GlowBotBack to home

Privacy Policy

Last updated: 14 June 2026

This policy reflects how GlowBot handles data. It is a working draft and should be reviewed by qualified counsel in Vietnam before being relied on as a binding agreement.

1. Who we are and what this policy covers

GlowBot provides an outsourced AI patient-success service for beauty and aesthetic clinics in Vietnam. We operate on a clinic's existing Zalo Official Account and Facebook Page to answer inbound messages, book appointments, and run patient-lifecycle follow-up.

This policy explains how we handle personal data for clinic users (owners and staff who log in to the dashboard) and customers (individuals who message a clinic through a channel GlowBot operates on that clinic's behalf).

Our role. For customer data, each clinic is the data controller and GlowBot is a data processor acting on the clinic's instructions. For clinic account data, GlowBot is the controller. We never use one clinic's data for another clinic, and we never sell personal data.

2. Data we collect

Clinic account data. Name, email, role, language preference, hashed login credentials, and session activity for dashboard users.

Channel and customer data. When a customer messages a connected Zalo OA or Facebook Page: message content, the platform-provided sender identifier and display name, timestamps, and any details the customer shares.

Clinic operational data. Information a clinic enters to run the service: treatments, pricing, promotions, staff and equipment profiles, FAQs, appointments, and patient records the clinic chooses to add.

Technical and usage data. Logs needed to run and secure the service, including IP address, request metadata, and an audit trail of sensitive actions.

Encrypted channel credentials. Access and refresh tokens for a clinic's Zalo OA and Facebook Page, stored encrypted and never shown to dashboard users.

3. How we use data

  • Operate the service: answer messages, qualify inquiries, book appointments, and run lifecycle follow-up.
  • Generate AI replies (see Section 5).
  • Attribute bookings under transparent, inspectable rules and prepare billing.
  • Provide the dashboard, support, security monitoring, and audit logging.
  • Comply with law and enforce our terms.

We do not use personal data for cross-clinic analytics, profiling across clinics, or advertising.

4. Legal bases

Where applicable law requires a legal basis, we rely on performance of our contract with the clinic, the clinic's and customers' consent for messaging on the relevant channel, and our legitimate interests in operating and securing the service in a way that does not override individual rights.

5. AI processing

GlowBot uses Anthropic's Claude models to generate conversational replies and lifecycle messages. Relevant conversation context and clinic knowledge are sent to Anthropic's API to produce a response. Under Anthropic's commercial API terms, this content is not used to train Anthropic's models. AI output is generated automatically, and clinic staff can take over any conversation at any time.

6. Sharing and subprocessors

We share personal data only with service providers that help us run GlowBot, under contract and only as needed:

SubprocessorPurposeRegion
AnthropicAI model processing (Claude API)United States
SupabaseDatabase, authentication, storageSingapore
RailwayApplication hostingUnited States / regional
Zalo (VNG)Messaging and ZNS on the clinic OAVietnam
Meta PlatformsFacebook Page messagingUnited States / regional

We also disclose data where required by law or to protect rights and safety. We do not sell personal data, and we do not share data between clinics.

7. Data isolation and security

  • Per-clinic isolation. Every record is stored with a clinic ID, and every request is checked against the logged-in clinic before any data is returned. Isolation is enforced in our application code on every request and fails closed.
  • Encryption. Channel tokens are encrypted at rest with AES-256-GCM. Traffic is served over HTTPS.
  • Access control. Dashboard access is per-user and clinic-scoped, with owner-only controls for settings, user management, exports, and deletion.
  • Restricted support access. Human support access uses a restricted role, is time-boxed and granted by the clinic, and is recorded in the audit log.
  • Audit logging. Sensitive actions are logged and visible to clinic owners in the dashboard.

8. Data retention

We retain clinic and customer data for as long as the clinic uses the service. A clinic can request deletion at any time. On a deletion request we schedule a full cascade delete after a short grace period (currently 48 hours) during which the clinic can cancel. After deletion, residual copies may persist briefly in encrypted backups before expiring on their normal cycle.

9. Your rights and choices

Clinic owners can export all of their clinic's data at any time and delete their account and data from the dashboard. Clinics and individuals may also request access, correction, or deletion by contacting us (Section 14). Because GlowBot processes customer data on behalf of clinics, customer requests are generally directed to, and fulfilled by, the clinic, and we assist the clinic in responding.

10. International transfers

Data may be processed outside Vietnam by the subprocessors listed in Section 6 (for example database hosting in Singapore and AI processing in the United States). We rely on appropriate safeguards and the protections in our agreements with those providers.

