This policy is for you — a member of the public who has written to, messaged or spoken with a service agent powered by Anita24, whether through a chat window on an organization’s website, WhatsApp, Facebook Messenger, Instagram, or a phone call. It explains what happens to what you say.
The agent belongs to the organization you contacted. Anita24 is the software behind it, provided by Luminata Software Development LTD, an Israeli company.
If you are an organization that uses Anita24 to run agents, a different policy applies to you: see the Privacy Policy for Customers.
1. You are talking to an AI agent
The agent replies automatically. It is software, not a person, although the organization may join the conversation or follow up with you afterwards.
Automated answers can be wrong, out of date or incomplete. Nothing an agent tells you is medical, legal, financial, tax, insurance, psychological or other professional advice, and you should confirm anything important directly with the organization before relying on it. If your matter is urgent or an emergency, contact the organization or the emergency services directly rather than the agent.
2. Who is responsible for your information
The organization you contacted decides what your information is used for, how long it is kept and who inside that organization can see it. In data protection terms, it is the controller. (In our Terms of Service we call it the "Providing Organization".)
Luminata handles your information on that organization’s behalf and follows its instructions. In data protection terms, we are its processor. That is why requests about your information usually go to the organization first — see section 8.
The way we handle information for the organizations that subscribe to Anita24 is set out separately in our Privacy Policy for Customers.
3. What we collect
Depending on how you got in touch:
- What you say — the text of your messages, and for phone calls the recording of the call and the text version of it.
- Contact details you choose to give — your name, phone number, email address.
- The details of your request — an appointment, an enquiry, an order, a complaint and so on.
- The identifiers needed to deliver the conversation — for example your phone number on WhatsApp, or the account and conversation identifiers the messaging platform gives us, so that your reply reaches you and not someone else.
- Basic technical information — the time of the conversation, your browser or device type, delivery and status information, and the address your connection comes from.
This is used to answer you, to carry out what you asked for, to show the conversation to the organization, to keep the service secure and working, and to meet legal obligations. Your conversations are not sold, are not used to advertise to you, and are not used to train or fine-tune general-purpose artificial-intelligence models — and our agreements with the AI providers we use do not permit them to do so either.
4. Phone calls: recording and transcription
If you call an agent, or an agent calls you, the call may be recorded and converted into text so that the agent can understand and answer you and so that the organization can see what was discussed. Where the law requires it, you will be told this at the start of the call and asked to agree. If you would rather not be recorded, say so and ask to be dealt with another way, or hang up and contact the organization by another route.
If you leave a voicemail with an agent, the message and its text version are handled in the same way.
5. Messaging apps
If you use WhatsApp, Facebook Messenger or Instagram to reach an agent, your message travels through Meta’s systems first and Meta’s own terms and privacy policy apply to that part of the journey. We receive your message and the identifiers needed to reply. If you ask Meta to delete the data connected to your use of these integrations, that request reaches us automatically; we act on it and give you a confirmation code and a web address where you can check the status. Section 11 says how quickly we act.
6. If we contact you first
An organization may use the platform to contact you — for example to call you back, confirm an appointment or follow up on a request. It is responsible for having a proper reason to contact you.
You can stop it. Tell the agent or the organization to stop contacting you, or write to support@anita24.com. We record the request and apply it to further outgoing calls and messages that organization makes through our platform. If more than one organization has contacted you through Anita24, tell us and we will apply your request to each organization you name. Ending marketing or follow-up contact does not stop you from getting in touch yourself.
7. Data security
We protect your information with measures including:
- Encryption in transit and at rest — what you send and what is stored is encrypted to reduce the risk of unauthorized access.
- Access control — stored conversations can be reached only by the organization you contacted, by authorized Luminata technical staff working under confidentiality obligations when support, operation or security requires it, and by the service providers listed in section 9, who process data on our behalf under contract.
- Separation — each organization’s data is kept separate from every other organization’s.
No system is completely secure. If a breach affects your information, the organization you contacted is responsible for telling you where the law requires, and we will support it in doing so.
8. Your rights
You can ask to:
- see the information held about you;
- correct it if it is wrong;
- delete it;
- limit or object to how it is used;
- receive a copy in a portable format;
- withdraw your agreement at any time, which does not undo what was done before you withdrew it;
- stop being contacted — see section 6.
Where to ask. Because the organization you contacted decides how your information is used, ask that organization first. If you cannot reach it, or it does not answer, write to us at support@anita24.com and we will pass the request on and help where we can. We may need to check who you are before acting.
Complaints. If you are not satisfied, you can complain to a data protection authority: in Israel, the Privacy Protection Authority; in the EEA or the United Kingdom, the authority where you live or work.
9. Where your information goes
We use a small number of service providers to run the platform. They act on our instructions and are bound by contract:
- Google Cloud / Firebase and Vercel — hosting, databases and running the software
- OpenAI, Anthropic and Google — the artificial-intelligence services that generate the agent’s replies
- Twilio — phone calls
- Meta Platforms — WhatsApp, Messenger and Instagram messaging
- Cloudflare — protecting our forms from automated abuse
The organization you contacted may also connect the platform to its own systems, such as a customer-management or calendar system. Those systems are that organization’s responsibility, and its own privacy policy covers them.
Apart from this, your information is disclosed only where the law requires it, where it is needed to deal with fraud or abuse or to defend a legal claim, or to a successor if our business is transferred.
10. Where your information is held
Luminata is in Israel and the providers listed above operate in Israel, Europe and the United States, so your information may be transferred between these places. Israel is recognized by the European Commission as offering an adequate level of protection. Where a transfer is not covered by such a decision, we use the European Commission’s Standard Contractual Clauses or another approved safeguard.
11. How long it is kept
The organization you contacted decides how long your conversation is kept. Unless it sets something different, conversations are kept for [retention period for conversation data — to be confirmed by counsel] and call recordings and their text versions for [retention period for voice recordings and transcripts — to be confirmed by counsel], after which they are deleted or permanently anonymized. Some information may be kept longer where the law requires it or where it is needed to defend a legal claim. Copies held in routine backups are removed as those backups are overwritten.
If you ask for your information to be deleted, we act on the request within [deletion SLA in days — to be confirmed by counsel] of it being verified. The same period applies to deletion requests that reach us through Meta, as described in section 5.
12. Cookies and technical information
The chat window uses only what it needs to work — for example remembering that you accepted this notice and keeping your conversation open while you browse. It does not use advertising cookies. The website you are visiting may use its own cookies, which are covered by that website’s own notice, not this one.
13. Children
Agents are generally intended for adults, and we do not knowingly collect information from children on our own account. Some organizations — a school, for example — may deploy an agent for younger users; where that happens, that organization is responsible for the extra protections the law requires. If you believe a child has given us personal information and it should not have been collected, write to support@anita24.com and we will arrange for it to be deleted.
14. Changes to this policy
We may update this policy. The version in force is always the one published here, with its date shown as "Last updated" at the top. If a change materially affects you, the updated notice will be shown in the chat and you will be asked to accept it again before you continue. The organization you contacted remains responsible for telling you about changes to its own notices.
15. Contact us
Questions, concerns, or the organization you contacted is not responding? Write to us:
Luminata Software Development LTD, [registered business address — to be confirmed by counsel], Israel
📧 General and support: support@anita24.com
📧 Privacy and data requests: support@anita24.com
Terms of Service
See also our Terms of Service for End Users (Hebrew: https://anita24.com/terms-of-service-he.html).