ArQonnect

Loading

Legal

Privacy Policy

Last updated 2026-09-23

This Privacy Policy explains how ArQonnect (operating the ArQonnect service, "ArQonnect", "we", "us") collects, uses, shares and protects personal information of (a) business customers who subscribe to ArQonnect and (b) end-users who interact with our customers' WhatsApp, Instagram and Messenger accounts via ArQonnect.

It applies to https://arqonnect.io, all subdomains (including https://app.arqonnect.io and https://api.arqonnect.io), our APIs, webhooks, and any messaging service we provide on behalf of a customer business.

1. Who we are

  • Legal entity: ArQonnect (operating from Lahore, Pakistan)
  • Country of operation: Pakistan
  • Registered address: Lahore, Pakistan
  • Website: https://arqonnect.io
  • App: https://app.arqonnect.io
  • API: https://api.arqonnect.io
  • Privacy contact: Compliance@arqonnect.io
  • General contact: hello@arqonnect.io

2. Data we collect

2.1 From business customers (account holders)

  • Account data: name, work email, organization name, job title, phone number (optional).
  • Authentication data: handled by our authentication provider. We store only the resulting user ID and email; passwords are never sent to our servers.
  • Billing data: handled by our PCI-DSS-compliant Merchant of Record. We store the last 4 digits of the card, the billing country, and the subscription status only.
  • Usage data: login timestamps, dashboard pages visited, features toggled, conversation volume, AI token spend.
  • Integration credentials: Channel-provider API keys and Meta Business credentials you paste into the dashboard. These are encrypted at rest with AES-256-GCM and decrypted only at the moment of an outbound API call.
  • Knowledge-base content: documents, FAQs and policies you upload to train your AI agent.

2.2 From end-users (your customers' customers)

  • Conversation data: the messages, media (images, voice notes, documents) and metadata exchanged on WhatsApp / Instagram / Messenger between an end-user and the business they contacted.
  • Messaging account data: phone number (E.164), display name and channel-specific user ID.
  • Technical data: IP address of the channel webhook callback, provider message IDs, timestamps.

2.3 From visitors to our website

Functional cookies for sign-in and theme preference. Where enabled in production, optional website analytics may load for aggregated traffic measurement. See our Cookie Policy for current categories and how to opt out.

3. Why we collect it (purpose & legal basis)

For each category we identify a purpose and the GDPR Art. 6 legal basis we rely on.

DataPurposeLegal basis
Account dataProvision and operate your accountContract
Billing dataProcess subscription payments, issue invoicesContract
Usage dataMonitor system health, prevent abuse, improve featuresLegitimate interest
Conversation dataRoute messages, generate AI replies, enable human handoffContract (with the business) / consent collected by the business from the end-user
Integration credentialsConnect to channel providers and send messagesContract
Technical dataSecurity monitoring, fraud preventionLegitimate interest
Knowledge-base contentGround AI responses in your own materialsContract
Marketing emailsNotify you about product updatesConsent (opt-in only)

4. How we use Meta Platform data

This section governs all data we obtain from the Meta APIs (WhatsApp Business API, Instagram Messaging API, Messenger Platform).

Arqonnect uses data obtained from Meta platforms solely to provide the services described in our Terms. We do not use Meta Platform Data to:

  • train consumer AI models;
  • serve advertisements;
  • build user profiles for advertising;
  • share with third parties for marketing purposes.

Meta Platform Data is used only to: (1) route messages between businesses and their customers, (2) power AI-assisted responses within Meta's 24-hour customer service window, (3) provide conversation analytics to the business account holder, and (4) enable human-agent handoff when the AI cannot resolve a query or escalation is requested. Data obtained from Meta APIs is not combined with data from other sources for advertising or profiling purposes.

