1.Who we are
Esynex is a multi-channel messaging platform operated by Ekvah, a company registered in Sri Lanka with offices in Colombo. In this policy, “Esynex”, “we” and “us” mean Ekvah acting as the operator of the Esynex service.
For privacy questions, write to privacy@esynex.com.
2.Scope and your role
This policy covers two different relationships, and your rights differ between them.
- Account holders. Businesses and their team members who sign up for Esynex. For your account data we are the data controller — we decide why and how it is processed.
- End customers. People who message a business through WhatsApp, Instagram, Facebook, Telegram, TikTok, X or email. For those conversations we are a data processoracting on the business’s instructions. The business decides what is collected and for how long; see section 13.
3.Data we collect
Account and identity
- Name, email address and (optionally) phone number.
- A hashed password, or a Google account identifier if you sign in with Google.
- Your role within the workspace (owner, member, platform administrator) and the workspace you belong to.
Business profile
- Business name, type, country, address, phone number and the description you provide during setup.
- Subscription tier and onboarding progress.
Conversations and contacts
- Message content, timestamps, direction, delivery and read state, and any attachments (images, documents, audio, video) sent or received through a connected channel.
- Contact records: name, phone number, email address, channel handle or platform user id, tags, notes and group membership.
- Orders created from conversations, including items, amounts, payment method, shipping address and status history.
- Campaign and announcement recipients, send state and opt-out status.
Technical and usage data
- IP address, browser user-agent and session records, used for security, session management and rate limiting.
- Audit events recording significant actions taken in your workspace (who changed what, and when).
- Aggregate product analytics about how the interface is used.
4.Channel data and credentials
When you connect a channel, you authorise Esynex to send and receive messages on your behalf. Depending on the channel we store:
- OAuth access and refresh tokens(Meta, Google, TikTok, X), held encrypted at rest and used only to call that provider’s API for your workspace.
- API credentials you enter manually, such as a WhatsApp Cloud API phone number id, WABA id and access token.
- Sender identities, such as the email address and display name outbound email is sent from.
Google OAuth data is used only to provide the feature you connected it for. Where we request Gmail scopes, that access is used solely to read and send mail in the mailbox you connected, and we do not use it to train generalised AI models. Disconnecting a channel revokes and deletes the stored credentials.
5.AI processing of messages
A core feature of Esynex is drafting and sending automated replies. To do this, the content of an incoming message — and relevant context such as your business description, FAQ entries and recent messages in the same conversation — is sent to a third-party large language model provider to generate a response.
- This happens only for channels where you have enabled AI auto-reply, or when you explicitly request a suggested reply.
- We instruct our AI providers not to use your content to train their general-purpose models.
- AI output can be wrong. Where a conversation is escalated to a human, that is recorded so you can review it.
- You can disable AI auto-reply for your whole workspace or per channel at any time from Settings.
6.How we use data
- To operate the inbox: receive, display, route and send messages.
- To generate AI replies and escalate conversations that need a human.
- To create and track orders, campaigns and announcements you initiate.
- To authenticate you, keep sessions secure and prevent abuse.
- To provide analytics and reporting inside your workspace.
- To send service messages such as verification and security notices.
- To meet legal, tax and accounting obligations.
We do not sell personal data. We do not use the content of your customer conversations for advertising.
7.Legal bases
Where the GDPR or a comparable law applies, we rely on the following bases: contract (providing the service you signed up for), legitimate interests (securing the platform, preventing abuse, improving the product), legal obligation (records we must keep), and consent where we ask for it — for example, optional marketing email, which you can withdraw at any time.
8.Sharing and sub-processors
We share data only with providers that help us run the service, and only to the extent they need it. Each is bound by contract to protect it.
| Provider | Purpose |
|---|---|
| Meta Platforms | WhatsApp Business, Facebook Messenger and Instagram messaging |
| Google sign-in, Gmail sending and reading, AI reply generation | |
| Telegram | Telegram bot messaging |
| TikTok | TikTok direct messaging |
| X Corp. | X direct messaging |
| Mailjet | Outbound transactional and campaign email |
| Cloud hosting and database providers | Running the application, storing data, caching and background jobs |
We may also disclose data where we are legally required to, or to establish or defend legal claims. If Esynex is involved in a merger or acquisition, data may transfer to the successor entity under the same protections; we will tell you before that happens.
9.International transfers
Esynex operates from Sri Lanka, and several of our providers process data in the United States, the European Union and other regions. Where personal data leaves its country of origin, we rely on the recipient’s own compliance frameworks and, where applicable, Standard Contractual Clauses.
10.Retention
- Conversations, contacts and orders are kept for as long as your workspace is active, because they are the record your business relies on.
- Channel credentials are deleted when you disconnect the channel.
- Sessions expire automatically and are revoked when you log out.
- Audit events are kept for up to 24 months for security and accountability.
- After account closure, workspace data is deleted within 90 days, except where we must keep records to meet a legal obligation.
11.Security
- Passwords are hashed with bcrypt; we never store them in readable form.
- Channel tokens and API credentials are encrypted at rest.
- Traffic is encrypted in transit with TLS.
- Access is scoped per workspace, and roles limit what each team member can do.
- Sessions can be revoked, and significant actions are recorded in an audit log.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.
12.Your rights
Subject to your local law, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to processing, or send it to another provider. You can also withdraw consent where we relied on it, and complain to your data protection authority.
Email privacy@esynex.com. We respond within 30 days and may ask you to verify your identity first.
If you are in California, you have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA.
13.If you messaged a business
If you contacted a business that uses Esynex, that business — not Esynex — decides what happens to your conversation. Please direct requests to access or delete your data to the business you messaged. If you cannot reach them, write to us at privacy@esynex.com and we will pass your request on and support them in answering it.
14.Children
Esynex is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child’s data has reached us, contact us and we will delete it.
15.Changes to this policy
We update this policy when the service changes. The date at the top always reflects the current version. If a change materially affects your rights, we will notify account holders by email or an in-app notice before it takes effect.
16.Contact us
Ekvah — Esynex
Colombo, Sri Lanka
Privacy: privacy@esynex.com
General: hello@esynex.com
See also our Terms of Service and Cookie Policy.