Privacy Policy

Last updated: 4 September 2026

1. Introduction

OTONO.MY (“OTONOMY”, “we”, “us”) is a product of Cansolve Digital Inc., the company responsible for the platform and the data controller for this policy. OTONOMY provides a platform that lets businesses configure specialized Experts to run conversations and business processes across voice, WhatsApp, SMS, email, social messaging, and calendar. This policy explains what we collect, why, and the choices you have. It applies to our website and the OTONOMY application.

2. Information we collect

Account & billing

Name, email, organization details, and billing information you provide when you create an account or subscribe to a plan.

Configuration data

Departments, Business Processes, Expert instructions, knowledge sources, and campaign settings you create inside the platform.

Conversation data

Call audio and transcripts, messages, email content, and metadata generated when your Experts communicate with your contacts on your behalf, along with derived intelligence such as summaries and lead scores.

Usage data

Log data, device and browser information, and product analytics used to operate and improve the service.

3. How we use information

4. Communications channels

OTONOMY operates through third-party channels including telephony providers, the WhatsApp Business Platform, SMS gateways, and email infrastructure. When your Experts communicate through these channels, message and call content is processed by those providers under their own terms in addition to ours. You are responsible for obtaining any consent required to contact your customers and for complying with applicable communications and marketing laws in your jurisdiction.

5. Meta Platform Data

Cansolve Digital Inc. is a Meta Tech Provider. When you connect a Facebook Page, an Instagram professional account, a WhatsApp Business Account or a Meta ad account to OTONOMY, we receive information from those accounts through Meta’s APIs (“Platform Data”). This section governs Platform Data specifically and applies in addition to the rest of this policy.

What we receive

Messages and comments people send to your Page, Instagram account and WhatsApp Business number, and the profile name and identifier of the person who sent them; the posts, media and stories on your accounts and their reach and engagement figures; your advertising accounts, campaigns, creatives, spend and performance metrics; leads submitted through your lead ads; your WhatsApp message templates and their approval status; and the identifiers of the assets you connected.

Our role

You remain the business responsible for your own accounts and for the people who contact you. We act as your service provider and process Platform Data on your documented instructions and on your behalf, for the purposes below and no others. Where your customers’ personal data is involved, you are the controller and we are the processor.

What we use it for

What we will not do

Retention and deletion on disconnect

You can disconnect any Meta account at any time in OTONOMY Settings, and you can remove OTONOMY from your Meta Business settings directly. Disconnecting revokes our access immediately and stops all further collection. On disconnection, on deletion of your OTONOMY account, or on a deletion request from you, we delete the Platform Data associated with that connection from our production systems within 30 days, and from backups within 90 days, except where a longer period is required by law. We also delete Platform Data when it is no longer needed for the purposes above, and we honour deletion signals we receive from Meta. To request deletion directly, email one@otono.my from the address on your account.

Security and transfers

Platform Data is encrypted in transit and is held in an access-controlled managed database that is encrypted at rest. The access tokens for your connected accounts are additionally encrypted by us (AES-256-GCM) before they are stored, so they are not readable from the database itself. Tokens are held server-side only: they are never returned to your browser and never made available to another customer’s workspace. Access by our staff is limited to the smallest number of people needed to operate and support the service. Platform Data may be processed in countries other than your own by the sub-processors in section 6; where required we rely on appropriate transfer safeguards.

Meta’s terms

Our use of Platform Data is additionally governed by the Meta Platform Terms and the Meta Developer Policies, and — for WhatsApp — the WhatsApp Business Terms. Where those terms are stricter than this policy, those terms apply. Information you receive from Meta through OTONOMY remains subject to Meta’s terms in your hands as well as ours.

6. Google user data

When you connect a Google Account to OTONOMY, you authorise us through Google OAuth to access specific data from that account. We request the narrowest scopes that let your Experts do the work you have asked them to do, and we request them only for the features you choose to switch on.

What we request, and why

Signing in. openid, email and profile — your name, email address and profile picture, used to create and sign you in to your OTONOMY account. This is all we ask for at sign-up.

Calendar. calendar.events — so an Expert can read your availability and create, reschedule and cancel the appointments your customers book. The read-only equivalent is not sufficient because booking requires writing events. We do not request the broader calendar scope: we never create, delete or re-share calendars themselves.

Contacts. contacts.readonly — so an Expert can match an incoming phone number or email address to your contacts, greet a returning customer by name, and file the conversation against the right record. We never write to your contacts.

Mailbox, only if you connect one. If you explicitly connect a Google mailbox so that an Expert can read and send email on your behalf, we request https://mail.google.com/. This is never requested at sign-up or sign-in, only when you choose to connect a mailbox, and you can disconnect it at any time.

How we use, store and share it

Google user data is used solely to provide the features described above, in response to actions you or your customers take. It is never used for advertising, never sold, and never used to train generative AI or machine learning models. OAuth access and refresh tokens are held encrypted at rest in Google Secret Manager and Google Cloud SQL in the United States. Calendar, contact and message data is fetched when it is needed to complete an action and retained only as long as that requires — we do not maintain a standing copy of your mailbox, calendar or address book.

We do not share Google user data with third parties, except with infrastructure sub-processors acting on our instructions and bound by contract. No member of our staff reads your Google user data, except where you have explicitly asked us to in order to resolve a support issue, where it is necessary for security purposes such as investigating abuse, or where we are compelled to by law.

Revoking access

You can disconnect your Google Account at any time from Settings → Profile inside OTONOMY, or at myaccount.google.com/permissions. When you revoke access, or when you delete your OTONOMY account, we delete the associated tokens and any cached Google user data within 30 days.

Limited Use

OTONOMY’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Sharing & processors

We share data with sub-processors that help us deliver the service — including cloud hosting, telephony and messaging providers, model providers, and analytics. We require appropriate safeguards from each. We may disclose information where required by law or to protect the rights and safety of users and the public.

8. Data retention

We retain conversation and configuration data for as long as your account is active or as needed to provide the service, then delete or anonymize it within a commercially reasonable period unless a longer period is required by law. You can request export or deletion as described below.

9. Your rights

Depending on your location, you may have rights to access, correct, export, or delete personal information, and to object to or restrict certain processing. To exercise these rights, contact us at the address below. If you are an end customer of an OTONOMY user, please contact that business directly, as they control the relevant data.

10. Security

We use industry-standard measures including encryption in transit, access controls, and monitoring. No system is perfectly secure, but we work to protect your data and to notify you of material incidents as required by law.

11. Contact

Questions about this policy? Email one@otono.my. OTONOMY is operated by Cansolve Digital Inc.