Privacy Policy
Effective date: 2026-08-11 — version 2026-08-11
This Policy explains how Dialog Man (the “Service”), available at dialogman.org and through its official channel integrations, processes personal data.
1. Data we process
Depending on the features you use, we process:
- account and authentication data, such as your email address, account id, session and security metadata;
- Telegram and Instagram connection identifiers, provider account details, capabilities, and connection state;
- provider-native conversation events, including participants, messages, timestamps, edits, deletions, media and delivery metadata that the provider makes available to the connected account;
- CRM data you enter or import, including contacts, typed endpoints, tags, fields, saved segments and consent decisions;
- Automation definitions and revisions, Broadcast audiences and content, and sanitized execution, delivery and failure records;
- billing, subscription, referral and partner records required to provide paid features and account for payments;
- web-push subscription details when you explicitly enable browser notifications; and
- security and operational records needed to protect the Service and diagnose failures.
For protected Content Access, we process a verified phone endpoint, an opaque challenge identifier, protected verification material, attempt and expiry metadata, and the exact session, channel and conversation scope. The six-digit WhatsApp code expires after 5 minutes. A successful grant expires after 15 minutes. The raw code is not kept in browser storage or application logs.
2. Lawful bases (GDPR)
The applicable basis depends on the feature and context:
- performance of a contract (Art. 6(1)(b)) for account access, requested channel operations, security, delivery and paid features;
- consent (Art. 6(1)(a)) where the Service asks you to connect a channel, enable a notification endpoint or authorize a communication workflow;
- compliance with legal obligations (Art. 6(1)(c)) for records we must retain, including applicable accounting or payment records; and
- legitimate interests (Art. 6(1)(f)) for proportionate fraud prevention, service security and reliability, where those interests are not overridden by your rights.
You can withdraw a consent-based authorization by disabling the relevant connection or endpoint. Withdrawal does not affect processing already carried out lawfully and does not remove records that must be retained under another lawful basis.
3. Purposes
We process data to authenticate users; connect Telegram and Instagram; display provider-native timelines; send manual replies; maintain consent-aware CRM; publish and run deterministic Automations; deliver bounded User and System Broadcasts; provide billing and partner accounting; protect sensitive content with WhatsApp OTP; send enabled notifications; prevent abuse; and operate and secure the Service.
Dialog Man does not use this MVP to generate personal advice, infer hidden facts about a conversation, or recreate provider events it did not receive.
4. Sharing and providers
We do not sell personal data. We disclose data only as needed to operate a feature or meet a legal obligation, including to:
- Telegram and Meta/Instagram for connected-channel receipt and delivery;
- the configured WhatsApp provider for OTP and permitted outbound delivery;
- hosting, storage, monitoring and security subprocessors;
- payment providers for subscriptions and related records; and
- public authorities or professional advisers when disclosure is legally required.
Each third-party platform also processes data under its own terms and privacy notice. A current subprocessor list is available on request.
5. International transfers
Data may be processed outside the EEA or UK. Where required, we use an applicable transfer mechanism, such as the European Commission’s Standard Contractual Clauses or an equivalent safeguard.
6. Retention
Retention follows the data category and the purpose for which it is required:
- bounded raw provider transport records are retained for 7 days;
- notification records are scheduled for retention for up to 90 days;
- Content Access security audit records are scheduled for retention for up to 395 days;
- billing provider events and the legally required part of financial audit history may be retained for up to 2,555 days; and
- account, provider-native conversation, CRM, Automation and Broadcast records remain while the related account or connection is active or until an applicable deletion request is completed.
A shorter period applies where the feature no longer needs the data. A longer period may apply when required by law, dispute resolution, fraud prevention or an active legal/security hold. Backups expire under the applicable backup cycle and are not restored for ordinary product use after deletion.
7. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, objection or portability, withdraw consent, and lodge a complaint with a competent supervisory authority. To make a request, contact privacy@dialogman.com. We may need to verify your identity before acting on the request.
8. Children
The Service is not directed to children under 16. We do not knowingly process personal data from children under 16. Contact us if you believe this has occurred.
9. Changes
We may update this Policy. The current version and effective date are published at this URL. Where required, we will give additional notice or request renewed consent before a material change takes effect.
10. Contact
- Privacy and data requests: privacy@dialogman.com
- General legal questions: legal@dialogman.com