This Privacy Policy explains how Thriveways processes personal data in connection with B.O.B (Bakery Order Bot), a WhatsApp-based ordering tool that lets bakery customers place bread orders via WhatsApp. This policy applies only to B.O.B; other Thriveways products are governed by their own notices.
1. Who we are
B.O.B is operated by Thriveways, a company registered in Romania and operating within the European Union. For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), Thriveways acts as the data controller for the data described below.
You can contact us about this policy or about your personal data at contact@thriveways.io.
2. Data we collect
We collect and process the following categories of data:
Bakery business information
- Business name
- Contact email address
- Phone number used for the WhatsApp bot
End-customer data (bakery customers)
- WhatsApp phone number
- Order details: product name, quantity, day of order, total amount
Usage data
- Message logs exchanged with the bot
- Session state during the ordering flow
3. Purposes and lawful bases
Under Article 6 of the GDPR, we rely on the following lawful bases:
- Performance of a contract (Art. 6(1)(b)) — to provide the B.O.B service to bakeries and to process orders placed by their customers through the bot.
- Legitimate interests (Art. 6(1)(f)) — to operate, secure, and improve the service, detect abuse, debug issues, and maintain message logs and session state. We balance these interests against your rights and freedoms.
- Legal obligation (Art. 6(1)(c)) — to comply with Romanian and EU bookkeeping, tax, and consumer-protection law where applicable.
- Consent (Art. 6(1)(a)) — where required, for example when a bakery customer first initiates a WhatsApp conversation with the bot, thereby choosing to share their WhatsApp phone number with the bakery and with us.
For bakery customers, the bakery is typically the data controller for their own customer relationships, and Thriveways acts as the processor on their behalf for the ordering data they collect through B.O.B.
4. How we share data
We do not sell personal data. We share data only with the service providers that make B.O.B work:
- Meta Platforms, Inc. (WhatsApp Business API) — provides the messaging infrastructure used to send and receive bot messages.
- Neon — hosts our PostgreSQL database, where order and account data is stored.
- Fly.io — hosts the B.O.B application that runs the ordering logic.
Each provider acts as a processor or sub-processor and handles personal data under appropriate contractual safeguards.
5. International transfers
Some of our service providers (in particular Meta and Fly.io) are based outside the European Economic Area or may process data in third countries. Where this happens, we rely on appropriate safeguards under Chapter V of the GDPR, such as the European Commission's Standard Contractual Clauses and any applicable adequacy decisions.
6. Data retention
We keep personal data only for as long as we need it for the purposes described above. Our default retention periods are:
- Bakery account information: for the duration of the service agreement, plus up to 10 years after termination to comply with Romanian accounting and tax obligations.
- End-customer order records: up to 5 years from the date of the order, in line with statutory limitation periods for consumer transactions.
- Message logs: up to 12 months, for security, debugging, and abuse prevention.
- Session state: up to 30 days after the ordering flow ends, then deleted.
We may keep data longer where required by law or to establish, exercise, or defend legal claims.
7. Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Access — obtain confirmation of whether we process your data and a copy of it.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”) — ask us to delete your data where one of the grounds in Art. 17 GDPR applies.
- Restriction — ask us to limit how we use your data in certain cases.
- Portability — receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, email contact@thriveways.io. You also have the right to lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP, dataprotection.ro), or with the supervisory authority in your EU country of residence.
8. Cookies and tracking
B.O.B does not currently use cookies or similar tracking technologies. If this changes, we will update this policy and, where required, ask for your consent before any non-essential cookies are set.
9. Security
We use technical and organisational measures appropriate to the risk, including access controls, encryption in transit, and managed hosting providers with their own security programmes. No system is perfectly secure, but we work to detect, contain, and respond to incidents promptly.
10. Changes to this policy
We may update this policy from time to time. When we do, we will change the “Last updated” date at the top of this page. Material changes will be communicated to bakery customers through the usual contact channels.
11. Contact
For any privacy question or request, contact us at contact@thriveways.io.
