Privacy Policy

Last updated: July 15, 2026

1. Data controller

Bongga SAS, domiciled in Colombia, is the data controller for the personal data collected through the app.bongga.dev platform and the bongga.dev website, in accordance with Colombian Law 1581 of 2012 and Decree 1377 of 2013.

Controller contact: support@bongga.dev

2. Data we collect

  • Sign-up data: company name, user name, email, and selected plan.
  • CRM usage data: WhatsApp conversations processed on the platform, contacts, leads and their contact details (name, phone, email where applicable), tags, notes, AI agent configurations, flows, and campaigns.
  • Advertising lead data: when the customer connects Meta Lead Ads or TikTok Lead Gen, we receive the data the person entered in the ad form (name, phone, email, and any other fields the customer configured in their ad).
  • Voice call data: if the customer enables voice agents, we process call metadata (duration, outcome) and, if the voice provider supports it and the customer enables it, the conversation transcript.
  • Payment data: handled directly by Mercado Pago. Bongga does not receive or store full card numbers or security codes; we only receive the subscription status and billed amounts.
  • Technical data: IP address, browser, operating system, access logs, and, on the public site, aggregated browsing analytics (Google Analytics).

We do not intentionally collect data from minors under 18 or sensitive data under article 5 of Law 1581 (health, sexual orientation, biometric data, among others), unless the customer itself enters such data into the platform to run its business (for example, clinics or medical practices that record patient information), in which case the customer acts as the data controller for that data with respect to its own data subjects, and Bongga acts solely as a data processor on the customer's behalf for that information.

3. Purposes of processing

  • Creating and managing the customer's account and organization on the platform.
  • Providing the contracted services: CRM, automation, AI agents, voice calls, and multichannel support.
  • Processing recurring payments through Mercado Pago and applying access restrictions for non-payment.
  • Sending transactional communications (activation, billing, support, service changes).
  • Improving the platform through aggregated, anonymized analysis.
  • Preventing fraud, abuse, or misuse of the platform.
  • Complying with applicable legal obligations in Colombia.

4. Data processors and international data transfer

To provide the service, Bongga shares data with the following data processors, each limited to its corresponding purpose:

  • Meta Platforms (WhatsApp Business API, Meta Lead Ads): sending/receiving messages and capturing advertising leads.
  • TikTok: capturing leads from ad forms (TikTok Lead Gen), when enabled by the customer.
  • AI model providers (routed through OpenRouter, including providers such as Anthropic, OpenAI, DeepSeek, or others depending on the agent's configuration): they process conversation content solely to generate the agent's automated replies. Bongga configures these integrations so that this content is not used to train these third parties' models, to the extent the relevant provider's policy allows it.
  • Vapi (or another voice provider configured by the customer): originate and manage phone calls with AI agents.
  • Mercado Pago: payment and subscription processing.
  • Supabase and DigitalOcean: hosting for the database and application infrastructure.
  • Google Analytics: aggregated analytics for the public site (not the authenticated panel).

Some of these processors process data on servers located outside Colombia. By using the platform, the customer authorizes this international transfer and transmission of data, which is carried out under each provider's security standards. We do not sell personal data to third parties for commercial or advertising purposes.

5. Data subject rights

Under Law 1581, the data subject has the right to:

  • Know the data Bongga holds about them.
  • Update and correct their data when inaccurate.
  • Request proof of the authorization given.
  • Revoke the authorization and request deletion of their data.
  • Access their data free of charge.

When the data subject is a customer or patient of a business that uses Bongga (not a direct Bongga user), they must first direct these requests to that business, which is the data controller for their data; Bongga will assist as data processor in handling them.

To exercise these rights, write to support@bongga.dev. We respond within a maximum of 15 business days.

6. Security

We implement technical and organizational measures to protect data: encryption in transit (TLS) and at rest (AES-256-GCM) for credentials and sensitive integrations, role-based access control, logical isolation per organization (each customer only accesses its own data), and audit logs for relevant operations. No system is 100% secure; in the event of a security incident affecting personal data, we will notify as required by applicable law.

7. Data retention

We retain data while the account is active and for the additional period required by applicable rules (including accounting/tax obligations). Upon cancellation of the service, the customer may request deletion of its data; we may retain encrypted backup copies for a reasonable additional period before final deletion.

8. Cookies and analytics

Bongga's public site uses necessary technical cookies and Google Analytics to understand aggregated site usage. The authenticated panel uses only cookies strictly necessary to maintain the session.

9. Changes to this policy

We will notify significant changes by email or within the panel at least 15 days in advance. The current version will always be available at this same address.