Legal

Privacy Policy

Last updated:

1. Who we are

CloudAIAgents (“CloudAIAgents”, “we”, “our”, “us”) is a product of VIET PICKLEBALL JOINT STOCK COMPANY, registered in Vietnam (tax ID 0318567827). Our registered office is at: 606/4/5C Quoc Lo 13, Hiep Binh Ward, Ho Chi Minh City, Vietnam. We act as the data controller for personal data processed through our service, except where you connect a third-party platform (e.g. Meta) — in which case data we receive from that platform is processed under our agreement with you and the applicable platform terms.

Contact for privacy matters: privacy@cloudaiagents.net. Data Protection Officer: dpo@cloudaiagents.net.

2. Scope

This Privacy Policy applies to cloudaiagents.net, all subdomains, the CloudAIAgents web application, and any integration we provide with Meta Platforms (Facebook Pages, Instagram Business and Threads). By using CloudAIAgents, you agree to this policy.

3. Data we collect

3.1 Data you give us directly

  • Account data: name, work email, password hash (bcrypt), workspace name, company size, optional phone number.
  • Billing data: processed by Stripe; we store only the last four digits of the card and the country of issuance.
  • Support communications: the content of emails, chats and tickets you send us.

3.2 Data we receive from Meta when you connect your accounts

When you authenticate with Facebook through the Login dialog, you authorise us to access only the scopes shown in the consent screen. We list every Meta permission we request and the precise feature it powers below — and we never ask for a scope that does not map to a user-visible feature.

Meta permissionData we obtainWhy we need it
public_profile, emailYour name, profile picture, email addressIdentify your CloudAIAgents user account.
pages_show_listList of Pages you manage (id, name, category)Render the page picker so you choose what to connect.
pages_manage_metadataPage metadata, ability to subscribe webhooksSubscribe the Page to inbox/comment webhooks for the Reply Agent.
pages_read_engagementComments, reactions, mentions on your PagesLet the Reply Agent see and triage incoming engagement.
pages_manage_engagementAbility to like, reply, hide, delete commentsPost replies and hide spam — only when you have explicitly enabled it.
pages_manage_postsAbility to publish on the PagePublish drafts that you have approved through the Content Agent.
pages_messagingMessages sent to your Page in MessengerLet the Reply Agent answer conversations the user has opened.
read_insightsAggregated Page insightsPower the Insight Agent’s weekly performance digest.
instagram_basicIG Business account profile (id, username, media)Display your IG account inside CloudAIAgents.
instagram_manage_commentsComments on your IG mediaTriage and respond to IG comments via the Reply Agent.
instagram_manage_messagesIG Direct messagesReply to opened IG Direct threads via the Reply Agent.
instagram_manage_insightsIG media and account insightsInclude IG metrics in the weekly digest.
instagram_content_publishAbility to publish media to IG BusinessPublish drafts you have approved.
threads_basic, threads_content_publish, threads_manage_replies, threads_read_repliesThreads profile, posts and repliesPublish to Threads and let the Reply Agent answer replies you receive.
business_managementList of businesses you belong to and their assetsRequired for agency accounts that manage multiple businesses from one CloudAIAgents workspace.

3.3 Data we collect automatically

  • Technical logs: IP address, browser user agent, timestamps. Retained 30 days for security and abuse prevention.
  • Product analytics: page views, feature usage. We use PostHog (self-hosted in Singapore). We do not sell or transfer this data.

4. How we use your data

  • Provide the CloudAIAgents service and its AI Agents (Reply, Content, Insight, Compliance).
  • Run the specific feature for which a Meta permission was granted — and nothing else.
  • Bill you for paid plans and handle support requests.
  • Detect abuse, prevent fraud and meet legal obligations.
  • Send transactional emails (login codes, billing receipts, digest reports). Marketing emails are sent only with separate opt-in and can be disabled at any time.

We do not sell your personal data. We do not use data obtained from Meta to build user-level advertising profiles or to train foundation models outside the page-specific context the user has explicitly enabled.

5. AI processing

The Reply Agent and Content Agent rely on large language models hosted by Anthropic (Claude) and, optionally, by you through Bring-Your-Own-Key. Prompts that contain message content are sent over TLS to the LLM provider. Anthropic does not use API inputs to train its models per its API terms. Anthropic retains API inputs for up to 30 days for trust and safety. You can disable AI processing entirely per workspace; in that case CloudAIAgents operates only as a scheduler/inbox.

6. Legal bases (GDPR)

  • Contract performance — for delivering the service you signed up for.
  • Consent — for connecting Meta accounts, optional marketing emails, optional analytics cookies.
  • Legitimate interests — for security logs, fraud detection, product improvement.
  • Legal obligation — for tax records and lawful requests.

7. Sharing

We share data only with the subprocessors strictly necessary to run the service:

ProviderPurposeLocation
Amazon Web ServicesApplication + database hosting (encrypted at rest)Singapore (ap-southeast-1)
AnthropicLLM inference for AI AgentsUnited States
StripePayment processingUnited States / EU
ResendTransactional email deliveryUnited States
PostHog (self-hosted)Product analyticsSingapore
SentryError monitoringEuropean Union

We do not share, sell or rent your personal data to advertisers, data brokers or any other third party. Where data leaves your region, we rely on EU Standard Contractual Clauses or equivalent mechanisms.

8. Retention

  • Account data: kept while your account is active.
  • Meta access tokens: stored encrypted; deleted within 24 hours after you disconnect a page or your Deauthorize callback fires.
  • Message content cache: kept up to 90 days, then purged. You can shorten the window to 7 days in workspace settings.
  • Audit logs: kept 18 months for security and compliance.
  • Backups: 30-day rolling encrypted backups; deleted data fully expires within 35 days.

9. Security

  • TLS 1.2+ everywhere; HSTS enabled.
  • Meta access tokens encrypted with AES-256-GCM using keys in AWS KMS.
  • Database encrypted at rest; least-privilege IAM; SOC 2 Type II in progress (target 2026 Q4).
  • Mandatory 2FA for all CloudAIAgents employees with production access.
  • Quarterly third-party penetration tests; in-scope vulnerabilities are disclosed at /security.

10. Your rights

Subject to applicable law, you can:

  • Access and export your data.
  • Correct inaccurate data.
  • Delete your data — via the self-service flow at /data-deletion or by emailing privacy@cloudaiagents.net. Deletion completes within 30 days and is reflected in our backups within 35 days.
  • Withdraw consent at any time (e.g. disconnect a Meta account, opt out of analytics).
  • Lodge a complaint with your local data protection authority.

11. International users

CloudAIAgents serves customers globally. By using the service, you understand that your data may be processed in Singapore and other jurisdictions where our subprocessors operate, under equivalent or stronger protections via Standard Contractual Clauses.

12. Children

CloudAIAgents is a B2B product not directed at children under 16. We do not knowingly collect data from minors. If you believe we have, contact us and we will remove it.

13. Changes

We may update this policy. Material changes will be announced in-product and by email at least 14 days before they take effect. The “Last updated” date above always reflects the current version.

14. Contact

VIET PICKLEBALL JOINT STOCK COMPANY
606/4/5C Quoc Lo 13, Hiep Binh Ward, Ho Chi Minh City, Vietnam
Tax ID: 0318567827
Email: privacy@cloudaiagents.net
DPO: dpo@cloudaiagents.net