YOUR DATA, CLEARLY HANDLED
Privacy policy
Last updated August 10, 2026
Effective Date: 11 August 2026 | Last Updated: 11 August 2026 | Version: 1.0 | Governing Entity: XRYZEX Group / XRYZEX Enterprises
1. Introduction & Scope of Licensing Agreement
1.1 This Data Privacy Policy (the "Policy") describes the privacy practices, data governance standards, retention commitments, and legal obligations that govern the collection, processing, storage, and disclosure of personal data by XRYZEX AI, a division of XRYZEX Group and XRYZEX Enterprises (collectively, the "Licensor", the "Company", "We", "Us", or "Our"). This Policy applies to all visitors of XRYZEX marketing surfaces, prospective licensees, licensed operators, and any natural person who interacts with the XRYZEX website, sales channels, support systems, or licensing infrastructure.
1.2 XRYZEX AI sells a Turnkey Voice AI Agency Software License — an unbranded, production-ready Voice AI platform codebase that agency buyers ("Licensees") purchase and deploy on their own cloud infrastructure (including, without limitation, Vercel, Supabase, and Vapi) in order to operate their own independent Voice AI agencies. This Policy is drafted to govern two materially distinct data environments, and each section below expressly identifies which environment it addresses:
- Visitor & Licensing Data — personal data collected directly by XRYZEX on its own marketing surfaces, sales channels, and licensing infrastructure (governed by Sections 2, 6, 7, 8, 9, and 10 of this Policy); and
- Deployment & End-Caller Data — data handled by the licensed software after a Licensee deploys it on the Licensee's own infrastructure (governed by Sections 4, 5, and 8 of this Policy).
1.3 By accessing any XRYZEX marketing surface, submitting a licensing inquiry, activating a license key, or otherwise engaging with the Company, you acknowledge that you have read and understood this Policy. Where this Policy references the licensed software's behavior, such references describe the engineering architecture of the codebase as delivered under license and are not representations that XRYZEX operates, hosts, or controls any Licensee deployment.
1.4 Capitalized terms not otherwise defined in this Policy carry the meanings assigned to them in the XRYZEX Terms of Service and the applicable Software License Agreement. In the event of any conflict between this Policy and a signed License Agreement, the signed License Agreement shall control with respect to the parties thereto.
2. Merchant of Record & Financial Processing (Paddle)
2.1 All commercial licensing transactions conducted through XRYZEX — including, without limitation, license fee collection, invoicing, tax collection, and checkout processing — are handled securely by Paddle.com Markets Limited ("Paddle") acting as the global Merchant of Record for XRYZEX. Paddle is the contracting merchant for each transaction and is responsible for the full financial lifecycle of every purchase, including payment authorization, settlement, currency conversion, refunds, and chargeback management.
2.2 As Merchant of Record, Paddle is the party that collects and processes payment card data, executes credit and debit card transactions, performs fraud screening, and remits applicable value-added tax (VAT), sales tax, goods and services tax (GST), and other indirect taxes to the appropriate taxing authorities in the jurisdictions where such taxes are due. Paddle also generates and issues all commercial invoices, receipts, and tax documentation associated with each licensing transaction.
2.3 XRYZEX never receives, processes, stores, or retains raw payment card numbers (PANs), card verification values (CVV/CVC), or cardholder authentication credentials. Payment card data is transmitted directly from the purchaser's browser or device to Paddle's PCI DSS-compliant payment infrastructure over encrypted channels. XRYZEX's systems receive only limited, non-sensitive order metadata — such as the purchaser's name, billing email address, licensed product identifier, transaction reference, and payment status — which is used solely for license fulfillment, activation, and support purposes.
2.4 Paddle operates as an independent data controller with respect to the payment data it processes and maintains its own privacy policy, data processing terms, and security obligations. By completing a purchase, you acknowledge that your payment data will be processed by Paddle in accordance with Paddle's privacy policy and applicable law. XRYZEX's processing of the limited order metadata described in Clause 2.3 is governed by this Policy and by the data processing terms agreed between XRYZEX and Paddle.
2.5 Tax residency, invoicing, and compliance questions relating to a specific purchase should be directed to Paddle through the checkout interface or to XRYZEX at support@xryzex.com, and XRYZEX will coordinate with Paddle as required to resolve the matter.
