Privacy Policy
Effective: 7 October 2026 · Operator: [Patas LLC — legal name as registered], Yerevan, Armenia ("Patas", "we") · Contact: hello@patas.am
Patas is an AI assistant that answers a business's customers on Telegram, WhatsApp and Instagram, books appointments, and gives the business owner a dashboard at app.patas.am. This policy explains what data we process, why, and what you can do about it. It applies to two kinds of people:
- Business owners and their staff — who sign up and use the dashboard.
- Customers of those businesses — who write to a business through a messaging app that Patas connects to.
1. What we collect
From business owners: email address and password hash (through Supabase Auth), name, business name, address, phone, working hours, services and prices, FAQs, staff names and hours, logo, the Telegram bot token and WhatsApp / Instagram connection details you provide, your Telegram chat ID if you link it for alerts, and billing records.
From customers who message a connected business: the messaging-app identifier (Telegram user ID and username, WhatsApp phone number, or Instagram-scoped ID), display name, the messages they send (text, voice notes, photos), bookings they make, and whether they agreed to marketing messages. Voice notes are transcribed to text and photos are described in text by an AI model so the assistant can answer; the text is kept with the conversation. Original audio and image files are fetched from the messaging platform when needed and are not stored by us beyond processing, except that photos may be retained for the business to view in its inbox.
Automatically: server logs (IP address, request time, status) kept for up to 30 days for security and debugging, and AI usage logs (tokens used, model, latency) without customer content beyond what is needed to improve answers.
We do not collect payment card numbers — payments are handled by Idram.
2. Why we process it
- To run the service: answer messages, book appointments, send reminders and confirmations, show the owner their inbox and calendar. (Performance of the contract with the business; for customers, the legitimate interest of the business in answering them.)
- To send the business owner operational emails and alerts (account, security, billing, "a customer needs you").
- To send a customer a reminder, a confirmation, a review request, a waitlist offer, or a rebooking suggestion about a visit they made or asked about. Marketing messages are sent only to customers who opted in, and they can opt out at any time by replying.
- To keep the service secure, prevent abuse, and meet legal obligations.
We do not sell personal data and do not use customer conversations to train AI models ourselves.
3. Who processes data for us
| Provider | Role | Location |
|---|---|---|
| Supabase | database, authentication, file storage | EU (Frankfurt) |
| Hetzner | servers | Germany |
| Google (Gemini API) | AI answers, speech-to-text, text-to-speech, image description, text embeddings | Google Cloud; data is not used by Google to train models under the paid API terms |
| Resend | transactional email | USA / EU |
| Telegram, Meta (WhatsApp, Instagram) | the messaging platforms your customers already use; they process messages under their own policies | — |
| Idram | payments | Armenia |
| Cloudflare | DNS, email routing | global |
Supabase
Role
database, authentication, file storage
Location
EU (Frankfurt)
Hetzner
Role
servers
Location
Germany
Google (Gemini API)
Role
AI answers, speech-to-text, text-to-speech, image description, text embeddings
Location
Google Cloud; data is not used by Google to train models under the paid API terms
Resend
Role
transactional email
Location
USA / EU
Telegram, Meta (WhatsApp, Instagram)
Role
the messaging platforms your customers already use; they process messages under their own policies
Location
—
Idram
Role
payments
Location
Armenia
Cloudflare
Role
DNS, email routing
Location
global
Each provider processes data only to provide its service to us, under its data-processing terms.
4. How long we keep it
- Business data, customers, conversations and bookings: for as long as the business account is active.
- When a business deletes its account, everything is removed 30 days later (the account can be restored within those 30 days). Backups expire within a further 30 days.
- A customer's data is deleted when the business deletes that contact, or on request (see § 6).
- Server logs: up to 30 days.
5. Security
Data is encrypted in transit (TLS) and at rest; every database query is scoped to one business (row-level security); messaging tokens are stored encrypted; access to production is limited to the founders. No system is perfectly secure — if we learn of a breach affecting you, we will notify affected businesses without undue delay.
6. Your rights
Under the Law of the Republic of Armenia on Personal Data Protection and, where applicable, the GDPR, you may ask to access, correct, export, restrict or delete your personal data, and to object to processing based on legitimate interest.
- Business owners: Settings → Account lets you download all your data and delete the account.
- Customers of a business: write to the business through the same chat and ask them to delete your data, or email hello@patas.am with the messaging app and identifier you used. See the data deletion page. We answer within 30 days.
You may complain to the Personal Data Protection Agency of the Republic of Armenia.
7. Children
Patas is a tool for businesses and is not directed at children under 16. Businesses are responsible for the content they offer through it.
8. Cookies
The dashboard uses only the cookies and local storage needed to keep you signed in and remember your language. The marketing site uses no tracking cookies.
9. Changes
We will post changes here and, for material changes, email business owners. Continued use after the effective date means acceptance.
Questions: hello@patas.am · [registered address]