Last updated: 5 September 2026
Privacy Policy
This policy explains which personal data is processed, for what purpose, where and for how long when you use the Dejavu service (the landing page at dejavu.dmrio.com, the business panel and the WhatsApp assistant). It is written according to how the system actually works; if a statement cannot be verified in the code, it does not appear here.
Service provider and data controller: Dejavu (dmrio.com). Contact: info@dmrio.com
1. Whose data do we process?
There are two groups of data subjects. The first is the business owners and their staff who sign up for Dejavu (the "Business"). The second is the end customers who book appointments by messaging the Business's WhatsApp number (the "Customer").
With regard to Business data, Dejavu is the data controller. With regard to Customer data, the Business is the data controller; Dejavu is the data processor, processing this data on behalf of and on the instructions of the Business.
2. Which data do we collect?
Business account: business name, name of the authorised person, phone number, e-mail address, branch details, list of services and prices, working hours, staff names, language preference, subscription plan and billing status.
WhatsApp connection: the Business's own WhatsApp account is connected via QR code. To keep the connection alive, session keys are stored on the server. Dejavu does not know and does not store the Business's WhatsApp password.
Customer data: WhatsApp phone number, WhatsApp profile name, appointment records (date, time, service, branch, staff member), the conversation history with the assistant (text) and, if a voice message was sent, its transcription.
Calendar integration: if the Business enables the Google Calendar connection, the access credentials are stored on disk encrypted with AES-256-GCM.
Technical records: server logs. Phone numbers are masked before being written to the logs.
The landing page does not use cookies and contains no third-party analytics or advertising scripts. The business panel only uses the session token required to maintain your session.
3. Why do we process it?
To book, reschedule and cancel appointments; to send WhatsApp reminders 24 hours and 1 hour before the appointment; to provide appointment, customer and daily summary information in the business panel; to manage subscriptions and billing; to answer support requests; and to keep the service secure and protected against misuse.
The conversation history is stored so that an ongoing booking flow with the same Customer (selected service, time, branch) can be continued. The customer memory feature reads previous appointments and preferences from these records.
4. Legal basis
Business data: formation and performance of the contract (subscription), legal obligations (invoicing and accounting records) and our legitimate interest in the security of the service.
Customer data: the Customer requests an appointment by messaging the Business's WhatsApp number; this processing is based on the formation and performance of the appointment relationship between the Customer and the Business. The Business is responsible for informing its own customers.
5. Where is the data stored?
The application and the database run in the Hetzner Online GmbH data centre in Germany.
So that the assistant can generate a reply, the message text is sent to AI providers (Google, Anthropic, OpenAI); some of these providers are located outside the European Union. The providers do not receive the phone number; they receive only the conversation text needed to generate a reply and the Business's service and hours information.
While messages travel over WhatsApp, WhatsApp's end-to-end encryption applies. The conversation history that reaches our server is stored in the database; the database file itself is not encrypted at the application layer but is protected at disk and access level.
6. Who do we share it with?
Your data is not sold to third parties and is not shared for marketing purposes.
The sub-processors we use to deliver the service: hosting (Hetzner, Germany), AI reply generation (the providers listed above), Google Calendar if the Business enables it, and the payment service provider used when paying for the subscription. Dejavu does not store card details.
In the event of a legal obligation (court order, request from a competent authority), only the data requested is shared, and only with the competent authority.
7. How long do we keep it?
While the account is active, data is kept for as long as it is needed for the service.
After the subscription is cancelled, data is retained for 30 days; if you return within this period, you continue where you left off. At the end of the 30 days, appointments, conversation records and customer details are deleted.
On your deletion request, appointments, conversation records and customer details are permanently deleted in a single operation (GDPR Article 17 — Right to Erasure). Invoicing and accounting records are kept separately for the statutory retention period.
8. How do we protect it?
Each business's data is kept under a separate identity; no business can access another's records.
Panel and API access is protected by keys verified with constant-time comparison, session tokens are signed with HMAC-SHA256, and request rates are limited.
Database queries use prepared statements and incoming data is validated against a schema. Calendar access credentials are encrypted with AES-256-GCM. Phone numbers are masked before being written to the logs.
9. Your rights
You have the right to access your data, to request its rectification, to request its erasure, to restrict processing, to data portability and to object. Send your request to info@dmrio.com; it will be answered within 30 days at the latest.
If you are a Customer, please first direct your request to the Business with which you booked the appointment; Dejavu carries out the Business's request. If you contact us directly, we will forward your request to the relevant Business.
If you are located in the European Union, you retain the right to lodge a complaint with your country's data protection authority; if you are located in Türkiye, with the Personal Data Protection Board (KVKK Kurulu).
10. Children
Dejavu is a service for businesses and does not open accounts for persons under 18. The obligation to verify a Customer's age rests with the Business.
11. Changes
When this policy changes, the date at the top of the page is updated. In the case of material changes, Business owners are informed by registered e-mail or via the panel.
Contact
For questions about these documents and for data requests: info@dmrio.com