Privacy Policy
At 100xSales Technologies Ltd., we are committed to transparent, privacy-first data handling. This policy explains how we collect, process, protect, and retain personal data across our AI sales automation platform and Meta messaging integrations.
1. Data Controller & Information We Collect
Data Controller Identity
The data controller responsible for your personal data is 100xSales Technologies Ltd., Level 12, Gulshan Avenue, Dhaka 1212, Bangladesh (referred to in this policy as '100xSales', 'we', 'us', or 'our'). We provide AI-powered conversational sales automation services to businesses worldwide.
Account & Merchant Profile Data
When you register for an account or subscribe to our services, we collect your full name, business email address, phone number, company name, billing address, and account credentials necessary to establish and administer your tenant workspace.
Customer & End-User Conversation Data
When our AI agents engage in conversations with your end-customers across messaging channels, we ingest inbound message payloads, timestamps, conversation histories, sender IDs, and customer inquiry text solely to generate automated sales responses and log interactions for your team.
Payment Information
All payment transactions are processed through PCI-DSS Level 1 compliant third-party payment gateways. 100xSales does not store or process your complete credit card numbers, CVVs, or sensitive banking credentials on our infrastructure.
2. Meta Platform Integrations & Specific API Scopes
Permissions & Scopes Requested
When you connect your Meta Business accounts, 100xSales requests access only to the explicit permissions required to fulfill automated messaging services: (a) 'whatsapp_business_messaging' and 'whatsapp_business_management' to receive incoming customer inquiries and transmit AI-generated replies via the WhatsApp Cloud API; (b) 'instagram_manage_messages' and 'instagram_basic' to process direct messages (DMs) and story replies; and (c) 'pages_messaging' and 'pages_read_engagement' to manage Facebook Messenger conversations.
Data Handled from Meta Platforms
We collect OAuth access tokens, page/business IDs, webhook payloads (inbound message text, sender identifier, attachments, timestamp), and message status updates. We do not access personal friend lists, private user profiles, or non-business feed activity.
Usage & Security of Meta Data
Meta user data is processed strictly in real-time to facilitate customer support and sales dialogues on behalf of the authorized merchant. Access tokens are encrypted at rest using AES-256. Meta platform data is never sold, rented, or transferred to third-party data brokers or ad networks.
Data Deletion on Meta Platforms
In accordance with Meta Platform Terms §3.2, you can revoke access at any time through Meta account settings or request complete data erasure through our dedicated Data Deletion Instructions page.
3. AI Processing, Model Training & End-User Transparency
Real-Time AI Response Generation
Inbound customer inquiries are processed via advanced large language models (LLMs) and retrieval-augmented generation (RAG) vector embeddings strictly to formulate real-time answers based on the merchant's approved product catalog and knowledge base.
No Foundation Model Training on Customer PII
We do not use customer personal identifiable information (PII), proprietary business data, or private end-customer conversation transcripts to train foundational third-party AI models without explicit affirmative consent.
Tenant Obligation for End-User Bot Disclosure
100xSales operates as a data processor for merchant customer interactions. Merchants (tenants) are contractually required under our Terms of Service to notify their end-users where required by law (including the EU AI Act and applicable US state laws) that they are communicating with an automated artificial intelligence system.
4. Legal Bases for Processing (GDPR Art. 6)
Contractual Necessity (Art. 6(1)(b))
Processing account information, billing details, and message transmissions is necessary to perform our contractual commitments and deliver the 100xSales SaaS service to you.
Legitimate Interests (Art. 6(1)(f))
We process telemetry, server error logs, and fraud prevention data based on our legitimate interest in maintaining system uptime, preventing spam/abuse, and enhancing platform security.
Legal Obligations (Art. 6(1)(c))
We retain transaction records, VAT/tax information, and audit histories to satisfy statutory bookkeeping, legal, and financial reporting requirements.
Consent (Art. 6(1)(a))
Where required by law (such as opt-in marketing newsletters or non-essential analytical cookies), we process data based on your freely given, explicit consent, which may be withdrawn at any time.
5. Data Retention Periods (GDPR Art. 13(2)(a))
AI Conversation Logs & Transcripts
Retained for an operational rolling period of 90 days to provide conversation history and analytics to the merchant, unless configured for a shorter custom retention period or earlier deletion by the tenant.
Account & Profile Records
Retained for the entire duration of your active subscription, plus a 30-day post-cancellation grace period to permit account export or reactivation before permanent automated deletion.
API Access Tokens & Credentials
Revoked and purged immediately upon channel disconnection, account termination, or receipt of a validated data deletion request.
Aggregated Metrics & Telemetry
Anonymized, de-identified performance metrics and token usage analytics are retained for up to 12 months for statistical analysis and capacity planning.
Statutory & Financial Records
Invoices, tax filings, and transaction records are securely archived for up to 7 years in accordance with applicable corporate tax laws.
6. Data Security & International Data Transfers
Security Architecture
We enforce enterprise-grade security standards including TLS 1.3 encryption for all data in transit, AES-256 encryption for data at rest, role-based access control (RBAC), multi-factor authentication (MFA), and 24/7 automated threat monitoring.
International Data Transfers (GDPR Art. 46)
Where data is transferred outside the European Economic Area (EEA), UK, or your country of origin to cloud service providers (such as AWS, Cloudflare, Pinecone, or Cloudinary), we ensure adequate protection through Standard Contractual Clauses (SCCs) approved by the European Commission, robust Data Processing Addendums (DPAs), and end-to-end encryption.
7. Your Rights (GDPR & CCPA / US State Privacy Laws)
GDPR Data Subject Rights (EU / UK)
You have the right to: (a) access your personal data; (b) rectify inaccurate information; (c) request erasure ('Right to be Forgotten'); (d) restrict or object to processing; (e) data portability; and (f) lodge a complaint with a supervisory data protection authority in your EU member state.
California Consumer Privacy Act (CCPA / CPRA) Rights
California residents have the right to: (a) Know what personal information is collected, disclosed, or shared; (b) Delete personal information; (c) Correct inaccurate personal information; (d) Opt out of the 'sale' or 'sharing' of personal information; and (e) Non-discrimination for exercising privacy rights. We do NOT sell your personal information.
How to Exercise Your Rights
To submit a privacy request or CCPA opt-out, email dpo@100xsales.ai or privacy@100xsales.ai, or visit our dedicated User Data Deletion Instructions page. We respond to all verified requests within 30 days without fee.
8. Cookies & Website Tracking
Essential Cookies
Required for basic website navigation, user authentication sessions, and security protection. These cannot be disabled.
Analytics & Performance Cookies
We use privacy-respecting analytics tools to measure aggregate website performance and identify broken features. You can control or block cookies through your browser settings at any time.
No Third-Party Advertising Pixels
We do not deploy invasive third-party cross-site advertising trackers or sell browsing profiles to ad exchanges.
If you wish to remove 100xSales permissions from your WhatsApp, Instagram, or Facebook account, or request a complete purge of your conversation records, view our dedicated guide.
Contact Our Data Protection Officer (DPO)
If you have any questions, concerns, or requests regarding this Privacy Policy or our compliance with GDPR, CCPA, and Meta Platform Policies, please contact:
Legal Entity: 100xSales Technologies Ltd.
Registered Office: Level 12, Gulshan Avenue, Dhaka 1212, Bangladesh
DPO Direct Email: dpo@100xsales.ai
Privacy Desk: privacy@100xsales.ai