Volraix (UEN 53531567L), registered in Singapore, is automation for Singapore businesses. This policy explains what personal data we collect, why, who we share it with, how long we keep it, and what you can ask us to do with it.
Who this covers
- Visitors to volraix.com, including anyone who sends an enquiry.
- Clients: businesses that subscribe to a Volraix product or commission a custom build, and the staff they authorise to use it.
- End customers: people who message a client’s business on WhatsApp, Instagram or Messenger and are answered by a Volraix assistant.
For end customers, the client business is the organisation that collects your data. Volraix processes it on that business’s instructions, which under the Personal Data Protection Act 2012 (PDPA) makes us a data intermediary. If you are an end customer with a question about how a specific business uses your data, ask that business. If a business asks us to find, export or delete a conversation, we do it.
What we collect
| From whom | Data | Why |
|---|---|---|
| Visitors | Your name, business name, a WhatsApp number or email address, and what you tell us about your trade, team size, the tasks you do by hand and the systems you use | To answer the enquiry and prepare a useful first reply |
| Clients | Contact details, business name and address, opening hours, staff names, connected Google Calendar and Meta business accounts, and billing records | To provide and bill the service you subscribed to |
| End customers | Display name, phone number or messaging ID, the content of messages sent to the business, and booking details such as service, date and time | To reply on the business’s behalf, offer available times and record the booking |
How the assistant uses messages
When an end customer messages a client business, the assistant reads the message, checks the business’s opening hours and connected calendar, and replies. The message is processed by an AI language model to understand the request and draft the reply. The assistant only offers times that are free in the calendar. When it is not confident, it hands the conversation to a person at the business.
The end customer starts the conversation. That is the basis on which we reply, and under the PDPA it is deemed consent by conduct for the booking they asked for. Anyone can stop it: reply “stop” and the assistant stops messaging and tells the business. We do not send marketing to people who have not asked for it.
What we do not do with platform data
Data we receive from WhatsApp, Instagram and Messenger is used only to run the service for the business that owns the account. We do not use it for advertising or ad targeting, do not build profiles from it, do not sell it, and do not pass it to data brokers or ad networks. Message content is not used to train AI models.
If a client disconnects their Meta business account or withdraws our access, we delete the platform data we hold for that account within 30 days. We also delete it if Meta instructs us to.
Who we share data with
We do not sell personal data. We share it only with the providers we need to run the service. Some process data on our instructions. Others run the platforms our products connect to and handle data under their own terms.
- Meta Platforms: the WhatsApp Business Platform, Messenger and Instagram messaging APIs carry the conversations. Meta handles that data under its own terms.
- Google: Google Calendar holds availability and bookings; website enquiries are recorded in a Google Sheet.
- Supabase: the database holding client accounts, conversation records and bookings, on our instructions.
- Netlify: hosting for volraix.com, on our instructions.
- Cloudflare: domain and email routing.
- Our AI model provider: the language model that reads messages and drafts replies. We only use a provider whose terms exclude training on customer data. We will name the provider here before the assistant is sold to the public, and we will name it to any client who asks.
Some of these providers store data outside Singapore. Where they do, we require them by contract to protect it to a standard comparable to the PDPA.
How long we keep it
- Website enquiries: 12 months from the date of the enquiry, then deleted.
- Client account data and bookings: for as long as the subscription is active, then 12 months after it ends so records can be restored or exported, then deleted.
- End-customer conversations: 12 months from the last message, or earlier if the client business or the end customer asks for deletion.
- Billing records: 5 years, as Singapore tax law requires.
Your rights
If you are a visitor or a client, you can ask us for the personal data we hold about you, ask us to correct it, or withdraw consent for its use. Email us and we answer within 30 days. You can also ask us to delete it, which the data deletion page explains.
If you are an end customer, the business you messaged handles access and correction requests, because it is the organisation responsible for your data. Ask that business. We help them answer you, and you can still ask us directly to delete a conversation.
Children
The service is built for businesses and is not intended for children. We do not knowingly collect data from anyone under 13. If we learn that we have, we delete it.
Security
Data is encrypted in transit, and encrypted at rest in our database. Access to production systems is limited to people who need it to run the service, protected by two-factor authentication.
If we discover a data breach, we tell the affected client business without undue delay, because for their customers’ data they are the organisation that must act. Where Volraix is the organisation responsible, we notify the Personal Data Protection Commission and the people affected within 3 calendar days of assessing that a breach is notifiable, either because it is likely to cause significant harm or because it affects 500 or more people.
Cookies
volraix.com sets no advertising or tracking cookies and runs no analytics. Our hosting provider records standard server logs, including IP addresses, to keep the site running and secure.
Changes
When this policy changes, the effective date at the top changes with it. Material changes that affect clients are sent to the account email before they take effect.
Contact
Our Data Protection Officer can be reached at eugenego@volraix.com. We give a postal address on request.