Privacy Policy & Data Processing Policy
Effective Date: July 27, 2026 · Last Updated: July 27, 2026
Ygrix Company ("Company," "Ygrix," "we," "us," or "our") is committed to protecting the privacy and security of data entrusted to us. This Privacy Policy & Data Processing Policy ("Policy") describes how Ygrix collects, uses, stores, discloses, and protects personal information in connection with our website (ygrix.com), platform, and cloud-based AI sales automation services, including Voice Robots and Chat Robots (collectively, the "Service").
This Policy applies to: representatives, employees, and agents of our corporate business clients ("Customers"); visitors to our website and web applications; and end users, leads, and contacts with whom Customer's Robots communicate ("End Users").
1.Dual-Role Privacy Architecture & Scope
To ensure full transparency and compliance with applicable United States data privacy laws (including CCPA/CPRA, VCDPA, CPA, and federal standards), Ygrix operates under a dual-role framework depending on the nature of the data processed.
A. Customer Account & Business Data (Ygrix as Data Controller / Business)
When business clients register, access our platform, interact with our website, communicate with our sales team, or pay for subscriptions, Ygrix acts as a Data Controller. We collect and determine the purposes and means of processing Customer corporate contact details, account credentials, billing records, and website usage telemetry.
B. End Client Data & Communications Content (Ygrix as Data Processor / Service Provider)
When Customer uses our Service to configure AI Voice and Chat Robots, upload contact lists, conduct calls, send messages, or generate conversation transcripts with End Users ("Customer Content" or "End Client Data"), Ygrix acts strictly as a Data Processor. Customer remains the sole Data Controller responsible for establishing the legal basis, obtaining required consents, and determining the purposes for contacting End Users. Ygrix does not sell, retain, or use End Client Data for its own independent business or commercial purposes.
2.Information We Collect and Receive
2.1 Information Collected for Customer Account Management
- Account & Contact Information: Name, corporate email address, business phone number, job title, company name, address, and login credentials.
- Payment & Billing Details: Payment card info, bank details, billing addresses, and transaction history (processed securely via PCI-compliant third-party payment processors).
- Technical Telemetry & Website Cookies: IP addresses, browser type, device information, operating system, pages visited, and usage analytics collected via cookies, web beacons, and log files.
2.2 Information Processed on Behalf of Customers (End Client Data)
- Contact Data: Phone numbers, names, email addresses, custom CRM metadata, and target contact lists uploaded or integrated into the platform by Customer.
- Conversational Content: Audio recordings of telephone conversations, voice-to-text transcripts, chat interaction logs, messages sent/received, call duration, and disposition flags.
- Technical Communication Logs: Telephony carrier metadata, timestamp, SIP call headers, SMS delivery status reports, and system diagnostics.
3.How We Use Your Information
3.1 Customer Data (Internal Business Purposes)
We use Customer Data to: provide, maintain, and administer Customer accounts and subscriptions; assign dedicated Personal Account Managers; process billing, invoicing, and payment processing; provide technical support, product updates, and customer communications; detect, prevent, and mitigate fraud, security incidents, and platform abuse; and comply with legal obligations and enforce our contractual rights.
3.2 End Client Data (Processing Strictly for Service Delivery)
We process End Client Data exclusively to: execute, route, and record AI-powered voice calls and chat interactions as directed by Customer; generate transcripts, conversation summaries, and performance analytics for Customer's viewing; enable integrations with Customer's CRM, telephony, and business tools; and deliver support and troubleshoot operational anomalies reported by Customer.
4.Artificial Intelligence & Machine Learning Guarantees
Ygrix leverages advanced Large Language Models (LLMs), Speech-to-Text (STT), and Text-to-Speech (TTS) technologies provided via enterprise API integrations.
- No Public Model Training: Ygrix does NOT use Customer Data, End Client Data, audio recordings, or conversational transcripts to train, retrain, fine-tune, or improve public, foundational, or third-party AI models (including those provided by OpenAI, Anthropic, or similar vendors), unless explicitly agreed otherwise in a signed Individual Agreement.
- Enterprise API Isolation: All AI model interactions occur via zero-retention or enterprise-grade privacy API endpoints where third-party AI infrastructure providers are contractually bound not to use transmitted data for model training or independent commercial development.
5.Sub-Processors and Third-Party Vendors
Ygrix utilizes carefully vetted third-party vendors, infrastructure providers, and sub-processors to deliver telephony, voice processing, cloud computing, and AI functionality. Categories include: Cloud Infrastructure & Database Hosting (e.g., AWS, GCP); Telephony Carriers & Communications APIs (e.g., Twilio, Plivo, Bandwidth); Speech Recognition & Voice Synthesis Engines; and AI Language Processing APIs.
Ygrix enforces data protection and security standards through contractual agreements with all sub-processors. Ygrix will notify Customer of material changes to its primary sub-processor network upon request or via updates to our technical documentation.
6.Data Retention, Manual Management, and Deletion Policy
6.1 End Client Data Retention & Control
- Customer Dashboard Control: Customer retains direct access to End Client Data and may view, export, or manually delete individual records or full datasets at any time.
- Automatic Inactivity Deletion: End Client Data is automatically deleted or permanently anonymized after 30 days of inactivity on an unmaintained campaign, unless a custom retention schedule is designated in an Individual Agreement.
- Post-Termination Deletion: Upon termination, all associated End Client Data will remain accessible for retrieval for thirty (30) days, after which it will be permanently and securely deleted from active production servers within thirty (30) days.
6.2 Customer Account Data Retention
Customer account details, financial transactions, and billing records are retained for as long as the account remains active and as necessary to satisfy legal, tax, accounting, or regulatory requirements (typically up to 7 years for financial audit compliance). Non-essential account data is deleted within 30 days upon receipt of a verified written termination request.
7.Data Security Measures
Ygrix maintains appropriate technical, organizational, and administrative security measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.
- Encryption: Data in transit is encrypted using industry-standard TLS 1.2+ protocols. Data at rest (including database records and audio files) is protected using AES-256 encryption.
- Access Control: Access to production systems and End Client Data by Ygrix personnel is strictly restricted on a need-to-know basis and protected by multi-factor authentication (MFA).
8.United States Privacy Rights (CCPA/CPRA, VCDPA, etc.)
To the extent U.S. state privacy laws apply:
- Right to Know: Customers and U.S. residents have the right to request information about the categories and specific pieces of personal information collected, disclosed, or processed.
- No Sale or Sharing: Ygrix does not sell personal data or End Client Data, nor does Ygrix share personal data with third parties for cross-context behavioral advertising.
- Right to Delete & Correct: Individuals have the right to request deletion or correction of their personal data held by Ygrix in its capacity as a Data Controller. For End Client Data where Ygrix acts as a Service Provider, requests received directly from End Users will be redirected to the respective Customer.
9.Contact Information
If you have any questions, concerns, or data privacy requests regarding this Policy or our data handling practices, please contact our Data Protection Office:
- Company: Ygrix Company
- Privacy Email: business@ygrix.com
- General Support: help@ygrix.com