5. AI disclosure

ArQonnect provides AI-powered messaging agents that interact with end-users on behalf of businesses. These agents use large-language-model (LLM) inference and retrieval-augmented generation (RAG) to produce responses. End-users may therefore be communicating with an AI rather than a human representative. Our agents are configured to identify themselves as AI when directly asked. Human support agents are available and will take over the conversation when the AI cannot resolve a query or when escalation is requested. This disclosure is provided to align with transparency expectations under applicable AI and platform policies, including Meta's platform policies.

6. Data retention

We tie every retention period to a specific purpose, in line with GDPR Art. 5(1)(e) (storage limitation). When the purpose ends or the limit is reached, data is deleted.

  • Account data: retained for the duration of your active subscription. Deleted within 30 days of account closure, cancellation, or a verified deletion request — whichever comes first.
  • Conversation data: retained for the duration of your active subscription so the AI agent has the context it needs to reply. Upon account closure or cancellation, all conversation data is permanently deleted within 30 days. You can request earlier deletion at any time by emailing Compliance@arqonnect.io. Inactive conversations within an active account may be moved to cold storage after 90 days of no activity.
  • Platform logs (technical): up to 90 days, then deleted.
  • Backups: encrypted database backups are retained for 30 days, then overwritten.

7. Storage & security

  • Managed cloud database hosting in Asia-Pacific by default.
  • Encrypted object storage for media (private access, signed URLs only).
  • TLS 1.2+ in transit everywhere.
  • AES-256-GCM at rest for all integration credentials and model API keys.
  • Role-based access control with separation between platform staff and business users; enforced 2FA for staff.
  • Per-tenant data isolation enforced in every database query.
  • Regular vulnerability scans; responsible disclosure at Compliance@arqonnect.io.

8. Sub-processors

We share the minimum personal information necessary with carefully selected service providers that help us operate ArQonnect. Categories include authentication, cloud hosting and storage, messaging channel delivery (including Meta for WhatsApp, Instagram and Messenger), AI model inference, email delivery, billing (Merchant of Record named on your invoice), and optional website analytics. A current list of providers is available to customers on request at Compliance@arqonnect.io. We notify customers in writing before adding or replacing a provider that materially changes how their data is handled.

9. International transfers

Where personal data is transferred outside your country (for example from the EU/UK to the United States), we rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent safeguards offered by our sub-processors.

10. Your rights (GDPR)

Subject to applicable law you have the following rights. To exercise any of them, email Compliance@arqonnect.io. We respond within 30 days.

  • Access: request a copy of the personal data we hold about you.
  • Rectification: ask us to correct inaccurate data.
  • Erasure (right to be forgotten): request deletion of your personal data. See also Data Deletion.
  • Portability: receive your data in a machine-readable format.
  • Restriction / objection: object to processing based on legitimate interest.
  • Withdraw consent: at any time, with effect for the future. Use the unsubscribe link in any marketing email.
  • Lodge a complaint with the data protection authority in your jurisdiction.

11. California residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act gives you the right to know what personal information we collect about you, the right to delete it, the right to correct inaccurate information, and the right to opt out of the "sale" or "sharing" of personal information. Arqonnect does not sell personal information and does not share personal information for cross-context behavioural advertising. To exercise these rights, contact Compliance@arqonnect.io.

12. WhatsApp opt-in & messaging consent

Arqonnect requires its business customers to obtain explicit opt-in consent from end-users before sending business-initiated WhatsApp template messages on their behalf. Acceptable opt-in mechanisms include website forms, WhatsApp keyword reply, and in-person consent. End-users can opt out at any time by replying STOP to any WhatsApp message; opt-out records are kept for at least 5 years and broadcast lists are updated within 24 hours of an opt-out request. Arqonnect does not send unsolicited messages.

13. Children

Arqonnect is a B2B service and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us so we can delete it.

14. Changes to this policy

We may update this policy from time to time. Material changes will be announced on this page and notified to account owners by email at least 30 days in advance.

15. Contact

Privacy questions, data subject requests, and DPA requests: Compliance@arqonnect.io. General inquiries: hello@arqonnect.io. Postal mail to ArQonnect, Lahore, Pakistan.