Privacy Policy
Last updated: 26 June 2026
This Privacy Policy explains how Dwosix SH.P.K. (“Dwosix”, “we”, “us”), operator of Barosa FrontDesk AI, collects, uses, shares, and protects personal data. It applies to our website, dashboard, and chat widget. We comply with the EU General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (FADP), and the Law on Protection of Personal Data of the Republic of Kosovo, as applicable.
1. Our role: controller and processor
We act in two different capacities depending on the data:
- As a controller for data about our business customers and their staff (account, billing, and website-visitor data we collect for our own purposes).
- As a processor for the personal data that our business customers process about their own End Users through the Platform (for example, the names, phone numbers, and messages of people who chat with a business’s widget). For that data, the business is the controller and our Data Processing Addendum governs how we handle it. End Users should contact the relevant business to exercise their rights over that data.
2. Personal data we collect
From business customers and staff
- Account data: name, email, password hash, business details, role.
- Billing data: plan, transaction records, and limited payment metadata (full card details are handled by our payment processor, not stored by us).
- Configuration data: knowledge base, services, prices, FAQs, opening hours, and AI settings you enter.
- Usage and technical data: log data, IP address, device/browser information, feature usage, and audit logs.
From End Users (as processor, on behalf of our customers)
- Contact and lead data: name, phone, email, requested service, and message content captured through the chat widget or channels.
- Conversation history and metadata (channel, timestamps, language).
We do not intentionally collect special-category data. You should not enter sensitive data (such as health or payment-card numbers) into chat unless strictly necessary and lawful.
3. How and why we use data (legal bases)
- To provide the Service — performance of our contract with you (GDPR Art. 6(1)(b)).
- To process AI interactions — sending message content to third-party AI providers to generate responses, on the basis of contract and our (and your) legitimate interests (Art. 6(1)(f)).
- Billing, security, fraud prevention, and audit logging — legitimate interests and legal obligation (Art. 6(1)(c) and (f)).
- Service emails and important notices — contract and legitimate interests.
- Marketing — only with your consent where required, which you can withdraw at any time (Art. 6(1)(a)).
4. AI providers and message content
To generate responses, conversation content is transmitted to third-party AI providers (such as OpenAI or Anthropic). These providers act as sub-processors and process the content to return a response. We select providers that contractually commit not to use submitted content to train their general models by default. Where you use your own Provider Key, your agreement with that provider also applies.
5. Who we share data with
- Sub-processors — AI providers, cloud hosting, email delivery, and payment processing partners, under data-processing agreements. A current list is available on request at privacy@barosa.ch.
- Messaging platforms — where you connect channels such as Messenger, Instagram, WhatsApp, or Telegram, message data flows through those platforms under their terms.
- Legal and safety — where required by law or to protect rights, safety, and security.
- Business transfers — in a merger, acquisition, or asset sale, subject to this Policy.
We do not sell personal data.
6. International transfers
Some providers may process data outside Kosovo, the EEA, or Switzerland. Where that happens, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms.
7. Data retention
We keep personal data only as long as necessary for the purposes above. Account and billing records are kept for the life of the account and as required by law (for example, tax records). Conversation and lead data is retained for the period configured by the relevant business customer or by default during the subscription, and deleted or anonymised within a reasonable period after account closure unless retention is legally required.
8. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. You also have the right to lodge a complaint with a supervisory authority (for example, the Information and Privacy Agency of Kosovo, your EU data-protection authority, or the Swiss FDPIC). To exercise your rights regarding data we control, contact privacy@barosa.ch. If your data was provided to a business using our Platform, please contact that business as the controller.
9. Security
We apply technical and organisational measures including encryption of secrets such as Provider Keys, encryption in transit, role-based access control, tenant isolation, rate limiting, input validation, and audit logging. No system is perfectly secure, but we work to protect data and to notify affected parties and authorities of breaches as required by law.
10. Cookies
Our website and dashboard use cookies and similar technologies. See our Cookie Policy for details and choices.
11. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children. End-User-facing widgets are operated by our customers, who are responsible for their own audiences.
12. Changes to this Policy
We may update this Policy from time to time and will post the new version here with an updated date. Material changes will be notified by email or in-app notice where appropriate.
13. Contact
Data controller: Dwosix SH.P.K., Rruga Xhevat Ajvazi 15, Gjilan, Republic of Kosovo.
Privacy contact: privacy@barosa.ch