Privacy Policy

Last updated: 2 October 2026

LONUT ("we", "us") is a sole proprietorship registered in Singapore (UEN 53462899X). We provide messaging automation and software services to business clients. This policy explains what personal data we handle, why, and your rights under Singapore's Personal Data Protection Act 2012 (PDPA).

Data we collect on our company website

Our company website, lonut.systems, does not use cookies, analytics trackers, or advertising pixels, except on its signup page described below. If you email us, we keep your email address and correspondence for as long as needed to handle your enquiry and maintain our business records.

Conciergr website, portal and signup

Conciergr's website, conciergr.com, works differently:

Data we process on behalf of clients

Our core service is operating automated customer-messaging systems for business clients on the WhatsApp Business Platform. When we do so, we act as a data intermediary (processor) for the client, who remains responsible for the customer relationship. In that role we may process:

Message content may be processed by our AI language-model provider (currently OpenAI, under API terms that do not permit training on the data) to generate replies. We do not use client customer data for advertising, we do not sell it, and we do not use it to train models.

Chat history imported at connection

When a client connects a WhatsApp number to our systems in coexistence mode, Meta provides a one-time copy of that number's recent conversation history (approximately the previous six months, both directions; the client chooses in the WhatsApp Business app whether to share it). We store that history on systems we operate, hosted by Cloudflare, and use it for two purposes, both on the client's behalf. The first is continuity: when a person who has written to the client before writes again, the client's automated assistant can see the earlier conversation and reply in context, in the same way and under the same terms as it handles messages received after connection. The second is a one-time setup analysis: contact details and identification numbers inside the messages (phone numbers, email addresses, postal addresses, NRIC and similar numbers) are masked by software running on systems we operate, and the text is then analysed by our AI language-model provider (currently OpenAI, under API terms that do not permit training on the data) to draft, for the client's review, a plain-language summary of the information the client's team commonly gives and a description of how the team writes. Names and the content of the conversations are not masked for this analysis; the drafts are written as general information about the business, not about any individual. Both drafts are sent only to the client, who checks them and decides whether to use them. Imported history is retained while the client's subscription is active and for 90 days after it ends, then deleted, or earlier at the client's request. It is not used for advertising, is not sold, and is never used to train AI models. Contact details the WhatsApp Business app synchronises to the WhatsApp Business Platform as part of coexistence are handled by Meta under WhatsApp's own privacy policy and are used by us only to operate the service.

Aggregated statistics

We may publish statistics about how the service is used, such as the share of enquiries that arrive outside business hours or how quickly replies are sent, calculated from message times and counts across several clients. Published statistics never include what any message says and never name or identify a client, a client's customer or any other person.

WhatsApp and Meta platform data

Our services are built on the WhatsApp Business Platform operated by Meta. Our access to and use of WhatsApp business data complies with the Meta Platform Terms and the WhatsApp Business Terms of Service. Messages are delivered through Meta's infrastructure and are also subject to WhatsApp's own privacy policy.

Retention

Conversation data processed for clients, including chat history imported at connection, is retained while the client's subscription is active so the service can maintain conversational context, or for a shorter period if the client directs. When a client's subscription ends, we retain their configuration, knowledge base and conversation data for 90 days in case they return, then delete them, keeping only anonymous counts that cannot identify anyone. Encrypted backups, held with a separate storage provider, and our hosting provider's recovery copies are kept for up to 30 days and then expire.

Security

We protect personal data with reasonable security arrangements as the PDPA requires: data is held on access-controlled systems, transferred only over encrypted connections, with contact details and identification numbers masked before any external analysis other than generating a reply, and accessible only to the people who operate the service.

Sharing and international transfers

We share data only with service providers necessary to operate our systems (e.g. Meta/WhatsApp for message delivery, Cloudflare for hosting and data storage, Backblaze for encrypted backups, and our AI language-model provider for reply generation), and where required by law. We do not sell personal data. Some of these providers process data outside Singapore, including in the United States; where they do, we transfer data under contractual terms that require a standard of protection comparable to the PDPA.

Your rights

Under the PDPA you may request access to or correction of personal data we hold about you, or withdraw consent to its processing, and you may ask us to delete it (see Deleting your data below). If your data was processed as part of a client's messaging service, we may refer an access or correction request to the relevant client, who controls that data; a deletion request we carry out ourselves.

Deleting your data

Anyone can ask us to delete the personal data we hold about them: a client, someone who signed in to the Conciergr portal, someone who emailed us, or someone who messaged one of our clients' WhatsApp numbers. Email [email protected] with "Delete my data" in the subject. If you messaged a business on WhatsApp, include the number you messaged from and the business's name; we may ask you to confirm the request from that number. We delete the data within 30 days and tell you when it is done. We keep only what the law requires us to keep, such as invoices, and anonymous counts that can no longer identify you, and we will tell you if anything was kept and why. If your data came to us through a client's WhatsApp service, we also tell that client. Encrypted backups and recovery copies expire on their own within 30 days after that.

Changes to this policy

We may update this policy from time to time; the date above shows the current version. Material changes affecting active clients will be notified by email or via the service.

Contact

For privacy matters, contact our data protection contact at [email protected]. If you are not satisfied with our response, you may complain to Singapore's Personal Data Protection Commission (pdpc.gov.sg).