Privacy policy
How your data is handled when you use Molvek Bot.
Last updated: 13 September 2026
Scope, data and legal grounds
Molvek OÜ is an Estonian software company and the operator of Molvek Bot. This policy covers our company website and Molvek Bot’s business messaging, customer and deal tracking, appointment management, knowledge base, business assistant and reporting. Additional channels and messaging modules are covered when activated by the business.
Molvek is the controller for its own company communications, business-account administration, contracts and support. It processes a business’s customer data as a processor under that business’s instructions. The business determines the purpose and legal grounds of its customer communications. This policy does not replace the business’s own customer notices or a required data processing agreement.
Data comes directly from you, the business using the service and integrations authorized by that business. It includes names, phone numbers and channel identifiers; messages and replies; leads, deals, notes and assignments; appointments; assistant conversations and reports; messaging permissions and campaign history; uploaded knowledge content; and necessary technical records. When you email us, we also process your address, message and attachments.
- Account setup, responding to your request and providing the service: steps toward or performance of a contract with you; for business representatives, our legitimate interest in managing the business relationship.
- Account security, abuse prevention, support and service reliability: our legitimate interests, balanced against your fundamental rights.
- Applicable accounting, tax and official-request requirements: the relevant legal obligation.
- Optional activities that require consent: your consent for the stated purpose, which you may withdraw. Authorizing Google access is not blanket consent to all other processing.
Withholding account or connection details needed for a feature may prevent it from working. Molvek Bot is intended for businesses, not for children to create accounts directly. A business must not upload special-category personal data or children’s data without the required legal and contractual arrangements.
Google Calendar access and use
The scope requested for Molvek Bot’s Google Calendar
connection is
https://www.googleapis.com/auth/calendar.events.owned. It permits viewing, creating, changing and deleting events
on calendars owned by the connecting Google account. The
technical permissions of this scope are broader than the
application’s use of them.
Event identifiers, summaries, start/end times, status and synchronization information are read. Events that do not match Molvek-created appointments are not turned into customer appointments. A new event includes the appointment time, time zone and a title containing the customer’s name, or phone number if no name is available. Technical identifiers link the event to its Molvek appointment record.
If the business enables the Notion connection, time changes and cancellations of Molvek appointments in Google Calendar are also reflected in the connected Notion appointment record. A read-only scope cannot create appointments; the owned-calendar scope is used instead of broader access to all shared calendars.
This connection does not request permission to read Gmail messages, Google Drive files or Google contacts. We do not receive or store your Google password. The connection’s refresh token is stored encrypted; an access token is used for requests to Google.
Molvek does not sell Google user data or other customer data, use it for advertising or ad targeting, or use it to train AI models. Use and transfer of Google data are limited by the Google API Services User Data Policy, including its Limited Use requirements. Human access is limited to circumstances permitted by that policy, such as the user’s affirmative consent to access specific data, security investigation or legal necessity.
What we store, where and for how long
Retention must be limited to what the processing purpose and applicable law require. There is no single fixed period for every category; the criteria below apply. The current system has no general automatic expiry deletion for customer records. Expiry or subscription termination does not itself trigger erasure; retention and deletion needs are reviewed through support.
| Data | Storage and retention |
|---|---|
| Google connection | The encrypted refresh token, calendar identifier and synchronization cursor support the connection. Revoking access stops new access to Google. Deleting the connection record held by Molvek is handled separately through support; Google revocation does not automatically erase that record. |
| Appointment records | Appointment times and status, Google event identifiers, linked record identifiers and synchronization hashes are retained. The need to retain them is determined by appointment delivery, the business’s necessary transaction history, contract termination and valid deletion instructions. |
| Messages and customer records | Messages, contact details, leads, deals, notes, assistant history, reports, permission/campaign records and operational history are stored to provide the service. Retention depends on the business’s documented purpose and instructions, the active customer relationship and any necessary legal claim or statutory retention. If notifications are enabled, subscription endpoints, keys and notification records are also processed. |
| Knowledge base | Uploaded document content, text chunks, document metadata and search vectors form the knowledge base the business maintains for replies and search. Removing a document or ending the service brings the related records and vectors within the deletion process. |
| Communications and contracts | Contact emails and support records are kept to resolve and follow up on the request. Contract or dispute records are limited to the period required by applicable legal obligations or the establishment, exercise or defence of legal claims. |
| Backups and technical logs | Where backups and technical logs are retained, their duration depends on recovery needs, security investigations and provider retention cycles. Exact provider-specific backup and log periods have not yet been verified. Deleting active data does not mean all backup copies are erased at the same time. |
Hosting location: The infrastructure check on 12 September 2026 places the application, PostgreSQL database and Redis services in Railway’s US region. The Qdrant Cloud endpoint is in the EU central region. We therefore do not promise that all customer data is stored exclusively in the EU. Other provider processing locations are subject to the transfer explanation below.
