01Who we are
Inboxi is a business messaging platform operated by IN General Digital Solutions LLC, a limited liability company registered in the State of New Mexico, United States ("the Company", "we", "us"). This Policy explains how we handle personal information in connection with the inboxi.app website and the Inboxi service.
- Controller
- IN General Digital Solutions LLC.
- Jurisdiction of establishment
- State of New Mexico, United States.
- Contact for data protection matters
- contact@inboxi.app. Correspondence is reviewed and answered by a member of the team.
02Two different roles we play
Inboxi handles two kinds of data, and our responsibilities differ between them. Please read this section before the rest of the Policy, because it determines which rules apply to what.
- Account data — we are the controller
- Information about you as our customer: your name, email address, company, billing details and how you use the product. We decide how this is processed, and this Policy governs it.
- Workspace content — we are the processor
- The messages, contacts and attachments that flow through your shared inbox. This belongs to you. We process it only on your instructions, in order to provide the service, and never for our own purposes.
03Information we collect
- Information you give us
- Your name, email address, telephone number, company name, workspace settings, and the content of any message you send us.
- Workspace content
- Messages, contact records and attachments synchronised from the channels you connect — such as WhatsApp Business, email, Instagram, Facebook and Telegram — together with the replies your team and our AI features generate.
- Information collected automatically
- IP address, browser and device type, operating system, pages viewed, feature usage, and diagnostic logs. This is standard web and application telemetry.
- Information from our payment provider
- On each payment we receive the amount, currency, date and outcome, the card scheme and its final four digits, and the billing name and country. We never receive or store a full card number.
04Why we process it
- To provide, operate and support the Inboxi service.
- To generate AI replies, classifications and routing decisions inside your workspace.
- To authenticate users and secure workspaces against unauthorised access.
- To bill subscriptions, issue receipts and keep the accounting records the law requires.
- To diagnose faults, monitor availability and improve reliability.
- To detect and prevent fraud, abuse and security incidents.
- To send service messages about your workspace, your subscription and material changes to the service.
We do not use personal information to make automated decisions producing legal or similarly significant effects about you.
05Legal bases for processing
For data subjects in the European Economic Area or the United Kingdom, we rely on the following legal bases under the General Data Protection Regulation:
- Performance of a contract
- Providing the service you subscribed to and collecting payment for it.
- Legitimate interests
- Securing the service, preventing abuse, diagnosing faults, and establishing or defending legal claims, balanced in each case against your rights and freedoms.
- Compliance with a legal obligation
- Retaining invoices and financial records for the periods prescribed by law.
- Consent
- Optional analytics and any marketing communication you expressly subscribe to. Consent may be withdrawn at any time without affecting processing already carried out.
Where we process workspace content, you are the controller and we act on your instructions as processor. If you require a data processing agreement, contact us and we will provide one.
06How AI features handle your messages
Inboxi uses third-party large language model providers to classify incoming messages and draft replies. When an AI feature runs, the relevant message content is transmitted to that provider, a response is returned, and the result is shown inside your workspace.
- Content is sent only when an AI feature is actually invoked for a message.
- Our model providers process this content under agreements that prohibit using it to train their models.
- AI features can be disabled per workspace in settings, in which case no content is transmitted to a model provider at all.
- AI-drafted replies are suggestions. Your team remains responsible for what is sent to a customer.
07Payment information
Card payments are processed by a third-party payment institution certified to PCI DSS Level 1. Card details are entered directly into that provider's certified environment; they do not traverse Inboxi's servers, and we have no facility to view, store or retrieve a full card number, expiry date or security code.
The information returned to us is confined to what is needed to reconcile an invoice. The payment provider processes transaction data as an independent controller under its own privacy policy.
08Cookies and analytics
The website and application use a limited number of cookies. Strictly necessary cookies keep you signed in and remember your language and display preferences; these cannot be disabled without breaking the service.
We also use a third-party analytics service to understand aggregate product usage so we can improve it. You can clear or block cookies in your browser at any time; blocking analytics cookies has no effect on the functionality available to you.
