Recepsi Privacy Policy

Version 0.11 · Last updated 11 October 2026

This policy explains how Xevix Pte. Ltd. (UEN 202425094Z, a company registered in Singapore), which runs Recepsi ("we", "us"), handles personal data. We've written it in plain English. If anything is unclear, email our Data Protection Officer at dpo@recepsi.com.

1. Two different roles — please read this first

A. When we are in charge (controller / "organisation" / "data controller" under Malaysia's PDPA). We decide how to use personal data about:

This policy fully applies to that data.

B. When we act for a business (processor / "data intermediary"). When you chat with a business's Recepsi receptionist — on its website or Telegram (and later WhatsApp) — that business is in charge of your data, and we process it on the business's behalf under a Data Processing Addendum. If you are one of those end-customers:

C. Telegram is a separate controller. If you chat with a business on Telegram, Telegram stores and handles your messages on its own platform under its own terms and privacy policy. We don't control those copies. (WhatsApp is different: when WhatsApp becomes available, Meta will process WhatsApp messages sent through our integration as a processor on the business's behalf. See section 4.)

2. Personal data we collect (as controller)

WhatExamplesWhere from
Account dataName, email, password (stored hashed by our database/auth provider), sign-in tokens and sign-in links, business name, phone, opening hours, address, industry, time zone, team members' names and emailsYou, at sign-up and in settings
Google sign-in data (only if you choose "Continue with Google")Your name, email address, profile photo and Google account IDGoogle, when you sign in with it
Hand-over settingsThe Telegram chat ID or email address where you want hand-over alertsYou
Billing data (paid plans only)Billing name and address, plan, invoices, payment status, card brand/last 4 digits. Full card details are collected and held by Stripe, not us.You and Stripe
Support requestsYour support messages and any screenshots you send usYou
Sign-up sourceThe referral or campaign tag in the link you used to sign up (for example, a referral code or campaign name)The sign-up link, automatically
Usage metricsChat and message counts, model token and spend totals, response times, error/status codes — stored against your business ID, with no chat contentAutomatically
Technical logsRequest IDs, business and conversation IDs, channel, timings, status codes; IP address and browser type in our hosting provider's (Cloudflare's) request logs. We do not log message content, names, phone numbers or emails.Automatically
Channel connection dataTelegram bot username/token (stored encrypted), and later your WhatsApp Business Account ID and numberYou, Telegram and Meta when you connect a channel

Cookies and analytics: our dashboard uses only the cookies/storage needed to keep you signed in. The chat widget uses browser local storage, not cookies: it stores an anonymous chat ID only after the visitor sends a message, holds only the chat session, and expires after 24 hours without activity. If a visitor looks like a possible bot, the chat window may run a Cloudflare Turnstile security check to block spam; this is for security only, not tracking or advertising. We use no third-party analytics or tracking tools, and no advertising trackers, at launch. We only count sign-up sources internally, in our own database. If we add analytics tools later, they will be cookieless and free of ad trackers, and we'll update this policy first.

We don't ask for sensitive data (such as health information, NRIC/passport numbers or bank account numbers) about you, and we ask that you don't send it to us.

PurposeLegal basis (GDPR/UK GDPR)Singapore / Malaysia PDPA
Create and run your account, provide the Service, connect channels, send sign-in links and hand-over alertsContractConsent / deemed consent; necessary for our contract with you
Count chats, enforce plan limits, bill youContract; legal obligation (tax records)Consent; legal obligation
Customer support and service messages (security alerts, plan limits, changes to terms)Contract; legitimate interestsConsent / deemed consent
Understand which channels bring sign-ups, using the sign-up source stored on your account (internal analytics only, never used for ad targeting)Legitimate interests (you can object)Consent / deemed consent; legitimate interests
Keep the Service secure, prevent fraud and abuse, enforce our terms and platform rulesLegitimate interests; legal obligationLegitimate interests exception (PDPA SG, First Schedule Part 3)
Improve the Service using usage metrics that we aggregate and de-identifyLegitimate interests (you can object)Business improvement exception (PDPA SG, Second Schedule Part 2)
Send product news by email (if you opt in)Consent; unsubscribe anytimeConsent; we follow the Spam Control Act and the DNC rules — we won't send marketing messages to Singapore numbers on the DNC Registry without clear and unambiguous consent
Comply with law, respond to lawful requests, handle disputesLegal obligation; legitimate interestsLegal obligation

We do not use your content or your customers' chats to train or fine-tune language models, and our language-model provider must not either (see section 4).

