1. Scope
This Privacy Policy applies to Epkora’s websites, hosted applications, APIs, live-chat widget, WordPress connector, public help centres, communications, and related services (the “Service”). It covers personal information Epkora LLC processes as a controller and information it processes for business customers.
It does not govern a customer’s independent practices, a third-party website or service, or data processed entirely by a connected provider outside Epkora’s control. Our Terms of Service govern use of the Service.
2. Our privacy roles
When Epkora is a controller
Epkora determines the purposes and means of processing for account registration, workspace administration, authentication and security, product telemetry, website operations, direct support, legal compliance, and Epkora’s own business records. In these contexts, Epkora is the controller, business, or equivalent responsible organization.
When Epkora acts for a Customer
A Customer generally decides why and how personal information in its tickets, contacts, live-chat conversations, knowledge base, HR records, workflows, and connected mailboxes is used. For that Customer Data, Epkora generally acts as processor, service provider, or contractor under the Customer’s instructions. The Customer is responsible for its notices, legal bases, instructions, and responses to End Users.
The same person can appear in both contexts. For example, an employee’s account-security record is handled by Epkora for its own security purposes, while the employee profile entered by the employer is Customer Data.
3. Privacy at a glance
No advertising business model
We do not sell or rent personal information or use it for cross-context behavioral advertising.
Customer-controlled content
Customers decide what support, CRM, workforce, and knowledge data they place in their workspace.
Epkora-developed AI
AMI is Epkora’s proprietary AI model, developed by the Epkora Lab team. Only selected context is processed for supported requests, and people should review output before using it.
Global infrastructure
Service infrastructure may process data outside your country, including in the United States and China.
4. Information we process
| Category | Examples | Typical source |
|---|---|---|
| Account and identity | Name, work email, verified status, phone and country, avatar, job title, language, timezone, role, account status, workspace memberships, invitation state. | You, a workspace administrator, or an identity provider. |
| Authentication and security | Salted password hash, authentication method, OAuth identifiers, two-factor method and encrypted TOTP secret, hashed recovery credentials, sessions, trusted devices, login and security activity. | You, your browser/device, identity providers, and our security systems. |
| Company and workspace | Business name, contact details, website, industry, size, logo, postal address, plan, settings, roles, and permissions. | Workspace owners and administrators. |
| Support, CRM, and work records | Contacts, leads, tickets, message content, sender and recipient details, mailbox data, tasks, events, tags, comments, assignment, status, priority, service-level and workflow records. | Customers, Authorized Users, End Users, and connected mailboxes. |
| Live-chat data | Visitor display name, optional email, conversation and message content, page title and path, coarse browser/device/OS metadata, status, assignee, tags, read state, internal notes, and satisfaction rating. | End Users, the embedding website, and Authorized Users. |
| Knowledge and content | Articles, categories, FAQs, news, authorship, images and branding media, publication state, search terms, page views, article identifiers, referrer, hostname, and coarse country. | Customers, Authorized Users, and help-centre visitors. |
| Workforce and HR data | Employee name, email, phone, country, gender, date of birth, photo, department, designation, employment type, joining date, manager, work location, attendance, leave, schedules, announcements, and related audit records. | The Customer, administrators, managers, and employees. |
| Billing and usage | Plan and entitlement state, usage counters, billing name/company/email, invoice recipients, tax identifier, billing address, invoices and payment summaries such as brand and last four digits if a future payment flow supplies them. | Customers and, when enabled, a payment provider. Epkora does not currently operate online checkout. |
| AI interactions | AMI conversations, prompts, selected workspace or conversation context, model responses, generated drafts, and feedback. | Authorized Users and Customer Data selected for the feature. |
| Integration data | WordPress site URL/domain/name, plugin version, workspace and embed identifiers, connection status, hashed installation credentials, last-seen time, configured domains, and customer mailbox or analytics settings. | The Customer, its WordPress site, and connected services. |
| Device, network, and diagnostics | IP address, approximate city/region/country, coarse browser/OS/device label, timestamps, page/route, referrer, web performance metrics, rate-limit signals, and error or operational logs. | Your request, browser, edge network, and hosting infrastructure. |
| Communications | Questions sent to Epkora, email address, subject, message, and optional name, phone, and company. | You. |
We may also receive information you choose to include in free-text fields. Please avoid including data that is not necessary for the intended business purpose.