We use HTTPS in transit, AES-256-GCM encryption for connection secrets and business-scoped access to business data. This does not mean all message content is encrypted at the application layer or that the service is an end-to-end encrypted archive. Security measures reduce risk; no internet service can guarantee absolute security.
We do not store your Google password or a complete archive of calendar events. Fields needed for synchronization are processed and Molvek appointment records are retained. The current WhatsApp flow does not download or store the contents of incoming image or audio files.
Service providers and sharing
The providers below participate in the stated data flows. Optional integrations process data only when the relevant feature is activated. Generating AI replies or search vectors is distinct from training on customer data. Required data processing terms must be established with providers acting on Molvek’s behalf. Services connected through the business’s own accounts may also have separate responsibilities under their account and privacy terms.
| Provider | Purpose and data |
|---|---|
| Anthropic | Customer messages, necessary conversation context and relevant business information sent for replies, suggestions and information extraction, including prompt caching. |
| Google Calendar connection, authorization tokens, appointment events and event fields read for synchronization. | |
| Meta / WhatsApp / Instagram | WhatsApp message delivery, phone numbers, message content, templates and delivery status. If Instagram is activated, message content and channel-specific user identifiers. |
| Telegram — if activated | Message content, chat and user identifiers through the Telegram Bot API. This connection is not enabled by default for every business. |
| Railway | Application and worker hosting; customer records, messages, connection details and job data in PostgreSQL and Redis. |
| Qdrant Cloud | Business knowledge-base text chunks, document metadata and search vectors. |
| OpenAI | Creates search vectors from knowledge-base text and search queries. Not used for standard response generation. |
| Notion | When connected by the business: lead, contact and appointment records, including appointment updates derived from calendar changes. |
| Browser push service — if activated | Depending on the operator’s browser: Google, Mozilla, Apple or Microsoft. The service relays encrypted notifications and processes the subscription endpoint and delivery metadata. Browser permission is required. |
| Cloudflare | IP addresses and technical request details when hosting this static website; emails sent to us through the active email routing service. |
International transfers: As disclosed above, service data may be stored in the US and sent to providers outside the EU/EEA. These transfers require an applicable adequacy decision or appropriate safeguards such as standard contractual clauses, with supplementary measures where needed. Verification of provider-specific agreements and transfer safeguards is ongoing; this text does not represent that those checks are complete or that we hold a particular certification. Contact info@molvek.com for information about the provider, processing location and relevant safeguards.
This website has no tracking tools, analytics scripts, advertising cookies or cookie-based language preference. Language selection uses page links only. The hosting provider may process technical request information to deliver the pages and protect its infrastructure.
Revoke Google access and request deletion
- Open third-party connections in the Google account used to connect the calendar.
- Select Molvek Bot and remove its access. This stops future access to Google; it does not automatically delete existing Molvek records or events already created in your calendar.
- To disconnect the integration and request deletion of data held by Molvek, email info@molvek.com with your business name and the scope of your request. Do not send passwords or access tokens. We may need to verify your authority.
After the scope of the request and your authority are verified, it is assessed under the business’s instructions and applicable law. Requested records, connection tokens and related search vectors are included in its scope. Records required by law or necessary to establish, exercise or defend a legal claim may be exempt from erasure; the reasons and affected data categories will be explained. Deletion is handled through support, without a guarantee of instant or simultaneous automated erasure across all systems. Copies in the business’s Google, Notion or other accounts may also require that service’s deletion tools.
Your rights and contact
Under applicable data protection law, you may access and obtain a copy of your data, correct inaccurate data, and request erasure, restriction, objection or portability where the relevant conditions apply. You may withdraw consent for processing based on consent without affecting lawful processing before withdrawal. You may object to processing based on legitimate interests for reasons relating to your situation.
Send requests to info@molvek.com. For GDPR requests where Molvek is the controller, we respond without undue delay and normally within one month of receipt. Where necessary because of the complexity or number of requests, this may be extended by two further months; we notify you of the reason within the first month. If a request is not fulfilled, the reasons and available remedies will be explained. This statutory response period is not a service promise that every backup copy will be automatically erased within one month.
If you are a customer of a business using Molvek Bot, you may contact that business as the controller. We assist the relevant business with requests received by us. We may ask for necessary and proportionate information to verify your identity, but never passwords or access tokens. Exercising your rights is generally free; statutory exceptions may apply to manifestly unfounded or excessive requests.
You may complain to a competent supervisory authority, including Estonia’s Data Protection Inspectorate, Andmekaitse Inspektsioon, particularly in the country where you live, work or where the alleged infringement occurred. Contacting us first is not a condition of that right.
- Company
- Molvek OÜ
- Country of incorporation
- Estonia
- Registry number
- —
- Registered address
- Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia
- Contact
- info@molvek.com
Material changes are explained on this page and, where required, notified to the business contact. The last-updated date identifies the text’s version. If a new purpose for Google data is proposed, necessary notice and consent will be obtained before the relevant access.