RONUS

Effective August 18, 2026

Privacy Policy

This explains what personal data we process, why, who we share it with, how long we keep it and what you can do about it. It is written to be understood. If anything is unclear, write to privacy@ronus.tech and we will explain it in plain language.

1. Who we are

RONUS is the trading name of RUFUS TECH LLC, a limited liability company formed in the State of South Carolina, USA. The team works from Spain and the service is provided to businesses in Spain and the United States.

As a US entity offering services to people located in the European Union, the GDPR applies to us under Article 3(2), and we have appointed in writing a representative in the Union under Article 27. You may contact them about any matter concerning the processing of your data.

We have not appointed a Data Protection Officer. We do process data that may relate to health, but we do so on behalf of our clients and under a processing agreement, and the organisation's current size and structure do not meet the Article 37 thresholds. We will revisit this as processing grows. In the meantime, the privacy address performs that contact function.

  • Controller: RUFUS TECH LLC, trading as RONUS.
  • Address: 3 Vantage Way, Apt 123, Greenville, South Carolina 29611, USA.
  • State registration number and EIN: in progress. They will be published in this section as soon as they are issued.
  • EU representative (Art. 27 GDPR): Juan Felipe Pulgarín López, Paseo de Invierno 2, 6.º C, 31500 Tudela (Navarra), Spain.
  • Data Protection Officer: not appointed. Privacy contact: privacy@ronus.tech.
  • General contact: contact@ronus.tech · Billing: billing@ronus.tech · Security: security@ronus.tech.

2. The roles we play, and why it matters

We process personal data in three distinct situations, and the rules are not the same.

When you visit ronus.tech, fill in the sign-up or cancellation form, talk to the chat assistant or write to us, RONUS is the controller: we decide what we collect and why. This policy covers that in full.

When you open a business account in the app and use it, RONUS is also the controller of that account's data: your email address, how you sign in, your profile, your team invitations, your devices and the access log. It is a different processing operation from the one above and it has its own section, number 4.

When we operate Oubi for a business, whether a salon, a barbershop or a clinic, that business is the controller and RONUS is the processor. We process their customers' data on their instructions and under the Data Processing Agreement we sign with them, published at ronus.tech/dpa. We describe that processing transparently here, but the business is the one that decides the purposes and answers for the legal basis towards those people.

If you are a customer of a business that uses RONUS and want to exercise your rights over your data, you must contact that business. If you write to us, we will help you find the right controller and pass your request on without delay.

3. What the website collects, and why

In our role as controller, the website collects little and discloses all of it:

  • Sign-up form (ronus.tech/start): first and last name, business name, city, WhatsApp number, email address, the plan you are interested in and whether you want to join the founder programme. Legal basis: pre-contractual steps at your request (Art. 6(1)(b)) and your consent for us to write to you (Art. 6(1)(a)). We also store the date and the version of this policy you accepted, because Art. 7(1) requires us to be able to demonstrate consent.
  • Cancellation form (ronus.tech/cancel): business name, account email and, if you want to tell us, the reason. Legal basis: performance of the contract (Art. 6(1)(b)).
  • If you write to us on WhatsApp or by email: your number or address, your name if you share it, and the content of your message. Legal basis: legitimate interest in answering people who contact us (Art. 6(1)(f)).
  • Usage analytics: pages viewed, approximate country, device type and referrer, aggregated and without cookies or any personal identifier (Vercel Web Analytics and Speed Insights). We do not profile you and do not track you across sites. Legal basis: legitimate interest in knowing which parts of the site work (Art. 6(1)(f)).
  • Website chat ("Talk to Oubi"): what you type in that chat leaves our server for OpenAI, which reviews it and drafts the reply. We store neither your messages nor the replies, and the request is sent flagged so the provider does not keep them either. Legal basis: legitimate interest in answering people asking about the product (Art. 6(1)(f)). Do not type anything there you would not want sent to an artificial intelligence provider.
  • So that nobody floods that chat, your IP address and the identifier in the oubi_cid cookie (section 21) are turned into an irreversible code before being stored: we use it to count messages and apply a temporary block if needed. Neither the original IP nor the original cookie reaches the database. That counter is deleted after 7 days without activity. Legal basis: legitimate interest in protecting the service (Art. 6(1)(f)).
  • When you submit a form, our server receives your IP address, as any server does, and uses it only to throttle automated submissions. We do not store it and we do not send it to anyone.

