Privacy Policy
Justo AI Concierge Platform
1. Introduction
Justo (operated by Justo LLC, "Company", "we", "us", or "our") provides an AI-powered concierge platform for hotels that automates guest communication via Instagram Direct Messages, WhatsApp Business messages, and website chat widgets. This Privacy Policy explains how we collect, use, store, share, and protect personal data when hotels and their guests use our platform at ai.justo.ua.
By using the Justo platform, you agree to the collection and processing of information as described in this Policy. If you do not agree, please discontinue use of the service.
This Policy applies to: (1) hotel businesses ("Clients") who connect their Instagram accounts, WhatsApp Business numbers, or website widgets and use the Justo admin panel, and (2) end users ("Guests") who interact with the AI agent via Instagram DM, WhatsApp, or the website chat widget.
How the assistant identifies itself, generates answers, communicates limitations, and hands conversations to hotel staff is described in our AI Transparency Notice.
2. Data We Collect
2.1 From Hotel Clients (business users)
- Name, email address, and contact information provided during registration
- Instagram Business account ID and WhatsApp Business Account / phone number IDs used during authorization and setup
- Meta access tokens required to receive and send Instagram or WhatsApp messages for the connected hotel account — stored encrypted
- Hotel knowledge base content: hotel name, address, check-in/out times, services, pricing, FAQs entered into the admin panel
- Billing information (if applicable for subscription management)
- Usage data: login activity, admin panel interactions, chat history accessed
2.2 From Guests (end users messaging the hotel)
- Instagram username and user ID, or WhatsApp wa_id / phone identifier, provided automatically by Meta when a message is received
- Content of Direct Messages or WhatsApp messages sent to the hotel's connected business account
- Timestamp and message metadata provided by the Instagram or WhatsApp API
- For website widget users: anonymous session ID stored in localStorage, message content, timestamp
- We do not collect: real names, phone numbers, email addresses, or any financial information from guests unless the guest voluntarily provides this in their message
2.3 Automatically collected technical data
- IP address, browser type, device type, access timestamps (for admin panel users)
- Server logs and error logs for security monitoring and debugging
- Cookies used for session management in the admin panel (functional cookies only)
3. How We Use the Data
3.1 To provide the service
- Receive Instagram DMs or WhatsApp messages and route them to the correct hotel account via webhook
- Process guest messages using AI (LLM API) to generate responses
- Send AI-generated or manager replies back to guests via the Meta Messaging API or WhatsApp Cloud API
- Display conversation history in the hotel manager's admin panel
- Enable hotel managers to take over conversations and hand back to the AI agent
3.2 To maintain and improve the service
- Monitor system performance, detect errors, and resolve technical issues
- Analyze aggregated, anonymized usage patterns to improve the platform
- Develop new features based on client feedback
3.3 To ensure security and prevent fraud
- Detect and prevent unauthorized access to hotel accounts
- Monitor for abuse of the AI agent (spam, harmful content)
- Verify identity of users accessing the admin panel
3.4 To comply with legal obligations
- Respond to lawful requests from government or regulatory authorities
- Maintain records as required by applicable Ukrainian and EU law
4. Data Sharing and Third Parties
We do not sell your personal data. We do not share data with third parties for advertising purposes. Data is shared only as necessary to operate the service:
| Third Party | Purpose and Data Shared |
|---|---|
| Meta Platforms (Facebook/Instagram/WhatsApp) | We receive and send messages via the Instagram Messaging API, Facebook Messenger Platform, and WhatsApp Cloud API. Guest message content and hotel Meta access tokens are transmitted over encrypted connections. Meta processes this data under their own Privacy Policy. |
| LLM API Provider (Anthropic Claude or OpenAI GPT) | Guest message text is sent to the AI provider's API to generate a response. Only message content is sent — no personal identifiers (name, email) unless included in the guest's message. The AI provider processes this under their API data policy and does not use it to train models. |
| Cloud Infrastructure Provider | Our servers and database are hosted on cloud infrastructure (EU or Ukraine region). The provider has access to encrypted server data only for operational purposes. |
| Telegram (optional) | If the hotel enables Telegram notifications, manager alert messages are sent via Telegram Bot API. Only a notification text is transmitted — no guest message content. |
| Law enforcement / Government | We will disclose data only when required by law, court order, or lawful government request, and only to the extent required. |
5. Meta Platform Data — Specific Disclosure
Justo integrates with the Instagram Messaging API, Facebook Messenger Platform, and WhatsApp Cloud API via registered Meta application settings. The following applies specifically to data received through Meta:
