1. Who we are
Otvetim helps businesses reply to customers on Instagram Direct, Telegram, web widget, and email. The business connects its channels, adds knowledge about the company, and the service helps run the conversation and hands complex situations off to a human operator.
In this policy, business customer means the company or sole proprietor that uses Otvetim. End user means the person who writes into a channel connected by the business.
2. What data we receive
From business customers we may receive:
- email, password (stored as a hash), company name, and workspace settings;
- service descriptions, prices, working hours, FAQ, knowledge base documents;
- channel settings and access tokens for connected integrations;
- data about operators who use the admin panel.
From end users in messengers we process only what is needed for the conversation with the business:
- the sender's identifier within the relevant channel;
- the text of messages sent to the connected business account;
- attachments, if the user sends an image or a voice message;
- timestamps, message identifiers, and technical data used for deduplication.
For Instagram we use only the instagram_business_basic and instagram_business_manage_messages scopes. We do not request access to the feed, stories, likes, follower lists, or messages that do not belong to the connected business account.
3. How we use the data
- To show the business its conversation history and the status of customer requests.
- To generate a reply based on the customer's message and the business's knowledge base.
- To respect platform limits, including the Meta 24-hour messaging window.
- To let the operator step into a conversation, fix a reply, or turn automation off.
- To maintain security, auditing, and reliable operation of the service.
We do not sell data, we do not use it for advertising retargeting, and we do not mix data between different business customers.
4. Sub-processors and storage
To run the service, we use a limited set of sub-processors:
- LLM providers — Anthropic and OpenAI — receive the request text and the business context needed to generate a reply; calls are routed through the OpenRouter gateway. Data is sent only to process the specific message and is not used by the providers to train models.
- Postgres stores the working data of the service. Business customer data is isolated per tenant schema.
- S3-compatible object storage is used for files and media attachments.
Data is transmitted over TLS. Secrets and access tokens are protected by infrastructure-level controls; if column-level token encryption is enabled for a given environment, it is applied on top of that.
5. Retention
- Conversations, messages, and related metadata are kept for as long as the business uses the service, unless a shorter retention window is set by contract or by the workspace's own policy.
- After a business account is closed, data may be kept for up to 30 days for recovery, export, and billing reconciliation, and is then deleted or anonymized.
- Technical logs are typically retained for up to 90 days.
- Instagram tokens are deleted or zeroed out as soon as the app is deauthorized or the channel is disconnected.
6. Deletion and user rights
If you are the owner of a connected Instagram business account, you can remove the app in your Instagram or Meta settings. After we receive the callback from Meta, we deactivate the connection, remove access tokens, and stop processing new events for that account.
If you are an end user who messaged a business on Instagram, Telegram, or the web widget, the automatic Meta callback may not identify your messages in our system. In that case, write to support@otvetim.by and provide the channel, your username or contact, and the business you wrote to. We will review the request and delete or anonymize the related data if we can reliably match it.
A detailed walkthrough is available on the Data Deletion page.
7. Security
- Meta webhook requests are verified by HMAC signature.
- Operator access is scoped to the business's workspace.
- Data of different business customers is stored separately.
- Sensitive actions are logged for auditing and incident review.
- We do not request unnecessary platform permissions from the business.
9. Policy changes
If the policy changes materially, we will update the date on this page and, where appropriate, notify business customers through the admin panel or by email.