We don't make decisions about you that have legal or similarly significant effects based solely on automated processing.

4. Who we share it with

We don't sell personal data, and we don't share it for cross-context behavioural advertising.

Service providers (sub-processors). We use these providers under contracts that require them to protect personal data and use it only to serve us. Contracting entities are taken from each provider's published terms (checked 10 Oct 2026).

Provider (contracting entity)What forWhat dataWhere processed
Cloudflare, Inc. (Cloudflare Self-Serve Subscription Agreement and Customer DPA v6.4) — Workers and R2Website and application hosting on Cloudflare's global edge network; bot and spam protection (Cloudflare Turnstile security checks in the chat window); once live, our nightly backup job (a Cloudflare scheduled Worker) and storage of the backups (R2)All web/app traffic passes through Cloudflare; once live, backups will contain a full copy of our database, encrypted with our own key before it leaves our databaseGlobal edge network — requests may be processed outside Singapore. Logs are kept briefly (Workers Logs: maximum 7 days) and contain no message bodies. Backups (once live): stored with an Asia-Pacific location hint, which Cloudflare applies on a best-effort basis, so backups may be stored outside Singapore
Supabase Pte. Ltd. (Singapore; Supabase Terms of Service — Supabase, Inc. if bought via a cloud marketplace)Database, sign-in, file and vector storageAccount data; Customers' knowledge sources, transcripts, contacts and bookingsSingapore region (ap-southeast-1). We use Supabase's free plan, which keeps no provider backups. We're setting up our own encrypted backups in Cloudflare R2; until they're live, there are no backup copies.
OpenAI OpCo, LLC (USA; OpenAI Services Agreement — contracting party for customers outside the EEA/Switzerland) — our only language-model provider at launch (chat replies and embeddings)Generating receptionist replies; turning the business's information into searchable "embeddings"The customer's message, recent chat history and relevant snippets of the business's informationOutside Singapore (US/global). OpenAI does not use API data to train its models; abuse-monitoring logs are kept up to 30 days (longer only where required by law or needed to prevent harm).
Plus Five Five, Inc. (USA), trading as Resend (Resend Terms of Service and Data Processing Addendum)Sending emails from @recepsi.com to business owners only: alerts, hand-over summaries and sign-in links. Never emails end-customers.Owner email address; hand-over summaries can include a short summary/snippet of a customer's chat and their contact detailsUnited States
Stripe Payments Singapore Pte. Ltd. (Stripe Services Agreement §12); Stripe Payments Europe, Limited is the additional party for personal-data processing under Stripe's DPASubscription payments (paid plans only; not in use until billing launches after the free beta)Owner billing data only — never end-customer chat dataStripe's DPA states that personal data is transferred to Stripe, LLC in the United States and may be transferred globally

Support requests. Your support messages and any screenshots are stored in our own database (Supabase, Singapore) and handled by our support system. Our code-hosting tool (GitHub) receives only opaque ticket reference IDs, never your messages, screenshots, contact details or business name. Because these IDs reveal no personal data, no personal data is transferred to GitHub.

Possible future sub-processor: we may add Anthropic, PBC (USA) as a fallback language-model provider. It is not used at launch, and we'll update this list and give business customers notice before using it.

Google sign-in (independent controller): if you choose "Continue with Google", Google authenticates you and shares your name, email address, profile photo and Google account ID with us. For users in Singapore, the provider is Google LLC (USA) under the Google Terms of Service and Google Privacy Policy (Singapore country versions; Terms effective 30 Jul 2026, Privacy Policy effective 1 Oct 2026). Google acts as an independent controller, not our sub-processor. You can remove Recepsi's access in your Google Account settings.

Platforms you choose to connect:

We also share personal data with professional advisers (under confidentiality); authorities where required by law; a buyer or investor in a merger, acquisition or asset sale (with notice); and anyone else with your consent.

