Privacy Policy
Last updated: 27 August 2026
LONUT ("we", "us") is a sole proprietorship registered in Singapore (UEN 53462899X). We provide messaging automation and software services to business clients. This policy explains what personal data we handle, why, and your rights under Singapore's Personal Data Protection Act 2012 (PDPA).
Data we collect on this website
This website (lonut.systems) does not use cookies, analytics trackers, or advertising pixels, except on the signup page described below. If you email us, we keep your email address and correspondence for as long as needed to handle your enquiry and maintain our business records.
Conciergr website, portal and signup
Our product website conciergr.com works differently:
- Analytics. conciergr.com uses Google Analytics, which sets cookies (such as
_ga) to give us aggregate statistics about how the site is used. We do not use this data to identify individual visitors and we do not run advertising pixels there. - Portal sign-in. The Conciergr customer portal and signup use Sign in with Google. We receive your name, email address and Google account identifier, keep a session cookie on your device for up to 30 days so you stay signed in, and store no Google passwords or access tokens.
- WhatsApp connection. The signup pages (on both domains) load Facebook's SDK to run Meta's official WhatsApp signup flow; Meta's own data practices apply to that flow. An invite code you enter is kept in your browser's session storage only until signup completes.
Data we process on behalf of clients
Our core service is operating automated customer-messaging systems for business clients on the WhatsApp Business Platform. When we do so, we act as a data intermediary (processor) for the client, who remains responsible for the customer relationship. In that role we may process:
- Phone numbers and profile names of people who message our clients' WhatsApp business numbers;
- The content of those messages (text, and media such as images or voice notes), used solely to generate a relevant reply on the client's behalf;
- Delivery and read metadata needed to operate the service reliably.
Message content may be processed by our AI language-model provider (currently OpenAI, under API terms that do not permit training on the data) to generate replies. We do not use client customer data for advertising, we do not sell it, and we do not use it to train models.
Chat history imported at connection
When a client connects a WhatsApp number to our systems in coexistence mode, Meta provides a one-time copy of that number's recent conversation history (approximately the previous six months, both directions). Before any analysis, personal data inside the messages (names, phone numbers, email addresses and similar) is masked by software running on our own systems; only the masked text is then analysed by our AI language-model provider (currently OpenAI, under API terms that do not permit training on the data) solely to capture how the client's team writes, so the client's automated assistant can match their tone of voice. Once that analysis completes, we delete the imported history and every intermediate copy from our systems, unless the client asks us to retain it; what remains is a short description of writing style that contains no personal data. Imported history is not used for advertising, is not sold, and is never used to train AI models.
WhatsApp and Meta platform data
Our services are built on the WhatsApp Business Platform operated by Meta. Our access to and use of WhatsApp business data complies with the Meta Platform Terms and the WhatsApp Business Terms of Service. Messages are delivered through Meta's infrastructure and are also subject to WhatsApp's own privacy policy.
Retention
Conversation data processed for clients is retained only as long as needed to provide the service and maintain conversational context, or as directed by the client, after which it is deleted. Imported chat history is deleted once tone analysis completes, as described above. When a client's subscription ends, we retain their configuration and knowledge base for 90 days in case they return, then delete them.
Security
We protect personal data with reasonable security arrangements as the PDPA requires: data is held on access-controlled systems, transferred only over encrypted connections, masked before any external analysis, and accessible only to the people who operate the service.
Sharing and international transfers
We share data only with service providers necessary to operate our systems (e.g. Meta/WhatsApp for message delivery, cloud hosting providers, and our AI language-model provider for reply generation), and where required by law. We do not sell personal data. Some of these providers process data outside Singapore, including in the United States; where they do, we transfer data under contractual terms that require a standard of protection comparable to the PDPA.
Your rights
Under the PDPA you may request access to or correction of personal data we hold about you, or withdraw consent to its processing. If your data was processed as part of a client's messaging service, we may refer your request to the relevant client, who controls that data.
Changes to this policy
We may update this policy from time to time; the date above shows the current version. Material changes affecting active clients will be notified by email or via the service.
Contact
For privacy matters, contact our data protection contact at hello@lonut.systems. If you are not satisfied with our response, you may complain to Singapore's Personal Data Protection Commission (pdpc.gov.sg).