Privacy Policy

// Last Updated: June 23, 2026

Welcome to Vonmatic. We are committed to protecting the privacy of your business operations and your customers' data. This policy outlines how we collect, handle, encrypt, and isolate information when you utilize our automation platform.

Data Controller

The data controller responsible for the processing of your personal data is:

Vonmatic

Dubai, United Arab Emirates

Data Protection Contact: privacy@vonmatic.com

1. Core Architecture & Data Isolation

Unlike traditional shared-database platforms, Vonmatic operates a Headless Multi-Tenant Engine Architecture.

  • Complete Isolation: Every workspace client receives an isolated, dedicated workflow routing execution instance powered by our privately hosted automation infrastructure (n8n). Your pipeline states and operational data matrices are completely siloed.
  • No Marketplace Interception: When you activate pre-built automation blueprints, data flows directly between your specified source endpoints and targets. We do not inspect, retain, or monetize payloads traversing your active pipelines.

2. Information We Collect

To provide a secure automation wrapper, we collect the following categories of information:

// Account & Workspace Metadata

Identification data (name, email, password hashes, telephone numbers) and role management settings collected during onboarding.

// Third-Party Credentials

API tokens and keys to external platforms (e.g., Meta WhatsApp Cloud API keys, Shopify tokens). These are instantly encrypted at the edge server layer and are never readable by internal personnel.

We also process Runtime Telemetry Logs (timestamps, payload byte sizes, success/failure execution states) strictly to generate your workspace dashboard analytics graphs.

3. Legal Basis for Processing (GDPR Art. 6)

We process your personal data only where we have a lawful basis to do so. The specific legal grounds depend on the type of data and the purpose of processing:

  • Contract Performance (Art. 6(1)(b)): Processing your account data, workspace configuration, and credentials is necessary to deliver the automation services you subscribed to. Without this data, we cannot provide your workspace.
  • Legitimate Interest (Art. 6(1)(f)): We process runtime telemetry logs, security audit trails, and aggregated usage analytics to maintain platform stability, prevent abuse, and improve our services. You may object to this processing at any time.
  • Consent (Art. 6(1)(a)): For optional marketing communications, non-essential analytics cookies, and product feedback surveys. You may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Legal Obligation (Art. 6(1)(c)): We retain billing records and transaction histories as required by applicable tax and financial regulations.

4. Advanced Data Security Standards

Data security is the absolute foundational priority of Vonmatic. We enforce enterprise-grade security protocols across all infrastructure layers:

  • Encryption-at-Rest: All customer credentials and connection strings are encrypted before storage utilizing AES-256 encryption via Supabase Vault. Decryption keys are managed server-side and never exposed to client applications.
  • Database Boundaries: Our storage system (Supabase) enforces strict Row-Level Security (RLS) gates. It is cryptographically impossible for a user belonging to one workspace ID to query or read data from another workspace instance.
  • Server-Side Only: Decryption of credentials occurs strictly on the server side during live automation executions. API keys and tokens are never sent to or accessible from client-side code.

5. How We Use and Share Information

We use the information we collect strictly to maintain your workspace operations, track subscription limit caps (such as your monthly message metrics), and output telemetry feeds directly to your internal dashboard metrics layout.

We never sell, rent, or trade your account details, workspace variables, or automated customer data payloads to third-party data brokers or marketing firms.

6. Third-Party Infrastructure Sub-Processors

To maintain high-availability edge routing across global networks, we partner with specialized, fully compliant cloud infrastructure sub-processors:

Database & Auth: Supabase Inc.Hosting & Edge: Vercel Inc.Orchestration Node: Self-hosted n8n EngineAnalytics: Vercel Web Analytics

All sub-processors are bound by Data Processing Agreements (DPAs) that meet the requirements of GDPR Article 28, ensuring they process personal data only on our documented instructions.

