Privacy Policy
Last Updated: September 15, 2026
Overview
Yudex Labs ("we", "our", or "the Platform") allows businesses to create and manage AI agents connected to WhatsApp Business.
2. Data We Collect
2.1 Business owner data (Tenant)
| Data | Purpose | Legal basis |
|---|---|---|
| Company name | Identify the business on the platform | Performance of the contract |
| Owner's phone number | Communication during onboarding and support | Performance of the contract |
| Business industry | Customize the agent | Performance of the contract |
| Email address (if provided) | Notifications and account recovery | Consent |
| Billing information (through PayPal) | Process subscription payments | Performance of the contract |
2.2 End user data (the business's customers)
| Data | Purpose | Legal basis |
|---|---|---|
| WhatsApp number | Identify the conversation | Legitimate interest of the business |
| Text messages sent to the agent | Generate AI responses | Legitimate interest of the business |
| Call and lead history | Maintain conversational context | Legitimate interest of the business |
| Voice call transcript | Record the content of the voice conversation with the agent | Legitimate interest of the business |
| Call audio recording | Reference, quality, and agent audit record | Legitimate interest of the business |
| Call metadata (duration, date, time) | Operational control and agent metrics | Legitimate interest of the business |
2.3 Data we do NOT collect
- We do not access the user's contact list.
- We do not collect geolocation data.
- We do not collect biometric data.
- We do not sell or share data with third parties for advertising.
- We do not use data obtained from Gmail to train, fine-tune, evaluate, or improve generalized artificial intelligence models.
- We do not store passwords — authentication is managed through Meta and PayPal.
2.4 Google Calendar integration
For users who enable calendar synchronization with Google Calendar, the platform uses a secure connection and requests authorization before accessing the information needed.
- Accessed data: We only read availability and events from the primary calendar of the Google account that authorizes the connection to prevent duplicate appointments, and we create, modify, or delete meeting events at your customers' request.
- Security: Connection credentials are stored securely.
- Use of information: Our access to and transfer of information received from Google follows the Google API Services User Data Policy, including the Limited Use requirements. We do not use this information to train generalized models or share it for advertising.
2.5 Email integrations (Gmail and Outlook Mail)
The platform allows Gmail or Outlook Mail to be connected for sending emails as actions configured in voice, Text, or WhatsApp scenarios. The connection is secure and requires the business owner's explicit authorization.
- Gmail: we request permission only to send messages on behalf of the connected account. We do not read, search, modify, or delete mailbox messages.
- Outlook Mail: the connection is limited to sending email. We do not access mailbox content to read or reply to messages.
- Data used: we use the validated recipient, subject, and configured action content. Connection credentials are protected and are not sent to AI models.
- Sending: the email is delivered asynchronously. We retain the information needed to know the delivery status, provide support, and handle privacy requests.
Gmail mailbox information is not provided to AI models and is not used to train, fine-tune, evaluate, or improve generalized models. AI-generated text for an action comes from conversation context and business configuration, not from reading the mailbox.
3. How We Use Data
- Provide and maintain the Service.
- Configure and customize the business agent using its knowledge base.
- Process payments through PayPal.
- Communicate service updates and technical support.
- Detect and prevent fraud.
4. AI Processing
- Conversations are processed through artificial intelligence services used by the platform and, for voice agents, through a specialized voice provider when the agent is configured with that service.
- Messages and the context needed to answer are processed in real time through artificial intelligence services used by the platform to generate responses.
- Data obtained from Gmail is not sent to AI models or used to train generalized models. AI may generate email text from the conversation and the business configuration.
- Conversation history is limited to the last 20 messages per session and stored temporarily, with automatic expiration after 24 hours.
5. Where Data is Stored
| Data | Location / Type | Duration |
|---|---|---|
| Tenant data | Secure storage | While the account is active |
| Temporary chat history | Temporary storage | 24 hours (automatic expiration) |
| Onboarding status | Temporary storage | 7 days (automatic expiration) |
| Knowledge base (embeddings) | Secure storage | While the account is active |
| Activity records | Secure storage | Last 100 turns per user |
| WhatsApp credentials | Secure storage | While the account is active |
| Email connection credentials | Encrypted database | While the connection is active or until it is disconnected |
| Email delivery records | Encrypted database | According to operational retention and while needed for audit and support |
| Voice call transcripts | Secure storage | While the account is active |
| Call audio recordings | Voice call provider (Retell AI) | According to Retell AI's retention policy |
Security measures
- Protection of connection credentials for external services, including WhatsApp, Google Calendar, Gmail, and Outlook Mail.
- Authenticity verification for all incoming webhooks (Meta, PayPal).
- Message deduplication to prevent duplicate processing.
