Legal

Privacy Policy

How Zoombot collects, uses, protects and deletes personal data.

Effective and last updated: 25 August 2026

1. Controller and scope

Zoombot is operated by Kirill Moiseev ("Zoombot", "we", "us"). This Policy applies to the Zoombot integration, its web pages, and its connections to meeting and team communication services.

Email: info@conmant.com.

2. Data we collect

Account and authorization data

  • Provider user and account identifiers, profile name and email when supplied by the provider.
  • OAuth access and refresh tokens. Tokens are encrypted at rest and are never displayed to another user.
  • Bitrix24 or Telegram user, installation, chat and message identifiers needed to deliver the requested workflow.

Meeting and content data

  • Meeting identifiers, titles, schedule, duration, host identity and join links.
  • Cloud recording metadata and, when the workflow requires it, recording files, audio, chat, transcripts and captions.
  • Generated summaries, decisions, action items and report delivery status.

Technical data

  • Signed webhook metadata, request timestamps, job status, security audit information and minimal diagnostic logs.
  • Necessary session cookies used to authenticate an embedded application. We do not use advertising or cross-site tracking cookies.

3. Why we process data

We process data only to provide and secure the functionality requested by the user:

  • connect an individual meeting account through OAuth;
  • list, create, update, start or delete that user's meetings;
  • publish a meeting card to a conversation chosen by that user;
  • download and process recordings or transcripts, produce a report, and return it to the originating conversation;
  • maintain account isolation, prevent fraud, diagnose failures and comply with deauthorization requests.

Depending on the context, the legal basis is performance of the service requested by the user, consent expressed through OAuth authorization, and our legitimate interest in operating a secure and reliable service. Where consent is the basis, it may be withdrawn at any time by disconnecting the integration.

4. Service providers and sharing

We do not sell personal data and do not use it for targeted advertising. Data is shared only as needed with:

  • the meeting provider, to perform the API operations requested by the user;
  • Bitrix24 or Telegram, to publish and update messages in the selected conversation;
  • transcription and AI processing providers, to create transcripts and summaries when those features are used;
  • infrastructure providers, to host encrypted tokens, application data and archived files;
  • authorities, only when legally required.

A report link shared into a conversation is accessible to recipients who possess that unguessable capability link. Users should share reports only in conversations whose participants are authorized to view them.

5. International transfers

Some providers may process data outside the user's country. Where applicable, we rely on the provider's contractual safeguards and other lawful transfer mechanisms. Users should also review the privacy terms of the meeting and communication services they connect.

6. Retention and deletion

  • OAuth credentials are retained while the connection is active and are removed when the user disconnects or the provider sends a valid deauthorization event.
  • Meeting metadata, locally archived files, transcripts and reports are retained while needed to provide the user's archive, until the user disconnects or requests deletion.
  • Cloud recordings may be moved to trash or deleted only after the service verifies that required local files and transcript data were saved correctly.
  • Short-lived authorization transactions and embedded sessions expire automatically.
  • Minimal security and operational logs may be retained for a limited period necessary to investigate abuse and reliability incidents.
A verified provider deauthorization event removes the provider connection and locally stored provider data for that exact user connection.

7. Security

We use encryption at rest for OAuth credentials, tenant-scoped database access, signed webhook verification, short-lived sessions, origin checks and least-privilege API scopes. No method of storage is perfectly secure; suspected incidents can be reported through our Security page.

8. Your rights and choices

Subject to applicable law, users may request access, correction, export, restriction, objection or deletion of their personal data. Users may disconnect the integration at any time from Zoombot or from the provider's marketplace. We may need to verify the requester before acting on a request.

To exercise a right or request deletion, use the instructions on the Support page.

9. Children

Zoombot is intended for workplace use and is not directed to children under 16. We do not knowingly collect children's data.

10. Changes

We may update this Policy when the service or legal requirements change. The effective date above will be updated, and material changes will be communicated through an appropriate service channel.

11. Contact

Privacy contact

Kirill Moiseev
info@conmant.com

Please include "Zoombot privacy request" in the subject. Do not email passwords, OAuth tokens or confidential meeting content.