3. Absolute IP Retention & Global Licensing Rights
3.1 Ironclad IP Protection Clause. XRYZEX Group / XRYZEX Enterprises retains 100% full legal ownership of all primary intellectual property rights in and to the licensed software, including, without limitation, all core software source code, compiled binaries, database structures and schemas, data models, API definitions, workflow configurations, prompt architectures, agent orchestration logic, documentation, design assets, brand assets, trademarks, service marks, trade names, trade secrets, patents, patent applications, and all derivative works thereof (collectively, the "XRYZEX IP"). Nothing in any license, agreement, or this Policy transfers, assigns, or conveys any ownership interest in the XRYZEX IP to any Licensee or third party.
3.2 A purchase of the Turnkey Voice AI Agency Software License grants the buyer only a limited, non-exclusive, non-transferable, non-sublicensable right to deploy and operate the licensed software for a single operating entity ("the 1-Entity Deployment Right"), subject to the terms of the applicable License Agreement. This license is a right to use, not a sale of the software or any component of the XRYZEX IP.
3.3 XRYZEX expressly retains the exclusive, perpetual, irrevocable, worldwide, unrestricted right to modify, upgrade, patch, maintain, market, advertise, promote, resell, re-license, sublicense, distribute, and otherwise exploit the licensed software and the XRYZEX IP in any current or future form, medium, or format, and to any third party, in any jurisdiction, without any obligation, accounting, or payment to any Licensee. This right survives the termination, expiration, or non-renewal of any license.
3.4 XRYZEX further retains the unrestricted right to create, develop, and commercialize derivative works, enhancements, successor products, and entirely new products built upon, inspired by, or derived from the XRYZEX IP. No Licensee shall acquire any right, title, or interest in any such derivative work by virtue of its prior license, and no Licensee shall register, claim, or assert any ownership, lien, or encumbrance over any portion of the XRYZEX IP.
3.5 Licensees may not reverse engineer, decompile, disassemble, copy, frame, scrape, rent, lease, loan, sublicense, or create derivative works of the licensed software except to the extent expressly permitted by the License Agreement or mandatory applicable law. Any unauthorized use, reproduction, or distribution of the XRYZEX IP constitutes a material breach of the license and may result in termination of the license and the pursuit of all available legal remedies, including injunctive relief and damages.
3.6 The IP retention and global licensing rights described in this Section 3 are not privacy provisions in the conventional sense; they are included in this Policy to make unmistakably clear that no data processing activity, deployment, or configuration by any Licensee can be construed as conferring any ownership, lien, or proprietary interest in the XRYZEX IP, and to establish the legal baseline against which all other clauses in this Policy operate.
4. Zero-Retention Architecture & Ephemeral Voice Processing
4.1 The licensed software is engineered under a Zero Raw Call-Data Retention Architecture. Voice interactions are processed ephemerally, in-memory, and in real time. The software is designed to stream audio and text into the voice processing pipeline, execute the conversational logic, and release the payload from memory immediately upon completion of each interaction. There is no design provision, no default configuration, and no supported feature that writes raw voice recordings, audio payloads, or full call transcripts to any local database.
4.2 Neither XRYZEX nor the licensed software, as delivered and configured under the standard license, stores raw call audio, audio payloads, or verbatim call transcripts on local databases, object storage, or any persistent medium controlled by XRYZEX. This zero-retention posture is a core architectural commitment of the product and is not dependent on any Licensee configuration to be effective.
4.3 The only data that may be logged in connection with a voice interaction is non-PII operational metric data, which is numerical and aggregate in nature and cannot, on its own, identify any natural person. Such operational metrics may include, without limitation:
- Call duration (measured in seconds or minute buckets);
- Interaction timestamps and timezone offsets;
- Call outcome codes and status flags;
- Concurrency and throughput counters;
- Latency and error-rate telemetry; and
- Aggregate usage statistics (for example, calls per hour or per day).
4.4 Because raw audio and verbatim transcripts are not retained, the standard attack surface for the disclosure, breach, or misuse of sensitive conversational content is materially reduced. XRYZEX does not build speaker profiles, does not perform biometric analysis, and does not derive behavioral inferences from any voice interaction processed by the licensed software.
4.5 Licensees who elect to enable optional logging, recording, transcription, or analytics features beyond the delivered baseline do so at their own discretion and assume full responsibility for any personal data such features may process. Any such optional features are separate from the Zero-Retention Architecture described in this Section 4 and are not operated, controlled, or supported by XRYZEX.
5. Separation of Roles (Licensee as Data Controller)
5.1 The buyer of the Turnkey Voice AI Agency Software License ("Licensee"), upon deploying the software to the Licensee's own cloud infrastructure, acts as the independent Data Controller for the Licensee's end-clients and for the callers who interact with the Licensee's deployed instances. The Licensee determines the purposes and means of processing of end-caller personal data, configures the deployment, and is responsible for the lawful basis, notice, consent, and compliance obligations applicable to those interactions.