5. Information about other people
Customers can enter information about employees, contacts, leads, customers, website visitors, message recipients, and other people. If you provide another person’s information, you must be authorized to do so and provide any notice or choice required by law.
Workforce records may include information that is sensitive under some laws, such as date of birth, gender, attendance, leave, and work-location information. Epkora does not determine whether a Customer should collect those fields. Customers should limit access and collect only what is lawful and necessary.
6. Live chat and the visitor widget
When an End User opens an Epkora chat widget, the Service creates an opaque visitor session and may process a display name, optional email, chat messages, the current page title and path, coarse browser/device/operating-system information, conversation status, assignments, internal notes, read state, and a voluntary rating. The session cookie normally lasts seven days unless cleared, revoked, or replaced.
Epkora uses the request IP address for security and rate limiting; the live-chat visitor and conversation records do not currently store the raw IP address. The embedding hostname may be checked against the Customer’s approved domain. Typing and realtime events are transmitted to operate the conversation.
Current live chat does not accept durable file uploads. Database fields reserved for attachment metadata do not mean an upload service is active. Customers must give their visitors an appropriate notice before deploying the widget.
7. Support forms, tickets, and email
A public support submission can include email, subject, message, and optional name, phone, or company. The Service may create or update a contact, ticket, lead, and follow-up task from that submission. Within a Customer workspace, support messages may be sent and received through mailboxes the Customer configures using SMTP and IMAP. Epkora stores message content and routing metadata needed to preserve the ticket history.
Mailbox passwords stored in Epkora are encrypted at rest with an application encryption key. The Customer’s chosen mail provider also processes message and connection data under its own terms. Current support forms and chat do not offer a production file attachment upload path.
When you contact Epkora itself, we use the message to respond, troubleshoot, protect the Service, and maintain appropriate business records. Account verification and security emails are sent through Epkora’s configured email service.
8. Knowledge bases, files, analytics, and media
Customers can publish articles, FAQs, news, images, logos, and favicons, and can restrict or expose content according to product settings. Supported branding media is stored with content type and size metadata in Epkora’s database. Customers should not upload confidential material to a public help centre.
Epkora’s first-party help-centre analytics can record page views, search activity, article identifiers, a referrer, hostname, coarse country, and a daily pseudonymous visitor key generated from the day, IP address, and user-agent information. The daily key is designed to measure visits without preserving the raw values in the analytics event. Search terms may contain personal information if a visitor types it.
A Customer may configure Google Analytics 4 or Google Tag Manager on its public help centre. Those tags are controlled by the Customer and may send information to Google or other tags the Customer loads. The Customer is responsible for an appropriate consent mechanism and disclosure. Epkora does not load those Customer tags in the administrative dashboard.
9. AMI and AI processing
AMI is Epkora’s proprietary AI model, developed and maintained by the Epkora Lab team. AMI stores conversation history, messages, generated material, and feedback associated with the Authorized User and workspace. For supported reply suggestions, the AMI processing service uses a limited selection of recent non-internal conversation content and relevant context such as the visitor display name or current page. The implementation does not intentionally include the visitor’s email, phone number, IP address, or internal notes in that reply-suggestion request, but personal information can still appear in message text.
Other AMI features may use Customer-selected knowledge or prompt content needed to perform the request. Customers must not submit information they are not authorized to provide to AMI for processing. Authorized Users should review output before acting on it.
10. Automatically collected data
- Security sessions: browser, operating system, device label, IP address, approximate city/region/country, timestamps, expiry, and login count.
- Requests and diagnostics: routes, status, timing, errors, rate-limit keys, and operational logs needed to run and protect the Service.
- Website analytics: Vercel Analytics receives page/route, referrer, coarse location and device information, and a daily generated identifier; Vercel states this product does not use third-party cookies.
- Performance: Vercel Speed Insights collects real-user web-vital and performance measurements with related page/device context.