09Who we share information with
We disclose personal information only to service providers engaged to perform defined functions on our behalf, and only to the extent each function requires. Every provider is bound by a written agreement restricting its use of the information to the purposes we specify. The categories engaged are:
- Payment processing
- A payment institution certified to PCI DSS Level 1 processes card transactions, issues receipts and performs fraud screening.
- Cloud infrastructure and hosting
- Providers that operate the servers, databases and content delivery on which the service runs.
- AI model providers
- Providers that generate replies and classifications, as described in the section on AI features.
- Messaging channel providers
- The platforms you connect — such as WhatsApp Business, email, Instagram, Facebook and Telegram — which necessarily receive and transmit the messages routed through them.
- Product analytics and communications
- Providers that measure aggregate product usage and deliver transactional email on our behalf.
Beyond the above, we disclose information only where required by law — a valid court order, subpoena or regulatory demand — or where necessary to establish or defend a legal claim. If the business is sold or merged, information may transfer as part of that transaction and affected customers would be notified in advance.
10International transfers
We are established in the United States, our delivery team operates from the Arab Republic of Egypt, and our providers maintain infrastructure across several regions. Your information will therefore be processed outside your country of residence, including in jurisdictions that may not afford an equivalent standard of data protection.
Where personal data is transferred out of the European Economic Area or the United Kingdom, we rely on the Standard Contractual Clauses adopted by the European Commission, which our providers incorporate into their data processing agreements with us.
11How long we keep it
- Workspace content
- Retained for as long as your workspace is active. After a subscription ends, content is retained for 30 days so you can export it or reactivate, and is then permanently deleted.
- Account and profile data
- Deleted within 90 days of the workspace being closed, unless a longer period is required by law.
- Invoices and financial records
- Retained for 7 years, as United States taxation and accounting rules require.
- Security and diagnostic logs
- Retained for up to 12 months.
You can request deletion of your workspace content at any time and we will action it without waiting for the periods above, save where we are legally required to retain a record.
12How we protect it
- All traffic to and from the service is encrypted in transit using Transport Layer Security.
- Payment data never reaches our infrastructure; it is transmitted directly to the payment provider.
- Access to production systems is restricted to the personnel who require it, using strong unique credentials and multi-factor authentication where the provider supports it.
- Workspaces are logically separated so that one customer's content is not reachable from another's.
- Servers and dependencies are kept at current patch levels and network access is restricted by firewall.
No system is perfectly secure. If a breach affects your personal information and creates a risk to you, we will notify you and the competent supervisory authority without undue delay and within the periods the law prescribes.
13Your rights
Wherever you are located, you may ask us to give effect to the following rights in respect of your personal information:
- Access — receive a copy of the information we hold about you.
- Rectification — correct anything inaccurate or incomplete.
- Erasure — have it deleted, save where an overriding obligation to retain it applies.
- Restriction — suspend our processing while a dispute is resolved.
- Portability — receive it in a structured, machine-readable format, or have it sent to another provider.
- Objection — object to processing carried out on the basis of our legitimate interests.
- Withdrawal of consent — at any time, for anything processed on that basis.
Residents of California are further afforded, under the CCPA as amended by the CPRA, the right to know what personal information is collected and why, the right to deletion, the right to correction, and the right to opt out of its sale or sharing. We neither sell nor share personal information within the meaning of those statutes, so no opt-out arises. We will never treat you differently for exercising any right.
Requests go to contact@inboxi.app. We respond within 30 days and charge nothing. If our response does not satisfy you, you may complain to the data protection authority in your jurisdiction.
14Children's privacy
Inboxi is a business product and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided information to us, write to contact@inboxi.app and it will be deleted.
15Changes to this Policy
We may amend this Policy as the service, our providers or our legal obligations change. The date at the head of this page reflects the version in force. Where an amendment materially affects how we handle your information, active customers are notified by email before it takes effect.
16Contact
Any question, request or complaint about this Policy or about how we handle personal information should be sent to contact@inboxi.app.