Zorunlu çerezler oturumunuzu açık tutar; analizler yalnızca onayınızla. Şuraya bakın: Gizlilik Politikası.

← Back to Monqez AI

Privacy Policy

Last updated: June 21, 2026

1. Who we are (Data Controller)

Monqez AI ("Monqez", "we", "us") provides an AI customer-service, sales and automation platform. The service is operated by المنقذ المبدع للبرمجة (Monqez), a sole proprietorship registered in Jordan. For any privacy matter — including the requests described below — contact us at support@monqezai.io. Our full registered postal address is available on request. If we are required to designate an EU/UK representative or Data Protection Officer for your region, their details will be added here.

2. Scope

This policy applies to everyone who uses Monqez AI, anywhere in the world. If you are in the European Economic Area (EEA), the United Kingdom or Switzerland, you have the rights described under the GDPR / UK-GDPR. If you are a California resident, you have the rights described under the CCPA/CPRA. Where local law gives you stronger protection, that local law applies.

3. Information we collect

We collect:

  • Account data — your name, email address and a securely hashed password. If you sign in with Google, we receive only your name and email from Google.
  • Business content you provide — knowledge-base documents, AI training instructions, conversations handled by your AI agents, and any contacts or leads you import or generate (including results from the Automation Library tools).
  • Messages from channels you connect — when you connect Facebook Messenger, Instagram, or WhatsApp, your AI agent receives the messages your customers send to those connected accounts (and the sender’s name/ID as provided by the platform) so it can read and reply on your behalf. We process this content only to operate the service you enabled; we never sell it or use it to train shared AI models.
  • Usage & technical data — log data, IP address, device/browser type, pages visited and feature usage, used to operate, secure and improve the service.
  • Payment data — when you buy a plan or bundle, payment is processed by our payment provider. We receive confirmation and billing details but never store your full card number.

4. How we use your information & legal bases

We use your information to provide and maintain the service, authenticate you, process payments, send service-related messages, respond to you, keep the platform secure, and meet legal obligations. Under the GDPR our legal bases are: performance of our contract with you (to deliver the service you signed up for); our legitimate interests (to secure, support and improve the service); your consent (for non-essential/analytics cookies, which you can withdraw at any time); and compliance with a legal obligation. We do not sell your personal information, and we do not use your private business content to train shared/public AI models.

5. AI processing

To generate replies, draft outreach and run automations, the content you submit is processed by our AI providers under enterprise API terms that prohibit using your data to train their public models: Google (Gemini) for AI replies, knowledge-base answers and the Test-AI sandbox; OpenAI for drafting sales emails and for non-Arabic voice features (speech-to-text and text-to-speech); and ElevenLabs for Arabic voice features (speech-to-text and text-to-speech). AI output can be inaccurate; you remain responsible for reviewing it. We do not make decisions producing legal or similarly significant effects about you solely by automated means without human oversight (GDPR Art. 22).

6. Who we share data with (recipients & sub-processors)

We share data only with service providers who process it on our behalf under contract, and only as needed to run the platform. Our current sub-processors include:

  • Google — sign-in (OAuth), the Gemini AI model, and website analytics (loaded only with your consent).
  • OpenAI — to draft sales emails and to power non-Arabic voice features (speech-to-text and text-to-speech), under API terms that prohibit training on your data.
  • ElevenLabs — to power Arabic voice features (speech-to-text and text-to-speech).
  • Apify — the scrapers behind the Sales Lead Finder (Google Places/Maps) and the Automation Library creator search (TikTok/YouTube/Instagram); it receives your search terms and returns publicly available results.
  • Qdrant (Qdrant Cloud) — vector memory for the AI knowledge base; it stores numeric embeddings of your knowledge-base content, not the raw files.
  • Hostinger — cloud hosting, database and storage; the platform (including our self-hosted automation engine) runs here, in the EU (Frankfurt, Germany).
  • Messaging channels you connect (WhatsApp / Meta Messenger & Instagram, Telegram) — to deliver and receive messages on those channels.
  • Email provider (Hostinger SMTP; Google/Gmail as a fallback) — to send transactional and account emails.
  • Payment provider (Stripe) — to process purchases when online billing is enabled; we never store full card numbers.

