Privacy Policy
Last Updated: August 29, 2026
This policy explains how Dubir Group LTD collects, uses, and protects personal data when you use Christine AI, our AI secretary service for solopreneurs and small businesses, and the website at christinehelps.com. We handle data in line with the EU General Data Protection Regulation (GDPR) and Cyprus data-protection law.
1. Controller
The data controller for your account data is Dubir Group LTD, a company registered in Cyprus (registration number HE 394277), registered office: Charalampou Mouskou & Grigori Afxentiou, 20, ATHINODOROU BUSINESS CENTER, 3rd floor, Flat/Office 306, 8010, Paphos, Cyprus. Privacy enquiries: [email protected].
2. Controller vs. Processor
There are two distinct roles to be aware of:
- For your account and our own operations (your name, login email, subscription, billing, usage), Dubir Group LTD is the controller.
- For the data of your customers (messages your customers send to your connected Instagram, Telegram, or iMessage channels, and the information they contain), you are the controller and Christine acts as your processor, handling that data on your instructions to reply to and assist your customers. You are responsible for having a lawful basis for that processing. We never use your customers' data for anything except operating your agent, and we do not train AI models on it.
3. What We Collect
You provide to us:
- Account data: your name, email address, and profile picture (when you sign in with Google), and billing details processed by Stripe.
- Business and agent configuration: your business information, instructions, knowledge files, and preferences you configure for your agent.
- Connected channel data: when you connect Instagram, we receive your Instagram Business account ID and an access token authorised through Meta's official login; when you connect Telegram or iMessage, the corresponding channel credentials. Messages, voice notes, photos, and documents sent to your connected channels are processed to generate replies and perform the tasks you request.
- Communications: messages you send to support.
Collected automatically:
- Technical & usage data: IP address, browser/device information, log data, and in-product usage (actions performed) needed to operate, bill, and secure the Service.
- Essential storage: an authentication token kept in your browser to keep you signed in.
- Analytics & advertising: our public marketing pages use analytics and advertising measurement tools (for example Google Analytics and Google Ads conversion tracking) that may set cookies or similar identifiers to measure traffic and campaign performance.
4. Instagram and Meta Platform Data
When you connect an Instagram Business or Creator account:
- We access it through Meta's official Instagram API with your explicit authorisation, using the permissions to read your basic account information and to receive and send direct messages on your behalf.
- Incoming DMs to your account are delivered to your dedicated agent, which uses them solely to generate replies and carry out your instructions. Conversation context is retained for your agent's memory while your account is active.
- Your Instagram access token is stored securely and used only to operate your agent. We do not sell or transfer Instagram data to third parties except the service providers listed in Section 6, and we use it only to provide the Service to you.
- Instagram policies apply to the channel itself — for example, replies are only possible within 24 hours of a customer's last message.
- You can disconnect Instagram at any time from your dashboard, which deprovisions your agent; associated channel data is deleted in line with Section 8. You may also request deletion at [email protected].
5. How We Use Data & Legal Bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide, maintain, and secure the Service | Performance of a contract |
| Process subscriptions, usage-based charges, and payments | Performance of a contract; legal obligation |
| Send service emails (e.g. sign-in codes, billing notices) | Performance of a contract |
| Improve and troubleshoot the Service; prevent abuse | Legitimate interests |
| Measure our website and advertising performance | Consent / legitimate interests |
| Comply with tax, accounting, and legal obligations | Legal obligation |
| Optional product updates or marketing (if offered) | Consent (you can withdraw at any time) |
We do not use your private messages or your customers' messages to train AI models.
6. Sharing & Sub-Processors
We do not sell your personal data. We share data only with service providers that help us run Christine, under contracts that require appropriate safeguards:
- Cloud hosting / infrastructure (Fly.io, EU region; Cloudflare): to run the application, your dedicated agent, and the website.
- Payment processing (Stripe): subscription and usage billing. Stripe handles the payment transaction as an independent controller of the payment data.
- AI model providers (e.g. Alibaba Cloud, OpenRouter): to process instructions and generate replies and documents. Content is processed to serve your requests and is not used by us to train models.
- Messaging platforms (Meta / Instagram, Telegram, Apple iMessage via LoopMessage): to receive and deliver messages on the channels you connect.
- Google: authentication (sign in with Google).
- Voice transcription (Groq): to transcribe voice notes you or your customers send.
- File storage (Backblaze B2): encrypted storage for files processed by the Service.
- Email delivery: to send account and service emails.
We may also disclose data where required by law, to enforce our Terms, or to protect rights, safety, and security. A current list of sub-processors is available on request at [email protected].
7. International Transfers
Where data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
8. Retention
We keep account data and agent configuration for as long as your account is active. Conversation history is retained while your account is active to give your agent memory and context. After you close your account or request deletion, we delete or anonymise personal data within 30 days, except where we must retain certain records (for example, billing and tax records) to comply with legal obligations. Log data is retained for up to 12 months for security purposes, then aggregated or deleted.
9. Your Rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability. Where processing is based on consent, you may withdraw it at any time. To exercise these rights, contact [email protected]; we will respond within 30 days. If your personal data was processed because you messaged a business that uses Christine, that business is the controller — please direct your request to them; we will assist as their processor. You also have the right to lodge a complaint with your local data protection authority.
If you are a California resident, you additionally have the rights to know, delete, and opt out of sale or sharing under the CCPA/CPRA. We do not sell or share your personal information as defined under the CCPA, and we will not discriminate against you for exercising your rights.
10. Security
All communications use TLS encryption; stored data is encrypted at rest. Each customer's agent runs in its own isolated environment. We apply role-based access controls and the principle of least privilege, and we will notify affected users of data breaches as required by applicable law. No method of transmission or storage is 100% secure.
11. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 18.
12. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will provide reasonable notice (for example, by email or in-app) and update the "Last updated" date above.
13. Contact
For any privacy question or request, email [email protected] or write to Dubir Group LTD, Charalampou Mouskou & Grigori Afxentiou, 20, ATHINODOROU BUSINESS CENTER, 3rd floor, Flat/Office 306, 8010, Paphos, Cyprus.