Legal

Privacy Policy

Last updated: 2026-05-03

1. Who we are

Arzan Hub ("Hub", "we", "us") is a multi-tenant communication platform operated by Arzan Cloud Qazaqstan LLP (TOO "Arzan Cloud Qazaqstan"), a limited liability partnership registered in the Republic of Kazakhstan under BIN 251240009182, with its registered office at K. Tynybekov str. 73, Lenger 160023, Tolebi district, Turkistan region, Kazakhstan. Hub provides API and embeddable UI for businesses ("Tenants") to manage messages with their end-users ("Customers") across WhatsApp, Instagram, Messenger, Telegram and other channels.

Contact: hello@arzan.cloud.

2. What data we process

Depending on which features a Tenant enables, Hub processes the following categories of personal data on behalf of the Tenant:

  • Channel credentials — OAuth tokens, API keys and webhook secrets for connected channels (WhatsApp Business, Instagram Graph API, Telegram Bot API, Green API, etc.). Stored encrypted at rest.
  • Customer profile data — phone number, username, profile name, avatar URL, locale — as provided by the channel.
  • Message content — text, media (images, audio, files), reactions, reply context, delivery and read status.
  • Conversation metadata — timestamps, assigned operator, AI agent mode, tags, internal notes.
  • Operational data — IP addresses of API callers, audit logs of tenant-initiated actions, error reports.

We do not sell personal data, do not use it for cross-tenant advertising, and do not train AI models on Customer messages.

3. Why we process it

  • To deliver messages between the Tenant and their Customers.
  • To provide the AI agent feature when explicitly enabled by the Tenant on a per-channel or per-conversation basis.
  • To maintain reliability, debug failures, and enforce abuse / rate limits.
  • To comply with legal obligations and lawful requests from authorities.

4. Legal basis (GDPR Art. 6)

Hub acts as a processor on behalf of each Tenant who is the controller of their Customers' data. The legal basis for processing is the contract between Hub and the Tenant, and the Tenant's own legal basis with their Customers (typically legitimate interest or consent).

5. Sub-processors

We use the following sub-processors:

  • Hetzner Online GmbH — dedicated servers in EU data centers (Falkenstein and Nuremberg, Germany).
  • Cloudflare, Inc. — DNS, DDoS mitigation and edge TLS.
  • MinIO — self-hosted object storage on the same EU infrastructure (no third-party cloud).
  • AI inference providers (OpenRouter, Anthropic, OpenAI) — only when the Tenant enables AI. Message content is sent under the providers' zero-retention policies where available.
  • Channel providers themselves: Meta Platforms (WhatsApp / Instagram / Messenger), Telegram, Green API. Communication with these providers is required to deliver messages.

6. Retention

Hub retains message content and customer profile data for the duration of the active Tenant subscription, plus 30 days after termination unless the Tenant requests immediate deletion. Audit logs are retained for 12 months.

End-users may exercise data deletion rights through the Tenant (controller) or directly via Hub at /data-deletion.

7. Security

  • TLS 1.2+ in transit, AES-256 at rest for credentials and message media.
  • Per-tenant isolation: tenant_id scope on every database row and queue job.
  • JWT-based authentication with short-lived access tokens (15 min) and rotated refresh tokens.
  • HMAC verification on all inbound webhooks (Meta, Telegram, custom).
  • Rate limiting and anomaly detection per tenant and per IP.

8. Your rights

If you are an end-user (Customer) you have the right to:

  • Request access to your data we process on behalf of a Tenant.
  • Request correction or deletion of your data.
  • Object to processing or withdraw consent.
  • Lodge a complaint with a supervisory authority.

To exercise these rights, contact the Tenant whose service you used, or write to us at hello@arzan.cloud — we will route the request to the appropriate Tenant (controller) or act directly if Hub is the controller (e.g. for our own marketing site).

9. International transfers

Hub processes data on infrastructure located in the European Union. Where data must leave the EU (e.g. AI provider in the US), we rely on Standard Contractual Clauses and require the recipient's contractual commitments to GDPR-equivalent protections.

10. Cookies & tracking

The marketing site at hub.arzan.cloud uses only essential cookies for security and language preference. We do not use third-party analytics or advertising cookies on this site. The embedded inbox UI inside Tenant products inherits the Tenant's cookie policy.

10a. Mobile app (iOS / Android)

In addition to the web inbox, we publish a native Arzan Hub app for iOS and Android. This section explains what data the app requests and how to manage it.

System permissions

Each permission is requested when you use the corresponding feature, not on first launch:

  • Camera — to capture photos and send them into a chat directly from the app.
  • Photos & Media Library — to attach previously saved files.
  • Microphone — to record voice messages.
  • Notifications — for push alerts about new customer messages. You can disable it in iOS/Android settings.

What the app stores locally

  • Operator's email and name (for profile display).
  • Access and refresh JWT tokens — in iOS Keychain or Android EncryptedSharedPreferences, not in regular file storage.
  • Conversation cache and drafts (offline mode) — cleared on logout or app uninstall.
  • Device push token — stored on our server for notification delivery; revoked on logout.

Account deletion in the mobile app

Per Apple App Store guideline 5.1.1(v), you can delete your account directly inside the app: Profile → "Delete account" (bottom red button) with double confirmation. Upon confirmation we immediately revoke all JWT tokens, delete push device tokens, obfuscate email and name in our DB, and stop notifications. Company data (contacts, deals, customer chats) remains — it belongs to the Tenant, not to your personal account. To delete everything, contact the Tenant owner or write to hello@arzan.cloud.

Tracking and advertising

We do NOT track user behaviour via third-party SDKs (no Facebook SDK, no ad trackers). Apple App Tracking Transparency prompt is not shown because the app does not track you across other apps or websites. Our mobile privacy manifest (PrivacyInfo.xcprivacy) is bundled with the app.

11. Changes

We will post material changes to this policy on this page and notify Tenants via email at least 30 days before they take effect.

12. Contact

Questions, complaints, or data subject requests: hello@arzan.cloud.

Privacy Policy · Arzan Hub