- HTTPS/TLS connections for all communications.
- Restricted access controls for data infrastructure.
6. Voice Calls & Recordings
The platform can make automated voice calls through AI agents. This service is enabled through Retell AI, an external provider specializing in voice AI.
6.1 Data processed in each call
- Audio recording: the call audio file is stored in Retell AI's infrastructure, subject to its retention policy.
- Transcript: it is generated automatically and stored in our encrypted database as part of the user's conversation history.
- Metadata: the call date, time, and duration are stored for operational agent metrics.
6.2 Use of call data
- Generate agent responses in real time during the call.
- Maintain conversational context across chat and voice sessions.
- Quality control and improvement of agent performance.
- Auditing and metric reports for the business owner.
6.3 Responsibility for recording notices
The business owner is solely responsible for informing end users, before or at the start of each call, that the conversation may be recorded and/or transcribed. This notice must comply with the laws applicable in the business's jurisdiction.
6.4 Call data retention
- Audio recordings: managed and retained by Retell AI under its own privacy policy.
- Transcripts: retained in our database while the business account is active, or until deletion is requested under section 8.
7. Third Parties We Share Data With
| Third party | Shared data | Purpose |
|---|---|---|
| WhatsApp de Meta | WhatsApp messages | Send and receive agent messages |
| OpenRouter | Conversation text | Generate AI responses |
| PayPal | Subscription data | Process recurring payments |
| MongoDB Atlas | All platform data | Storage |
| Google Cloud Platform | Runtime infrastructure | Hosting |
| Google Calendar | Event and calendar data | Check availability and schedule meetings automatically |
| Gmail | Recipient, subject, and content of the email to be sent; not mailbox content | Send emails requested by a configured action |
| Outlook Mail | Recipient, subject, and content of the email to be sent; not mailbox content | Send emails requested by a configured action |
| Retell AI | Call audio and transcripts | Process and store AI agent voice calls |
We do not sell, rent, or share data with third parties for marketing or advertising purposes.
8. Business Owner Rights
As a business owner using the platform, you have the right to:
- Access: Request a copy of all your stored data.
- Rectification: Correct inaccurate data.
- Deletion: Request deletion of your account and all associated data.
- Portability: Receive your data in a structured format.
- Objection: Object to processing of your data for specific purposes.
To exercise any of these rights, email soporte@yudexlabs.com or contact us on WhatsApp.
9. End User Rights
End users (the business's customers who speak with the agent) may:
- Ask the business owner to delete their conversation history.
- Stop interacting with the agent at any time.
- Ask what data is stored by contacting the business owner.
The business owner is responsible for processing customer data. Yudex Labs acts as the data processor.
10. Data Retention
- Active account: Data is retained while the subscription is active.
- Canceled account (churned): Agent data (knowledge base and configuration) is retained for 90 days after cancellation to allow reactivation without data loss. After 90 days, it is deleted automatically.
- Requested deletion: Deletion is completed within 30 days of the request.
11. Cookies and Tracking Technologies
The Yudex Labs web dashboard uses only cookies that are strictly necessary to authenticate the business owner. We do not use advertising cookies, third-party analytics, or cross-site tracking.
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Keep the owner's session authenticated after signing in with OTP. | 1 hora |
| Renewal cookie | Renew the session automatically without requesting the OTP code again. | 30 días |
Both cookies are HttpOnly, Secure and SameSite=Lax. You can sign out from the dashboard at any time, which removes them from your browser.
11.1 Meta Data Deletion Callback
As an app connected to Meta's platform, Yudex Labs implements the Data Deletion Callback required by Meta. When a user requests deletion of their data through Facebook settings or Meta Business Manager, Meta automatically notifies our platform and we process the request within 30 days.
If you prefer to request deletion directly instead of going through Meta, email soporte@yudexlabs.com with the subject "Data deletion request" from the email address associated with your account. You will receive a confirmation code and be able to check the status of your request.
12. Children's Privacy
Yudex Labs is not directed at children under 18. We do not knowingly collect children's data. If we discover that information from a child has been collected, we will delete it.
13. International Transfers
Data may be processed on servers located outside Colombia, including those of our storage, communication, and artificial intelligence service providers. These transfers take place under each provider's terms of service, data processing agreements, and applicable legal mechanisms.
14. Changes to This Policy
We reserve the right to update this policy. Significant changes will be notified to registered business owners through WhatsApp or email at least 15 days in advance.
15. Contact
For privacy questions:
- Email: soporte@yudexlabs.com
- WhatsApp: Write to the Yudex Labs number
- Address: Colombia
This policy complies with Law 1581 of 2012 (Colombia) and its regulatory decrees, as well as the requirements of the WhatsApp Business Policy and Meta Platform Terms.