1. Introduction & Roles Under Data Protection Laws
Ouron AI ("Ouron", "we", "us", or "our") respects the privacy rights of all users, merchants, and their prospective buyers. This Privacy Policy sets forth our practices regarding the collection, processing, transfer, storage, and security of information processed through the Ouron platform and APIs (the "Service").
1.1 Distinct Roles: Data Controller vs. Data Processor
Under international data protection laws (including the Indonesian Personal Data Protection Law — UU PDP No. 27/2022, the EU General Data Protection Regulation — GDPR, and the California Consumer Privacy Act — CCPA):
- Ouron as Data Controller: With respect to direct account registration data (e.g. merchant name, email address, password hashes, subscription records, and direct merchant communications), Ouron acts as a Data Controller.
- Ouron as Data Processor / Service Provider: With respect to conversational message data, customer phone numbers, WhatsApp privacy identifiers (@lid), order forms, and transaction details transmitted between merchants and their buyers via connected channels, the Merchant/Vendor is the Data Controller, and Ouron acts solely as a Data Processor processing data strictly on the Merchant's instructions.
2. Categories of Information We Collect
We process data across several operational categories:
2.1 Account & Merchant Profile Data
- Contact Information: Name, business email, phone number, and physical business location;
- Authentication Credentials: Encrypted/hashed passwords (bcrypt), JWT authorization tokens, and OAuth tokens for connected channels;
- Billing Records: Transaction identifiers, plan subscriptions, and credit balances (payment card numbers are processed directly by authorized PCI-DSS payment gateways and are never stored on Ouron servers).
2.2 Conversational & Inbound Message Data (Processed for Merchants)
- Chat content, customer responses, inquiries, and customer-submitted custom form fields;
- Telecommunication identifiers, including E.164 normalized phone numbers, WhatsApp JIDs, and WhatsApp Linked Privacy IDs (@lid);
- Order and booking records: Selected catalog items, line totals, reservation dates, and merchant payment confirmation timestamps;
- Payment proof image URLs transmitted by buyers for merchant payment verification.
2.3 Technical & Operational Telemetry Data
- IP addresses, browser user agent strings, device characteristics, access timestamps, and API response latency;
- Diagnostic telemetry, token consumption counts, and system performance metrics.
3. Purposes & Lawful Bases of Processing
We process information exclusively for legitimate business and operational purposes:
- Service Provisioning & AI Routing: Executing automated conversation workflows, querying merchant knowledge bases (RAG), checking calendar availability, and generating responses;
- System Reliability & Abuse Prevention: Monitoring API rate limits, detecting spam, preventing cyber attacks, and mitigating security breaches;
- Billing & Usage Enforcement: Calculating token consumption and managing subscription quotas;
- Legal Compliance: Complying with statutory reporting requirements, tax rules, and lawful government subpoenas.
No Selling of Personal Data: Ouron does NOT sell, rent, or lease your personal data or your customers' communication records to data brokers, advertisers, or third-party marketing companies under any circumstances.
4. AI Infrastructure & Authorized Sub-processors
To deliver automated conversational intelligence and global messaging infrastructure, Ouron engages reputable enterprise sub-processors. All sub-processors are bound by strict data protection agreements and confidentiality covenants.
| Sub-processor |
Function / Service |
Data Processed |
| Google Cloud / Gemini API |
Enterprise Large Language Model inference |
Transient prompt context & chat inquiries |
| DeepSeek AI / OpenCode |
Multi-provider LLM conversational reasoning |
Transient prompt context & chat inquiries |
| Tencent Cloud |
Cloud compute & secure application hosting |
Encrypted database & app runtime |
| Supabase Inc. |
PostgreSQL managed database with TLS 1.3 |
Encrypted merchant records & logs |
| Meta Platforms / WhatsApp |
Inbound/outbound social chat delivery |
Customer messages & sender IDs |
| Twilio Inc. |
SMS & WhatsApp Business API transport |
Message delivery payloads |
| Brevo (Sendinblue) |
Transactional emails (verification & resets) |
Merchant email addresses |
Zero Training on Proprietary Data: Commercial enterprise API agreements with our primary AI providers (e.g. Google Cloud Enterprise) strictly prohibit the use of merchant operational prompts or customer chat data to train public foundation models.
5. Technical & Organizational Security Safeguards
Ouron implements defense-in-depth technical and organizational controls to protect data against accidental loss, unauthorized access, alteration, or disclosure:
- Encryption in Transit: All HTTP traffic is strictly encrypted using Transport Layer Security (TLS 1.3 / HTTPS);
- Authentication Security: Industry-standard JSON Web Tokens (JWT) with secure HTTP-only cookies, robust secret keys, and bcrypt cryptographic password hashing;
- Database Isolation: Multi-tenant isolation enforced at database query layers;
- Restricted Infrastructure Access: Server access restricted to SSH key-pair authentication with strict firewall rules and IP whitelisting.
SECURITY DISCLAIMER: WHILE OURON IMPLEMENTS RIGOROUS INDUSTRY-STANDARD SAFEGUARDS, NO METHOD OF TRANSMISSION OVER THE INTERNET OR ELECTRONIC STORAGE IS 100% SECURE. OURON CANNOT GUARANTEE ABSOLUTE IMMUNITY FROM ZERO-DAY VULNERABILITIES, TARGETED STATE-SPONSORED ATTACKS, OR UNAUTHORIZED ACCOUNT ACCESS RESULTING FROM COMPROMISED VENDOR PASSWORDS.
6. Merchant Obligations & End-User Consent Representations
Because the Merchant acts as the Data Controller regarding their own customers:
- The Merchant represents, warrants, and covenants that they have legally obtained all required consents, authorizations, and opt-ins from their customers prior to routing messages through Ouron;
- The Merchant is solely responsible for publishing their own consumer privacy notice informing buyers that messages may be processed by automated systems and AI service providers;
- The Merchant agrees to indemnify and hold harmless Ouron from any regulatory fines, claims, or penalties arising from the Merchant's failure to obtain legal messaging consent.
7. Data Retention & Deletion Rights
Retention Duration: We retain account data and customer conversation logs only for as long as your workspace remains active, or as required to fulfill legal, tax, accounting, or security audit requirements.
Right to Erasure & Account Deletion: Upon voluntary account termination or written request to legal@ouron.it.com, Ouron will permanently purge or anonymize your operational chat records and database rows within thirty (30) business days, except where retention is legally mandated by law or court order.
8. International Data Transfers
Ouron operates cloud infrastructure globally. By using the Service, you acknowledge and agree that your data may be transferred to, stored, and processed in cloud servers located outside your jurisdiction. We ensure that international transfers comply with applicable cross-border data transfer mechanisms, standard contractual clauses, and encryption standards.
9. Privacy Contact & Data Rights Inquiries
For any questions regarding this Privacy Policy, data subject access requests (DSAR), or privacy rights inquiries, please contact our Data Protection Team: