Legal

Privacy Policy

Last updated: 2026-05-03

1. Who we are

Arzan Hub ("Hub", "we", "us") is a multi-tenant communication platform operated by Arzan Cloud. Hub provides API and embeddable UI for businesses ("Tenants") to manage messages with their end-users ("Customers") across WhatsApp, Instagram, Messenger, Telegram and other channels.

Contact: hello@arzan.cloud.

2. What data we process

Depending on which features a Tenant enables, Hub processes the following categories of personal data on behalf of the Tenant:

  • Channel credentials — OAuth tokens, API keys and webhook secrets for connected channels (WhatsApp Business, Instagram Graph API, Telegram Bot API, Green API, etc.). Stored encrypted at rest.
  • Customer profile data — phone number, username, profile name, avatar URL, locale — as provided by the channel.
  • Message content — text, media (images, audio, files), reactions, reply context, delivery and read status.
  • Conversation metadata — timestamps, assigned operator, AI agent mode, tags, internal notes.
  • Operational data — IP addresses of API callers, audit logs of tenant-initiated actions, error reports.

We do not sell personal data, do not use it for cross-tenant advertising, and do not train AI models on Customer messages.

3. Why we process it

  • To deliver messages between the Tenant and their Customers.
  • To provide the AI agent feature when explicitly enabled by the Tenant on a per-channel or per-conversation basis.
  • To maintain reliability, debug failures, and enforce abuse / rate limits.
  • To comply with legal obligations and lawful requests from authorities.

4. Legal basis (GDPR Art. 6)

Hub acts as a processor on behalf of each Tenant who is the controller of their Customers' data. The legal basis for processing is the contract between Hub and the Tenant, and the Tenant's own legal basis with their Customers (typically legitimate interest or consent).

5. Sub-processors

We use the following sub-processors:

  • Cloud infrastructure: dedicated servers in EU.
  • Object storage: self-hosted MinIO (no third-party cloud).
  • AI inference providers (OpenRouter, Anthropic, OpenAI) — only when AI agent is enabled by the Tenant. Message content is sent to these providers under their zero-retention policies where available.
  • Channel providers themselves: Meta (WhatsApp / Instagram / Messenger), Telegram, Green API. Communication with these providers is required to deliver messages.
  • Email: transactional notifications via SMTP relay.

6. Retention

Hub retains message content and customer profile data for the duration of the active Tenant subscription, plus 30 days after termination unless the Tenant requests immediate deletion. Audit logs are retained for 12 months.

End-users may exercise data deletion rights through the Tenant (controller) or directly via Hub at /data-deletion.

7. Security

  • TLS 1.2+ in transit, AES-256 at rest for credentials and message media.
  • Per-tenant isolation: tenant_id scope on every database row and queue job.
  • JWT-based authentication with short-lived access tokens (15 min) and rotated refresh tokens.
  • HMAC verification on all inbound webhooks (Meta, Telegram, custom).
  • Rate limiting and anomaly detection per tenant and per IP.

8. Your rights

If you are an end-user (Customer) you have the right to:

  • Request access to your data we process on behalf of a Tenant.
  • Request correction or deletion of your data.
  • Object to processing or withdraw consent.
  • Lodge a complaint with a supervisory authority.

To exercise these rights, contact the Tenant whose service you used, or write to us at hello@arzan.cloud — we will route the request to the appropriate Tenant (controller) or act directly if Hub is the controller (e.g. for our own marketing site).

9. International transfers

Hub processes data on infrastructure located in the European Union. Where data must leave the EU (e.g. AI provider in the US), we rely on Standard Contractual Clauses and require the recipient's contractual commitments to GDPR-equivalent protections.

10. Cookies & tracking

The marketing site at hub.arzan.cloud uses only essential cookies for security and language preference. We do not use third-party analytics or advertising cookies on this site. The embedded inbox UI inside Tenant products inherits the Tenant's cookie policy.

11. Changes

We will post material changes to this policy on this page and notify Tenants via email at least 30 days before they take effect.

12. Contact

Questions, complaints, or data subject requests: hello@arzan.cloud.