Legal information
Privacy Policy
This policy explains how SEROS processes information when an authorized business connects communication channels such as Instagram, Facebook, WhatsApp, or Viber.
Effective date: August 8, 2026
1. Scope and roles
SEROS is a customer-communication platform used by authorized businesses to manage conversations with their customers. The business operating the connected social account determines why customer information is processed and is normally the data controller. SEROS processes that information to provide the service to that business.
If you contacted a business through Instagram, Facebook, WhatsApp, or another channel, that business’s own privacy notice also applies.
2. Information we process
- Connected business-account identifiers, account names, channel configuration, and integration status.
- Customer identifiers made available by the channel, display names, conversation metadata, messages, comments, and supported attachments.
- Delivery, read, error, and webhook events needed to operate and troubleshoot communication workflows.
- Authorized staff account details, access roles, security events, and audit records.
- Technical data such as timestamps, request identifiers, service logs, and device or session information needed for security and reliability.
Access tokens and other integration credentials are encrypted and are not displayed in ordinary application views.
3. How information is used
- Receive, organize, route, display, and reply to communications.
- Create and maintain customer and conversation records.
- Run business-authorized automations and AI-assisted workflows.
- Authenticate users, enforce access controls, and prevent abuse.
- Monitor reliability, diagnose failures, and maintain audit trails.
- Comply with applicable law and valid legal requests.
Businesses using SEROS are responsible for having an appropriate legal basis, providing required notices, and honoring channel-specific rules for their communications.
4. Sources and service providers
Information comes from authorized workspace users, connected channel providers, customers communicating with the connected business, and normal operation of the service. We use infrastructure and hosting providers to run the application, databases, queues, and security controls. Connected channel providers, including Meta, process information under their own terms and privacy policies.
We do not sell personal information. Information is disclosed only as needed to provide the service, follow authorized workspace instructions, protect the service, or comply with law.
5. Retention and security
Information is retained according to workspace configuration, business instructions, legal obligations, and operational needs. Integration credentials are removed or made unusable when an integration is deleted or revoked. Residual encrypted backup copies expire under the applicable backup schedule.
Safeguards include encryption in transit, encryption of integration secrets, role-based access, tenant isolation, signed-webhook validation, audit logging, and restricted operational access. No system can guarantee absolute security.
6. Choices and rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, or objection. Customers should first contact the business whose account they messaged, because that business can identify the relevant conversation and workspace. Authorized workspace owners can disconnect channel integrations and initiate data deletion through their account administrator.
Instructions for removing connected-app access and requesting deletion are available on the Data deletion.
7. Changes and contact
This policy may be updated as the service or applicable requirements change. The effective date above identifies the current version. For privacy questions, contact the administrator of the SEROS workspace or the business whose social account you contacted.