Introduction Resonoon, SAS ('Resonoon', 'we', 'us') is registered at 12 Rue de la Part-Dieu, 69003 Lyon, France, under SIREN 934 012 139. This Privacy Policy explains how personal data is collected, used, stored, shared, and deleted when you use our website at www.resonoon.com and our cloud services, including AI assistants, messaging integrations, shared workspaces, customer-support tools, and related features (collectively, the 'Services'). Resonoon acts as controller for account, website, billing, and direct business-contact data. When a business customer uses the Services to process conversations or other data on its behalf, that customer is generally the controller and Resonoon acts as its processor or service provider.
Collection of Information We collect the information necessary to provide and secure the Services.
Account and workspace data may include names, email addresses, telephone numbers, profile information, organisation details, roles, settings, authentication records, subscription and billing information.
Customer content may include assistant configuration, knowledge files, conversations, messages, notes, tickets, contact information, attachments, audio, and other content submitted by customers or their end users.
Connected-channel data may include Facebook Page IDs and names, Instagram Professional account IDs and usernames, WhatsApp Business account and phone-number identifiers, provider access tokens, webhook identifiers, sender and recipient identifiers, message text, attachments, timestamps, reactions, postbacks, and delivery or read events made available by the relevant provider.
We also collect technical and security information such as IP address, browser and device information, request timestamps, diagnostic events, and audit logs.
Visitor Information Joining our waitlist or subscribing to updates allows us to collect your PII, like name and email. We may contact you about new features or updates, with the option for you to opt-out.
Cookies We use Cookies and Web Beacons to gather information for service improvement. Cookies are small text files placed on your device, with your consent, to identify you and monitor your interaction with our Services. You can manage Cookie settings in your browser, but this may affect your access to our Services.
Web Beacons Web Beacons are used to deliver Cookies, measure service performance, and monitor visitor interaction. These are invisible and not stored like Cookies.
Service Usage Information We automatically log usage details (Log Data), including browser type, visit duration, approximate location, and engagement metrics, to analyze and enhance our Services.
Mobile Device Information Information from your mobile device, including device ID and operating system, is collected to improve service delivery.
Location Information With your consent, we collect approximate location data or device location data to personalize our Services. You can disable location services on your device.
How We Use and Share Information We use personal data to provide, maintain, secure, and improve the Services; authenticate users; operate workspaces and integrations; store and route conversations; generate configured AI responses; enable authorised human operators to reply; provide support; prevent fraud and duplicate event processing; comply with legal obligations; and communicate about the Services.
Data is shared only where necessary to perform the Services, follow a customer's instructions, protect the Services, complete a transaction, obtain consented services, or comply with law. Within a customer workspace, authorised users may access data according to the roles and permissions configured by that customer. Resonoon does not sell Meta Platform Data or use connected-channel messages, identifiers, or access tokens for advertising.
Processors and Service Providers We use carefully selected processors and service providers that may process personal data only to provide contracted services on our behalf and subject to appropriate confidentiality and data-protection terms.
Microsoft Azure provides cloud hosting, computing, databases, secrets management, monitoring, and related infrastructure.
Amazon Web Services EMEA SARL provides Amazon S3 storage for conversation files and media in the Europe (Frankfurt) region in Germany.
OpenAI Ireland Ltd. provides AI processing used to generate assistant responses and process content as configured by our business customers.
HubSpot supports customer relationship management, sales, and marketing communications and does not receive connected-channel content unless it is intentionally supplied for those purposes.
These providers may use subprocessors disclosed in their respective contractual and privacy documentation. We assess providers according to the data and services involved.
Business Transactions In business transitions, such as mergers or acquisitions, your PII may be transferred or disclosed in compliance with legal standards.
Legal Compliance and Protection We may preserve or disclose information where required by applicable law, a binding legal process, or to protect rights, safety, and the integrity of the Services. Requests from public authorities are reviewed for legal validity and scope. Where reasonably possible and lawful, we challenge requests that appear unlawful, notify the affected customer, and limit disclosure to the information legally required.
Facebook, Instagram, and WhatsApp Integrations A customer may choose to connect Facebook Messenger, Instagram Direct, or WhatsApp to a Resonoon assistant. Connection is initiated by an authorised account owner through the relevant Meta or Instagram OAuth or embedded-signup flow. Resonoon requests only the permissions required for the selected integration.
We use connected account identifiers and profile information to show the selected Page or Professional account, prevent conflicting bindings, maintain webhook subscriptions, and route events to the correct assistant. We process incoming messages and media to display them in the customer's Resonoon workspace, produce configured AI responses, and permit authorised operators to respond. We process event identifiers and status data to prevent duplicate handling and diagnose delivery.
Provider access tokens and application secrets are handled server-side, are not returned to the browser through integration APIs, and are not used to access unrelated accounts, publish social content, or manage advertising. Disconnecting an integration removes the active Resonoon binding and provider subscription. Existing conversation records remain subject to the retention and deletion rules below. Use of Meta products is also governed by Meta's applicable terms and privacy policies.
Data Retention and Deletion We retain personal data only for as long as necessary to provide the Services, comply with contractual and legal obligations, resolve disputes, and protect the Services.
Integration credentials are retained while the integration remains connected and are removed or replaced when the customer disconnects or reconnects the channel. Technical webhook receipt records used for duplicate prevention are automatically deleted after 14 days. Conversation attachments stored for active conversations are automatically removed from external file storage after 90 days, while the related message record may remain without the file. Conversation text and metadata remain until deleted by an authorised customer, the workspace or account is deleted, a valid deletion request is completed, or they are no longer required for the purposes described in this Policy.
Residual copies may remain temporarily in restricted backups and logs until their normal deletion cycle completes. We may retain limited information where required by law, to establish or defend legal claims, or to document a completed deletion request.
Information Security We apply technical and organisational safeguards appropriate to the nature of the data, including encryption in transit, access controls, role-based workspace permissions, restricted server-side credential handling, webhook signature verification, logging controls, backups, and monitoring. No system can guarantee absolute security, and customers are responsible for protecting their accounts, connected-provider access, and authorised-user permissions.
Third-Party Services and Links The Services may connect to or link to third-party platforms such as Meta, Instagram, WhatsApp, email providers, payment providers, and other customer-selected services. Those platforms process data under their own terms and privacy policies. Customers decide which integrations to enable and are responsible for having a lawful basis to provide end-user data through them.
Your Data Protection Rights Depending on applicable law, you may request access to, correction of, deletion of, restriction of, or portability of your personal data; object to certain processing; withdraw consent where processing relies on consent; and lodge a complaint with a competent supervisory authority. You can update certain account information through the Services or submit a request to sales@resonoon.com. We may need to verify your identity and authority before completing a request. If Resonoon processes your data on behalf of a business customer, please contact that customer first; we will assist the customer in responding as required by law.
International Transfers Our infrastructure and providers may process data in countries other than your own. Core production services are hosted in the European Union, while some providers or their authorised subprocessors may process data in other jurisdictions. Where required, we rely on data-processing agreements, adequacy decisions, Standard Contractual Clauses, and supplementary technical and organisational safeguards for international transfers.
Children's Privacy We do not knowingly collect information from children under 13. If we become aware of such collection, we take steps to remove the information promptly.
Policy Updates We may update this Privacy Policy to reflect changes to the Services, providers, or applicable law. Material changes will be communicated through the Services, our website, or by email where appropriate. This version was last updated on 23 July 2026.
Contacting Resonoon For questions regarding this Privacy Policy, contact us at sales@resonoon.com.