Privacy Policy
Effective date: 1 July 2025
1. Who we are
MOHR Programming ("MOHR AI," "we," "us," or "our") is the data controller responsible for the personal data described in this policy. We are registered at 16 محمد مندور م نصر, Egypt. If you have questions about this policy or how we handle your data, contact us at privacy@mo-hr.ai.
2. Scope
This policy covers two things we operate: the mo-hr.ai marketing website, and the MAI product, available at mai.mo-hr.ai. Where this policy describes something specific to one or the other, it says so.
3. What we collect from website visitors
We keep data collection on this website to a minimum:
- Contact form — if you submit our contact form, we collect your name, email address, phone number, company name (optional), and message. This is sent to our team by email so we can respond to you; it is not added to a marketing list or shared with third parties.
- Language preference — if you switch the site language, we store that preference in your browser's local storage. It stays on your device and is not sent to us.
- No cookies, no analytics, no tracking pixels — this website does not use cookies, analytics tools, advertising pixels, or any other visitor-tracking technology.
4. Meta platform integrations
MAI, our product available at mai.mo-hr.ai, connects to a customer's Facebook Page and/or Instagram professional account so that MAI can reply to messages that Page's or account's own end users send to it. To do this, MAI requests the following permissions from Meta. This section explains, permission by permission, what each one grants us, what data we receive, why we need it, and how long we keep it.
pages_messaging
- What it grants: lets MAI receive messages sent to a connected Facebook Page and send replies within Meta's messaging window.
- Data we receive: message content, the sender's page-scoped ID, and message timestamps.
- Why we need it: this is the core permission that lets MAI answer messages sent to a customer's Page.
- Retention: message content is retained for 30 days, then deleted.
pages_show_list
- What it grants: lets MAI list the Facebook Pages a connecting user administers, so they can choose which Page to connect.
- Data we receive: Page names and Page IDs. No message content.
- Why we need it: without this, a customer could not select which of their Pages to connect to MAI.
- Retention: kept for as long as the connection is active, and deleted when the Page is disconnected.
instagram_basic
- What it grants: lets MAI resolve the Instagram professional account linked to a Page the customer has chosen to connect.
- Data we receive: the Instagram account ID and username. No message content.
- Why we need it: MAI needs this to identify which Instagram account belongs to the connected Page.
- Retention: kept for as long as the connection is active, and deleted when the account is disconnected.
instagram_manage_messages
- What it grants: lets MAI receive Instagram direct messages sent to a connected account and send replies.
- Data we receive: message content, the sender's Instagram-scoped ID, and message timestamps.
- Why we need it: this is the permission that lets MAI answer Instagram DMs sent to a customer's connected account.
- Retention: message content is retained for 30 days, then deleted.
business_management
- What it grants: required by Meta as a dependency of the permissions above, so MAI can access the business assets a customer has authorized.
- Data we receive: no additional message content beyond what is described above.
- Why we need it: Meta requires this permission alongside the messaging permissions; we do not use it for anything beyond enabling them.
- Retention: kept while the connection is active, deleted on disconnection.
- We reply only to conversations the end user starts. We do not send unsolicited, promotional, or broadcast messages through these integrations.
- We do not sell, rent, or share this data with third parties for their own purposes.
- We do not use message content to train third-party AI models.
- Message content is processed by a third-party AI language model provider to generate replies, acting as a sub-processor on our behalf.
- Message content is retained for 30 days, then deleted.
- When a customer disconnects their Page or Instagram account, we revoke our access to it at Meta and delete the stored message content and connection data associated with it. See Data Deletion below for details.
5. Sub-processors
We use a small number of service providers ("sub-processors") to operate MAI and this website, by category:
- Hosting and infrastructure — to run the website and MAI.
- AI inference — to process message content and generate replies, as described above.
- Email delivery — to send transactional emails, such as contact form notifications.
6. Legal basis and rights
For website visitors, we process contact form submissions on the basis of your consent when you submit the form. For MAI, our customers are the controllers of their own end users' personal data — the people who message their Facebook Page or Instagram account — and we act as a processor on our customers' behalf.
You have the right to access, correct, delete, or object to the processing of your personal data. To exercise these rights regarding the website, contact privacy@mo-hr.ai. If your request concerns messages sent to one of our customers' connected Pages or Instagram accounts, we recommend contacting that business directly, since they are the controller of that data; we will also assist our customer in fulfilling your request.
7. Data deletion
You can remove your connection to MAI and the message data associated with it in two ways:
- Self-serve — sign in to MAI, go to the channel connections screen, and disconnect the Facebook Page or Instagram account. This revokes MAI's access at Meta and deletes the stored message content and connection data for that channel.
- Manual request — email privacy@mo-hr.ai with the name of the connected Page or Instagram account and we will process the deletion within 30 days.
8. International transfers, security, children, and changes
- International transfers: we may store and process data on servers operated by our hosting and AI infrastructure providers, which may be located outside Egypt. Where that happens, we take reasonable steps to keep it protected consistent with this policy.
- Security: we apply reasonable technical and organizational measures to protect data against unauthorized access, alteration, or loss.
- Children's data: this service is not directed at, and we do not knowingly collect personal data from, individuals under 18.
- Changes to this policy: we may update this policy from time to time. If we make material changes, we will update the effective date at the top of this page.
- Contact: for any question about this policy, email privacy@mo-hr.ai.