6a. Access by our staff

A limited number of authorised Monqez personnel can access systems containing your data, strictly to operate, support, secure and maintain the service, under confidentiality obligations and role-based access controls. Our routine support tools redact customer conversation content and mask connected credentials, and administrative actions and any support "view-as" (impersonation) sessions are recorded in an internal audit log. We never sell your data and never use it to train shared models across customers. The full, current list of sub-processors is published at monqezai.io/subprocessors, and business customers can review our Data Processing Agreement at monqezai.io/dpa.

7. International data transfers

We operate globally, so your information may be processed in countries outside your own, including outside the EEA/UK. Where we transfer personal data out of the EEA/UK, we rely on an adequacy decision where one exists, or on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum), so your data keeps an equivalent level of protection. A copy of the safeguards is available on request.

8. Data retention & deletion

We keep your account and content for as long as your account is active. You can delete your data at any time in one of these ways:

  • Delete your account or download a copy of your data at any time from Settings → Account, or email support@monqezai.io. We erase your personal data within 30 days, and from routine backups within a further 90 days — keeping only records the law requires us to retain (e.g. tax).
  • For connected Meta channels (Facebook Messenger / Instagram): remove the Monqez app from your Facebook Settings → Apps and Websites, or disconnect the channel in Integrations. Removing the app triggers Meta’s data-deletion request to us (https://monqezai.io/api/meta/data-deletion); we then delete the message data we received for that user and provide a confirmation code. You can also email us to request deletion directly.

8a. Legal retention

We keep some records longer only where the law requires it (e.g. tax/accounting) or to establish, exercise or defend legal claims; we delete them once that purpose ends.

9. Your rights

Depending on where you live, you have some or all of the following rights over your personal data:

  • Access — get a copy of the data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data ("right to be forgotten").
  • Restriction & objection — limit or object to certain processing, including processing based on legitimate interests.
  • Portability — receive your data in a portable format, or have it sent to another provider.
  • Withdraw consent — at any time, where we rely on consent (e.g. analytics cookies).
  • Complain — lodge a complaint with your local data-protection authority (in the EEA, your national supervisory authority; in the UK, the ICO).
  • California (CCPA/CPRA) — know, delete, correct, and opt out of any "sale"/"sharing" (we do not sell or share your personal information), without discrimination.

10. How to exercise your rights

Email support@monqezai.io from the address on your account. We respond within 30 days (GDPR) or 45 days (CCPA); we may need to verify your identity first. Exercising your rights is free unless a request is manifestly unfounded or excessive.

11. Cookies & analytics

We use essential cookies to keep you signed in and maintain your session — these are always on because the service cannot work without them. We also use analytics cookies (Google Analytics) to understand how the site is used; these load only after you accept them in our cookie banner, and you can change or withdraw your choice at any time. We do not use advertising cookies.

12. Security

We protect your data with encryption in transit (HTTPS/TLS); sensitive fields such as integration credentials and API tokens are additionally encrypted at rest with AES-256-GCM. We enforce strict multi-tenant isolation so one customer can never see another’s data, plus access controls and regular encrypted backups. No method of transmission or storage is 100% secure, but we work hard to protect your information and notify affected users and regulators of a qualifying breach as required by law.

13. Children

Monqez AI is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16 (or the minimum age in your country). If you believe a child has provided us data, contact us and we will delete it.

14. Changes to this policy

We may update this policy as the service or the law evolves. We will post the new version here and update the "Last updated" date, and we will notify you of material changes by email or in the app. Continued use after changes take effect means you accept the updated policy.

15. Contact us

Questions or requests about your privacy: support@monqezai.io.

AboutSecurityPricingPrivacyRefund PolicyTerms