Skip to content
Start free

Privacy Policy

Last updated:

This policy explains what data Risti handles, why, who receives it, how long we keep it and how you can have it deleted. We have kept it short and plain.

1. Who we are

Risti (risti.io) is operated by Individual Entrepreneur TASHMUXAMEDOV OLIMDJON NASIROVICH, registration No. 7322967, Qush Qo'ndi ko'chasi, 8-uy, Shayxontohur tumani, Toshkent, Uzbekistan.

In this policy, "Risti", "we" and "us" mean this operator. You can reach us at info@risti.io or +998 99 815 48 28.

2. What Risti does

Risti is a shared inbox for businesses. A business connects its channels, and its team answers customers from one place.

The channels a business can connect are: WhatsApp Business (through the WhatsApp Cloud API), Instagram messages and comments, Messenger where connected, Telegram, email and a chat widget on its website.

The team works with tickets and voice calls. Calls can be recorded, but only after a notice. Optional AI features (reply suggestions, call summaries and a phone assistant) work only when an organization turns them on itself.

3. Who is responsible for which data

If you wrote to a business that uses Risti, that business decides what happens to your messages. You can ask it directly, or write to us and we will pass your request on.

  • Conversations with a business's customers: the business is the controller. Risti processes this data on the business's behalf and follows its instructions.
  • Accounts of the business's team members: Risti is the controller.
  • Visitors of risti.io: Risti is the controller.

4. Data we receive from WhatsApp, Instagram and Messenger

When a business connects its WhatsApp, Instagram or Messenger account, we receive:

  • the content of messages and when they were sent;
  • attached files: photos, video, audio and documents;
  • the sender's display name;
  • the sender's phone number (WhatsApp);
  • the sender's username and profile id (Instagram, Messenger);
  • the sender's profile picture, where the platform provides it;
  • delivery and read statuses of messages;
  • comments on the business's posts (Instagram).
  • The access tokens of the connected accounts. We store them encrypted.

5. Other data

  • Messages from the other channels a business connects: Telegram, email and the website chat widget.
  • Voice calls. If the business turns recording on, the caller hears a notice first. Recordings and their transcripts are kept for 90 days.
  • Account data of the business's team members.

6. Why we use the data

We use the data only to provide Risti to the business:

  • to show the business's team the messages from all connected channels in one place;
  • to send the team's replies back to the customer through the same channel;
  • to run tickets and voice calls;
  • to produce AI results (reply suggestions, call summaries, the phone assistant), only when the organization has turned that feature on;
  • to send account emails to team members.

7. What we never do

  • We do not sell data.
  • We do not use data for advertising.
  • We do not use customers' messages to train models.

8. Who receives the data

  • Hosting and storage providers that run the service.
  • The messaging platforms themselves. A reply the business sends goes back through Meta, Telegram or the email provider.
  • AI providers, only when the organization has turned an AI feature on. Currently these are Anthropic and Google. They receive only the content needed for that result.
  • An email delivery provider, for account emails.
  • Authorities, where the law requires it.

9. How we protect the data

  • Data is encrypted in transit (TLS).
  • Message bodies are encrypted at rest, with a separate key for each organization.
  • Inside each organization, access depends on each team member's role.
  • A tamper-evident audit log records actions.
  • Our staff's access is read-only, and every access is recorded.

10. How long we keep the data

  • Messages: for the period the business sets in its settings (from 30 days to 10 years), or until the business or the person asks for deletion.
  • Call recordings and transcripts: 90 days.
  • Account data: while the account exists.
  • After an organization is closed, its data is deleted within 30 days.
  • Backups are overwritten on their normal rotation.

11. How to have your data deleted

You can ask for deletion at any time. The Data Deletion page explains the steps for customers of a business, team members and organization owners.

The short version: write to info@risti.io and tell us the business name and the phone number or username you used. We complete deletion requests within 30 days.

12. Your rights

You have the right to:

  • access your data;
  • have it corrected;
  • have it deleted;
  • withdraw your consent;
  • complain to the authority that supervises personal data.

13. Children

Risti is not directed to children under 16.

14. Applicable law

This policy follows the law of the Republic of Uzbekistan, including the Law "On Personal Data". Disputes are settled by the courts of Tashkent.

15. Contact

For any question about this policy or your data, write to info@risti.io or call +998 99 815 48 28.

Who operates Risti

Risti is operated by Individual Entrepreneur TASHMUXAMEDOV OLIMDJON NASIROVICH (registration No. 7322967). Address: Qush Qo'ndi ko'chasi, 8-uy, Shayxontohur tumani, Toshkent, Uzbekistan. Phone: +998 99 815 48 28. Email: info@risti.io

+998 99 815 48 28info@risti.io