Legal

Privacy Policy

Last updated: July 21, 2026

This Privacy Policy explains how Dovaneka collects, uses, stores, and shares personal data when you use our website, product, and related services.

Who we are

Dovaneka ("Dovaneka", "we", "us", or "our") operates the website dovaneka.com, the dashboard at app.dovaneka.com, and related APIs and chat widgets (together, the "Service"). Dovaneka provides AI assistants ("AI employees") that help small businesses answer their customers 24/7 on WhatsApp, Telegram, and website chat.

Operator identity (placeholder): Dovaneka — registered company name and address to be added. For privacy and legal requests, contact hello@dovaneka.com.

Scope of this policy

This policy covers: (1) visitors to our marketing website; (2) business clients who create accounts and use the Service; and (3) end customers who chat with a business client's AI employee through connected channels. Where we process end-customer data on behalf of a business client, that client is typically the controller and we act as a processor — see “Controller and processor roles” below.

What data we collect and why

We collect and process the following categories of data:

  • Account data: business owner name, email address, authentication credentials, organization and company settings.
  • Knowledge base content: text, files, URLs, prices, FAQs, and other material you upload or connect so the AI can answer accurately.
  • Conversations and messages: content of chats between end customers and your AI employee or human staff, including names, phone numbers, emails, or other details the end customer chooses to share in the conversation.
  • Channel credentials: WhatsApp Business / Meta connection data and Telegram bot tokens that you provide; we store these encrypted.
  • Usage and technical logs: timestamps, feature usage, approximate volume of AI replies, IP address, browser/device information, and diagnostic logs needed to operate and secure the Service.
  • Landing-page leads: business name, website (optional), contact details, and niche submitted via demo-request forms on dovaneka.com.
  • Billing and subscription metadata: plan selection and payment status (payment card data, if any, is handled by payment providers — not stored by us in full).

We use this data to provide and improve the Service, generate AI replies, route conversations to human staff, send service emails, prevent abuse, comply with law, and respond to support and privacy requests.

Controller and processor roles

For account data, website analytics limited to essential operations, and landing-page leads submitted to us, Dovaneka typically acts as an independent controller.

For end-customer conversations and related personal data processed inside a client's workspace, the business client is the controller. Dovaneka is a data processor: we process that data only to provide the Service (generate AI replies, store conversation history for the client, hand off to human staff, and operate connected channels). End-customer conversations belong to the business client.

AI / LLM processing disclosure

To generate replies, relevant message content and excerpts from the client's knowledge base are sent to third-party large language model (LLM) providers — currently OpenAI, and potentially Anthropic or Google in the future. Those providers process the data as our sub-processors to return model outputs.

Under OpenAI's API terms, data submitted via the API is not used to train OpenAI's models. We configure our use of LLM APIs consistent with that non-training posture. If we enable additional LLM providers, we will take a comparable approach under their respective API terms and update this policy as needed.

AI outputs can be incomplete or incorrect. Clients should review critical replies and are responsible for the accuracy of their knowledge base and for how AI responses are used with their customers.

Sub-processors

We use carefully selected sub-processors to operate the Service:

  • OpenAI — generating AI responses from conversation context and knowledge-base content.
  • Resend — transactional and notification email delivery.
  • Hosting provider (VPS) — application hosting, databases, and related infrastructure.

We may update this list as our stack evolves. Material changes will be reflected in this policy's “Last updated” date.

Data retention

We retain personal data only as long as needed for the purposes described in this policy, including:

  • Account and workspace data: for the life of the account and a reasonable period afterward for backup, dispute resolution, and legal compliance.
  • Conversations and knowledge base: while the client account remains active, subject to client deletion requests and product retention settings.
  • Landing-page leads: for sales follow-up and a limited period thereafter unless you ask us to delete them sooner.
  • Security and usage logs: for a limited operational period needed to investigate incidents and maintain service integrity.

When a client requests deletion of end-customer data, we cascade deletion where feasible and anonymize or remove message content associated with that data subject so it is no longer attributable to an identifiable person, except where we must retain limited records for legal or security reasons.

Security measures

We implement technical and organizational measures appropriate to the risk, including encryption in transit (TLS), encryption of stored channel credentials, access controls and least-privilege access for staff systems, isolation of production environments, monitoring and logging, and regular dependency and server updates. No method of transmission or storage is 100% secure; we work to protect data but cannot guarantee absolute security.

International transfers

We and our sub-processors may process data in countries other than where you or your end customers are located (for example, LLM and email providers often process data in the United States or EU). Where required, we rely on appropriate safeguards such as standard contractual clauses or the provider's equivalent transfer mechanisms.

Your rights and how to exercise them

Depending on applicable law, you may have the right to request access to your personal data, correction, export/portability, deletion, restriction of processing, and objection to certain processing. You may also lodge a complaint with a supervisory authority where applicable.

Business clients and account holders can email hello@dovaneka.com to exercise these rights regarding data we control. For end-customer data processed inside a client's workspace, please contact the business you chatted with first (they are the controller); we will assist the client in fulfilling verified deletion, access, and export requests, including cascading deletion and anonymization of messages where applicable.

Cookies

We use only essential and session cookies (and similar storage) needed to run the website and authenticated product — for example, session authentication and basic security. We do not use advertising or cross-site tracking cookies on the marketing site.

Children

The Service is directed to businesses and is not intended for children under 16 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact hello@dovaneka.com and we will take appropriate steps.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Continued use of the Service after changes take effect constitutes acceptance of the updated policy where permitted by law.

Contact

For privacy or legal requests, or any questions about this policy: hello@dovaneka.com.

Postal / registered address: to be added when the legal entity is registered. Until then, use hello@dovaneka.com.

Questions? hello@dovaneka.com

Terms of Service