7. International Data Transfers

Some of our sub-processors operate outside the European Economic Area (EEA). Where personal data is transferred internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): We rely on EU-Commission-approved Standard Contractual Clauses with all sub-processors located outside the EEA, including those in the United States.
  • EU-U.S. Data Privacy Framework: Where applicable, our US-based sub-processors are certified under the EU-U.S. Data Privacy Framework, providing an adequacy-level mechanism for transatlantic data flows.
  • Supplementary Measures: All data in transit is protected by TLS encryption, and credentials are encrypted at rest before any cross-border transfer occurs.

8. Cookies & Tracking Technologies

We use cookies and similar technologies to operate and improve the platform. Here is what we deploy:

// Strictly Necessary

Session tokens, authentication state, CSRF protection, and theme preference. These cannot be disabled as they are essential for platform operation.

// Analytics (Consent Required)

Vercel Web Analytics for anonymous page-view metrics. No personal identifiers are collected. Only activated after you accept analytics cookies via our consent banner.

You can manage your cookie preferences at any time via the cookie settings accessible from the footer of every page. We do not use advertising or cross-site tracking cookies.

9. Data Retention Periods

We retain personal data only for as long as necessary to fulfill the purposes described in this policy:

  • Account data: Retained for the duration of your active subscription, plus 30 days after account deletion to allow recovery requests.
  • Billing records: Retained for 7 years as required by UAE Commercial Transactions Law and applicable EU tax regulations.
  • Runtime telemetry: Aggregated and anonymized after 90 days. Raw logs are purged automatically.
  • Encrypted credentials: Permanently deleted immediately upon credential removal or workspace deletion. No backups are retained.

10. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), United Kingdom, or any jurisdiction with equivalent data protection laws, you have the following rights regarding your personal data:

  • Right of Access (Art. 15): Request a copy of all personal data we hold about you, including processing purposes and data categories.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
  • Right to Erasure (Art. 17): Request deletion of your personal data. You can exercise this immediately via the "Danger Zone" in your dashboard, or by contacting us directly.
  • Right to Restriction (Art. 18): Request that we limit processing of your data while a dispute or verification is pending.
  • Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format (JSON export available from your workspace settings).
  • Right to Object (Art. 21): Object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.
  • Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, email privacy@vonmatic.com. We will respond within 30 days. No fee is charged for reasonable requests.

11. Automated Decision-Making

Our AI Receptionist and automation workflows execute pre-configured logic sequences on your behalf (e.g., routing leads, scheduling appointments, sending templated responses). These automations:

  • Operate based on rules and templates you explicitly configure, not autonomous profiling.
  • Do not produce legal or similarly significant effects on individuals without human oversight.
  • Can be reviewed, modified, or disabled by you at any time from your workspace dashboard.

12. Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. You may contact:

  • Your local Data Protection Authority in the EU/EEA Member State of your habitual residence or place of work.
  • The UK Information Commissioner's Office (ICO) if you are located in the United Kingdom.

We encourage you to contact us first at privacy@vonmatic.com so we can attempt to resolve your concern directly.

13. Data Lifecycle & "Danger Zone" Rights

You maintain absolute control over your workspace parameters. If you trigger a deletion action inside your settings console ("Danger Zone"), our backend system instantly contacts our private orchestration node to completely wipe and drop your unique workflow copies. Deleting a credential instantly drops its associated encrypted record from our data vault permanently.

14. Children's Privacy

Vonmatic is a business-to-business automation platform. Our services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that a user is under 16, we will promptly delete their account and associated data.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes:

  • We will notify you via email to the address associated with your account at least 30 days before the changes take effect.
  • A prominent notice will be displayed in your workspace dashboard.
  • The "Last Updated" date at the top of this page will be revised.

Continued use of the platform after the effective date constitutes acceptance of the updated policy.

16. Categories of Sources of Personal Data

We collect personal data about you from the following sources:

  • Directly from you: When you create an account, configure your workspace, connect integrations, submit support requests, or communicate with us via email or chat.
  • Automatically through the Services: When you use the platform, we collect device information, IP address, browser type, and interaction data through essential cookies and Vercel Web Analytics.
  • From third-party authentication providers: When you sign in via OAuth (e.g., Google), we receive your name, email, and profile identifier from that provider.