4. What we collect when you open a business account in the app

Here too we are the controller and not a processor: what your business account collects, and what for, is decided by us, not by a client of ours.

Legal basis: performance of the contract and the pre-contractual steps you ask for when registering (Art. 6(1)(b)). The access log and the security checks rest on our legitimate interest in detecting improper access (Art. 6(1)(f)).

Recipients: the same providers listed in section 7, each for its own part. Nobody else receives this data, and it is neither sold nor shared for advertising.

How long we keep it: for as long as your business is a RONUS client and, afterwards, whatever section 12 says. A sign-up you start and leave half-finished deletes itself after 90 days. A request already resolved, approved or rejected, is kept [to be confirmed with counsel]. Here is what we collect and what for, bullet by bullet:

  • Sign-up request: your email address, the business name, the sector, the address, the city, the time zone, the currency, your website or Instagram if you give one, your phone number and the record that you verified it with a code, and the language you register in. The RONUS team reviews that request and notes whether it is approved or rejected.
  • How you sign in: a password, always stored encrypted and readable by no one at RONUS, or your Google or Apple identity if you choose to sign in with them. In that case we receive your email address and an account identifier from them, never your password.
  • Your profile inside the app: the email address, your role in the business (owner or team), the location you belong to, and the language you want the app in.
  • The invitations you send to your team: the invited person's email address and the status of the invitation.
  • The images you upload: your logo, the cover, your service photos and those of your public page.
  • The devices where you want to receive alerts: a notification identifier issued by Apple, Google or Expo, whether it is an iPhone or an Android, and the device language. It is not your number and it does not locate you.
  • Log of sign-ins and sensitive operations: who did what, when and from which IP address.
  • If you switch on payments: the identifiers of your Stripe account and its status. Card details never pass through our systems.
  • If you have an assistant: your business's artificial intelligence provider key, stored encrypted in a secrets vault, never visible from the app.

5. None of this is mandatory

Giving us your data is voluntary: no law and no contract requires it. The only consequence of not giving it is that we cannot reply or build anything for you.

The fields marked with an asterisk are the ones we need to do the work: without a business name and a way to reach you there is no possible setup.

6. What the service processes on behalf of our clients

When Oubi answers a business's WhatsApp or phone, we process data about the people who write or call. We do so as a processor. Depending on the case, the assistant and the platform may process:

  • Phone number and profile name of the person writing or calling.
  • The content of the conversation: WhatsApp messages, while it is being handled. Once the voice channel is active, also what is said on the call (section 10).
  • Appointment data: service, date, time, duration, price, status and changes.
  • Deposit data: amount, currency, payment status and its gateway reference. Card details never pass through our systems: Stripe collects and stores them.
  • Notes the business writes on a customer or appointment record. It is a free-text field: if the business records health information there (allergies, treatments), it becomes a special category under Art. 9 and its processing is the business's responsibility, which must have an Art. 9(2) basis. Our contract forbids using that field for health data without agreeing it with us first.
  • Reviews: first name, rating and comment, published on the business's public page. Only someone who had a real appointment can write one: reviews are tied one-to-one to the appointment and verified by the phone number used to book.
  • Date of birth, where the system asks for it to confirm that the person booking is an adult. It is kept for at most 24 months (section 22).
  • In the app's consumer account: your first and last name if you give them, an optional recovery email address (giving it or not does not change how long we keep your profile) and an optional profile photo, served only through signed links that expire (section 13).
  • The businesses you save as favourites in the app, so you can find them again.
  • The messages you write to a business from the app's chat: their text is kept for 90 days and then replaced (section 12).
  • The devices where you want to receive alerts: a notification identifier issued by Apple, Google or Expo, whether it is an iPhone or an Android, and the device language. It is not your number and it does not locate you.
  • The date of your last activity. It is generated by the system, not typed by you, and it is what decides when your profile is deleted for inactivity (section 12).
  • The record that the terms and minimum age notice was delivered to you before booking over WhatsApp: when it was delivered, which version of the text you saw, in which language, over which channel, the message's delivery reference and the booking it belongs to. It is the proof that acceptance took place.
  • What does NOT leave your phone: the categories you mark as your tastes in the app are stored only in the device's own secure storage. They never travel to our servers and they disappear if you uninstall the app.

