Privacy Policy
Last updated: 17 September 2026
1. Who we are
AgentoGoPlus (the “Service”) is operated by AgentoGoPlus, a sole proprietorship registered in Thailand under commercial registration number [COMMERCIAL REGISTRATION NUMBER] (“we”, “us”). The Service lets a business build an AI assistant from its own documents, website content, and FAQs, and connect that assistant to messaging channels such as Facebook Messenger and LINE.
This policy explains what personal information we handle, why, who we share it with, how long we keep it, and how to have it deleted.
2. Two different roles
The Service handles two kinds of personal information, and our responsibilities differ for each:
- Business users. When someone signs up and administers a workspace, we act as the controller of their account information and decide how it is used, as described below.
- End users of a connected channel. When a member of the public messages a business’s Facebook Page or LINE account, we process that conversation as a processor on behalf of that business. The business is the controller and its own privacy policy governs the exchange. Requests about that data should go to the business, though we will assist it in responding.
3. Information we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account information | Name, email address, and the provider account identifier for the login method used. | You, or the identity provider you sign in with (Facebook, LINE). |
| Workspace content | Documents you upload, website addresses you ask us to read, FAQs, announcements, business details, and assistant configuration. This may contain personal information if you choose to include it. | You. |
| Channel connection data | The identifier and name of the Facebook Page or LINE account you connect, and the access token that authorises us to send and receive messages for it. | Facebook or LINE, when you authorise the connection. |
| Conversation data | Messages sent to a connected Page or account, the platform-assigned sender identifier, timestamps, and the replies the assistant generates. | The messaging platform, when an end user contacts the business. |
| Technical and log data | IP address, browser and device information, and records of errors and system events. | Automatically, when the Service is used. |
We do not knowingly collect special categories of personal data (such as health, biometric, or political data), and you should not upload such data to a workspace.
4. Information obtained through Facebook and Meta
We use Meta’s platform in two separate ways, through two separate Meta applications. Signing in with Facebook and connecting a Facebook Page are independent authorisations, and granting one does not grant the other:
| Meta app | Permission | Why we request it |
|---|---|---|
| Sign-in app | public_profile, email | To create and sign you in to your AgentoGoPlus account when you choose Facebook as your login method. |
| Messenger app | pages_show_list | To show you the list of Facebook Pages you administer so you can choose which one to connect. |
| Messenger app | pages_messaging | To receive messages sent to the connected Page and to send the assistant's replies. |
| Messenger app | pages_manage_metadata | To subscribe the connected Page to our message webhook, and to unsubscribe it when you disconnect. |
The two apps hold separate authorisations and separate tokens. Removing one from your Facebook account does not remove the other — see section 8.
We do not publish posts, comments, or any other content to your Page. We do not access your advertising accounts, friend lists, photos, or any Page data beyond what is listed above. We do not sell personal information, and we do not use data obtained through Meta’s platform for advertising or for training general-purpose AI models.
5. How we use information
- To create and secure your account and authenticate you.
- To process your workspace content into the knowledge base the assistant answers from.
- To receive messages from connected channels and generate and deliver replies grounded in that workspace’s content.
- To operate, monitor, debug, and secure the Service, and to prevent abuse.
- To respond to your support requests and to meet our legal obligations.
Where the law requires a legal basis, we rely on performance of our contract with you, our legitimate interest in operating and securing the Service, your consent where you have given it (for example, when authorising a channel connection), and compliance with legal obligations.
7. How long we keep information
- Conversation context used to keep a chat coherent is short-lived and expires automatically within hours of the exchange.
- Channel access tokens are held in encrypted form only while the channel is connected, and are deleted when you disconnect it.
- Workspace content and account data are kept until you delete them or close your account, after which they are removed from live systems promptly and from backups within 30 days.
- Logs are retained for a limited period for security and troubleshooting.
8. Deleting your data
You can remove data yourself at any time:
- Disconnect a channel. In the Service, open Connect and choose Disconnect. This deletes the access token we hold and unsubscribes our app from your Page, so we stop receiving its messages. It does not by itself withdraw the authorisation you gave at Facebook, which you can remove separately as described below.
- Delete or clear workspace content. Documents, website sources, and FAQs can each be deleted from their pages in the Service. Announcements can be cleared or switched off.
- Revoke access from Facebook. Go to Facebook Settings → Settings & Privacy → Settings → Apps and Websites and remove our app. We use two Meta apps — one for signing in and one for Messenger — so remove both if you want to withdraw both authorisations.
To close your account and have all associated data deleted, email [email protected] from the address on your account with the subject “Data deletion request”. We will confirm within 30 days. If you are an end user who messaged a business’s Page, contact that business, or write to us and we will forward your request to them.
9. Security
Traffic is encrypted in transit with TLS. Channel credentials are encrypted at rest with authenticated encryption, and each workspace’s data is isolated so that one customer cannot read another’s. Access to production systems and the credentials protecting them is restricted to authorised people who need it to operate and support the Service. No system is perfectly secure, and we cannot guarantee absolute security.
10. International transfers
We and our service providers may process information in countries other than your own. Where personal data is transferred out of a jurisdiction that restricts such transfers, we rely on appropriate safeguards, such as standard contractual clauses.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us at [email protected]. You may also have the right to complain to your local data protection authority.
12. Children
The Service is intended for businesses and is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect their personal information; if we learn we have, we will delete it.
14. Changes to this policy
We may update this policy from time to time. The date at the top shows when it last changed, and we will notify you of material changes through the Service or by email.
15. Contact us
AgentoGoPlus — sole proprietorship, commercial registration no. [COMMERCIAL REGISTRATION NUMBER]
[email protected]
Support is available by email. We do not guarantee support response times. Requests that carry a legal deadline, such as deletion requests, are answered within the period stated in section 8.