5.2 XRYZEX is neither the data controller nor the data processor for the Licensee's end-client phone conversations. XRYZEX does not route, intercept, monitor, record, store, or otherwise process the substantive content of any caller conversation occurring on a Licensee's independent deployment instance. XRYZEX has no access to, no liability for, and no ownership over caller interactions occurring on any Licensee deployment.
5.3 Because the Licensee is the Data Controller, the Licensee bears sole responsibility for ensuring that its deployment and its handling of end-caller data comply with all applicable laws and regulations, including, without limitation, the Telephone Consumer Protection Act (TCPA), the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), the Indian Digital Personal Data Protection (DPDP) Act and Rules, and any other applicable privacy, telemarketing, and consumer-protection statutes. This responsibility includes obtaining any required consent, honoring call-recording notice requirements, maintaining do-not-call compliance, and responding to data-subject requests.
5.4 XRYZEX's role with respect to the Licensee is limited to that of a software licensor. XRYZEX does not provide legal advice, does not guarantee compliance with any specific law or regulation, and makes no warranty that any particular deployment configuration will satisfy the Licensee's regulatory obligations. Licensees are strongly encouraged to obtain independent legal counsel regarding their telemarketing, recording, and privacy compliance programs.
5.5 To the fullest extent permitted by law, XRYZEX disclaims all liability for any claims, damages, fines, penalties, or regulatory actions arising from a Licensee's processing of end-caller personal data, including claims arising from unauthorized access to, loss of, or disclosure of such data on a Licensee's deployment. Nothing in this Policy limits any liability that cannot be limited under applicable law.
6. Information Collected Directly by XRYZEX
6.1 XRYZEX collects only a narrow, purpose-limited set of personal data directly from individuals who engage with its marketing surfaces, sales channels, and licensing infrastructure. The categories of information collected directly by XRYZEX are as follows:
6.1.1 Pre-Sales Licensing Inquiries
When you submit a licensing inquiry or apply for a license through XRYZEX marketing surfaces, we may collect the following categories of data:
- Name — your full legal or business name;
- Agency Name — the name of the agency or operating entity you represent;
- Email Address — your business contact email address;
- Deployment Goals — information you voluntarily provide about your intended use case, deployment scale, and business objectives; and
- Optional Correspondence — any additional information you choose to include in your inquiry or follow-up communications.
6.1.2 System Access Verification & License Activation Records
To protect the integrity of the licensing infrastructure and to prevent unauthorized use of the XRYZEX IP, XRYZEX may process the following categories of technical and verification data:
- License Key Activation Records — the license key identifier, activation timestamp, and the number of activations associated with a license;
- System Access Verification Logs — authentication events, IP addresses, user-agent strings, and access timestamps associated with licensed portals or support systems; and
- Account Identifiers — usernames, email addresses, and role identifiers used to administer licensed access.
6.2 XRYZEX does not engage in the systematic collection of browsing behavior for advertising purposes, does not sell personal data, and does not share personal data with third parties for their own independent marketing purposes. XRYZEX processes the categories described in this Section 6 solely for the purposes of responding to inquiries, evaluating license applications, fulfilling and activating licenses, providing support, preventing fraud and abuse, and maintaining the security and integrity of its systems.
6.3 The legal bases for XRYZEX's processing of directly collected data include, where applicable: the performance of a contract or pre-contractual steps at your request; legitimate interests in operating, securing, and improving the licensing business; compliance with legal obligations; and, where required, your consent, which may be withdrawn at any time.
7. Sub-Processors & Infrastructure Providers
7.1 XRYZEX relies on a limited set of third-party infrastructure providers and sub-processors to operate its business and to support the licensed software. Each provider is engaged for a specific, functional role and is subject to appropriate data processing and confidentiality obligations. The principal providers and their functional roles are disclosed below:
- Paddle.com Markets Limited ("Paddle") — acts as the global Merchant of Record for all licensing transactions, handling checkout, payment card processing, tax collection and remittance, invoicing, refunds, and chargebacks. Paddle processes payment data as an independent controller and is not a sub-processor of XRYZEX for payment card data.
- Vapi AI — provides the voice and conversational AI runtime components that the licensed software integrates with to execute real-time voice interactions. Vapi processes voice streams and conversational context in the course of delivering its API services to Licensee deployments.
