Legal
Privacy Policy
This policy explains what the Detoximex service does with data. It describes current practice and is updated as the service changes.
1. About this policy
“Detoximex” refers to the Detoximex service operated at detoximex.com, an AI sales assistant for businesses that receive customer enquiries on messaging channels. This policy applies to the website, the application, and the AI agent that operates on a customer's connected channels.
Detoximex is an independently developed product and is not currently offered by an incorporated company. As the service moves to paid commercial operation, an operating entity will be established and this policy will be reissued naming that entity and its regulator-facing details. Until then this document intentionally makes no claim about corporate registration, licensing, or tax status.
2. Two different roles
- For our business customers — the people who create a workspace and use the product — Detoximex decides what account data is needed to run the service, and is responsible for it.
- For their end customers — the people who message a business through a connected channel — the business decides why the data is collected and how long it is kept. Detoximex processes that data on the business's instructions in order to operate the service on its behalf.
If you contacted a business that uses Detoximex and want your data corrected or removed, contact that business first, since it controls the record. If you cannot reach it, you can reach us through the route in section 9 and we will pass the request on.
3. What the service processes
- Account data — name, business email address, authentication records, workspace membership and role.
- Business and workspace data — company name, working hours, language settings, staff records including staff contact numbers and calendar identifiers, policy rules and agent configuration.
- Lead data — the enquirer's phone number and profile name as supplied by the messaging platform, plus the qualification details they give during the conversation, and the score our fixed rules calculate from those details.
- Conversations and messages — the full content of messages exchanged with the AI agent or with staff through the workspace, timestamps, delivery status, and provider message identifiers used to prevent duplicate replies.
- Inventory — the listings, products or services a business uploads, including any file it imports.
- Knowledge — the documents a business uploads for the AI agent to answer from, and the numeric representations (embeddings) generated from them to make retrieval possible.
- Integration data — where a business connects a CRM or calendar, the records exchanged with that system and the access tokens needed to do so, held server-side only.
- Usage, quality and security logs — per-run records of which agent ran, which model and version, token counts, estimated cost, latency and outcome; error records; automated quality evaluations of a sample of AI replies; audit records of configuration changes; and usage counters used for billing.
- Payment data — plan, subscription status, invoice records and the payment provider's customer and subscription identifiers. Payments are processed by Paddle as Merchant of Record; card numbers are handled entirely by Paddle and are never received or stored by Detoximex.
Do not place payment card numbers, government identification documents, passwords, or health information into conversations, uploads or the knowledge base. The service is not designed to hold them.
4. Why it is processed
To operate the service; to reply to and qualify enquiries on behalf of a business; to answer questions from that business's own approved documents; to book meetings and update a connected CRM; to alert staff and support human takeover; to measure quality, cost, latency and reliability; to detect and investigate abuse and secure the platform; to take payment; and to meet obligations that apply to us.
A sample of AI replies is scored automatically — for example to detect an answer that was not grounded in the business's own content, or an escalation that should have happened. This is a service-quality control. It is not used to make decisions about individuals.
5. Service providers
Data is shared only with the providers needed to run the service, each under that provider's data protection terms:
- Meta Platforms — WhatsApp Business Cloud API message delivery.
- OpenAI — model processing for replies, retrieval and quality evaluation.
- Supabase — application database and authentication.
- Vercel — application hosting and delivery.
- n8n — automation and integration execution.
- HubSpot — CRM synchronisation, where a business enables it.
- Google — calendar availability and meeting creation, where a business enables it.
- Paddle — Merchant of Record for subscription billing, payment processing and applicable sales-tax/VAT handling.
- Stripe — legacy/sandbox billing processor, retained for historical records only.
- Resend — authentication and transactional email.
Personal data is not sold, and it is not shared for advertising.
6. International processing
Detoximex is offered globally and its providers operate infrastructure in multiple countries, so data is processed outside the country where a business or its customers are located. Where that happens we rely on the contractual data protection terms offered by each provider. The processing locations that apply to a specific workspace are confirmed with that business on request.
7. Retention
While a workspace is active, conversation, lead, inventory, knowledge and operational records are retained so the service can function and so the business keeps its own history. After a workspace is terminated, our current operational practice is to delete workspace content within 30 days of the deletion process starting, other than records we must keep for accounting or to resolve a dispute.
This is current operational practice reflecting how the system is built today, not a fixed contractual retention commitment. A definitive retention schedule will be published with the incorporated operating entity.
8. Deleting data
Business customers. You can request deletion of a workspace and everything in it from the account settings area of your workspace, or through the contact route published on detoximex.com, from the account owner's registered email address. We confirm the request, delete the workspace content from production systems, and instruct our providers to do the same. Our operational target is to complete this within 30 days of confirming the request. Backup copies age out on their normal rotation cycle rather than being edited individually.
People who messaged a business using Detoximex. The business holds your record and can delete it from its workspace. If you cannot reach the business, contact us from the account settings area of your workspace, or through the contact route published on detoximex.com with the phone number you used and the name of the business, and we will forward the request and confirm to you once it has been actioned.
Deleting a workspace is irreversible and removes conversation history, leads, inventory and knowledge for every user of that workspace.
9. Your rights and how to reach us
Depending on where you live, you may have rights to access the personal data held about you, to have it corrected, to have it deleted, to restrict or object to certain processing, and to receive a copy in a portable form. You can exercise these rights from the account settings area of your workspace, or through the contact route published on detoximex.com.
We may need to verify who you are before acting, and where we hold data on behalf of a business customer we will refer the request to that business and support them in answering it.
10. Security
Workspace data is isolated at the database level rather than only in application code, provider credentials are held in dedicated secret storage and are never exposed to the browser, and configuration changes are recorded with their previous and new values. The security overview describes these controls and states plainly what the service does not yet have, including the absence of any third-party security certification.
11. Children
Detoximex is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.
12. Changes to this policy
This policy is updated when practices change, and materially when an operating entity is established. Business customers are told about material changes through the account owner.