Privacy Policy
Effective: 18 April 2026
Last updated: 18 April 2026
1. Who We Are
This Privacy Policy explains how LYT BROX PTE LTD (UEN: 202538612N), a company incorporated in Singapore ("Lyt Brox", "we", "us", "our"), collects, uses, stores, and discloses your personal data.
We operate AI-powered operational platforms for businesses. Depending on the context:
- When you visit our website or use our platform directly, we are the data controller — we decide what data to collect and why.
- When we process data on behalf of our business clients, we are the data processor — our clients decide the purposes, and we process under their instructions. See our Data Processing Addendum for those terms.
Our Data Protection Officer can be reached at sales@lytbrox.com.
2. What Data We Collect
Data you provide to us
- Account information: name, email address, phone number, company name, job title
- Business data: customer records, price lists, quotation details, invoice data, meeting schedules, and other operational data you upload or create on our platform
- Communications: messages you send through the platform (including WhatsApp and email messages processed by our system), support tickets, and correspondence with us
- Payment information: billing address, payment method details (processed by our payment provider Stripe — we do not store full card numbers)
Data we collect automatically
- Technical data: IP address, browser type and version, device information, operating system
- Usage data: pages visited, features used, time spent on the platform, click patterns
- Log data: server logs, error logs, access timestamps, referring URLs
Data from third parties
- WhatsApp Business API (Meta): sender phone numbers, message content, delivery status for messages routed through our platform
- Email providers: email addresses, email content, and delivery metadata for messages processed by our system
- Public lead sources: business contact information from publicly available sources (company websites, business directories) for lead enrichment
3. Why We Collect It
The first two entries apply to this website. The remainder apply only to deployed client platforms, and only where that platform uses the service in question. The website itself has no database, no AI processing and no payment processing.
| Purpose | Data used | Legal basis |
|---|---|---|
| Google LLC (Apps Script, Sheets, Gmail) | Website enquiry intake, storage and notification | Name, email, phone, company, industry, enquiry message, referring page and campaign parameters submitted through the website contact form |
| Netlify | Website hosting and content delivery | Request logs, IP addresses |
| Provide and operate the Service | Account info, business data, communications | Contract performance |
| AI-powered features (scoring, classification, auto-replies, drafting) | Business data, message content, lead information | Contract performance; Consent (for automated decision-making) |
| Process payments and billing | Payment info, account info | Contract performance |
| Improve and develop the Service | Usage data, log data | Legitimate interest |
| Ensure security and prevent fraud | Technical data, log data, IP addresses | Legitimate interest; Legal obligation |
| Communicate with you (support, updates, notices) | Account info, email address | Contract performance; Legitimate interest |
| Comply with legal obligations | As required by law | Legal obligation |
4. Automated Decision-Making and AI
Our platform uses artificial intelligence to:
- Score and classify leads based on business signals (company size, industry, engagement patterns)
- Draft replies to customer messages via WhatsApp and email
- Classify inbound messages by urgency, intent, and sentiment
- Generate quotations and documents based on your business data and templates
These AI features assist your decision-making — they do not make binding decisions without human review. Messages that our AI drafts are held for your approval before being sent, unless you have explicitly enabled auto-send for specific categories. You can adjust auto-send thresholds or disable AI features at any time through your dashboard settings.
5. Who We Share Data With
We do not sell your personal data. We do not share your personal data with advertisers or data brokers. We share data only with the following categories of recipients, and only as necessary to provide the Service:
| Sub-processor | Purpose | Data accessed |
|---|---|---|
| Supabase | Database, authentication, file storage, backend functions | All application data |
| OpenAI | AI processing (classification, generation, analysis) | Message content, business data sent via prompts |
| Resend | Transactional email delivery | Email addresses, email content |
| Google (Gemini) | AI image generation and analysis | Prompts and generated content |
| Meta (WhatsApp Business API) | WhatsApp message delivery and receipt | Phone numbers, message content, delivery status |
| Stripe | Payment processing | Payment method details, billing address, transaction data |
All sub-processors are bound by data processing agreements that require them to protect your data to standards at least as protective as this Privacy Policy.