- Supabase — provides the open-source backend infrastructure (including PostgreSQL database services, authentication, and storage) that Licensees commonly use to host the licensed software's application layer. Supabase acts as an infrastructure provider to the Licensee's deployment, not to XRYZEX.
- NextAuth (Auth.js) — provides the authentication and session-management library used within the licensed software to secure application access. NextAuth is an open-source library embedded in the codebase; it does not operate a separate data-processing service on behalf of XRYZEX.
- Telephony Providers — third-party telephony and SIP trunking providers that connect the licensed software to the public telephone network. These providers route call signaling and audio between the telephone network and the Licensee's deployment.
- Cloud & Hosting Providers — infrastructure providers (including Vercel and other cloud platforms) on which XRYZEX marketing surfaces and the licensed software may be hosted. These providers process data solely to deliver hosting, compute, and network services.
7.2 XRYZEX maintains a current list of sub-processors and will provide reasonable notice of any material changes to that list. Where a sub-processor processes personal data on behalf of XRYZEX, XRYZEX requires such sub-processor to comply with applicable data protection law and to provide a comparable level of protection to that described in this Policy.
7.3 For the avoidance of doubt, the infrastructure providers described in this Section 7 that serve Licensee deployments (including Vapi, Supabase, NextAuth, and telephony providers) are engaged by, and provide services to, the Licensee, not XRYZEX. XRYZEX is not a party to, and has no visibility into, the data-processing arrangements between a Licensee and such providers.
8. Global Privacy Framework Compliance
8.1 XRYZEX designs its data governance program to support compliance with the principal global privacy frameworks applicable to its business, and the licensed software is engineered to enable Licensees to meet their own obligations under these frameworks. This Section describes the standards that inform XRYZEX's approach and the architectural features that support Licensee compliance.
8.1.1 General Data Protection Regulation (GDPR)
- Article 5 — Data Minimization. XRYZEX applies the principle of data minimization to all processing: personal data is limited to what is adequate, relevant, and necessary in relation to the purposes for which it is processed. The Zero-Retention Architecture described in Section 4 is a direct implementation of the minimization principle, ensuring that raw call audio and transcripts are not retained.
- Article 17 — Right to Erasure ("Right to be Forgotten"). Data subjects may request the erasure of their personal data from XRYZEX systems by contacting support@xryzex.com. XRYZEX will honor such requests where required by applicable law and where no legal obligation or legitimate interest requires continued retention.
- Additional GDPR obligations. XRYZEX supports lawful-basis documentation, data-subject access rights, portability, rectification, and restriction of processing, and maintains appropriate technical and organizational measures as described in Section 9.
8.1.2 California Consumer Privacy Act (CCPA) & California Privacy Rights Act (CPRA)
- XRYZEX does not sell or share personal information as those terms are defined under the CCPA/CPRA, and does not engage in cross-context behavioral advertising.
- California residents have the right to know, the right to delete, the right to correct, the right to limit the use of sensitive personal information, and the right to non-discrimination for the exercise of privacy rights.
- Because XRYZEX is neither controller nor processor for end-caller conversations on Licensee deployments, California residents who are callers on a Licensee's deployment should direct their CCPA/CPRA requests to the relevant Licensee as Data Controller.
8.1.3 India — Digital Personal Data Protection (DPDP) Act & DPDP Rules 2025
- XRYZEX processes personal data of data principals in India in accordance with the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, including the principles of lawful processing, purpose limitation, data minimization, accuracy, storage limitation, and reasonable security safeguards.
- Where consent is the lawful basis for processing, XRYZEX obtains free, specific, informed, unconditional, and unambiguous consent with a clear affirmative action, and honors consent withdrawal.
- Data principals in India may exercise their rights of access, correction, and erasure through support@xryzex.com.
8.1.4 Cross-Border Data Transfers & APP 8
- XRYZEX may process data using infrastructure located in multiple jurisdictions. For transfers of personal information to recipients outside the originating jurisdiction, XRYZEX applies appropriate safeguards, including standard contractual clauses, adequacy determinations, and contractual assurances of a substantially similar level of protection.
- For Australian data subjects, XRYZEX aligns its cross-border disclosure practices with Australian Privacy Principle (APP) 8, ensuring that overseas recipients are bound by obligations no less onerous than those imposed by the Australian Privacy Act, and that XRYZEX remains accountable for such disclosures.
- Because Licensee deployments run on the Licensee's own infrastructure, cross-border transfer decisions for end-caller data are made by the Licensee as Data Controller, and the Licensee is responsible for ensuring that such transfers comply with applicable law.
