Ainomiq ReplySign in

Privacy Policy

Ainomiq B.V. · Amsterdam, the Netherlands · KvK 42032616 · Last updated 6 September 2026

Who we are

Ainomiq Reply is operated by Ainomiq B.V., Brederodestraat 10 B, 1054 MT Amsterdam, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 42032616, VAT number NL869396559B01. We provide an AI assistant that answers messages on a business's own WhatsApp number, grounded in that business's own knowledge base.

Our role (controller and processor)

For data about the businesses that sign up (account holders), we act as a data controller. For the WhatsApp message data we handle on a business's behalf, the business is the controller and we act as its processor, processing that data only on its instructions. Contact privacy@ainomiq.com about the Data Processing Agreement (DPA) and processing arrangements for your business.

What we process

For each connected business we process: the WhatsApp messages sent to and from that business, the contact's WhatsApp ID and display name, the knowledge base content the business provides, account details (name, email), and an encrypted access token used to send replies on the business's behalf. To generate a reply we include recent messages from the same conversation for context. We also process subscription and billing status, security records and product usage. Website analytics include page paths, referral and campaign data, session identifiers, viewport size, language and timezone. Visitor identifiers are held in session storage; signed-in usage can be associated with the account and business.

How we use it and our legal basis

We process messages and knowledge on the business's instructions to generate replies, display conversations and support human handoff. The business is responsible for identifying and communicating its lawful basis to its contacts. We process account and subscription details to perform our contract with the business, billing records to meet legal obligations, and security records to protect accounts and prevent abuse. Product analytics help us understand service use and reliability; they are also shared with Ainomiq's internal reporting system.

Service providers

We rely on a small number of providers to deliver the service:• Meta Platforms (WhatsApp Cloud API) to send and receive messages on the business's number.• OpenAI to generate replies and search your knowledge. Message content, recent conversation context and relevant knowledge are used to produce answers. Knowledge text and search queries are also sent for embedding, which helps retrieve relevant information.• Supabase for database hosting and storage.• Vercel for application hosting and compute.• Resend to send transactional email (for example password reset and verification messages).• Stripe for subscription payments and invoicing. Full card details are entered in Stripe's hosted checkout. Reply processes customer, subscription, invoice and payment references, amounts and billing status to provide access and reconcile payments. Stripe may also process information for its own legal and regulatory obligations.Contact privacy@ainomiq.com for the processing arrangements that apply to your business. OpenAI does not use API data to train its models by default.

Storage and deletion

The application uses Supabase for its primary database and Vercel for hosting. Processing locations also depend on the providers listed above; using Reply does not mean all processing stays within the EU. Contact privacy@ainomiq.com for the applicable provider locations and international transfer arrangements.Message and knowledge data remain linked to the business until an owner deletes the relevant data or the business is removed, unless a shorter retention setting applies. Account data remain while the account is in use. When a business is deleted, a user account that also belongs to another business is retained for that other business. Billing records held by Stripe are separate from conversation data and may be retained to meet legal obligations.A completed dashboard deletion removes the selected data from the active application. It does not delete copies in a contact's WhatsApp history or automatically erase records held independently by payment and messaging providers. Ask privacy@ainomiq.com about a specific access or deletion request, including any retained copies.

AI-generated replies

Replies are generated by an AI system and sent from the business's own number using the knowledge and rules configured by that business. AI-generated replies can be incomplete or incorrect. Handoff flags notify the business that a conversation needs attention; a team member must review and take over where needed. Businesses must inform contacts when they interact with an automated assistant and meet the transparency and consent requirements that apply to them.

Security

Access tokens are encrypted at rest with AES-256-GCM and are never displayed or logged. Data is isolated per business (tenant). Stored data is encrypted at rest by our hosting providers. We never log full tokens or secrets.

Your rights

Subject to applicable law you have the right to access, rectify, erase, restrict, and object to processing of your personal data, and the right to data portability. Business owners can delete knowledge and conversation data or disconnect WhatsApp from the dashboard. Whole-business or account deletion is available directly only for businesses without billing records. If billing records exist, request a deletion review, including after a subscription has been cancelled. See our Data Deletion page. To exercise any right, contact privacy@ainomiq.com. You also have the right to lodge a complaint with a supervisory authority; in the Netherlands this is the Autoriteit Persoonsgegevens.

Contact

Questions about this policy, or to request our DPA or subprocessor list: privacy@ainomiq.com.