Aim Infosoft - Automation is a business messaging platform operated by Aim Infosoft. We collect only the information needed to run the platform and to send the messages our customers ask us to send. This policy covers both our website visitors and the data our business customers process through the product.
For our website, account signup and billing, we are the data controller. For the contacts, conversations and message content inside a workspace, the business that owns that workspace is the controller and we act as its processor, handling that data only on its instructions and only to provide the service.
02
Information we collect
Account and workspace details (name, work email, phone, company, plan and billing information); website inquiry and newsletter submissions; contact records a customer imports or captures through forms and links; message content and metadata for conversations sent or received through connected channels; templates, workflows, segments and integration settings; and technical logs such as IP address, timestamps, user agent and error traces needed for security, abuse prevention and support.
03
Meta Platform Data (WhatsApp, Instagram, Messenger)
When a business connects a WhatsApp Business Account, Facebook Page or Instagram professional account, we receive from Meta only what is required to operate that connection: account and phone number identifiers, the display name and profile metadata of the connected asset, access tokens, message templates and their approval status, and the inbound and outbound messages plus delivery statuses for that account. On the coexistence flow we may also receive the contact list and recent chat history that the business chooses to sync from its WhatsApp Business App. Access tokens and API secrets are stored encrypted at rest and are never shown in the interface, logs or API responses.
04
How data is used
To provide the product: deliver and receive messages, run the shared inbox, execute the automations a customer builds, sync templates, report on usage and billing, and provide support. Where a customer enables AI features, the relevant message text and knowledge-base content are sent to the configured AI provider solely to generate that reply or draft. We do not use Meta Platform Data, message content or contact lists for advertising, profiling, resale, credit or insurance decisions, or to train our own models, and we do not build cross-business audiences from it.
05
What we never do with your data
We do not sell personal data. We do not share Meta Platform Data with data brokers, ad networks or any third party for their own purposes. We do not combine one workspace's data with another's, and we do not use it to enrich a profile of a person outside the workspace that collected it.
06
Workspace isolation
Every contact, conversation, template, workflow and user record is bound to its workspace and filtered by workspace on every database read. Staff access is limited to named platform administrators and is used only to operate the service or to resolve a support request raised by that business. Where support needs to act inside a workspace, that access is granted through a revocable link tied to a single user, and every use is recorded with a timestamp and IP address.
07
Service providers
We rely on a short list of processors: Meta (WhatsApp Cloud API, Messenger and Instagram messaging), our cloud hosting and database provider, our transactional email provider, and — only if the customer enables AI features — the AI provider they select. Each receives only the data needed for its function and is bound by contract to protect it. Payment card details, where applicable, are handled by the payment provider and never stored by us.
08
How long we keep data
Workspace content is retained while the account is active. When a workspace is closed, its contacts, conversations, messages, templates, workflows and users are deleted within 30 days, except records we must keep longer for tax, accounting or legal reasons (typically invoices). Technical and security logs are kept for up to 12 months. A deletion request removes data ahead of these periods — see the data deletion page.
09
International transfers
Data may be processed in the country where our hosting provider and Meta operate their infrastructure, which may differ from your own. Where required, transfers rely on standard contractual clauses or an equivalent safeguard.
10
Your rights
Depending on where you live, you may ask us to access, correct, export or delete your personal data, or to restrict or object to its processing. If your data sits inside a business's workspace, contact that business first — it decides what is kept. You can also write to us at info@aiminfosoft.com and we will route the request or act on it directly, and we will respond within 30 days.
11
Security
Signing in requires a password and, for every workspace user, two-factor authentication. API keys and Meta access tokens are stored encrypted, inbound webhook deliveries are signature-verified, and traffic is served over HTTPS. Support access issued by a platform administrator is the one exception to the second factor: it uses a single-purpose revocable link instead, and is logged. No system is perfectly secure, so we also keep audit trails and review access.
12
Cookies and website tracking
Our website sets essential cookies for sessions, CSRF protection and your cookie choices. Analytics or marketing cookies are set only after you accept them in the consent banner, and you can change or withdraw that choice at any time through "Cookie settings" in the footer. The signed-in product itself uses only the cookies required to keep you logged in. See the Cookie Policy for the detail.
13
Automated decisions and AI
We do not make decisions with legal or similarly significant effects about anyone by automated means. Where a workspace enables AI features, the model drafts or suggests a reply from the message and the knowledge-base content supplied at that moment; it does not decide eligibility, pricing or access, and a person can always take over the conversation.
14
Security incidents
If a breach affects personal data we hold, we will investigate immediately, notify the affected businesses without undue delay with what we know and what we are doing about it, and notify regulators where the law requires it. As a processor for workspace content, we support our customers in meeting their own notification duties.
15
Children
The platform is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child's data has reached us, contact info@aiminfosoft.com and we will remove it.
16
Changes and contact
We update this policy when the product or our processors change, and material changes are announced in the app. Questions, data requests and privacy complaints go to info@aiminfosoft.com, Aim Infosoft.
Still need clarity?
Email info@aiminfosoft.com
or use the contact form — Aim Infosoft answers these directly.
Aim Infosoft - Automation uses cookies to keep you signed in, secure our forms and — only if you agree — measure how the site is used.
Read the Cookie Policy.
Cookie preferences
Choose what we may store on this device.
Necessary
Always on
Sessions, security tokens and authentication. The site cannot work without these, so they cannot be switched off.
Analytics
Which pages and campaigns bring people in. Aggregated and used only to improve the site.
Marketing
Measures ad campaigns across platforms like Google, Meta and LinkedIn. Never uses your workspace data.