8.2 This Section 8 is a statement of XRYZEX's compliance posture and engineering commitments. It does not constitute legal advice, does not guarantee compliance with any specific law for any particular Licensee deployment, and does not create any obligation on XRYZEX to monitor, audit, or enforce Licensee compliance.
9. Data Security Standards & Encryption
9.1 XRYZEX maintains a defense-in-depth security program designed to protect the confidentiality, integrity, and availability of the data it processes and to support the secure operation of the licensed software. The security standards described in this Section apply to XRYZEX's own systems and are provided as reference guidance for Licensee deployments.
9.1.1 Encryption in Transit
All data transmitted to and from XRYZEX systems, and all data transmitted between the licensed software and its integrated services, is encrypted in transit using industry-standard cryptographic protocols, including TLS 1.2 and TLS 1.3. XRYZEX disables legacy protocols (SSLv3, TLS 1.0, and TLS 1.1) and enforces strong cipher suites, forward secrecy, and certificate validation across its surfaces.
9.1.2 Encryption at Rest
Where any data is persisted by XRYZEX or recommended for persistence in the licensed software, such data is encrypted at rest using strong, industry-recognized encryption algorithms (including AES-256) with managed key rotation. The Zero-Retention Architecture minimizes the volume of data requiring at-rest encryption by ensuring that raw call audio and transcripts are not stored.
9.1.3 Access Control Protocols
- Least-Privilege Access — access to systems, databases, and administrative functions is granted on a least-privilege basis and restricted to personnel whose roles require it;
- Authentication & Authorization — access is protected by strong authentication mechanisms, including multi-factor authentication for administrative access, and role-based access control (RBAC);
- Session Management — sessions are secured through the licensed software's authentication layer (NextAuth), with appropriate expiry, rotation, and revocation controls; and
- Audit Logging — access and administrative events are logged to support detection, investigation, and accountability.
9.1.4 Infrastructure Isolation
XRYZEX's systems and the licensed software's components are designed to run in isolated, tenant-aware environments. Licensee deployments are independent instances on the Licensee's own cloud infrastructure, providing logical and physical separation between customers. XRYZEX recommends that Licensees apply network segmentation, firewalling, and environment separation consistent with the isolation model described in this Policy.
9.2 XRYZEX also maintains incident-response, vulnerability-management, and personnel-security practices, including confidentiality obligations for all personnel who may access XRYZEX systems. While no system can guarantee absolute security, XRYZEX applies reasonable and appropriate technical and organizational measures commensurate with the risk and sensitivity of the data processed.
10. Rights of Data Subjects & Contact Information
10.1 Subject to applicable law, data subjects whose personal data is processed directly by XRYZEX may exercise the following rights:
- Right of Access — to obtain confirmation of whether and how XRYZEX processes your personal data and to receive a copy of such data;
- Right to Rectification — to correct inaccurate or incomplete personal data;
- Right to Erasure — to request deletion of your personal data where permitted by law (GDPR Art. 17);
- Right to Restrict Processing — to request restriction of processing in the circumstances permitted by law;
- Right to Data Portability — to receive your personal data in a structured, commonly used, machine-readable format where applicable;
- Right to Object — to object to processing based on legitimate interests or for direct marketing; and
- Right to Withdraw Consent — to withdraw any consent previously provided, without affecting the lawfulness of processing carried out before withdrawal.
10.2 To submit a privacy inquiry, an access or erasure request, a correction request, or a licensing verification, or to exercise any other right described in this Policy, contact XRYZEX at:
Email: support@xryzex.com
Subject line: "Privacy Request" or "Licensing Verification"
Response target: within 30 days of verified receipt (or as otherwise required by applicable law)
10.3 XRYZEX will verify the identity of any requester before fulfilling a request and may require reasonable additional information where necessary to prevent unauthorized access or disclosure. XRYZEX will respond to verified requests within the timeframes required by applicable law, and will notify the requester of any extension, denial, or reason for non-action.
10.4 Licensing verification. Because XRYZEX is neither controller nor processor for end-caller data on Licensee deployments, XRYZEX cannot access, retrieve, or produce records of caller conversations. Requests for caller data must be directed to the relevant Licensee as Data Controller. XRYZEX will, however, verify the validity and activation status of any license key upon request, to the extent such verification does not disclose confidential or security-sensitive information.
10.5 If you believe your privacy rights have been infringed, you may also lodge a complaint with the supervisory authority or data protection authority in your jurisdiction. XRYZEX cooperates with such authorities in accordance with applicable law.