Privacy Policy & Personal Data Protection
Committed to complete transparency, confidentiality, and data minimization in full compliance with Kuwait CITRA DPPR (Regulation No. 26 of 2024).
1. Scope & Core Definitions
This Privacy Policy explains how AUTONIQUE collects, processes, and protects personal data from website visitors, subscribing clinic and salon businesses, and end customers/patients interacting with our WhatsApp AI booking assistant.
2. Personal Data We Process
We collect and process only the minimal data strictly necessary to facilitate, confirm, and remind users of appointment bookings:
Contact Identifiers
Name, WhatsApp mobile number, and business contact email address.
Booking Details
Requested specialty, selected practitioner/stylist, appointment slot, and reschedule history.
3. WhatsApp Messaging Consent & Opt-Out
In accordance with Meta Business terms and Kuwait telecommunications standards, automated booking updates and reminders are only transmitted following explicit user opt-in. Any user can immediately opt out of follow-up notifications at any time by replying STOP.
“By submitting, you agree that Autonique may contact you on WhatsApp about this enquiry, including follow-up messages. Reply STOP at any time to opt out.”
4. Data Protection Mechanisms for Sensitive Data
AUTONIQUE implements comprehensive, multi-layered technical and organizational security mechanisms to protect all sensitive personal data, user credentials, and OAuth tokens against unauthorized access, alteration, disclosure, or destruction:
Encryption at Rest & in Transit
All sensitive records, OAuth tokens, and calendar credentials are encrypted at rest using industry-standard AES-256 encryption, and encrypted in transit using TLS 1.3.
Role-Based Access & Least Privilege
Access to authentication tokens and sensitive records is strictly restricted to authorized system services under least-privilege principles with immutable audit logging.
Key Management & Tenant Isolation
Cryptographic keys are managed via cloud Key Management Services (KMS) with automated key rotation and strict multi-tenant database isolation.
Vulnerability Scanning & Monitoring
Infrastructure is continuously monitored with automated vulnerability scanning, rate-limiting, and real-time threat detection.
5. Data Retention & Zero Third-Party Sale
AUTONIQUE does not sell, lease, or monetize customer or patient data with third-party advertisers. Information is retained solely for the duration required by our business clients to service appointments and satisfy statutory obligations under CITRA regulations.
6. Google Calendar Data
1. Data We Access: When you connect Google Calendar, Autonique accesses the calendar information required to provide the integration (via the calendar.events OAuth scope), such as event details, dates, times, and event identifiers, from the calendars you authorize. We do not access your Gmail, contacts, or Google Drive files through this integration.
2. How We Use Google Calendar Data: Google Calendar data is used solely to provide and operate the calendar integration, including synchronizing appointments, handling rescheduling and cancellations, and keeping the dashboard and the connected Google Calendar in sync. Google user data is not used to develop, improve, train, or fine-tune generalized artificial intelligence or machine learning models, and is not used for advertising or marketing profiling.
3. Sharing and Protection: We do not sell, rent, or share Google user data with third parties except where necessary to provide the requested service or where required by law. OAuth credentials and tokens are protected using appropriate security measures (encryption at rest and in transit) during storage and transmission.
4. Retention and Deletion: You can disconnect Google Calendar from your dashboard at any time. You can also revoke Autonique's access through your Google Account Permissions. When you disconnect the integration, we remove the OAuth credentials and calendar connection data that we no longer need to provide the service. You may also request deletion of your Google-related data by contacting us at hello@autonique.ai.
Autonique's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the features described above and is not used to train generalized or non-personalized AI/ML models.
Privacy Inquiries & Data Rights
To request data access, rectification, or permanent record deletion, reach out to our privacy administration desk: