Legal
Privacy Policyv1.0
Last updated 3 June 2026 (v1.0)
BentoKit Concierge ("the Service") is an AI customer-support assistant operated by RioBlocks ("we", "us"). This policy explains what personal data we process, why, and the choices you have. It applies to concierge.bentokit.ai and to the support assistant our business customers embed on their websites and connect to messaging channels such as WhatsApp.
- Our role
- Data we process
- WhatsApp data
- How we use it
- Legal bases
- Sharing
- Retention
- Your rights
- Security
- Contact
1. Our role (controller vs. processor)
We act as a data controller for data about our direct business customers (the businesses that subscribe to the Service) and visitors to concierge.bentokit.ai. When a business customer uses the Service to talk with their end customers β for example through a website chat widget or a connected WhatsApp Business number β that business is the controller of those conversations and we act as their data processor, handling the data on their behalf and under their instructions.
2. Data we process
- Account data β name, work email, business name, and login credentials of the people who administer a workspace.
- Billing data β subscription plan and payment status. Card payments are processed by our payment provider; we do not store full card numbers.
- Knowledge-base content β the product, policy, and support material a business customer provides so the assistant can answer questions.
- Conversation data β messages exchanged between an end customer and the assistant (website widget or connected messaging channels), including message text, timestamps, and any images or voice notes the user sends.
- Contact / lead data β contact details a visitor chooses to share to be connected with a human (e.g. name, email, phone).
- Technical data β IP address, device/browser information, and basic usage logs used to operate the Service, prevent abuse, and apply rate limits.
3. WhatsApp Business Platform data
When a business customer connects a WhatsApp Business number, we use the WhatsApp Business Platform (the WhatsApp Cloud API provided by Meta) to send and receive messages on that business's behalf. In that flow we process the end customer's WhatsApp phone number, WhatsApp profile name, and message content (text, images, and voice notes) solely to deliver the business's support conversation and any human-handoff the user requests.
Meta Platforms processes this data as part of operating WhatsApp; its handling is governed by Meta's and WhatsApp's own terms and privacy policies. We do not use WhatsApp message content for advertising, and we do not sell it. Use of information received from the WhatsApp Business Platform follows Meta's Platform requirements.
4. How we use data
- To operate the assistant and generate answers from the business customer's approved knowledge base.
- To route conversations, capture human-handoff requests, and notify the business.
- To provide, secure, and improve the Service, prevent abuse, and enforce usage limits.
- To manage subscriptions and billing.
- To comply with legal obligations.
To generate answers we send the relevant conversation text and knowledge-base context to large-language-model providers acting as our processors. We do not permit those providers to use this data to train their general models.
5. Legal bases
Where the LGPD (Brazil) or GDPR (EU/UK) applies, we rely on: performance of a contract (to provide the Service), legitimate interests (to secure and improve the Service and prevent abuse), consent (where required, e.g. for certain messaging), and compliance with legal obligations.
6. Who we share data with
We share data only with service providers ("sub-processors") that help us run the Service, under contract and only as needed:
- Meta Platforms β WhatsApp Business Platform message delivery.
- Large-language-model providers β to generate assistant responses.
- Payment processor β subscription billing.
- Hosting / infrastructure providers β to run the Service.
We do not sell personal data. We may disclose data if required by law or to protect rights, safety, and the integrity of the Service. Some providers may process data outside your country; where required we use appropriate safeguards for international transfers.
7. Data retention
We keep personal data only as long as needed for the purposes above or as required by law. Conversation and contact data are retained for the duration of the business customer's subscription and then deleted or anonymised within a reasonable period, unless a longer period is legally required. A business customer or end user can request earlier deletion (see Data deletion).
8. Your rights
Subject to applicable law, you may request access to, correction of, deletion of, or a copy of your personal data, and you may object to or restrict certain processing or withdraw consent. To exercise these rights, contact us at privacy@bentokit.ai. If you are an end customer of one of our business customers, we may direct your request to that business as the controller. You also have the right to lodge a complaint with your data-protection authority (in Brazil, the ANPD).
9. Security
We use technical and organisational measures β including encryption in transit, access controls, and secret management β to protect personal data. No method of transmission or storage is completely secure, but we work to protect your information and review our practices regularly.
Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children.
Changes to this policy
We may update this policy from time to time. We will post the new version here with an updated version number and date. Continued use after a material change may require re-acceptance in the product.
10. Contact
BentoKit Concierge is operated by RioBlocks. For privacy questions or to exercise your rights, contact privacy@bentokit.ai.
See also our Terms of Service (v2.2) and Data deletion instructions.