Privacy policy

What Yixnova processes, why, and how you stay in control — in plain language.

This text is a template and needs legal review before launch.

Two roles

Yixnova is the controller for business account data and a processor on behalf of businesses for their website visitors. Visitor data belongs to that business.

What we collect from visitors

  • A random visitor ID (stored in the browser, not personally identifying).
  • Chat messages and page context (only which page the chat was opened on).
  • Contact details — only after the visitor sees the notice and explicitly presses Send. No keystrokes are captured while typing.

How we protect it

  • Contact fields are encrypted with AES-GCM; keys can be rotated.
  • Every query is scoped to a single business; businesses can never see each other’s data.
  • Your data is never used to train a shared model.

Retention

Conversations are kept for your plan’s retention window (30 days to 2 years), then deleted automatically. Businesses can export or delete at any time.

Sub-processors

Cloudflare (hosting, database, AI inference), an email provider (notifications) and a payment provider (billing). The current list is available on request.

Your rights

To exercise access, correction, deletion or objection rights under GDPR, KVKK or CCPA, email privacy@yixnova.com. If you were a visitor to a business’s website, you can also contact that business directly.