Privacy Policy

Last updated: September 18, 2026

1. Who We Are

esek.io ("we", "our", "us") operates a business messaging platform that connects service providers ("Business Customers") with their customers ("End Users") via the WhatsApp Business Platform and, where enabled, Instagram and Facebook Messenger. We act as a Technology Provider under the Meta Business Platform and process data on behalf of our Business Customers in accordance with Meta's Platform Terms and Business Messaging guidelines. This policy explains how we collect, use, and protect personal data.

2. Data We Collect

We collect data from two audiences: Business Customers who register to use our platform, and End Users who communicate with those businesses via WhatsApp, Instagram, or Facebook Messenger.

From Business Customers

From End Users (via WhatsApp conversations)

Connected Instagram and Facebook Messenger accounts

When a Business Customer enables these channels and authorizes a connection, we receive the selected professional Instagram account or Facebook Page identifier, account name, authorizing account identifier, granted permissions, and access credentials. We encrypt the credentials and use them to operate that business's messaging connection.

For customers who message a connected account, we receive a Page-scoped Messenger customer identifier or Instagram-scoped customer identifier, available profile name, message content, supported attachments, and any reply, story, or referral context supplied by Meta. We keep each account's conversations separate. Authorized staff can link a channel identity to an existing customer record. We do not infer that two people are the same person from a matching profile name. Supported attachments may be stored privately so staff can view them after the provider's temporary download link expires.

When authorized staff open a conversation or ask Iska (Copilot) for a customer profile, we may also retrieve the available profile name, Instagram username and profile link, and profile photo URL from Meta. We store an available display name on the channel identity; the additional profile fields are fetched on demand rather than saved to that customer record.

Authorized staff can read and reply to these messages. When the business enables AI assistance and the applicable consent requirements are met, message text and relevant history are processed by the AI providers described below. The retention and deletion rules for these channels are described in section 8.

From End Users (via AI phone calls)

When a Business Customer turns on the AI phone assistant, calls forwarded to the phone number we provide are answered by an AI voice assistant on that business's behalf. The assistant says that it is an AI assistant at the start of every call. For each such call we collect:

AI calls and voicemail. During AI answering, call audio is processed live. We keep the written transcript, summary and message as the record of the call. We also keep a private recording of the call audio, both the caller's side and the assistant's side, for up to 7 days. We use it only to investigate problems and check quality, and then it is deleted automatically. It is not used to train AI models and is not shared for advertising. Depending on where the call comes from, callers may hear at the start of the call that it is recorded. Erasing a call, or deleting the workspace, deletes this recording immediately. When the business has insufficient minutes and balance, direct phone calls switch to voicemail: callers hear a greeting asking them to leave a message after the tone, and we privately store up to two minutes of their message. Authorized workspace members can play it. Erasing the caller’s record also deletes this recording.

Calls answered by the AI phone assistant end automatically after five minutes.

Optional device permissions

3. Legal Basis for Processing

4. How We Use Data

We use WhatsApp, Instagram, and Facebook Messenger data strictly for the purposes described above. We do not use End User data for advertising, profiling, or any purpose unrelated to providing the messaging service.

5. Data Sharing

We do not sell personal data. Data may be shared with the following third-party processors:

The full list of sub-processors, with what each one receives and where it processes data, is on our Sub-processors page.

6. Google Account Data

Connecting a Google account to esek.io is optional. You can use every part of esek.io without it, and you see exactly what you are granting on Google's own consent screen. Two things use it:

Removing a linked document in Settings deletes the access we hold for it. You can also revoke it directly at https://myaccount.google.com/permissions.

esek.io's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this data to anyone, we do not use it for advertising, and we do not allow humans to read it except where you have asked us to, where it is needed for security, or where the law requires it.

7. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States, where our servers are hosted and where Meta and most of our sub-processors operate. Each sub-processor and the place where it processes data are listed on our Sub-processors page. For transfers from the EU, the EEA and the UK, we rely on the EU-US Data Privacy Framework (including its UK Extension) where the recipient is certified under it, and on Standard Contractual Clauses (with the UK Addendum for UK data), together with data processing agreements with each processor.

8. Data Retention

Whose record a call is. A record of a call to a business is that business's own customer record, in the same way a written note of the call would be. It is not part of the personal account data of the staff member who works there. Two consequences follow, and we would rather state them plainly than leave them to be discovered:

If you called a business that uses esek.io and you want the record of your call erased, ask the business, or write to us at privacy@esek.io. Erasing a call clears the caller's phone number, the transcript, the summary, any message taken, and any recording of the call we still hold, and marks the call as erased on request. What remains is how long the call lasted and what it cost the business, which says nothing about who called or what was said. We keep that much because it is the evidence for a charge already made.

Disconnecting a social account and deleting its data. Disconnecting Instagram or Messenger stops new messaging through that connection and clears its stored credentials. It does not by itself erase existing conversations or records the business already holds. To request erasure of social-platform data, contact privacy@esek.io with the connected account or Page and the business concerned. We verify the request and its scope, including records shared with other channels, and confirm the outcome. A request that still needs verification or review is not treated as a completed deletion. Customers who do not have an esek account can use the same contact address.

When Meta sends us a verified authorization-revocation notice, we stop the affected connection and clear its credentials. When Meta sends a data-deletion request, we also begin erasure of the associated social data and return a confirmation code and status-page link. Shared records, exports, recovery backups, or AI history may require additional review before the request can be marked complete. Removing a disconnected channel from the connection list only hides that connection; it does not erase its history.

9. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or port your personal data, or to object to or restrict certain processing. To exercise any of these rights, contact us or see our Data Deletion page for the deletion request process. We will respond within 30 days.

10. Children's Data

Our service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will delete it promptly.

11. Cookies and Local Storage

The web application uses a cookie to keep you signed in and a short-lived cookie that protects connecting a Google account. It keeps your sign-in, your settings, your cookie choice and a random identifier that helps prevent repeated trials in your browser's local storage. If you arrive through a referral link, a cookie remembers the referral for 60 days. The application loads Google's libraries only when you connect Google Drive, loads Paddle's checkout only when you pay, and stores a notification token only if you turn on browser notifications.

Our marketing website and signup flow also store, in your browser, a randomly generated identifier and the campaign parameters from the address you arrived on. We use them to measure how the site performs and to attribute a signup to the advertisement that led to it. They are set by us and stay in our own systems, with one exception: for visitors who accepted marketing cookies, or who are outside the EU, the EEA and the United Kingdom and have not declined them, the Meta ad click identifier from that address is sent to Meta with the signup, as described under Meta (Conversions API) in section 5.

Our marketing website additionally carries advertising tags from Meta and Google Ads. These tags set their own cookies and report page views to Meta and Google so we can measure and attribute our advertising. They load only after consent. Visitors in the EU, the EEA and the United Kingdom are asked before they load; elsewhere they load without a prompt. A browser that sends a Global Privacy Control signal is treated as having declined, wherever the visitor is. The tags do not load on the application's own screens.

12. Security

All data is transmitted over TLS. Passwords are hashed with bcrypt. Database access is restricted to authenticated services inside our private network. Access tokens received during WhatsApp Embedded Signup or Instagram and Messenger authorization are stored encrypted and scoped to the minimum required permissions.

13. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email to registered Business Customers. Continued use of the platform after changes constitutes acceptance of the updated policy.

14. Contact

Questions about this policy? Contact us at privacy@esek.io.

15. Who we are

The controller of the personal data described in this policy is Zak Goichman, trading as esek.io, a sole proprietor (עוסק מורשה) registered in Israel. For customer messaging data processed on a Business Customer’s behalf, that business determines the purposes of processing and esek.io acts as its processor.

Our Israeli business registration number is available on request from legal@esek.io.