VortexiaHome
Legal documentsPrivacy PolicyTerms of ServiceData Deletion
Legal · Privacy

Privacy Policy

Effective date: August 3, 2026

This Privacy Policy explains how the Vortexia platform operator ("Vortexia", "we", "us" or "our") processes information when businesses use the Vortexia service, including when they connect third-party messaging, social-media or email accounts.

The legal operator for a customer may also be identified in that customer's order form or service agreement. This Policy does not replace the privacy notices or terms of any connected third-party platform.

1. Scope and roles

Vortexia is a business platform. A customer that connects a channel generally determines why it communicates with its contacts and is responsible for providing any notices and obtaining any permissions required by law or by the connected platform. Vortexia processes those communications to provide the service and also processes limited account and security data for its own platform operations.

This Policy covers administrators and users of a Vortexia workspace, as well as people who communicate with a business through an account that the business has connected to Vortexia.

2. Information we process

  • Vortexia account and workspace data, such as username, account identifiers, role, tenant or workspace association and configured assistant assignments.
  • Connected-account data, such as provider name, external account, Page or mailbox identifiers, display name, username, avatar, public contact link, granted permissions, connection status and token expiry information.
  • Authorization data required to operate a connection. This can include OAuth access or refresh tokens, bot tokens, webhook secrets or, for a manually configured mail server, mailbox credentials and server settings.
  • Conversation and contact data, such as external user and conversation identifiers, sender name, email address where applicable, subject, message text, message type, timestamps, attachment metadata, delivery state, reply relationships and provider event data needed to process the message.
  • Service and security data, such as webhook and synchronization status, error records, audit information and technical logs used to protect and operate the service.

3. How we use information

  • Authenticate, validate and maintain the channel connection requested by the workspace administrator.
  • Receive, normalize, display, route and send messages through the connected provider.
  • Maintain a unified conversation history and delivery state across the Vortexia inbox.
  • When a workspace enables an AI assistant, process relevant conversation content and context to classify conversations and prepare or send responses under that workspace's settings.
  • When a workspace enables contact sharing, make the connected account's public handle, link or email address available to that workspace's chat engine so it can be offered during eligible conversations.
  • Secure, troubleshoot and improve the reliability of the service, enforce agreements and comply with applicable legal obligations.

4. Connected platforms and service providers

Depending on what the customer enables, Vortexia may exchange data with services such as Meta products (including Facebook Pages, Messenger, Instagram and WhatsApp), Google, Microsoft, Telegram, Viber and customer-selected email servers. Each provider processes data under its own terms and privacy policy.

We may also use hosting, database, monitoring, security and AI-processing providers to operate Vortexia. They receive only the information reasonably required for their service and are subject to contractual or legal safeguards where required. We do not sell personal information.

5. Credentials and security

OAuth passwords entered in an official provider authorization window are not sent to or stored by Vortexia. Tokens returned after authorization, bot credentials and manually supplied email credentials are encrypted at rest. Connections and data access are limited by user and workspace permissions, and supported provider webhooks are authenticated or signature-checked.

No system can guarantee absolute security. Customers must protect their Vortexia and provider administrator accounts, use only accounts they are authorized to connect and notify us promptly of suspected unauthorized access.

6. Retention and disconnection

Connection credentials are retained while needed to operate an authorized connection. When a user disconnects a channel in Vortexia, the service attempts to unsubscribe the provider webhook where supported, disables AI handling and contact sharing, and clears the stored connection credentials.

Disconnecting a channel does not by itself delete the local conversation and message history already stored in Vortexia. That history and related account metadata are retained while the customer account remains active and while reasonably needed to provide the service, maintain security, resolve disputes or meet legal obligations. A verified deletion request is required to remove this stored history. Residual copies may remain temporarily in restricted backup or recovery systems and are removed or overwritten through their normal lifecycle, unless longer retention is legally required.

7. Your choices and rights

  • Workspace administrators can disable AI handling or contact sharing without disconnecting the account.
  • Workspace administrators can disconnect a channel to stop future access and clear its stored credentials.
  • Subject to applicable law and verification, a person may request access, correction, deletion, restriction, objection or a portable copy of relevant personal information.
  • A person who communicated with one of our business customers should normally contact that business first because it controls the purpose of the conversation. The person may also contact us and identify the business, platform and account involved.

8. International processing

Vortexia, its customers, connected platforms and service providers may operate in different countries. Information may therefore be processed outside the country where it was collected. We use contractual, technical or other safeguards where required by applicable law.

9. Children

Vortexia is intended for business use and is not directed to children. Customers must not knowingly use the service to collect children's information in violation of applicable law or platform rules.

10. Changes and contact

We may update this Policy as the service or legal requirements change. The effective date above identifies the current version. Questions and verified privacy requests may be sent to [email protected] or submitted through the support channel available inside Vortexia.

Vortexia platform operatorPrivacy and data requests: [email protected]
Return to Vortexia