Privacy Policy
Last updated: 2026-08-02
ФОП "Ушакова Дар'я" (Ukraine) operates Ally-agent, an AI assistant that answers customer messages and books appointments on behalf of businesses. This policy explains what personal data the service processes and why.
Our role: controller and processor
Two different relationships exist, and the rules differ for each.
- For the businesses that use Ally-agent (their account, staff logins, billing): we are the data controller.
- For the customers of those businesses (people who write to the assistant or are booked by it): the business is the controller and we act as a processor on its instructions. If you are such a customer, contact the business directly first — we will assist them in answering you.
What we process
- Conversation content: the messages a customer sends and the assistant's replies, including transcripts of voice messages and phone calls.
- Contact and booking details: name, phone number, and where applicable email, plus the service, staff member, date and time of an appointment.
- Account data for business users: email, name, role, and audit records of actions taken in the dashboard.
- Technical data: timestamps, channel used, and error diagnostics. Database error fields that can carry row values are deliberately stripped before anything reaches logging.
We do not ask for and do not want payment card data, government identifiers, or health information. Please do not send them to the assistant.
Why we process it, and on what basis
- To answer the customer and create, look up or change their appointment — performance of the service the business asked for.
- To show the business its own conversations and calendar, and to hand a conversation to a human when needed.
- To keep the service secure and working: rate limiting, error tracking, abuse prevention — our legitimate interest.
- To meet legal obligations where they apply.
Who else receives data (sub-processors)
The service depends on the following providers. Each receives only what it needs to do its part.
- Amazon Web Services (EU, eu-central-1) — hosting and the database where conversations and bookings are stored (encrypted at rest).
- Amazon Bedrock — Anthropic Claude (EU inference profile) — generates the assistant's replies. Requests are sent to an EU inference profile, so inference does not leave EU regions. AWS states that it does not use inputs or outputs to train models.
- Amazon Transcribe (EU, eu-central-1) — converts voice messages and calls to text, in the same EU region.
- Google (Gemini embeddings API) — converts the business's knowledge-base text and customer questions into vectors for search. This provider is outside the EU; see "International transfers".
- ElevenLabs (voice calls) — speech recognition and synthesis for phone calls, where the business has enabled voice.
- Telegram — delivers messages on that channel. Other messaging channels are added only when a business enables them.
- Altegio — the booking system some businesses use. Where it is connected, appointments are created there and mirrored in our calendar.
We do not sell personal data and do not share it for advertising.
Where data is stored, and international transfers
Conversations, bookings and account data are stored in the European Union (AWS eu-central-1, Frankfurt), encrypted at rest. Reply generation and speech-to-text also run in EU regions.
Two flows leave the EU: text sent to Google's embeddings API for knowledge search, and audio/text exchanged with ElevenLabs when a business uses phone calls. These transfers rely on the providers' standard contractual clauses and equivalent safeguards.
How long we keep it
- Conversations and bookings: for as long as the business's account is active, because the business needs its own history. On account closure we delete or anonymise within 90 days.
- Audit and security records: up to 12 months.
- Backups: database snapshots are retained on a rolling schedule and are overwritten in the normal course; a deletion request is applied to live data immediately and to backups as they roll over.
Security
- Each business's data lives in its own database schema, and access is scoped per tenant on the server — not merely hidden in the interface.
- Data is encrypted in transit and at rest. The database is not reachable from the public internet.
- Credentials and API keys are held in a managed secrets store, never in the database or in logs.
- Access to production is limited to the people who operate the service and is audited.
Your rights
Under the GDPR you can request access to your data, correction, deletion, restriction, portability, and object to processing based on legitimate interest.
Write to privacy@ally-agent.com. If you are a customer of a business using Ally-agent, tell us which business, so we can route the request to the controller. We answer within one month. You may also complain to your national data protection authority.
Cookies
The dashboard sets only what it needs to work: a session cookie for signed-in users and a cookie remembering the chosen interface language. There is no advertising or cross-site tracking.
Changes and contact
We update this page when the service changes and record the date above. Questions or requests: privacy@ally-agent.com · https://app.ally-agent.com