7. Who we share data with (sub-processors)

To run the service we rely on technology providers. Each one that processes personal data does so under a processing agreement, solely to provide their service to us and never for their own purposes.

The full, current list, with each provider's purpose and location, is published at ronus.tech/subprocessors. We also announce additions and removals there in advance, as Article 28(2) requires. These are the main ones:

  • Supabase: database, authentication, file storage and realtime. European Union region (Ireland).
  • OpenAI: the language models that draft the replies of the assistant, of the insights panel and of this website's chat. United States.
  • Twilio: WhatsApp, SMS and phone number verification. United States.
  • Stripe: collection of subscription fees and deposits. United States and Ireland.
  • Vercel: hosting of this website and the public surfaces. A US company; the deployment runs in its Frankfurt (Germany) region.
  • Expo: push notifications and app builds. It receives the device's notification identifier and the text of every alert we send you. United States.
  • Cloudflare: content delivery network and secure access to our servers. United States.
  • Zoho: transactional email to businesses and to people who use the app (the recovery email code, the notice before deletion for inactivity), and receipt of this website's forms. It receives the email address and the content of the message. The account is hosted in its European Union region.
  • Google: Android notifications, app store and internal storage of each assistant's scripts. For notifications it receives the device identifier and the text of every alert. United States.
  • Apple: app store and iPhone notifications. For notifications it receives the device identifier and the text of every alert. United States.
  • OpenStreetMap (Nominatim), CARTO and unpkg: the app's map. When someone opens the page of a business that shows a map, it is their own device that looks the address up in Nominatim and downloads the map (CARTO) and the library that draws it (unpkg). They receive the business address and that device's IP address. European Union and United States.
  • Hetzner: the private server running the assistant's workflow orchestrator and our business API, with its own database; the conversational memory lives there. Germany (Nuremberg).
  • VAPI: provider announced for the future handling of voice calls. United States. It does not receive any data yet: the voice channel is not active, and we announce it here with the advance notice Article 28(2) requires (section 10).

8. International transfers

The main database is in the European Union. Several of the providers listed above are in the United States, so international transfers of personal data do take place.

Those transfers rely on the Standard Contractual Clauses approved by the European Commission and, where the provider is certified, on the EU-US Data Privacy Framework. We also apply supplementary measures: encryption in transit, minimisation of what is sent, and per-business isolation.

One nuance we prefer to say out loud: not all the US providers we use have EU data residency enabled. We are working on it and will announce it in this section when it changes. If you need the exact detail for your case, write to privacy@ronus.tech and we will give it to you in writing.

9. Artificial intelligence: what reaches the model

Oubi runs on third-party language models. You should know what leaves our systems towards them and what does not.

On each conversation turn, the model receives the incoming message, a window of that conversation's recent history, the phone number and profile name of the person writing, and the business's catalogue of services, prices and hours. It drafts the reply from that.

What the model does not do: it does not decide on its own whether or how much to charge. Amounts, availability and payments are resolved by our system with deterministic rules that the model cannot override. The business's insights assistant receives customer data pseudonymised: identifiers such as "Customer 3", never names.

