Telp privacy and data

Privacy Policy

This policy explains what data we process, why we process it, who receives it, how long we keep it and the rights available when you use Telp.

Last updated: September 9, 2026

Who we are and our roles

Telp is an Artifision product. The service provider is Artifision, a sole proprietor registered in Serbia. Registration number: 68411556. Tax ID: 115497218. Registered address: Cara Lazara 42, sprat 3, stan 26, 32102 Čačak, Srbija. Privacy contact: [email protected].

Artifision is the controller for data processed for the Telp website, accounts, sales, support, security and platform administration. When a user or organization connects a channel and uses Telp for conversations with its customers, that user or organization normally determines the purpose and legal basis, while Artifision processes data on their behalf as a processor under the agreement and instructions.

Data we process

  • Account and customer data: name, email and phone number, company name where applicable, role, language, settings, permissions, authentication data and billing contact details.
  • Conversation and CRM data: messages, attachments, images, voice messages, contacts, lead data, summaries, statuses, handoff notes, operator replies and activity history.
  • Voice calls: status, duration, participants, technical events, transcripts when requested and recordings where recording is enabled, permitted and the caller has received the required notice or provided consent.
  • AI and automation data: agent instructions, assigned knowledge, knowledge-search queries, tool calls, structured input and output, confirmation cards, webhook results, errors, audit records and usage data.
  • Billing and subscription data: Paddle customer and transaction identifiers, selected plan, subscription and payment status, currency, amount, tax, invoice number, billing dates, refund or adjustment status and data needed for transaction support and reconciliation.
  • Technical and security data: IP address, browser, device, URL, request time, logs, rate-limit data, security events, session and CSRF data.

Paddle payments

For self-service online purchases, Paddle acts as Merchant of Record and separately processes data required for checkout, payment collection, tax, fraud prevention, payment documents, the customer portal and refunds. Paddle may collect name, email, billing address, tax information, payment-method details, device data and other transaction data under its own privacy notice.

Telp receives limited customer, subscription, transaction, invoice, tax and payment-status data from Paddle to activate the plan, display billing history, provide support and reconcile a refund or dispute. Telp does not receive or store the complete payment-card number or its security code.

Paddle Privacy Notice

Facebook, Messenger, Instagram and WhatsApp

When a business connects a Meta channel, we may process the Facebook Page ID and name, Page tasks and permissions, Instagram professional account ID, app-scoped ID, username and account type, WhatsApp Business Account ID, phone number ID, display number and business name, together with connection and webhook subscription status.

For messages, we may receive app-scoped sender and recipient identifiers, content, timestamp, message ID, replies, reactions, attachments or media IDs. We use this data to route the event to the correct tenant and conversation, display it in the inbox and send a response through the same channel.

OAuth and Page/WhatsApp access tokens are used server-side only to connect accounts, verify subscriptions and send messages. They are stored encrypted and are not sent to the widget, an operator browser or the AI model. Meta also processes data under its own terms and privacy policy.

Purchases in a connected Shopify store

When a business enables purchases through its connected store, Telp prepares a cart from the confirmed product selection. The customer confirms delivery, the final total and payment in the store. This flow does not collect payment-card numbers or security codes in Telp.

For customer service, we retain the verified order reference, purchased items, total, currency and payment status at confirmation. We use an available phone number to associate the purchase with a contact; if no phone is available, we use an available email. When first and last name are available from the shipping address, we use them as the CRM contact name and record their source because they may belong to the package recipient. This flow does not retrieve the full shipping address or customer profile.

Temporary checkout links and purchase-checking data are stored encrypted for at most 24 hours after preparation. Tracking then stops. Confirmed purchases remain with their conversation under the conversation retention rules. Purchase status and results may form part of AI response context; checkout secrets and the separate buyer-data snapshot are excluded from model-facing tool results.

Access and deletion requests are scoped to the store and the source of each data copy, including purchase records, derived copies and related notes. Independent data from other connected channels or stores is preserved. Authorized business users can download a prepared export to respond to the customer request.

