Legal
Privacy Policy
What Oleon Workspace collects, why it holds it, and who else touches it. Written to be read rather than to be survived.
Who this policy is from
Oleon Workspace is made and operated by Olee AI in Sri Lanka. This policy covers the workspace, the mobile app, the marketing pages you are reading now, and the interfaces that connect the product to WhatsApp, Instagram, Messenger, Telegram and the web.
It does not cover the channels themselves. What Meta does with a WhatsApp message on its own servers is governed by Meta's policies, not by this one, and the same is true of Telegram. Where the product hands data to somebody else, that handover is named in this document.
The two roles we play
Almost every question about this product has a different answer depending on whose data is being asked about, so the distinction comes first.
- Your account, where we decide
- The organisation, the projects, the people who sign in, the billing details and the record of what those people did. We chose to collect this, we decide how long it is kept, and we answer for it directly.
- Your conversations, where you decide
- The messages your business exchanges with its customers, the contacts behind them, and anything your team attaches to them. Your business decided to hold those conversations. We hold them on your instruction, act on your instruction, and delete them when you tell us to.
If you are a customer of a business that uses Oleon Workspace and you want your messages removed, that business is who to ask. We will act on their instruction, and we will help them carry it out, but we will not delete their records because a third party asked us to. There is a section at the end for you.
What we collect
- Account details
- Your name, email address, phone number and profile picture, the organisation and projects you belong to, your role in each, and your notification and appearance settings.
- Sign-in data
- A hashed password, your two-factor secret if you have turned it on, the sessions currently open and the devices they are open on, and the times you signed in and out.
- Conversation content
- Messages sent and received on your connected channels, in both directions, with their attachments: images, audio, video, documents and locations. Also the contact records behind them, the labels and notes your team adds, and the state of each conversation.
- Records of work
- Call logs, activity logs, reported conversations, the requests AI clients make through MCP, and the usage counters your invoice is calculated from. These exist so that a question about what happened has an answer.
- Billing details
- The billing name, address and email on your invoices, and the record of what was charged and when. Card numbers are entered on our payment provider's own pages and are never sent to us or stored by us. We hold a token that lets us charge the card again, not the card.
- Technical data
- IP address, browser and device, the pages you opened and when, and errors the application ran into. This is what makes an outage diagnosable and an intrusion visible.
- A device signature, once
- When a project starts a trial the browser is asked for a fingerprint. It is used for one thing, which is stopping the same device from taking the same free trial repeatedly, and it is not used to follow anyone around the product or the web.
What we use it for
- Running the product: delivering messages, showing the inbox, keeping it in step across your devices and holding it while you are offline.
- Answering on your behalf, where you have turned the agent on. What that involves is set out in the next section.
- Billing you: counting usage against your allowance, raising invoices, and taking the payment.
- Keeping the account safe: detecting unusual sign-ins, rate limiting, stopping abuse, and giving you the logs to check us with.
- Supporting you, which sometimes means a member of our team looking at a conversation you have asked us about.
- Meeting obligations we cannot opt out of, such as keeping financial records.
We do not sell personal data. We do not share it with advertisers, we do not build advertising profiles, and there is no third-party analytics or advertising script on any page of this product. That is a statement about the code as it stands, and it is checkable: the pages load no tracker.
How the agent uses message content
This is the part most worth reading closely, because it is the part where your conversations leave our servers.
When the agent is turned on for a project, the content of an incoming message, along with enough of the recent conversation to make sense of it, is sent to an AI model provider so a reply can be generated. Material you train the agent on is also sent, once, to be turned into a search index so the agent can find the right passage later.
- The work is done by a third-party model provider under contract, reached both directly and through a gateway that routes the request.
- This happens only for projects with the agent enabled. A project running a human inbox alone does not send message content to a model provider.
- A generated reply is a guess, and it can be wrong. You decide whether it sends, and you are responsible for what your business says.
- We do not use your conversations to train our own models, and we do not permit them to be used to train anyone else's.
How long we keep it
- Conversations
- Kept for as long as the project is open, because a support history is worth nothing if it stops at last quarter. You can export it at any time and you can ask us to delete it.
- Account data
- Kept while the account is open. When an organisation closes we remove its data within 90 days, other than what we are required to keep.
- Billing records
- Kept for as long as Sri Lankan tax and company law requires, which is longer than the account itself. This is the one category we cannot delete on request.
- Logs
- Activity, call and MCP logs are kept while the project is open. Technical and security logs are kept for a shorter period and then rotated away.
How it is protected
- Everything travels over TLS, between you and us and between us and every service named above.
- Sensitive fields, including conversation history and stored credentials, are encrypted with keys held separately from the data.
- Access inside the product is decided by role: what a person can see is what their role in that organisation allows, checked on the server on every request rather than hidden in the interface.
- Two-factor authentication is available on every account, and we recommend it for anyone who can see conversations.
- Administrative actions are logged, and the logs are visible to you rather than only to us.
No system is beyond reach, and a policy claiming otherwise is telling you something false. If a breach affects your data we will tell you, and we will tell you what we know rather than the least we can get away with.
Your rights
Under Sri Lanka's Personal Data Protection Act No. 9 of 2022 you can ask us to do the following with data we hold about you as an account holder.
- See what we hold, and get a copy of it.
- Correct it where it is wrong. Your name, phone number and picture you can change yourself in the product.
- Delete it, except where we are required to keep a record.
- Withdraw a consent you gave, which stops the processing that rested on it rather than what came before.
- Object to how we are using it, and have a person rather than a process consider the objection.
Write to the address at the foot of this page. We will answer within 30 days, and if we need longer we will say so and why before that period is out. There is no charge for a reasonable request.
If you messaged a business that uses Oleon
You may have arrived here from a business's WhatsApp or Instagram rather than as a customer of ours. If so, your conversation is held in that business's workspace, and it is that business, not us, who decides what happens to it.
Ask them first: they can find your conversation, export it and delete it themselves. If you cannot reach them, write to us and we will pass the request on and press for an answer. What we will not do is delete a business's records because somebody else asked us to, and you would not want us to for your own.
Children
Oleon Workspace is a tool for businesses and is not meant for anyone under 18. We do not knowingly collect a child's personal data as an account holder. If you believe a child has an account here, write to us and we will remove it.
Changes to this policy
This policy will change as the product does, and the date at the top is how you tell. Where a change materially affects your rights, such as a new recipient of your data, we will tell account holders by email before it takes effect rather than quietly reposting the page.
Contact
Questions about this policy, and any request to see, correct or delete your data, go here.
Oleon