We use these models through their APIs under their business terms, which state that data sent via the API is not used to train their systems. The specific data processing agreement with the main provider is in the process of being formalised, and this line will be updated once it is signed. When we ship a feature that changes what is sent, we will say so here before switching it on.

Oubi identifies itself as an assistant at the start of a conversation and never impersonates a person. The business, as the deployer, is the one that must inform its customers they are talking to an artificial intelligence system; we provide the mechanism for that notice to appear in the first message.

10. Voice calls

Today the assistant handles WhatsApp conversations. Voice call handling is announced and in preparation, and is not active yet: no call is processed or recorded. We prefer to say it here in advance, which is how new data recipients should be announced.

Once the voice channel is switched on: the audio will be processed in real time so the conversation can take place and will not be retained; what is said will stay, like the rest of the conversation, in the assistant's memory for the period in section 12. Announcing that the call is handled by an automated system, and whether it is transcribed, is the business's obligation as controller, and several US states and Spain have specific rules about it. RONUS will provide the notice at the start of the call, and this policy will be updated before the switch-on.

11. Automated decisions

Four things happen without a person intervening, and we would rather you knew about them:

If an appointment requires a deposit and the deposit is not paid within the set window, the appointment is cancelled automatically and a notice is sent. There is a cap on simultaneous active bookings per phone number, to prevent abuse. And a conversation with the assistant can trigger a cancellation or a refund, always through deterministic checks that verify amount, currency and status against the gateway before any money moves, and that fail closed.

The fourth one: when you book, our server infers which country you are in from your IP address and compares it with the country of the business. If they do not match, the booking is refused. It is a measure against fraudulent use from another country; we store neither that country nor the IP address anywhere, and if either of the two cannot be determined, the booking is NOT blocked. If you are travelling and still need to book, write to the business or to support@ronus.tech.

We do not carry out profiling with legal effects on you, nor Article 22 automated decisions that significantly affect you. The platform does compute internal groupings of the business's own customers (who has not returned, who misses appointments), which the business uses to run itself. If you believe an automated decision has harmed you, write to us and a person will review it.

12. How long we keep each thing

Almost all of these periods are scheduled jobs that run against the database on their own and can be verified. The few that are applied by hand today, or that are still to be set, say so in their own bullet: we would rather publish the real state than a number that is not met.

  • SMS verification codes: deleted 24 hours after they expire.
  • Assistant conversation content (the memory Oubi uses to remember what you were discussing): 30 days.
  • Text of in-app chat messages: 90 days. After that the text is replaced and only the record that a message existed remains.
  • Context of an incomplete payment: 48 hours.
  • Notification queue and receipts: 30 days; queue history, 90 days.
  • Audit log, including IP address: 12 months, and then the whole row is deleted. The exception is four entries that make up a business's file (its closure, its suspension, its reactivation and the rejection of a sign-up request): those rows are kept longer, but after 12 months they lose the IP address and any detail beyond the minimum needed to know what happened. We keep them under legitimate interest in being able to investigate improper access and to reconstruct a business closure years later.
  • Record of a business account deletion: 90 days from completion. If any residue remains unresolved, that record is kept until it is resolved, and may therefore exceed 90 days in those specific cases.
  • Internal erasure log: when a deletion runs we note what was deleted and how many rows, with a random identifier and none of the person's data. It is the proof that the erasure happened, and today it is kept with no set period.
  • Commercial contact data from the website form: up to 24 months from the last contact, or until you ask us to delete it. We apply this period by hand, because those forms arrive in our mailbox and not in the database; if you want yours deleted sooner, write to us and we will do it.
  • A business's sign-up request: if you start it and do not finish it, it deletes itself after 90 days. Once resolved, approved or rejected, it is kept [to be confirmed with counsel].
  • The comment you leave when abandoning sign-up: 12 months; after that the text is deleted and only the count remains.
  • Record of acceptance of the terms before booking: today it is not purged, and its period is [to be confirmed with counsel]. It is the proof that acceptance took place, and losing it is worse than keeping it too long.
  • Anti-abuse counter for this website's chat (the IP address and the cookie turned into an irreversible code): 7 days without activity, unless a block is in force.
  • Consumer profile in the app (your booking account): deleted after 12 months of inactivity, whether or not you added an email. Before deleting it we notify you by email or by push notification, whenever we have one of the two; if we cannot reach you by either route, the deletion goes ahead anyway, because a retention period cannot stay suspended forever. Signing in again is enough to keep the account.
  • Record of ownership of a verified phone number: 24 months. It ensures that if your number is recycled and given to someone else, that person does not see your data.
  • Invitations to join a business: 90 days if not accepted. The trace of an accepted invitation is deleted when the account it granted access to ceases to exist, and after one year at most.
  • Technical integration events: 12 months; only the most recent of each type is kept, as a marker that the integration worked at some point.
  • A business's customer records, appointments and reviews: for as long as that business is a RONUS client. The business, as controller, decides whether to delete them sooner, and can rectify and erase them from its own panel.
  • Billing and payment records: for as long as applicable tax and commercial law requires. If a business cancels its account, its record of payments and refunds is archived and kept for 6 years from each transaction; after that it is deleted.
  • Backups: rotating, encrypted copies. Data deleted in production disappears from backups when the rotation reaches them, not at the same moment. Until then it is isolated and would only be used to restore service after a disaster.

