BotFactory

Privacy Policy

Effective date: 4 October 2026

This policy explains what data BotFactory AI receives, why we need it, who we share it with, how long we keep it and how to delete it. It covers the website botfactory.kg and the BotFactory AI service — an AI assistant that replies to customers on Instagram, WhatsApp and Telegram on behalf of a connected business. If the Russian and English versions differ, the Russian version prevails.

1. Who we are

The BotFactory AI service is provided by SERENE GRUPP LLC (taxpayer ID 00906202510487), address: 100 Razzakov St., Bishkek, Kyrgyz Republic (“we”, “us”).

For any questions about your data, email serenegrupp@gmail.com or message @botfactory.ai on Instagram.

2. Whose data we process

  • Website visitors who submit a request form.
  • Business clients — entrepreneurs and companies that connect our assistant to their Instagram, WhatsApp or Telegram account.
  • Customers — people who send messages to a business’s Instagram, WhatsApp or Telegram where our assistant is active, or comment on its Instagram posts.

We decide how and why visitor and client data is used and are responsible for it. We process customer data on behalf of the business the customer wrote to: the business decides why it needs the data, and we process it only to run the assistant. Customers may contact either the business or us about their data.

3. Website requests

When you submit a request on our website, we receive what you enter in the form: your name, phone or WhatsApp number, the business’s Instagram account, the type of business, the approximate number of messages per day and your comment.

We use this data to contact you, to build a demo assistant from the products in your public Instagram profile and to offer you a contract. We process it with your consent, which you give by ticking the box in the form. You can withdraw consent at any time by contacting us.

Requests are stored in our cloud spreadsheet, or arrive in our WhatsApp if you sent the request from there.

4. Business client data

To sign a contract and run the assistant, we receive from the client:

  • the contact person’s name, phone and email, the business name and the details needed for contracts and invoices;
  • the catalogue: products or services, prices, availability, photos, address, opening hours, delivery and payment terms, answers to frequent questions;
  • contacts of the staff to whom the assistant hands over customers;
  • our correspondence with the client about the assistant.

We do not receive or store bank card data: payments are made by invoice or through payment services.

5. Customer data

When a person writes to a business where our assistant is active or comments on its Instagram post, we receive:

  • the user identifier issued by Instagram or Telegram, or the phone number in WhatsApp;
  • the name and username from the profile, if the platform provides them;
  • message and comment text, photos, voice messages and other attachments, and message timestamps;
  • details the person provides to place an order or booking: name, phone, delivery address, items and quantities, preferred time.

We use this data to:

  • reply to the customer on behalf of the business: give prices, check availability, take orders and bookings;
  • reply to comments on the business’s posts and send a direct message to people who asked about price or availability;
  • pass orders, bookings and conversations to the business’s staff;
  • hand the conversation over to a human when the assistant cannot help or the customer asks for a person;
  • produce statistics for the business: number of conversations and orders, how many arrived at night;
  • improve that business’s assistant: once a month we review its conversations and adjust its script and instructions.

We do not ask for health, religious or other special categories of data. If a person shares such data in a conversation — for example, when booking a clinic appointment — it is used only for that booking and passed to the business.

6. Data from Meta platforms and Telegram

The assistant works through Meta’s official interfaces: the Instagram API and the WhatsApp Business Platform. We get access to a business account only after its owner connects the account and approves the permissions in Meta’s dialog.

Through these interfaces we receive identifiers of the connected Page, Instagram account and WhatsApp Business number, access tokens issued by Meta, and the customer messages and comments listed in section 5. Comments on posts are public; we process them only to reply and pass the question to the business.

We use data received from Meta only to reply to messages on behalf of the connected business, pass orders to it and show it conversation statistics. We do not sell this data, do not share it with advertising networks or data brokers, do not use it for advertising and do not build profiles of people from it. We comply with the Meta Platform Terms and Meta’s Developer Policies.

Telegram. If the business connects Telegram, the assistant works through the official Telegram Bot API. We receive the person’s Telegram user ID, the name and username from their profile, and the messages they send to the bot.

7. Artificial intelligence

To generate a reply, the customer’s message, the history of the current conversation and the relevant catalogue items are sent to a large language model provided by a third party. The model produces a reply, and the assistant sends it to the customer. We send the model only what is needed to reply. Voice messages are converted to text, and photos and screenshots are analysed by the model to understand the question and find the item in the business’s catalogue.

Replies are generated automatically and may contain mistakes. The assistant does not make decisions with legal effect for a person: prices, deadlines and order terms are confirmed by the business.

Personal data from one business’s conversations is not used in other businesses’ assistants. We use aggregated insights without personal data — for example, which questions are asked most often in a niche — to improve the service.

8. Who we share data with

  • The business the customer wrote to: conversations, orders, bookings and the contact details left for the order.
  • Meta Platforms and Telegram: messages pass through Instagram, WhatsApp and Telegram, and these companies process them under their own terms.
  • Technical infrastructure providers: the platform the assistants run on, hosting, AI model providers and the cloud spreadsheet service used for website requests. They receive only what is needed to run the service.
  • CRM and payment services — amoCRM, Bitrix24, Altegio, MBank, O!Dengi, Elsom — if the business has connected them to its assistant.
  • Government authorities — only when required by law.

Our providers’ servers may be located outside the Kyrgyz Republic. Only the data needed to run the service is transferred there.

We do not sell personal data or share it for advertising.

9. How long we keep data

  • Website requests — 12 months if no contract is signed; otherwise as client data.
  • Customer conversations — while the contract with the business is active, but no longer than 12 months after the last message. After the contract ends, we delete them within 30 days. Before that, the business may request an export of its conversations.
  • Meta and Telegram access tokens — deleted within 24 hours after the business disconnects the assistant.
  • Client data, contracts and invoices — for the term of the contract and then as long as accounting and tax law requires.

10. How we protect data

The website and the service use encrypted HTTPS connections. Only staff who need access for their work can see conversations and client data, each with a personal login. Meta access tokens are never shared with third parties or published. We choose providers with their data protection practices in mind.

If we learn of a breach affecting your data, we will notify the business and, where required, the affected people and the competent authority.

11. Your rights

You can:

  • find out what data we hold about you and get a copy;
  • ask us to correct inaccurate data;
  • ask us to delete your data or restrict its processing;
  • withdraw your consent;
  • lodge a complaint with the competent personal data protection authority of the Kyrgyz Republic.

Email serenegrupp@gmail.com. We confirm receipt within 3 business days and fulfil the request within 30 days. Step-by-step deletion instructions are on the Data deletion page.

12. Website and cookies

The website does not use cookies, analytics counters or advertising pixels. Fonts are loaded from Google Fonts, which means Google receives the visitor’s IP address and browser details. Our hosting provider may automatically log technical request data — IP address, browser type, time — to protect against attacks. We do not use these logs to identify visitors.

If we add analytics or advertising pixels, we will update this section first.

13. Children

The service is intended for businesses. We do not knowingly collect children’s data. If you are a parent and your child has chatted with an assistant, contact us and we will delete the conversation.

14. Changes to this policy

We publish new versions on this page with the date at the top. We notify clients of material changes 14 days in advance.

15. Contact

SERENE GRUPP LLC, taxpayer ID 00906202510487
100 Razzakov St., Bishkek, Kyrgyz Republic
Email: serenegrupp@gmail.com
Phone and WhatsApp: +996 550 910 611
Instagram: @botfactory.ai