Privacy Policy

Last updated: 26 September 2026

1. Introduction

This Privacy Policy explains how Aeris ("we", "us", or "our") collects, uses, discloses, and protects personal data when you use our Service. It applies to all users — business owners (admin accounts) and their end customers, whether they interact via the public chat widget or by messaging a connected Facebook Page, Instagram account or WhatsApp Business number.

We are committed to complying with the Personal Data Protection Act 2010 (PDPA) of Malaysia.

2. Data We Collect

2.1 Account Data (Admin Users)

When you register for an account:

  • Email address and password (managed by Supabase Auth)
  • Subscription and billing details (plan, billing cycle, invoice history)
  • Locale and timezone preferences

2.2 Business Configuration Data

Data you enter to configure the Service:

  • Business name, description, and profile settings
  • Appointment categories, availability windows, menu items, staff records, locations, rental units, FAQ entries
  • Module settings and preferences

2.3 Operational Data

Data generated through normal use:

  • Conversation and message history (including AI responses)
  • Food orders, appointments, shift records, inventory movements
  • Scheduled task configurations
  • Pending actions and job logs

2.4 Usage and Analytics Data

  • Daily AI request counts and usage logs
  • Session activity: timestamp, IP address, country (derived via GeoIP lookup), browser/device (User-Agent)
  • System event logs (tool calls, job outcomes)

2.5 Guest / End-Customer Data

When your end customers interact with your public chat widget:

  • Chat messages sent to the widget
  • Name, email, or phone number if provided during a booking or order
  • IP address and country (session activity logging, 5-minute debounce)

We act as a data processor for end-customer data on your behalf. You are the data controller for that data and are responsible for informing your customers about its collection and use.

2.6 Messaging Channel Data (Messenger, Instagram, WhatsApp)

When you connect a messaging channel, we receive the messages your customers send to it. See Section 6 — Messaging Channels for what is collected, how assisted replies work, and how long this data is kept.

3. How We Use Your Data
PurposeLegal Basis (PDPA)
Providing and operating the ServiceContractual necessity
Billing and invoice generationContractual necessity
AI response generation (sent to AI providers)Contractual necessity / legitimate interest
Receiving and replying to messages on connected channelsContractual necessity
Session activity logging for security and analyticsLegitimate interest
Sending transactional emails (invoices, support)Contractual necessity
Improving the ServiceLegitimate interest
Complying with legal obligationsLegal obligation

We do not sell your personal data to third parties.

4. Data Sharing

We share data with the following categories of third parties, solely to operate the Service:

Third PartyPurposeWhere
RailwayApplication hosting — the servers that run the Service, receive messages from Meta and process background jobsSingapore
SupabaseDatabase hosting and authenticationSingapore
Anthropic / Google (Gemini) / MiniMax / DeepSeekAI model inference — conversation messages are sent, including messaging channel messages when AI auto-reply is enabled (Section 6). Only the provider the business has selected receives dataAnthropic and Google: US. MiniMax: Singapore and China. DeepSeek: China. Defaults to Anthropic (US)
Ollama (self-hosted)AI model inference on a server the business runs itself, if selectedThe business's own infrastructure
Meta PlatformsDelivering and receiving messages on your connected Facebook Page, Instagram account or WhatsApp Business number (if connected)US
ResendTransactional email deliveryUS
GoogleCalendar integration (if enabled)US
BraveWeb search results (if enabled)US

We require all sub-processors to maintain appropriate data protection standards.

5. Data Retention
Data TypeRetention Period
Account and business config dataFor the life of your account + 30 days after termination
Conversation and message historyFor the life of your account + 30 days after termination
Session activity logsCleaned up periodically; raw logs purged after 90 days
Invoice records7 years (tax and accounting compliance)
End-customer chat dataFor the life of your account + 30 days after termination
Messaging channel messages (Messenger, Instagram, WhatsApp)Deleted 12 months after receipt (see Section 6)
Messaging channel raw webhook payloadsErased 30 days after receipt (see Section 6)
Messaging conversation state (paused flag, disclosure timestamp)For the life of your account (see Section 6)

After retention periods expire, data is permanently deleted and cannot be recovered.

6. Messaging Channels

Businesses may connect their Facebook Page, Instagram professional account, or WhatsApp Business number to the Service. This section describes how data from those channels is handled. As with the chat widget, we act as a data processor for your customers' messages; you are the data controller.

