Privacy: Product Architecture Overview, Not a Legal Entity Policy
This page outlines how data is structured and processed within the volbor workspace. It is not a privacy policy for a specific corporate entity, not an exhibit to an agreement, and not a legal opinion under any single jurisdiction's laws. No legal entity name or registered address is stated on this website. If a different policy text was presented to you during registration or checkout, that document governs.
GDPR and comparable international data protection frameworks serve as a neutral conceptual baseline for discussing personal data handling. They are referenced strictly as operational benchmarks, not as a claim of official certification or statutory compliance.
Ambiguous Data Storage Risks
- Unclear workspace contents: Messages, agent identities, channel identifiers. Without an explicit data catalog, it is easy to make baseless promises like 'we never store anything.'
- Permissions broader than necessary roles: Entire conversation histories are exposed to every workspace member, even when only a specific front-line team handles support.
- Exfiltration to personal messenger apps: Conversation fragments forwarded to employee smartphones bypass central workspace access controls entirely.
- Disconnecting channels confused with permanent deletion: Disconnecting an integration stops incoming messages but leaves existing records stored in the database.
Data Types and Access Privileges
Data required to respond to customers
Message text, channel identifiers, and account profiles of teammates invited to the workspace. Without message content, support agents cannot maintain conversation continuity. The workspace stores this information strictly to power your business communications, not as a proprietary advertising profile that could be sold to third parties. The product maintains no external data marketplace or data broker exchange.
Who inside your organization can access it
Only users assigned appropriate roles. Configure permissions on our security and access control (ACL) pages. Sharing account credentials invalidates granular role-based security entirely.
What data flows into your external systems
Data only exports if you explicitly enable webhooks or APIs. In that scenario, your own infrastructure is the recipient, and retention policies are determined by your environment. If integrations are inactive, do not describe automated external exports to customers.
What to communicate to your customers
Your website terms and channel greeting messages should transparently disclose that conversation transcripts are visible to your support team within the workspace. volbor does not publish boilerplate disclosures in your chat widget automatically unless you configure the copy.
What This Page Does Not Claim
This page does not specify server host countries, exact retention windows in days, or named data sub-processors: these specific details are not published on this public website. It does not certify that your records have been erased until you complete the procedures on our data deletion page and confirm the outcome in your dashboard. Furthermore, this document does not constitute marketing consent from your end customers.
Frequently Asked Questions
Do you sell conversation data?
No commercial product offering third-party conversation feeds exists, nor does this page propose one. Who can view messages inside your workspace is strictly governed by your internal role configurations.
Can we cite GDPR as our applicable law?
Only if your organization and legal counsel have determined it applies to your operations. This website does not assign your jurisdiction or replace local statutory obligations with neutral terms.
Can other volbor customers view our conversations?
No. Roles and permissions are strictly isolated within your individual tenant workspace. This statement describes architectural tenancy, not an independent SOC 2 isolation audit or third-party certification.
Where can we request a copy of our data?
Directly within the options available in your workspace dashboard. There is no public administrative email address published on this website to receive email requests; please see our contacts page. Do not promise customers an export button that you have not verified.
How are file attachments handled?
They are stored as part of the conversation thread if the originating channel delivered them to Inbox. If a file attachment was blocked or failed to upload, do not claim in your policies that the file is stored.
Related Documentation
- Terms of Service
Why it's needed: To distinguish general workspace usage terms from technical data descriptions.
What happens without it: A single isolated paragraph risks being cited as the entire binding agreement. - Data Deletion
Why it's needed: To distinguish disconnecting an integration channel from permanently deleting conversation logs.
What happens without it: Customers may be mistakenly told that historical conversation records no longer exist. - Security
Why it's needed: To restrict who can open and view customer conversations.
What happens without it: Published storage practices will diverge from actual operational access levels. - Access Permissions (ACL)
Why it's needed: To actively configure granular roles rather than merely reading about theoretical permissions.
What happens without it: Security policies remain decorative website copy without technical enforcement. - Webhooks & API
Why it's needed: To account for automated data exports into external systems when integrations are active.
What happens without it: Customers are not informed of secondary data storage locations. - Contact Us
Why it's needed: To avoid searching for an email address that does not accept unauthenticated inquiries.
What happens without it: Inquiries are sent to unmonitored channels.