13. Security

What we actually do:

  • Encryption in transit (TLS) and encryption at rest in the database.
  • Strict isolation between businesses via row-level security in the database itself: one business cannot read another's data even if it tries, and that includes files.
  • Mandatory second factor and recent re-authentication for RONUS staff before any sensitive operation, with an allowlist of addresses.
  • Redaction of emails, phone numbers and identifiers in all our server logs: personal data does not end up in a log file.
  • Photos and files are served through signed links that expire within an hour: having an image's address is not enough to view it.
  • Every payment is verified against the gateway before being treated as valid, failing closed: if we cannot confirm it, we do not assert it.

14. If there is a security breach

If we detect a security breach affecting personal data, we record it in our internal breach register, notify the affected business without undue delay and, where required, the supervisory authority within the 72 hours of Article 33 and the affected individuals under Article 34.

If you believe you have found a security flaw in our systems, write to security@ronus.tech. We will not take action against anyone who reports in good faith and without accessing third-party data beyond what is strictly needed to demonstrate the flaw.

15. Your rights (European Union)

Over the data for which we are the controller, you may exercise:

  • Access: know what data of yours we hold and obtain a copy.
  • Rectification: correct anything wrong or incomplete.
  • Erasure: ask us to delete it, where it is no longer necessary or you withdraw consent. If you delete your consumer account in the app, your record in the CRM of every business where you booked is anonymised with a code, no name and no phone number, in one go, without having to ask each business separately. Your published reviews are kept, because they are opinions about a business and carry only your first name; if you also want them removed, ask and they are removed.
  • Restriction: ask us to keep it but stop using it while a dispute is resolved.
  • Objection: object to processing based on legitimate interest, including commercial communications. The WhatsApp assistant applies it on its own: if you write that you do not want to receive more messages, it records your objection automatically and that business stops contacting you through that channel.
  • Portability: receive in machine-readable format the data you gave us, and have us pass it to another provider where technically feasible.
  • Withdraw your consent at any time, without affecting what we did with it beforehand.

16. How to exercise them and where to complain

Write to privacy@ronus.tech, or to the EU representative at the address in section 1. No form and no particular wording is needed: just tell us what you want. We reply within one month, extendable to two if the request is complex, in which case we tell you before the first month ends. It is free, except for manifestly unfounded or repetitive requests.

We will only ask you to prove your identity if we have reasonable doubts about who you are, and only as far as needed to resolve them.

If you believe we have mishandled your data you may complain to the Spanish Data Protection Agency (www.aepd.es) or to the supervisory authority of your country of residence. We would appreciate hearing from you first, but it is not a requirement.