- Bot protection: Vercel BotID and its underlying protection may evaluate network and browser signals on protected unauthenticated actions such as registration and password recovery.
- Address suggestions: for signed-in address forms, the typed address prefix and optional country bias are sent server-side to Mapbox when autocomplete is configured.
- Font delivery: the current global stylesheet requests Geist font styles and assets from Google Fonts, which receives ordinary request metadata such as IP address, browser information, and referrer headers.
Where approximate security location is not supplied by the edge network, Epkora may send an IP address to country.is to resolve a city, region, and country. We use this information to show and protect account sessions, not for precise location tracking.
11. Why we process information and our legal bases
| Purpose | Information | Legal basis when Epkora is controller |
|---|---|---|
| Provide and administer the Service | Account, workspace, configuration, communications, integrations, and usage. | Performance of a contract or steps requested before entering one; legitimate interests in delivering a business service. |
| Authenticate and protect | Credentials, sessions, IP, device/location, activity, challenge and anti-bot signals. | Performance of contract; legitimate interests in preventing abuse and protecting users; legal obligations where applicable. |
| Support and communicate | Contact details, questions, messages, and diagnostic context. | Performance of contract; legitimate interests in responding and maintaining customer relationships; consent where required. |
| Operate, measure, and improve | Usage, feature events, aggregated analytics, web performance, feedback, and diagnostics. | Legitimate interests in reliability, usability, capacity, and product improvement, balanced against privacy rights. |
| Provide requested AI features | Prompts, selected context, output, and feedback. | Performance of contract or steps at the user’s request; for Customer Data, the Customer’s documented instructions. |
| Meet legal and business obligations | Transactions, account, security, complaint, and legal-request records. | Compliance with law; establishment or defense of legal claims; legitimate interests in governance and recordkeeping. |
| Send optional marketing | Business contact details and communication preferences. | Consent where required, or legitimate interests where permitted; you can opt out. |
Where Epkora acts as processor, the Customer determines the legal basis. Where consent is the basis, it may be withdrawn for future processing without affecting earlier lawful processing. Where we rely on legitimate interests, you may object as described below.
14. AMI transparency
AMI is Epkora’s proprietary AI model, developed and maintained by the Epkora Lab team. Epkora designs and controls AMI’s product experience, orchestration, safeguards, and integration with the Service. To generate requested output, AMI processes the prompt and context needed for the selected feature.
We may update AMI’s technology or supporting infrastructure as needed to operate or improve the Service. If that materially changes the privacy risk, we will update this Policy and provide additional notice where required. AMI does not independently send a reply to an End User merely because a draft was generated; an Authorized User controls whether to use it.
15. Sale, sharing, and targeted advertising
Epkora does not sell or rent personal information. Epkora does not share personal information for cross-context behavioral advertising and does not use Customer Data to target advertising. We do not offer money for personal information.
Disclosures to service providers and Customer-directed integrations are made to operate the Service and are not treated by Epkora as a sale. If our practices change, we will update this Policy and provide any legally required opt-out mechanism before the new practice begins.
16. International data transfers
Epkora is established in the United Arab Emirates and uses global providers. Information may be processed in the UAE, United States, China for some AMI processing, and other countries where service providers or Customer-selected integrations operate. Privacy laws in those places may differ from those in your country.
Where a restricted transfer mechanism is legally required, Epkora will use an available lawful mechanism appropriate to the transfer, such as approved contractual terms, an adequacy decision, or an applicable exception, and will assess supplementary safeguards as required. This statement does not claim that a particular contractual module or certification is already in place for every transfer. Customers needing documented transfer terms should contact us before submitting regulated data.