6.1 What we receive and store

When a channel is connected, Meta delivers messages sent to your connected account to us via webhook. For each message we store:

  • The message text, the sender's platform identifier and display name, and timestamps
  • The channel it arrived on, and which business account it belongs to
  • The original webhook payload as received from Meta, kept temporarily for diagnostic purposes
  • One small record per conversation: whether automated replies are paused for it, and when the automated-assistant notice was last sent

To connect and operate a channel we also store the connected account's identifiers and an access token issued by Meta. Tokens are encrypted at rest (AES-GCM), decrypted only in our backend to call Meta's APIs, and are never sent to any browser.

6.2 Assisted (automated) replies

Channel messages are shown in your message queue, where your staff read and reply to them. You may optionally enable AI auto-reply. When it is enabled:

  • Recent messages from the conversation are sent to the AI provider configured for your account (by default Anthropic, in the US; the business may instead select Google, MiniMax or DeepSeek — see Section 4) in order to draft the reply. This happens only while auto-reply is enabled, and only for the conversation being answered.
  • The first automated reply in any conversation carries a visible notice that it is automated.
  • Automated replies are drafted only from your business profile and the FAQ answers you have written. They are plain text and cannot take any action.
  • If a customer asks for a person, they receive one short acknowledgement and the conversation is handed to your staff. If a customer asks us to stop, nothing further is sent. In both cases automated replies stay paused for that conversation until a member of your staff resumes them.

6.3 Retention and deletion for channel data

  • Raw webhook payloads are erased 30 days after the message arrives; the parsed message remains.
  • Messages are deleted 12 months after they are received. Both windows are enforced by a scheduled daily job.
  • Per-conversation state (the paused flag and the disclosure timestamp) is kept for the life of your account. This is deliberate: it is the record that a person asked not to receive automated replies, and deleting it would cause those replies to resume.
  • Disconnecting a channel deletes its stored access token immediately.
  • Closing your account deletes all associated messages, conversation records and tokens.

6.4 Meta platform data

Data received from Meta's platforms is used only to provide the messaging features described above, in accordance with the Meta Platform Terms and Meta's Developer Policies. We do not sell it, use it for advertising, or use it to train AI models.

7. Data Security

We implement the following technical and organisational measures:

  • Encryption in transit: All data transmitted between your browser, the frontend, and backend is encrypted via HTTPS/TLS.
  • Encryption at rest: Data stored in Supabase (Postgres) is encrypted at rest by Supabase.
  • Access control: Row-Level Security (RLS) policies in the database enforce per-account data isolation. Service-role access is limited to backend processes only.
  • API key management: API keys and secrets are stored as environment variables and never exposed to clients.
  • Authentication: Managed by Supabase Auth with JWT-based bearer tokens.

No system is completely secure. In the event of a data breach that affects your personal data, we will notify you as required by applicable law.

8. Cookies and Local Storage

The Service uses browser localStorage for:

  • Session preferences (developer mode toggle, invoice acknowledgement state)
  • Authentication tokens (managed by Supabase SSR)

We do not currently use third-party tracking cookies or advertising pixels.

9. Your Rights

Under the PDPA and general data protection principles, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete personal data
  • Delete your personal data (subject to legal retention requirements)
  • Withdraw consent where processing is based on consent
  • Data portability — request an export of your data before account deletion

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

EU/EEA users: If you are located in the EU or EEA, you have additional rights under the GDPR, including the right to lodge a complaint with your local supervisory authority. Please note this Service is not specifically directed at EU residents; if you have EU customers, consult a GDPR specialist regarding your obligations as a data controller.

10. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, contact us and we will delete it promptly.

11. International Data Transfers

Your data may be processed in countries outside Malaysia (Singapore, where our servers and database are hosted; the US, for Anthropic and Google; and China, where a business has selected MiniMax or DeepSeek as its AI provider). We take reasonable steps to ensure adequate protection is in place for such transfers, including contractual safeguards with sub-processors.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice at least 14 days before taking effect. The "Last updated" date at the top of this page always reflects the current version.

13. Contact

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data:

Email: [email protected]
Company: AerisOS Technologies · 202603112170 (MA0345698-U)

We aim to respond to all privacy-related enquiries within 30 days.

Have a question about your data?

Contact us