Back to Home

Privacy Policy

Effective: 18 April 2026

Last updated: 18 April 2026

1. Who We Are

This Privacy Policy explains how LYT BROX PTE LTD (UEN: 202538612N), a company incorporated in Singapore ("Lyt Brox", "we", "us", "our"), collects, uses, stores, and discloses your personal data.

We operate AI-powered operational platforms for businesses. Depending on the context:

  • When you visit our website or use our platform directly, we are the data controller — we decide what data to collect and why.
  • When we process data on behalf of our business clients, we are the data processor — our clients decide the purposes, and we process under their instructions. See our Data Processing Addendum for those terms.

Our Data Protection Officer can be reached at sales@lytbrox.com.

2. What Data We Collect

Data you provide to us

  • Account information: name, email address, phone number, company name, job title
  • Business data: customer records, price lists, quotation details, invoice data, meeting schedules, and other operational data you upload or create on our platform
  • Communications: messages you send through the platform (including WhatsApp and email messages processed by our system), support tickets, and correspondence with us
  • Payment information: billing address, payment method details (processed by our payment provider Stripe — we do not store full card numbers)

Data we collect automatically

  • Technical data: IP address, browser type and version, device information, operating system
  • Usage data: pages visited, features used, time spent on the platform, click patterns
  • Log data: server logs, error logs, access timestamps, referring URLs

Data from third parties

  • WhatsApp Business API (Meta): sender phone numbers, message content, delivery status for messages routed through our platform
  • Email providers: email addresses, email content, and delivery metadata for messages processed by our system
  • Public lead sources: business contact information from publicly available sources (company websites, business directories) for lead enrichment

3. Why We Collect It

The first two entries apply to this website. The remainder apply only to deployed client platforms, and only where that platform uses the service in question. The website itself has no database, no AI processing and no payment processing.

PurposeData usedLegal basis
Google LLC (Apps Script, Sheets, Gmail)Website enquiry intake, storage and notificationName, email, phone, company, industry, enquiry message, referring page and campaign parameters submitted through the website contact form
NetlifyWebsite hosting and content deliveryRequest logs, IP addresses
Provide and operate the ServiceAccount info, business data, communicationsContract performance
AI-powered features (scoring, classification, auto-replies, drafting)Business data, message content, lead informationContract performance; Consent (for automated decision-making)
Process payments and billingPayment info, account infoContract performance
Improve and develop the ServiceUsage data, log dataLegitimate interest
Ensure security and prevent fraudTechnical data, log data, IP addressesLegitimate interest; Legal obligation
Communicate with you (support, updates, notices)Account info, email addressContract performance; Legitimate interest
Comply with legal obligationsAs required by lawLegal obligation

4. Automated Decision-Making and AI

Our platform uses artificial intelligence to:

  • Score and classify leads based on business signals (company size, industry, engagement patterns)
  • Draft replies to customer messages via WhatsApp and email
  • Classify inbound messages by urgency, intent, and sentiment
  • Generate quotations and documents based on your business data and templates

These AI features assist your decision-making — they do not make binding decisions without human review. Messages that our AI drafts are held for your approval before being sent, unless you have explicitly enabled auto-send for specific categories. You can adjust auto-send thresholds or disable AI features at any time through your dashboard settings.

5. Who We Share Data With

We do not sell your personal data. We do not share your personal data with advertisers or data brokers. We share data only with the following categories of recipients, and only as necessary to provide the Service:

Sub-processorPurposeData accessed
SupabaseDatabase, authentication, file storage, backend functionsAll application data
OpenAIAI processing (classification, generation, analysis)Message content, business data sent via prompts
ResendTransactional email deliveryEmail addresses, email content
Google (Gemini)AI image generation and analysisPrompts and generated content
Meta (WhatsApp Business API)WhatsApp message delivery and receiptPhone numbers, message content, delivery status
StripePayment processingPayment method details, billing address, transaction data

All sub-processors are bound by data processing agreements that require them to protect your data to standards at least as protective as this Privacy Policy.