17. Retention, account closure, and deletion
Epkora retains information for the period reasonably needed to provide the Service, follow Customer instructions, secure accounts, resolve disputes, enforce agreements, and meet legal obligations. The current implementation does not establish one fixed, platform-wide deletion period for all database records or backups.
| Record | Current approach |
|---|---|
| Account and workspace records | Kept while the account or workspace remains active and afterward as needed for closure, security, disputes, and legal records. There is no universal self-service deletion control in the current product. |
| Customer support, CRM, HR, workflow, knowledge, and ticket data | Kept according to Customer use and workspace lifecycle. Plan reporting windows govern what reports expose; they are not a promise that every underlying operational record is automatically erased on that date. |
| Live-chat visitor session | The browser cookie and server-side authorization expire after seven days by default. Conversation and message history can remain in the Customer workspace after visitor-session expiry. |
| Account sessions and security state | Sessions expire or can be revoked; expired and revoked rows and expired challenges/trusted devices are pruned by security maintenance and account events. A limited account security-activity history is maintained. |
| AMI history and feedback | Conversation history remains until removed through available product functionality or the workspace lifecycle. Feedback may be retained separately to understand quality and abuse. |
| Knowledge-base analytics | Retained as needed for Customer reporting and product operation. Daily visitor identifiers are pseudonymous, but search text and event records may persist beyond the daily identifier window. |
| WordPress connection records | Connection status, site metadata, and hashed credentials remain while connected and as needed after revocation for security and audit purposes. Short-lived authorization codes expire. |
| Logs and backups | Rotated or deleted according to operational, security, provider, and recovery needs. Epkora does not promise one fixed period for these records in this Policy. |
An authorized workspace owner may request account closure at support@epkora.com. We may verify identity, authority, and workspace ownership. Deletion can be limited or delayed by another Customer’s control, legal holds, fraud and security needs, accounting obligations, disputes, backups, or data that has been aggregated or de-identified. Disconnecting WordPress or another integration stops that connection but does not itself delete the workspace or all prior content.
18. How we protect information
Epkora uses measures designed to protect personal information, including tenant-scoped access controls, role-based permissions, salted password hashing, HTTP-only and secure production cookies, two-factor authentication options, session revocation, rate limiting, bot protection, and encryption for TOTP secrets and stored mailbox credentials. Access is restricted according to operational need.
These measures reduce risk but cannot eliminate it. Users must protect their credentials and recovery codes, use appropriate permissions, keep connected systems secure, and report suspected compromise promptly. Epkora does not claim an external security certification in this Policy.
19. Security incidents
Epkora maintains processes to investigate suspected security incidents, contain harm, restore operation, and preserve relevant evidence. If an incident involving personal information requires notice, Epkora will notify affected Customers, individuals, regulators, or authorities in the manner and timeframe required by applicable law and our contractual role.
Customers are responsible for notices arising from their own systems, configurations, or instructions, with Epkora’s assistance where legally or contractually required. Report a suspected incident privately to support@epkora.com.
20. Your choices and privacy rights
Depending on your location and Epkora’s role, you may have rights to access, know about, correct, delete, restrict, stop, or object to processing; receive portable data; withdraw consent; opt out of certain uses; and complain to a regulator. Rights are subject to legal exceptions and verification.
- For data in a Customer workspace, contact that Customer first. Epkora will route or assist with requests when appropriate.
- For an Epkora-controlled account or website request, email support@epkora.com and identify the account, workspace, jurisdiction, and right requested.
- We may ask for information reasonably necessary to verify identity and authority. Authorized agents must show valid authorization.
- We will respond within the period required by applicable law and explain any denial or extension. We do not discriminate for exercising a privacy right.
You can manage many choices directly by updating account details, revoking sessions or trusted devices, changing notification permissions, disconnecting integrations, adjusting Customer analytics, or clearing browser cookies/storage. Account deletion is currently request-based as explained in Section 17.
21. Requests from Customer End Users
If you contacted a company through an Epkora-powered chat, support inbox, form, or help centre, that company is normally responsible for your information. Contact it using the details on its website or in its communications. Epkora cannot independently decide to delete or disclose a Customer’s records without authority because doing so could affect other people, legal obligations, or the Customer’s rights.
If you cannot identify or reach the Customer, contact Epkora with the relevant website domain and enough context to route the request. We will not ask for more personal information than reasonably necessary.
22. United Arab Emirates disclosures
Epkora LLC is based in Dubai, United Arab Emirates. The UAE’s Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data regulates many forms of personal-data processing and provides rights that can include access, correction, restriction, stopping processing, portability, and objection to certain automated processing, subject to its scope and exceptions.
