Legal

Privacy Policy

This policy describes how Issyx Labs collects, uses and protects your personal data across all its services, including Sofia and AI automation services.

Last updated: June 16, 2025 Version 1.0 RGPD · LOPD-GDD · CCPA
Executive summary: Issyx Labs only collects the data necessary to provide the service. We do not sell data to third parties. You can exercise your rights at any time by writing to soporte@issyxlabs.com.

1 Data controller

Issyx Labs acts as data controller for personal data collected through its platforms, services and products.

2 Services covered by this policy

This Privacy Policy applies to all current and future services offered by Issyx Labs, including:

Current services

  • Sofia — AI-powered virtual receptionist that manages conversations, appointments and leads through WhatsApp Business API
  • Process automation — Implementation of automated flows using Make.com and other integration tools
  • Business intelligence dashboards — Creation and management of KPI dashboards connected to real data
  • Operational consulting — Consulting in supply chain, operations, ERP and continuous improvement
  • Web issyxlabs.com — Corporate website and lead capture forms

Future services

  • AI agents specialized by sector (legal, medical, real estate, educational)
  • AI and automation training platforms
  • Integrations with CRM, ERP and business management systems
  • Mobile applications and personal productivity tools
  • Predictive analytics and forecasting services

3 Data we collect and purpose

DataSourcePurpose
Full nameWeb forms, WhatsAppService identification and personalization
Email addressForms, direct emailCommunications, quotes and support
WhatsApp / phone numberWhatsApp Business APICommercial support and automation
Company name and dataForms, contractsService personalization and delivery
WhatsApp messagesMeta/WhatsApp APIConversation management by Sofia
Appointment and calendar dataGoogle CalendarSchedule management and reminders
Website browsing dataCookies, analyticsExperience improvement and analytics
Billing informationContracts, billingCommercial management and tax obligations

We do not collect special categories of data (health, ideology, biometrics) unless expressly authorized and legally justified.

4 Sofia — Virtual receptionist via WhatsApp

Sofia is the flagship product of Issyx Labs. It acts as a virtual receptionist managing incoming conversations through WhatsApp Business API on behalf of Issyx Labs client companies.

Datas procesados por Sofia

  • Phone number of the user initiating the conversation
  • Content of messages sent to the business WhatsApp number
  • Appointment data, scheduling preferences, and confirmations
  • Contact information voluntarily provided during the conversation
  • Conversation history to contextualize future responses

Responsibility roles

Issyx Labs acts as data processor when Sofia processes data on behalf of a client company. The client company is the data controller respecto a sus usuarios finales. Issyx Labs acts as responsable when processing data of its own clients and leads.

Conversation retention

  • Active conversations: 90 days in operational memory
  • Transcripts for analysis: anonymized after 90 days
  • Activity logs: 12 months

Future services basados en Sofia

Issyx Labs may develop specialized versions of Sofia for different sectors (healthcare, legal, real estate, education) and additional channels (Instagram, Telegram, email). Any new service involving the processing of additional data will be communicated through an update to this policy.

5 Legal basis for processing

ProcessingLegal basis
Client and contract managementContract execution (Art. 6.1.b RGPD)
Commercial communications to clientsLegitimate interest (Art. 6.1.f RGPD)
Sofia conversationsUser consent + contract with client company
Web forms and lead captureExplicit consent (Art. 6.1.a RGPD)
Analytical cookiesConsent (Art. 6.1.a RGPD)
Billing and accountingLegal obligation (Art. 6.1.c RGPD)
Direct marketing to non-clientsExplicit consent

6 Sub-processors and third parties

Issyx Labs does not sell or disclose personal data to third parties for commercial purposes. Data is shared only with the following sub-processors, all with signed DPAs:

ProviderServiceCertification
Meta / WhatsApp Business APISofia messaging channelWhatsApp Business Policy · RGPD DPA
Google WorkspaceMail, Calendar, Sheets, DriveISO 27001 · SOC 2 Type II
Make.com (Celonis SE)Automation platformISO 27001 · SOC 2 · GDPR DPA
OpenAIAI engine for Sofia responsesSOC 2 Type II · API DPA
AnthropicAlternative AI engineSOC 2 Type II · DPA
Looker Studio (Google)KPI DashboardsISO 27001 · SOC 2
Tally.soLead capture formsGDPR compliant
GitHub (Microsoft)Web hostingISO 27001 · SOC 2

7 International transfers

Issyx Labs operates in Spain, Mexico and the United States. Some sub-processors process data outside the European Economic Area. In all cases, Standard Contractual Clauses approved by the European Commission apply, guaranteeing a level of protection equivalent to the GDPR.

8 Retention periods

  • Active clients: during the contractual relationship + 5 years
  • Leads and contacts without a contract: maximum 2 years from last contact
  • WhatsApp conversations (Sofia): 90 active days, then anonymized
  • Activity and access logs: 12 months
  • Billing data: 6 years (Spanish tax obligation)
  • Consulting session data: 5 years after the last session

9 Security

  • Encryption in transit: TLS 1.2+ (HTTPS enforced on all services)
  • Encryption at rest: AES-256 in Google Workspace and Make.com
  • Two-factor authentication (2FA) on all administrative access
  • Data segmentation by client (unique client_id in Sofia)
  • Automatic daily backups with 30-day retention
  • Notification to the AEPD within 72 hours of a security breach

10 Your rights

You can exercise any of these rights free of charge by writing to soporte@issyxlabs.com. We respond within a maximum of 30 calendar days.
RightDescription
AccessKnow what data we hold about you and for what purpose.
RectificationCorrect inaccurate or incomplete data.
ErasureDelete your data when no longer necessary or you withdraw consent.
ObjectionObject to processing for direct marketing purposes.
RestrictionSuspend processing while a complaint is resolved.
PortabilityReceive your data in a structured format (JSON, CSV).
Withdraw consentAt any time, without affecting prior processing.
Spanish Data Protection Agency (AEPD)
www.aepd.es

You can file a complaint with the AEPD if you believe the processing violates regulations.

11 Minors

Issyx Labs services are directed exclusively at persons over 18 years of age and businesses. We do not knowingly collect data from minors. If we detect we have collected data from a minor without parental consent, we will delete it immediately.

12 Changes to this policy

Issyx Labs may update this Privacy Policy when necessary, especially when launching new services or products. Material changes will be communicated by email to active clients with at least 15 days notice. The current version will always be available at issyxlabs.com/en/privacy-policy.html.

13 Contact

Privacy contact — Issyx Labs
soporte@issyxlabs.com

We respond within 72 business hours. To exercise GDPR rights include: full name, copy of identity document and description of the right you wish to exercise.