- We receive Instagram DM, Facebook Messenger Page, and WhatsApp Business message data via webhook notifications from Meta after the hotel client authorizes or connects the relevant account
- We store Meta access tokens in encrypted form in our database. These tokens are used solely to receive messages and send responses on behalf of the hotel's connected Instagram account, Facebook Page, or WhatsApp Business number
- We do not access any data beyond what is required by the permissions granted: instagram_business_basic, instagram_business_manage_messages, whatsapp_business_management, whatsapp_business_messaging, pages_messaging, pages_manage_metadata, pages_show_list, and pages_read_engagement
- We do not access Instagram content, media, followers, WhatsApp catalogs, marketing lists, Facebook Page publishing, comments, insights, ads, or any data beyond guest messaging and the account/page/phone-number metadata needed to route messages to the hotel's inbox
- When a hotel client disconnects their Instagram, Facebook Page, or WhatsApp account from Justo, we delete their Meta access token and unsubscribe from webhook notifications within 24 hours
- Guest Instagram usernames, Facebook Messenger PSIDs, WhatsApp wa_id / phone identifiers, and message content are stored for the duration of the hotel's active subscription and deleted upon account termination
Data Deletion: Hotel clients may request deletion of all data associated with their account by contacting info@justo.com.ua. Justo also provides a data deletion callback URL at https://ai.justo.ua/meta/data-deletion for Meta's automated deletion requests.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Hotel account data (name, email, settings) | Duration of active subscription + 30 days after termination |
| Meta access tokens | Duration of active Instagram, Facebook Page, or WhatsApp connection; deleted immediately upon disconnection |
| Guest message history (Instagram DMs, Facebook Messenger Page messages, and WhatsApp messages) | Duration of active hotel subscription; deleted upon account termination |
| Website widget chat sessions | 90 days from last interaction, then anonymized |
| Server logs and technical data | 90 days for operational logs; security incident logs up to 1 year |
| Backup data | Maximum 30 days in encrypted backups after deletion from primary database |
7. Data Security
- All data is transmitted over encrypted HTTPS/TLS connections
- Meta access tokens are stored encrypted at rest using industry-standard encryption
- Admin panel access is protected by authentication and session management
- Database access is restricted to authorized personnel only
- We conduct regular security reviews and vulnerability assessments
- In the event of a data breach affecting personal data, we will notify affected clients within 72 hours as required by applicable law
8. Your Rights
As a user of the Justo platform — whether a hotel client or an end guest — you have the following rights regarding your personal data:
- Right of access: request a copy of personal data we hold about you
- Right to rectification: request correction of inaccurate data
- Right to erasure: request deletion of your personal data ("right to be forgotten")
- Right to restriction: request that we limit processing of your data
- Right to object: object to processing based on legitimate interest
- Right to withdraw consent: withdraw consent at any time (does not affect lawfulness of prior processing)
- Right to data portability: receive your data in a structured, machine-readable format
To exercise any of these rights, contact us at info@justo.com.ua. We will respond within 30 days. We may ask you to verify your identity before processing the request.
Hotel guests who wish to request deletion of their Instagram or WhatsApp message data should contact the hotel directly, or contact us at info@justo.com.ua with the hotel name and their Instagram username or WhatsApp phone identifier.
9. Cookies
The Justo admin panel (ai.justo.ua) uses functional cookies only for session management (keeping you logged in). We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
The website chat widget uses localStorage (not cookies) to maintain an anonymous session ID for the duration of the chat. No personally identifiable information is stored in localStorage.
See the separate Cookie Policy for browser-storage details and user controls.
10. Children's Privacy
The Justo platform is a business-to-business service intended for hotel operators and their adult guests. We do not knowingly collect personal data from children under 13. If we become aware that a child under 13 has provided personal data, we will delete it promptly. Please contact info@justo.com.ua if you have concerns.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this document. For material changes, we will notify hotel clients via email to the address registered in their account. Continued use of the platform after changes take effect constitutes acceptance of the updated Policy.
12. Contact
For any questions about this Privacy Policy, data requests, or concerns about how we handle your data:
Email: info@justo.com.ua
Platform: ai.justo.ua
Company: Justo LLC, Kyiv, Ukraine
Data Deletion Callback: https://ai.justo.ua/meta/data-deletion
Justo Privacy Policy | Version 1.2 | July 2026 | English