reply is operated by Ainomiq B.V., Brederodestraat 10 B, 1054 MT Amsterdam, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 42032616, VAT number NL869396559B01. We provide an AI assistant that answers messages on a business's own WhatsApp number, grounded in that business's own knowledge base.
Our role (controller and processor)
For data about the businesses that sign up (account holders), we act as a data controller. For the WhatsApp message data we handle on a business's behalf, the business is the controller and we act as its processor, processing that data only on its instructions. A Data Processing Agreement (DPA) is available on request at privacy@ainomiq.com.
What we process
For each connected business we process: the WhatsApp messages sent to and from that business, the contact's WhatsApp ID and display name, the knowledge base content the business provides, account details (name, email), and an encrypted access token used to send replies on the business's behalf. To generate a reply we include recent messages from the same conversation for context.
How we use it and our legal basis
We use message data solely to generate support replies grounded in the business's own knowledge base and to let a human agent take over. The legal basis for processing on behalf of a business is that business's own basis under its agreement with the people it messages (typically performance of a contract or legitimate interest); for our own account and security data the basis is performance of our contract with the business and our legitimate interest in running the service securely.
Service providers (subprocessors)
We rely on a small number of providers to deliver the service:• Meta Platforms (WhatsApp Cloud API) to send and receive messages on the business's number.• OpenAI to generate replies. Message content and recent conversation context are sent to OpenAI's API to produce each answer.• Supabase (EU region) for database hosting and storage.• Vercel for application hosting and compute.• Resend to send transactional email (for example password reset and verification messages).• Stripe for subscription payments and invoicing. Card and payment details go directly to Stripe and never touch our servers; we store only your Stripe customer reference, plan, and billing status.A current subprocessor list is available on request. Under OpenAI's API data usage policy, data submitted through the API is not used to train its models.
Where data is stored and retention
Our primary database is hosted in the EU. Some subprocessors process data outside the EU under appropriate safeguards: OpenAI (United States) for reply generation, Stripe (United States) for payment processing, and Resend (Asia-Pacific region) for sending email. We keep message and conversation data until the business deletes it or its account is closed; on deletion we remove it from our live systems promptly and from routine backups within 30 days. We keep limited administrative audit logs (records of actions such as connecting a number or deleting data) for security purposes; these are removed when the account is deleted.
AI-generated replies
Replies are generated by an AI system and sent from the business's own number. The assistant answers only from the business's knowledge and hands off to a person when it is unsure. We recommend businesses tell the people they message that an automated assistant may respond, and obtain any consent their local law requires.
Security
Access tokens are encrypted at rest with AES-256-GCM and are never displayed or logged. Data is isolated per business (tenant). Stored data is encrypted at rest by our hosting providers. We never log full tokens or secrets.
Your rights
Subject to applicable law you have the right to access, rectify, erase, restrict, and object to processing of your personal data, and the right to data portability. Businesses can delete their knowledge base, conversations, connection, and entire account from the dashboard at any time (see our Data Deletion page). To exercise any right, contact privacy@ainomiq.com. You also have the right to lodge a complaint with a supervisory authority; in the Netherlands this is the Autoriteit Persoonsgegevens.
Contact
Questions about this policy, or to request our DPA or subprocessor list: privacy@ainomiq.com.