Sources of data

  • Directly from you when you create an account, complete a form, send a message or attachment, or participate in a call.
  • From the business using Telp and its authorized users, agents, knowledge, tools and connected systems.
  • From connected channels and providers, including Paddle, Meta, Telegram, AI providers, audio infrastructure, email, CRMs, webhooks and automation services.
  • Automatically through security, audit, billing and technical logs generated while the service operates.

Why we use data

  • To provide accounts, connect channels, receive and send messages and operate a unified inbox.
  • To let an AI agent respond, search assigned knowledge, use approved tools and hand a conversation to an operator.
  • To execute confirmed business actions and connect Telp to systems selected by the business.
  • To retain recordings and operational records where configured, permitted and necessary.
  • To maintain tenant isolation, prevent abuse, troubleshoot errors, measure usage and improve reliability.
  • To manage plans, subscriptions, transactions, customer-portal access, payment support, refund requests and reconciliation with Paddle records.
  • To meet contractual, accounting, tax, security and other legal obligations.

AI processing and automated decisions

Relevant conversation context, instructions, knowledge-search results and approved tool definitions may be sent to the selected AI provider to generate a response or tool call. Secret keys and technical credentials are not part of the AI prompt.

Telp should not be used for decisions producing legal or similarly significant effects without appropriate human review. The business using Telp decides when an operator, validation or written action confirmation is required.

Cookies and similar technologies

Telp uses necessary session, authentication and CSRF cookies, including the Telp session and XSRF token, so sign-in, forms and request protection work. Hosting and security providers such as Cloudflare may set necessary cookies to prevent abuse and maintain the service.

The conversation widget uses browser local storage so a visitor can continue an active conversation. When a visitor starts a conversation, the business using Telp may receive allowed campaign tags, the landing page and the external referral source. Telp removes other query parameters and fragments from that context before it is stored.

We currently do not use advertising or cross-site tracking cookies on the public legal pages. If we introduce analytics or marketing technology that requires consent, we will update this policy and present the appropriate choice before activating it.

Recipients and international transfers

We may share data with the user or organization using Telp and its authorized members, and with Paddle and hosting, database, storage, security, email, AI, voice transport, communication-channel and automation providers where required to provide the service. Data is also sent to systems explicitly connected by the user, such as a CRM, help desk, Make, n8n or a webhook.

Some recipients may process data outside Serbia or the European Economic Area. Where required, we use contractual and other available safeguards and limit transfers to data needed for the relevant function. We may disclose data to competent authorities where legally required.

Retention periods

  • Meta and other channel credentials are stored encrypted while a channel is connected and are removed during deauthorization, disconnection or channel deletion.
  • Call recordings have an expiry date based on channel or tenant settings. The default period is up to 90 days unless configured or agreed otherwise. After expiry, the recording is deleted from storage and the recording register.
  • Conversations, messages, attachments, tool calls and audit data are kept while needed for an active account, contracted service, support, security or record keeping. An authorized user may delete a conversation, which also deletes its stored recordings and attachments.
  • Billing, tax, security and dispute records are kept for the period required by law or a legitimate business need. Residual backup copies expire through the normal backup rotation and are not used for active processing.

Your rights

Where applicable, you may request access, correction, deletion, restriction, portability or object to processing and withdraw consent. Email [email protected] and include the channel, approximate date and information needed to locate the record and verify identity. We respond without undue delay, normally within 30 days where that deadline applies.

If the business using Telp is the controller, we will forward the request or assist that business. You may lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection in Serbia through poverenik.rs, or another competent supervisory authority.

Security

We use access controls, tenant isolation, encryption of sensitive channel tokens, server-side secrets, audit records, HTTPS and permission limits. No internet service is free of all risk, but we regularly review measures appropriate to the data and platform functions.

Children

Telp is a business platform and is not directed to children. If you believe a child's data was processed without an appropriate basis, contact us so we can investigate and act.

Changes and contact

The current version is published on this page with its revision date. We will provide notice through the service or another appropriate channel for material changes where required.

For questions, rights requests or deletion requests, email [email protected]. Controller: Artifision, Cara Lazara 42, sprat 3, stan 26, 32102 Čačak, Srbija.