11. Customers messaging a clinic

If you message a clinic that uses GlowBot, you are interacting with that clinic's own Zalo OA or Facebook Page. Some replies may be generated by GlowBot's AI on the clinic's behalf. The clinic decides what data to keep and is your primary point of contact for privacy requests about your conversation.

12. Children

GlowBot is a business service for clinics and is not directed to children. Clinics are responsible for handling any data relating to minors in line with applicable law and parental-consent requirements.

13. Changes to this policy

We may update this policy as the service or the law changes, and will post the updated version with a new last-updated date.

14. Contact

Questions or requests about this policy: hello@glowbot.vn.

Terms of Service

Last updated: 14 June 2026

These terms reflect how the GlowBot service works. They are a working draft and should be reviewed by qualified counsel in Vietnam before being relied on as a binding agreement.

1. Agreement

These Terms govern use of the GlowBot service by a beauty or aesthetic clinic ("clinic", "you"). By using the service or starting a pilot, you agree to these Terms. GlowBot is a business-to-business service and is not offered to consumers.

2. The service

GlowBot is an outsourced AI patient-success service. It operates on your existing Zalo Official Account and Facebook Page and is human-first: your team handles messages as usual, and GlowBot steps in only when a message goes unanswered past a threshold you set, arrives outside your staffed hours, or during a volume spike. Your staff can take over any conversation at any time. Depending on your tier, GlowBot also supports appointment booking, lifecycle follow-up, upsell handling, dormant-patient reactivation, and post-treatment check-ins.

3. Accounts and eligibility

You must provide accurate account information and keep credentials secure. Accounts are provisioned for clinic owners and staff, and the clinic owner controls who has access. You are responsible for activity under your accounts.

4. Connecting your channels

You authorize GlowBot to connect to and act on your Zalo OA and Facebook Page to receive and send messages on your behalf. You confirm you are entitled to grant this access and that your use of those platforms complies with their terms and with applicable messaging and consent rules. You can disconnect a channel at any time.

5. Your data

You own your clinic and customer data. GlowBot processes it as your service provider under the Privacy Policy above. You can export all of your data at any time and request deletion at any time. On termination, we make your data available for export and then delete it on the schedule described in the Privacy Policy.

6. Fees and billing

Pricing follows the published agency model: a monthly floor, a per-booking fee on bookings attributed to GlowBot, and, on eligible tiers, a commission on upsell uplift and a fee on reactivated dormant patients. New clients begin with a 30-day pilot during which floor, per-booking, upsell, and reactivation fees are waived; you pay only Zalo ZNS message pass-through costs.

A booking counts as GlowBot-attributed only under transparent rules (for example: the AI sent at least three messages, the booking was created within 48 hours of the AI's last message, and no staff member was actively handling the conversation; off-hours bookings handled by the AI always count). Every attributed booking links to its conversation and reasoning in the dashboard. You may flag any attributed booking within 30 days, and if we got it wrong we credit it back.

7. Commitment and termination

After a pilot converts to a paid engagement, a minimum term applies (currently three months), after which either party may terminate on 30 days' written notice. We may suspend or terminate the service for non-payment or for breach of these Terms. You may stop using the service and disconnect your channels at any time.

8. Acceptable use

You agree not to use GlowBot to send unlawful, deceptive, or harassing messages, to violate the platform rules for Zalo or Facebook, or to process data you are not entitled to process. You are responsible for the accuracy of the clinic information (pricing, treatments, promotions) you provide for the AI to use.

9. No medical advice

GlowBot supports patient communication and scheduling. It does not provide medical advice, diagnosis, or treatment. Clinical decisions remain with your licensed practitioners. You are responsible for reviewing and standing behind the information your clinic publishes and the care you provide.

10. Service availability and AI limitations

We work to keep the service available and accurate, but AI-generated responses can be imperfect. You are responsible for the human-oversight controls available to you (thresholds, takeover, knowledge-base accuracy). Except where a specific service-level commitment is stated for your tier, the service is provided on an as-available basis.

11. Disclaimers and limitation of liability

To the extent permitted by law, GlowBot is provided without warranties of any kind, and our aggregate liability arising from the service is limited to the fees you paid for the service in the three months before the event giving rise to the claim. We are not liable for indirect, incidental, or consequential damages. Nothing in these Terms limits liability that cannot be limited under applicable law.

12. Changes

We may update these Terms as the service or the law changes, and will post the updated version with a new last-updated date. Material changes that affect a paid engagement will be communicated to you.

13. Governing law

These Terms are governed by the laws of Vietnam, and disputes are subject to the competent courts of Vietnam, unless your signed order form states otherwise.

14. Contact

Questions about these Terms: hello@glowbot.vn.

© 2026 GlowBot. Back to home