6. International Data Transfers
Your data may be transferred to and processed in countries outside of Singapore, including the United States (where many of our sub-processors are based). When we transfer personal data internationally, we ensure appropriate safeguards are in place, including contractual data protection clauses with our sub-processors that meet the requirements of the PDPA and, where applicable, EU Standard Contractual Clauses under the GDPR.
7. Data Retention
| Data type | Retention period |
|---|---|
| Account information | Duration of your account + 30 days after termination |
| Business and operational data | Duration of your account + 30 days after termination |
| Communications (messages, emails) | Duration of your account + 30 days after termination |
| Payment and billing records | 7 years (Singapore tax and accounting requirements) |
| Technical and usage logs | 90 days |
| Security event logs | 1 year |
When data is no longer needed, it is securely deleted or anonymised. You may request earlier deletion — see "Your Rights" below.
8. Data Security
We implement technical and organisational measures to protect your data, including:
- Encryption in transit (TLS/HTTPS for all connections)
- A Content Security Policy restricting where the website may send data
- Input length limits and automated-submission controls on the enquiry form
- Enquiry data written as plain text, never as executable spreadsheet content
Deployed client platforms carry additional controls appropriate to that platform, including encryption at rest, row-level access isolation, role-based access control and audit logging. Those are specified in the agreement for that deployment rather than here.
No method of transmission or storage is 100% secure. If you become aware of a security vulnerability, please report it to sales@lytbrox.com.
9. Data Breach Notification
In the event of a personal data breach that is likely to result in significant harm to affected individuals, we will notify the Personal Data Protection Commission (PDPC) and the affected individuals as soon as practicable, and in any case within 3 calendar days of our assessment. Where we are acting as a data processor, we will notify the relevant data controller without undue delay. Where GDPR applies, we will notify the relevant supervisory authority within 72 hours.
10. Your Rights
Under the Singapore PDPA and (where applicable) the GDPR, you have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete personal data.
- Withdrawal of consent: Withdraw your consent for data processing at any time. This may affect our ability to provide certain features.
- Deletion: Request deletion of your personal data, subject to legal retention requirements. See our Data Deletion page for the full process.
- Data portability (GDPR): Request your personal data in a structured, machine-readable format.
- Object to processing (GDPR): Object to processing based on legitimate interests, including profiling.
- Restrict processing (GDPR): Request that we limit the processing of your data in certain circumstances.
- Object to automated decision-making (GDPR): Request human review of decisions made solely by automated processing that significantly affect you.
How to exercise your rights: Email sales@lytbrox.com with your request. We will verify your identity and respond within 30 days. If we need more time, we will inform you of the reason and the expected timeline.
Complaints: If you believe we have not handled your personal data properly, you may lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore at www.pdpc.gov.sg. If GDPR applies, you may also lodge a complaint with your local data protection authority.
11. Cookies and Tracking
Our website and platform use the following types of cookies and tracking technologies:
- Essential cookies: Required for authentication, security, and basic platform functionality. These cannot be disabled.
- Analytics cookies: Help us understand how you use the Service so we can improve it. These collect anonymised usage data.
We do not use advertising cookies or tracking pixels from ad networks. You can control cookie settings through your browser preferences.
12. Children's Privacy
Our Service is intended for businesses and business professionals. It is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you become aware that a child has provided us with personal data, please contact us and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. For material changes, we will provide at least 14 days' notice by email or by posting a prominent notice on the Service. The "Last updated" date at the top of this page will always reflect the most recent revision.
14. Contact
LYT BROX PTE LTD
UEN: 202538612N
60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051
Data Protection Officer: sales@lytbrox.com
General enquiries: sales@lytbrox.com