Privacy Policy
Last updated: 30 August 2026
Klydos ("we", "us") provides an AI sales assistant that businesses connect to their own Facebook Page or Instagram account to reply to customer messages. This policy explains what we collect, why, and how to have it deleted.
Who the data belongs to
Klydos is a business-to-business tool. A business (our "customer") connects their own Page and remains the controller of the conversations on it. We process that data on their behalf as a service provider.
What we collect
- Account data — name, email address, and workspace details of the business users who sign in to Klydos.
- Page connection data — the Facebook or Instagram Page identifier and the access token the business grants us, used solely to receive and send messages for that Page.
- Message data — the content and timestamps of messages exchanged between the business's Page and people who message it, plus the sender's platform-scoped identifier and public profile name where the platform provides it.
- Catalog data — products, prices, and descriptions the business uploads so the assistant can answer questions about them.
- Operational logs — technical records of requests and errors used to keep the service running.
We do not collect payment card numbers, government identifiers, health data, or precise location.
How we use it
Message and catalog data is used to generate replies on behalf of the connected business, to show that business their own conversation history, and to keep the service operating and secure. Account data is used to authenticate users and provide support.
We do not sell personal data, and we do not use the contents of customer conversations to train general-purpose AI models.
Who we share it with
We share data only with the service providers needed to run Klydos:
- Meta Platforms — to receive and deliver messages on the connected Page.
- Our AI model provider — message text is sent to generate a reply, under terms that prohibit using it for model training.
- Our hosting, database, and background-processing providers, which store and process data on our behalf.
We may also disclose data where required by law.
Tenant separation
Every record is scoped to the workspace that owns it, and every query is filtered by that workspace. One business cannot access another business's conversations, customers, or catalog.
How long we keep it
Conversation and catalog data is retained while the business's account is active. When a Page is disconnected, we stop receiving new messages for it and delete the stored access token. When an account is closed, associated data is deleted within 30 days, except where a longer period is legally required.
Your rights
You may request access to, correction of, or deletion of your personal data. If you messaged a business that uses Klydos, see our data deletion instructions. Depending on where you live, you may also have the right to object to processing or to lodge a complaint with your data protection authority.
Contact
Questions or requests: privacy@klydos.com.