6. International Data Transfers

Your data may be transferred to and processed in countries outside of Singapore, including the United States (where many of our sub-processors are based). When we transfer personal data internationally, we ensure appropriate safeguards are in place, including contractual data protection clauses with our sub-processors that meet the requirements of the PDPA and, where applicable, EU Standard Contractual Clauses under the GDPR.

7. Data Retention

Data typeRetention period
Account informationDuration of your account + 30 days after termination
Business and operational dataDuration of your account + 30 days after termination
Communications (messages, emails)Duration of your account + 30 days after termination
Payment and billing records7 years (Singapore tax and accounting requirements)
Technical and usage logs90 days
Security event logs1 year

When data is no longer needed, it is securely deleted or anonymised. You may request earlier deletion — see "Your Rights" below.

8. Data Security

We implement technical and organisational measures to protect your data, including:

  • Encryption in transit (TLS/HTTPS for all connections)
  • A Content Security Policy restricting where the website may send data
  • Input length limits and automated-submission controls on the enquiry form
  • Enquiry data written as plain text, never as executable spreadsheet content

Deployed client platforms carry additional controls appropriate to that platform, including encryption at rest, row-level access isolation, role-based access control and audit logging. Those are specified in the agreement for that deployment rather than here.

    No method of transmission or storage is 100% secure. If you become aware of a security vulnerability, please report it to sales@lytbrox.com.

    9. Data Breach Notification

    In the event of a personal data breach that is likely to result in significant harm to affected individuals, we will notify the Personal Data Protection Commission (PDPC) and the affected individuals as soon as practicable, and in any case within 3 calendar days of our assessment. Where we are acting as a data processor, we will notify the relevant data controller without undue delay. Where GDPR applies, we will notify the relevant supervisory authority within 72 hours.

    10. Your Rights

    Under the Singapore PDPA and (where applicable) the GDPR, you have the following rights:

    • Access: Request a copy of the personal data we hold about you.
    • Correction: Request correction of inaccurate or incomplete personal data.
    • Withdrawal of consent: Withdraw your consent for data processing at any time. This may affect our ability to provide certain features.
    • Deletion: Request deletion of your personal data, subject to legal retention requirements. See our Data Deletion page for the full process.
    • Data portability (GDPR): Request your personal data in a structured, machine-readable format.
    • Object to processing (GDPR): Object to processing based on legitimate interests, including profiling.
    • Restrict processing (GDPR): Request that we limit the processing of your data in certain circumstances.
    • Object to automated decision-making (GDPR): Request human review of decisions made solely by automated processing that significantly affect you.

    How to exercise your rights: Email sales@lytbrox.com with your request. We will verify your identity and respond within 30 days. If we need more time, we will inform you of the reason and the expected timeline.

    Complaints: If you believe we have not handled your personal data properly, you may lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore at www.pdpc.gov.sg. If GDPR applies, you may also lodge a complaint with your local data protection authority.

    11. Cookies and Tracking

    Our website and platform use the following types of cookies and tracking technologies:

    • Essential cookies: Required for authentication, security, and basic platform functionality. These cannot be disabled.
    • Analytics cookies: Help us understand how you use the Service so we can improve it. These collect anonymised usage data.

    We do not use advertising cookies or tracking pixels from ad networks. You can control cookie settings through your browser preferences.

    12. Children's Privacy

    Our Service is intended for businesses and business professionals. It is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you become aware that a child has provided us with personal data, please contact us and we will delete it promptly.

    13. Changes to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. For material changes, we will provide at least 14 days' notice by email or by posting a prominent notice on the Service. The "Last updated" date at the top of this page will always reflect the most recent revision.

    14. Contact

    LYT BROX PTE LTD

    UEN: 202538612N

    60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051

    Data Protection Officer: sales@lytbrox.com

    General enquiries: sales@lytbrox.com