This text is a template and needs legal review before launch.
Two roles
Yixnova is the controller for business account data and a processor on behalf of businesses for their website visitors. Visitor data belongs to that business.
What we collect from visitors
- A random visitor ID (stored in the browser, not personally identifying).
- Chat messages and page context (only which page the chat was opened on).
- Contact details — only after the visitor sees the notice and explicitly presses Send. No keystrokes are captured while typing.
How we protect it
- Contact fields are encrypted with AES-GCM; keys can be rotated.
- Every query is scoped to a single business; businesses can never see each other’s data.
- Your data is never used to train a shared model.
Retention
Conversations are kept for your plan’s retention window (30 days to 2 years), then deleted automatically. Businesses can export or delete at any time.
Sub-processors
Cloudflare (hosting, database, AI inference), an email provider (notifications) and a payment provider (billing). The current list is available on request.
Your rights
To exercise access, correction, deletion or objection rights under GDPR, KVKK or CCPA, email privacy@yixnova.com. If you were a visitor to a business’s website, you can also contact that business directly.