1 Data controller
Issyx Labs acts as data controller for personal data collected through its platforms, services and products.
- Name: Issyx Labs
- Operating address: Madrid, Spain
- Contact email: soporte@issyxlabs.com
- Web: https://issyxlabs.com
- Area of operation: Spain, Mexico, and the United States
2 Services covered by this policy
This Privacy Policy applies to all current and future services offered by Issyx Labs, including:
Current services
- Sofia — AI-powered virtual receptionist that manages conversations, appointments and leads through WhatsApp Business API
- Process automation — Implementation of automated flows using Make.com and other integration tools
- Business intelligence dashboards — Creation and management of KPI dashboards connected to real data
- Operational consulting — Consulting in supply chain, operations, ERP and continuous improvement
- Web issyxlabs.com — Corporate website and lead capture forms
Future services
- AI agents specialized by sector (legal, medical, real estate, educational)
- AI and automation training platforms
- Integrations with CRM, ERP and business management systems
- Mobile applications and personal productivity tools
- Predictive analytics and forecasting services
3 Data we collect and purpose
| Data | Source | Purpose |
|---|---|---|
| Full name | Web forms, WhatsApp | Service identification and personalization |
| Email address | Forms, direct email | Communications, quotes and support |
| WhatsApp / phone number | WhatsApp Business API | Commercial support and automation |
| Company name and data | Forms, contracts | Service personalization and delivery |
| WhatsApp messages | Meta/WhatsApp API | Conversation management by Sofia |
| Appointment and calendar data | Google Calendar | Schedule management and reminders |
| Website browsing data | Cookies, analytics | Experience improvement and analytics |
| Billing information | Contracts, billing | Commercial management and tax obligations |
We do not collect special categories of data (health, ideology, biometrics) unless expressly authorized and legally justified.
4 Sofia — Virtual receptionist via WhatsApp
Sofia is the flagship product of Issyx Labs. It acts as a virtual receptionist managing incoming conversations through WhatsApp Business API on behalf of Issyx Labs client companies.
Datas procesados por Sofia
- Phone number of the user initiating the conversation
- Content of messages sent to the business WhatsApp number
- Appointment data, scheduling preferences, and confirmations
- Contact information voluntarily provided during the conversation
- Conversation history to contextualize future responses
Responsibility roles
Conversation retention
- Active conversations: 90 days in operational memory
- Transcripts for analysis: anonymized after 90 days
- Activity logs: 12 months
Future services basados en Sofia
Issyx Labs may develop specialized versions of Sofia for different sectors (healthcare, legal, real estate, education) and additional channels (Instagram, Telegram, email). Any new service involving the processing of additional data will be communicated through an update to this policy.
5 Legal basis for processing
| Processing | Legal basis |
|---|---|
| Client and contract management | Contract execution (Art. 6.1.b RGPD) |
| Commercial communications to clients | Legitimate interest (Art. 6.1.f RGPD) |
| Sofia conversations | User consent + contract with client company |
| Web forms and lead capture | Explicit consent (Art. 6.1.a RGPD) |
| Analytical cookies | Consent (Art. 6.1.a RGPD) |
| Billing and accounting | Legal obligation (Art. 6.1.c RGPD) |
| Direct marketing to non-clients | Explicit consent |
6 Sub-processors and third parties
Issyx Labs does not sell or disclose personal data to third parties for commercial purposes. Data is shared only with the following sub-processors, all with signed DPAs:
| Provider | Service | Certification |
|---|---|---|
| Meta / WhatsApp Business API | Sofia messaging channel | WhatsApp Business Policy · RGPD DPA |
| Google Workspace | Mail, Calendar, Sheets, Drive | ISO 27001 · SOC 2 Type II |
| Make.com (Celonis SE) | Automation platform | ISO 27001 · SOC 2 · GDPR DPA |
| OpenAI | AI engine for Sofia responses | SOC 2 Type II · API DPA |
| Anthropic | Alternative AI engine | SOC 2 Type II · DPA |
| Looker Studio (Google) | KPI Dashboards | ISO 27001 · SOC 2 |
| Tally.so | Lead capture forms | GDPR compliant |
| GitHub (Microsoft) | Web hosting | ISO 27001 · SOC 2 |
7 International transfers
Issyx Labs operates in Spain, Mexico and the United States. Some sub-processors process data outside the European Economic Area. In all cases, Standard Contractual Clauses approved by the European Commission apply, guaranteeing a level of protection equivalent to the GDPR.
8 Retention periods
- Active clients: during the contractual relationship + 5 years
- Leads and contacts without a contract: maximum 2 years from last contact
- WhatsApp conversations (Sofia): 90 active days, then anonymized
- Activity and access logs: 12 months
- Billing data: 6 years (Spanish tax obligation)
- Consulting session data: 5 years after the last session
9 Security
- Encryption in transit: TLS 1.2+ (HTTPS enforced on all services)
- Encryption at rest: AES-256 in Google Workspace and Make.com
- Two-factor authentication (2FA) on all administrative access
- Data segmentation by client (unique client_id in Sofia)
- Automatic daily backups with 30-day retention
- Notification to the AEPD within 72 hours of a security breach
10 Your rights
| Right | Description |
|---|---|
| Access | Know what data we hold about you and for what purpose. |
| Rectification | Correct inaccurate or incomplete data. |
| Erasure | Delete your data when no longer necessary or you withdraw consent. |
| Objection | Object to processing for direct marketing purposes. |
| Restriction | Suspend processing while a complaint is resolved. |
| Portability | Receive your data in a structured format (JSON, CSV). |
| Withdraw consent | At any time, without affecting prior processing. |
You can file a complaint with the AEPD if you believe the processing violates regulations.
11 Minors
Issyx Labs services are directed exclusively at persons over 18 years of age and businesses. We do not knowingly collect data from minors. If we detect we have collected data from a minor without parental consent, we will delete it immediately.
12 Changes to this policy
Issyx Labs may update this Privacy Policy when necessary, especially when launching new services or products. Material changes will be communicated by email to active clients with at least 15 days notice. The current version will always be available at issyxlabs.com/en/privacy-policy.html.
13 Contact
We respond within 72 business hours. To exercise GDPR rights include: full name, copy of identity document and description of the right you wish to exercise.