Legal
Privacy Policy
Effective date: 13 July 2026
This Privacy Policy explains how Xynetra (“we”, “us”) collects, uses, and protects personal data in connection with our websites and the Xynetra Recover service (the “Service”). We are committed to handling personal data in line with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and other applicable privacy laws.
1. Who this policy covers, and our two roles
We process personal data in two distinct roles:
- As a controller — for data about you, our customer: account details, billing information, website usage, and communications with us.
- As a processor — for data about your customers (the people who book appointments with your business): names, phone numbers, appointment times, and message content. We process this data only on your behalf and under your instructions to deliver the Service. If you are an end customer of one of our business clients, that business is responsible for your data; please direct requests to them, and we will assist them in fulfilling your rights.
2. Data we collect
- Account data: name, business name, email address, password (stored as a secure hash), billing region.
- Billing data: processed by our Merchant of Record, Paddle.com, which collects payment card details, billing address, and tax information. We never receive or store full card numbers. Pakistan-based customers paying by bank transfer or mobile wallet provide payment reference details which we store for verification.
- Service data (processed on behalf of our clients): customer names, WhatsApp phone numbers, appointment dates and times, message content exchanged with the automated assistant, waitlist entries, and calendar event details.
- Technical data: IP address, browser type, device information, and usage logs collected when you use our website and dashboard, including via strictly necessary cookies for authentication. We do not use advertising cookies.
3. How and why we use data (legal bases)
- To provide the Service and perform our contract with you (Art. 6(1)(b) GDPR): operating reminders, processing replies, slot recovery, reports, and support.
- To process payments and comply with legal obligations (Art. 6(1)(c)): invoicing, tax, and accounting via Paddle.
- For our legitimate interests (Art. 6(1)(f)): securing the Service, preventing abuse, improving features using aggregated and de-identified usage data, and sending service-related communications.
- With your consent (Art. 6(1)(a)) where required: for example, marketing emails, which you can withdraw at any time via the unsubscribe link.
- Automated message classification: customer replies are processed by an AI language model to classify intent (confirm, cancel, reschedule, or other) so the Service can respond. Messages that cannot be handled automatically are forwarded to the relevant business owner. This processing is essential to the Service; no automated decision with legal or similarly significant effect is made about individuals.
4. Service providers (sub-processors)
We share personal data only with providers necessary to run the Service, under contracts that protect the data:
- Paddle.com Market Ltd — Merchant of Record, payment processing and tax handling (UK/EU/US).
- Supabase — database and authentication hosting (cloud regions as configured).
- Meta Platforms (WhatsApp Business Platform) — delivery of WhatsApp messages.
- Google LLC (Google Calendar API) — reading and updating appointment events.
- OpenAI — processing of message text for intent classification.
- Hosting and infrastructure providers for our automation and website (including our server host and Vercel).
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising.
5. International transfers
We operate from Pakistan and use service providers in the United States, the EU, and the UK. Where personal data subject to the GDPR or UK GDPR is transferred internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework certifications of our providers.
6. Retention
We keep account data for as long as your account is active and for up to 12 months afterwards, unless a longer period is required by law (e.g. tax records retained by Paddle). Service data (appointments, reminders, message logs) is retained while your subscription is active to operate the Service and produce reports, and is deleted or anonymized within 90 days of account termination, except where retention is legally required. You may request earlier deletion at any time.
7. Security
We apply appropriate technical and organizational measures: encryption in transit (TLS), encrypted storage with our cloud providers, row-level security and role-based access on databases, secret-managed API credentials, and least-privilege access. No system is perfectly secure; if we become aware of a personal data breach affecting you, we will notify you and the relevant authorities as required by law.
8. Your rights
Depending on your location, you may have the right to: access the personal data we hold about you; receive a copy in a portable format; correct inaccurate data; request deletion; restrict or object to processing; withdraw consent; and not be discriminated against for exercising these rights (CCPA). To exercise any right, email info@xynetra.com; we respond within 30 days (or as required by applicable law). EU/UK residents may lodge a complaint with their local supervisory authority; California residents may contact the California Privacy Protection Agency.
9. Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16 as a controller. Appointment data processed on behalf of our clients may incidentally include minors (e.g. a parent booking for a child); such data is controlled by the relevant business.
10. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email or in-product notice, with the updated effective date shown at the top. The current version always applies.
11. Contact
Data controller: Xynetra, Lahore, Pakistan. Email: info@xynetra.com.
Prepared for Xynetra, Lahore, Pakistan.
Questions? Email info@xynetra.com.