Privacy Policy
Last updated: 6 July 2026
Pamio is a booking and management platform for businesses. Business administrators and team members use Pamio to schedule and manage appointments; customers interact with the business through chat (Telegram, WhatsApp) and, where enabled, phone calls. This policy explains what personal data we process, why, and your rights over it.
This policy covers the Pamio web application, the Pamio Android app (a wrapper around the same web application), and the chat/voice channels customers use to reach the business.
1. Who is responsible for your data
Pamio provides the platform. Each business decides what customer information to enter and how to use it — for that information the business is the data controller and Pamio acts as its data processor. For the accounts of business staff (administrators and team members) and for running and improving the service, Pamio is the controller. Questions either way: info@pamio.io.
2. Who can use the app
The Pamio app is for business administrators and team members (adults). Customers do not use the app — they interact with the business through Telegram, WhatsApp, or phone. There is no consumer/customer sign-up in the app.
3. What we collect
| Whose data | What | Why |
|---|---|---|
| Business staff (admins / team members) | Name, email address, phone number; a password (stored only as a secure hash) or a Google account used to sign in; the business’s details; sign-in and usage activity; usage analytics (pages viewed, features used) and session recordings of the app interface, with customer details and typed input masked. | To create and secure accounts, sign you in, and operate the app. |
| Customers (entered by the business) | Name, phone number, email; appointment and booking history; messages exchanged with the business’s assistant over chat; transcripts of phone calls (text only, where calls are enabled). | To schedule appointments, send reminders/confirmations, and let staff manage the customer’s bookings and conversation history. |
| Everyone | Basic technical data needed to run a web service (e.g. request and security logs). | Security, reliability, and abuse prevention. |
We do not collect payment-card details, precise device location, health data, or special-category data through the app. We do not record call audio — only a text transcript where calling is enabled.
4. How we use personal data
- Operate the service: scheduling, bookings, the in-chat assistant, reminders and notifications, and account management.
- Keep accounts secure and prevent abuse.
- Provide support and communicate about the service.
- Maintain and improve reliability and quality.
We do not sell personal data, and we do not use it for third-party advertising.
5. Legal bases (GDPR)
- Contract — to provide the service to a business and its staff.
- Legitimate interests — to secure, maintain, and improve the service — including analysing how staff use the app — balanced against your rights.
- Consent — where you opt in to something specific (e.g. browser notifications); you can withdraw it at any time.
6. Service providers we rely on
We use a small set of trusted providers (sub-processors) to run Pamio. They process data only on our instructions and under contract:
- Amazon Web Services (AWS) — hosting and storage, in the European Union (Ireland region).
- Google — sign-in for staff who choose “Sign in with Google”.
- Anthropic — powers Pamio’s AI assistant (processes the chat messages sent to the assistant).
- Telnyx — WhatsApp messaging and, where enabled, phone calls and number provisioning.
- Telegram — the Telegram messaging channel, where a business uses it.
- OpenAI — real-time voice for phone calls, where a school enables calling.
- Amazon SES — sending transactional emails (e.g. invitations, password resets).
- PostHog — product analytics and session replay for the staff app, hosted in the European Union (Frankfurt).
Where a provider processes data outside the EU/EEA, that transfer is covered by appropriate safeguards (such as Standard Contractual Clauses).
7. Where data is stored, and for how long
Pamio’s data is stored in the European Union (AWS Ireland). We keep personal data for as long as the relevant account is active and as needed to provide the service. When a business deletes its account, the associated data is removed; staff and customer records can also be deleted on request. Some limited records may be retained where required by law.
8. Security
Data is encrypted in transit (HTTPS/TLS). Passwords are stored only as secure hashes. Access is restricted and the platform runs inside a private network. No system is perfectly secure, but we take reasonable measures to protect personal data.
9. Your rights
Subject to applicable law, you can request to access, correct, delete, export, or restrict your personal data, and you can object to certain processing. Account holders can delete their account from within the app. To exercise any right, contact info@pamio.io — for customer data, the relevant business (as controller) may need to action the request, and we will assist.
If you are in the EU/EEA and have a concern, you may also lodge a complaint with your local data protection authority. In Ireland, this is the Data Protection Commission (dataprotection.ie).
10. Children
Pamio is not directed at children, and the app is used by adult business staff. Customer records are entered and managed by the business.
11. Changes to this policy
We may update this policy from time to time. We’ll change the “Last updated” date above and, for material changes, take reasonable steps to let account holders know.
12. Contact
Pamio · info@pamio.io