UAE residents may submit a request using Section 20. Complaints may also be directed to the competent UAE data-protection authority where the law provides. Free-zone or sector-specific privacy rules may apply instead of or alongside the federal law in some cases; Customers remain responsible for identifying rules specific to their operations.
23. European Economic Area and United Kingdom
If the EU GDPR or UK data-protection law applies and Epkora is the controller, our legal bases are summarized in Section 11. You may request access, rectification, erasure, restriction, portability, or objection, and may withdraw consent. You may also lodge a complaint with the supervisory authority where you live, work, or believe an infringement occurred.
Epkora is not established in the EEA or UK. International transfers are addressed in Section 16. No automated decision producing legal or similarly significant effects is part of the verified AMI implementation. A Customer using Epkora to make such decisions must not do so without independent legal review and appropriate human involvement.
24. Canada
Where Canadian private-sector privacy law applies, Epkora is accountable for personal information under its control and uses it for purposes a reasonable person would consider appropriate. You may request access to and correction of your personal information and challenge compliance. Consent requirements vary with context, sensitivity, and applicable provincial or federal law.
Submit a request or complaint to the contact in Section 30. If a concern is not resolved, you may contact the Office of the Privacy Commissioner of Canada or the applicable provincial regulator.
25. United States and California disclosures
State privacy laws apply only when their territorial, business, and other thresholds are met. Where one applies, residents may have rights to know, access, correct, delete, or obtain a copy of personal information and to opt out of sale, targeted advertising, or certain profiling. Epkora does not sell personal information or use it for cross-context behavioral advertising.
For California transparency purposes, the categories collected in the preceding 12 months can include identifiers; customer records; commercial and internet/network activity; approximate geolocation; professional or employment information; Customer-provided content; and inferences limited to security, product operation, and support context. Sources, purposes, and recipients are described in Sections 4, 10, 11, and 13. Sensitive personal information can include account credentials, precise contents of communications, and Customer-provided HR fields, but Epkora does not use sensitive information to infer characteristics for advertising.
We do not knowingly disclose personal information of people under 16 for sale or targeted advertising. California residents may use Section 20 and may appeal or complain as their applicable law provides. Because Epkora does not sell or share for cross-context advertising, it does not currently provide a “Do Not Sell or Share” link.
26. Children
The Service is designed for businesses and is not directed to children. Individuals under 18 may not create an Epkora account. We do not knowingly collect personal information directly from a child under 13 through Epkora’s own account and marketing services.
A Customer must not use Epkora to process children’s data unless it has a lawful basis, provides required notices, obtains any necessary parental authorization, and configures suitable safeguards. Contact us if you believe a child created an account or that Epkora controls information collected from a child unlawfully.
27. Service and marketing communications
We send account verification, password recovery, security, invitation, transactional, and important service messages as needed to operate an account. You cannot opt out of essential messages while keeping the related account active.
If Epkora sends optional marketing, you can unsubscribe through the message or contact us. An opt-out does not stop operational communications, and we may keep a minimal suppression record to respect the request. Customers independently control communications they send through their own workspaces and must provide legally required choices.
28. Automated decision-making
Epkora uses rules for security, rate limiting, routing, workflow actions, service-level tracking, and AI assistance. The verified Service does not use AMI to make solely automated decisions for Epkora that produce legal or similarly significant effects on a person. AI output is assistance for an Authorized User to review.
Customers configure their own workflows and determine how outputs are used. They must provide human review, notice, explanation, contest procedures, and other safeguards where required, and must not use the Service for prohibited high-impact decisions.
29. Changes to this Policy
We may update this Policy when the Service, providers, or law changes. We will post the updated version and change the “Last updated” date. If a change materially affects how we use personal information, we will provide additional notice through the website, Service, or account email where required. Earlier versions may be requested from us if available.
30. Contact Epkora
For privacy questions, rights requests, complaints, or account closure requests, contact:
A4 Building
Dubai South
Dubai
United Arab Emirates
Privacy email: support@epkora.com
Privacy Policy: www.epkora.com/privacy