17. How We Disclose Personal Data

We disclose your personal data only to the following categories of recipients, and only to the extent necessary:

  • Service Providers: Infrastructure providers (Supabase, Vercel), payment processors (Stripe), and our self-hosted automation engine (n8n), all bound by DPAs.
  • Analytics Partners: Vercel Web Analytics receives anonymous, non-identifiable page-view metrics only after you consent to analytics cookies.
  • Legal Obligations: We may disclose data if required by law, court order, or to protect the rights, property, or safety of Vonmatic, our users, or the public.
  • Platforms You Authorize: When you connect WhatsApp, HubSpot, Shopify, or other integrations, data flows directly between your workspace and those platforms. We facilitate the connection but do not retain or inspect the payload content.

We do not sell personal data to data brokers, advertisers, or any third party. We do not serve behavioral advertising.

18. Business Transfers

If Vonmatic undergoes a merger, acquisition, or asset sale, your personal data may be transferred to the acquiring entity. In such an event:

  • We will notify you via email at least 30 days before the transfer takes effect.
  • The acquiring entity will be bound by this Privacy Policy until a new one is communicated to you.
  • You will have the option to delete your account and data before the transfer completes.

19. WhatsApp & Messaging Consent

Vonmatic sends automated WhatsApp messages on behalf of our clients to their customers. Regarding messaging consent and data:

  • Opt-in data is never shared: Messaging originator opt-in data and consent records will not be shared with any third parties, excluding the WhatsApp Business API provider (360dialog) required to deliver messages.
  • Your responsibility: As stated in our Terms of Service, you (the workspace owner) are responsible for obtaining proper consent from your end customers before sending them automated messages via our platform.
  • Message content: We do not read, store, or analyze the content of WhatsApp messages processed through your automations. Messages are transmitted in real-time and not retained on our servers.

20. Aggregated & De-identified Data

We may create aggregated, de-identified, or anonymized data from the personal data we collect, for example, aggregate platform usage statistics or industry benchmarks. Such data does not identify any individual user and may be used for any lawful business purpose, including improving our services and publishing industry reports.

21. "Do Not Track" Signals

Our platform does not currently respond to "Do Not Track" (DNT) browser signals because there is no industry-standard interpretation of DNT. However, since we do not serve behavioral advertising or cross-site tracking cookies, the practical effect is the same: we do not track you across other websites.

22. California Resident Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: You may request what personal data we have collected, the sources, the business purpose, and the categories of third parties we have disclosed it to over the past 12 months.
  • Right to Delete: You may request deletion of your personal data, subject to certain legal exceptions (e.g., billing records we must retain by law).
  • Right to Correct: You may request correction of inaccurate personal data we hold about you.
  • Right to Opt-Out of Sharing: While we do not sell personal data, our use of analytics cookies may constitute "sharing" under the CCPA. You can opt out via our cookie consent banner or by emailing us.
  • Non-Discrimination: We will not deny you services, charge different prices, or provide a different quality of service for exercising your CCPA rights.

To submit a request, email privacy@vonmatic.com with "CCPA Request" in the subject line. We will verify your identity and respond within 45 days.

23. Tracking Opt-Out & Cookie Management

You can control cookies and tracking through the following methods:

  • Our cookie consent banner: Decline analytics cookies when prompted. You can update your preferences at any time via the cookie settings link in our footer.
  • Browser settings: Most browsers allow you to block or delete cookies via the preferences/options menu. Note: disabling essential cookies may prevent you from logging in to the platform.

For more information about cookies in general, visit allaboutcookies.org.

Vonmatic Security & Compliance Team

Email: privacy@vonmatic.com | Web Terminal: /contact

Vonmatic · Dubai, United Arab Emirates