17. Notice for United States residents

If you reside in California, Virginia, Colorado, Connecticut, Utah, Texas or another state with a consumer privacy law, you have the right to know what personal information we collect, to obtain a copy, to correct it, to request its deletion and not to be discriminated against for exercising those rights. They are exercised the same way: by writing to privacy@ronus.tech.

Categories of personal information we process, in CCPA/CPRA terms: identifiers (name, phone, email, WhatsApp number); commercial information (requests, appointments, bookings, interaction history); internet activity (pages viewed and technical data, in aggregate); audio and electronic information (the content of calls and messages); and, in the service for dental and aesthetic sectors, information that may relate to health.

Sources: from you when you fill in a form or write to us; automatically from your browser; and, in the service, from the client business and its own customers.

Sensitive personal information (SPI): the health-related information we process in the service is treated as SPI under the CPRA. We use it only to provide the service the client asked for and for legally permitted purposes; we do not use it to infer characteristics about you. You may ask us to limit its use by writing to privacy@ronus.tech.

You may appoint an authorised agent to exercise your rights on your behalf; we will ask them for proof of authorisation.

18. We do not sell your personal information

We do not sell personal information and we do not share it for cross-context behavioural advertising, in the sense the CCPA/CPRA and other US state laws give those terms. We never have and it is not part of our business model: our revenue comes from the fees businesses pay.

There is no advertising pixel, third-party analytics SDK or social network integration in any of our systems. That is why this site has no "Do Not Sell My Information" button: there is nothing to switch off.

19. HIPAA and healthcare clients

If you are a US client handling Protected Health Information (PHI), such as a dental clinic or a medical aesthetics centre, RONUS acts as a Business Associate and we sign a Business Associate Agreement before processing a single record. The template is published at ronus.tech/baa.

Without a signed BAA we do not process PHI. If a client enters PHI into the system without having signed the BAA, they are in breach of our contract and we will say so.

20. Messages we send

Everything that leaves our systems towards a person today is transactional: appointment reminders, cancellation notices, verification codes and activity notifications to the business owner. None of it is advertising.

If we ever send commercial communications, it will be with your prior consent and with a clear way to opt out in every message. Messages to the number you leave in the sign-up form are to answer what you asked for.

A note about what our clients do: the app lets a business owner message their own customers from their own phone. Those messages do not come from RONUS and the business answers for them, including any rules on commercial messaging that apply to it.

21. Cookies

This website uses no analytics or advertising cookies, and carries no banner because there is nothing to consent to. The only cookie this site may leave you is oubi_cid, which appears if you write to the chat assistant and serves only to stop abuse. That one, and those of the app and the panel, are strictly necessary and are detailed, with name, purpose and duration, in the Cookie Policy: ronus.tech/cookies.

22. Minors

The service is aimed at businesses and adults. You must be 18 or over to contract and operate a business account.

Booking also requires being an adult, and we do not delegate that to the business: the app and the assistant ask you to declare you are over 18 before completing a booking, and where the system asks for your date of birth to confirm it, that date is kept for at most 24 months. We do not direct the service at minors and do not market it to them.

If you believe we hold data about a minor that we should not, write to privacy@ronus.tech and we will delete it.

23. Changes to this policy

When we change something we will update the date above. If the change is material (a new purpose, a new recipient, a longer retention period), we will notify clients at least 30 days in advance by email, and account holders inside the app.

Previous versions are retained and we will send them to you on request.

24. Contact

Write to us. We answer.

  • Privacy and rights requests: privacy@ronus.tech
  • Security: security@ronus.tech
  • Contracts, DPA and BAA: legal@ronus.tech
  • Billing and cancellations: billing@ronus.tech
  • Everything else: contact@ronus.tech
  • Postal mail: RUFUS TECH LLC, 3 Vantage Way, Apt 123, Greenville, SC 29611, USA.
  • EU representative: Juan Felipe Pulgarín López, Paseo de Invierno 2, 6.º C, 31500 Tudela (Navarra), Spain.