5. International transfers

Our database is in Singapore. Personal data is processed outside Singapore by: our language-model provider OpenAI (US/global); Cloudflare's global edge network, which may process requests outside Singapore; once live, our encrypted backups in Cloudflare R2, stored with an Asia-Pacific location hint that Cloudflare applies on a best-effort basis, so they may be outside Singapore; Resend (US) for emails to business owners; once billing launches, Stripe (transfers to Stripe, LLC in the US); Telegram, if connected; and later Meta (WhatsApp), with Singapore local storage where available. For Malaysian businesses and their customers, storing data in Singapore is itself a transfer out of Malaysia. GitHub receives only opaque ticket reference IDs that reveal no personal data, so no personal data is transferred to it.

You can ask us for a copy of the relevant safeguards.

6. How long we keep it

DataHow long
Account dataWhile your account is open; purged within 30 days of account deletion, except marketing consent and opt-out records (see below)
Chat transcripts, contacts (including contact-form leads) and bookings (processed for Customers)As chosen by the business: 30, 90, 180 or 365 days (default 12 months); purged within 30 days of account deletion
Unanswered questions (processed for Customers)Same as the chat transcript they come from; deleted with the conversation or the business's account, or on an erasure request
Usage counters (counts and token/spend totals, no content)24 months. When an account is deleted, they are reduced to anonymous totals that can't be linked to the business
Technical logsBriefly — Cloudflare Workers Logs up to 7 days; Supabase logs per plan default (≤30 days)
Language-model provider copiesOpenAI: abuse-monitoring logs up to 30 days (longer only where the law requires it or to prevent harm); no training
Billing and tax records5 years (from the end of the relevant financial year / year of assessment), as required by Singapore law: Companies Act 1967 s199 and Income Tax Act 1947 s67; IRAS record-keeping requirements
Privacy requests to dpo@recepsi.comKept while the request is open. The message, sender's email address and attachments are deleted 12 months after the request is closed. A record with no personal data (reference ID, request type, jurisdiction, dates and outcome) is kept for 24 months as evidence that we responded.
Support requestsTicket text: 12 months, then deleted automatically. Screenshots: automatically deleted after 30 days
Sign-up sourceKept with your account; deleted with it
Marketing consent and opt-out recordsFor the life of your account, plus 24 months after your account is purged, so we can prove consent and honour opt-outs. After the purge, each record keeps only a pseudonymous owner ID, a hashed email address, the time, the version of the consent wording, the source, and a keyed hash of the IP address. It keeps no name and no raw IP address. This pseudonymised record is still personal data. We keep it because of our legal obligations and our legitimate interests in showing that we comply with marketing and anti-spam rules.
BackupsWe're setting up nightly backups of our database, encrypted with our own key before they leave the database, stored in Cloudflare R2 and kept for 8 days. Until they're live, we keep no backup copies, so deleted data is gone once it's deleted from our database. Once live, deleted data will leave backups within about 8 days.

7. How we protect it

8. Data breaches

If we have a data breach affecting personal data we control, we'll assess it quickly; the PDPC expects this within 30 days of becoming aware. If the breach is notifiable under the Singapore PDPA (likely to cause significant harm, or affecting 500 or more people), we'll notify the PDPC as soon as practicable and within 3 calendar days of that assessment. Where there's likely significant harm, we'll also notify affected individuals, at the same time or after notifying the PDPC. Where the Malaysian PDPA applies, we'll notify the Personal Data Protection Commissioner as soon as practicable and within 72 hours, and affected individuals within 7 days after that where the breach is likely to cause significant harm. Where GDPR/UK GDPR applies, we'll notify the supervisory authority within 72 hours. For data we process for a business, we'll tell that business without undue delay and within 48 hours of becoming aware, so it can meet its own deadlines. Our security team runs a documented breach response plan.

9. Chat data we process for businesses (end-customers)

When you chat with a business's Recepsi receptionist, we process — for that business — your messages and the receptionist's replies, any contact details you share (such as name, phone number, Telegram username/ID), booking requests, and an anonymous chat session ID. We use it only to reply to you, qualify your enquiry, make booking requests and alert the business when a human needs to take over. If the receptionist is busy, it asks for your contact details and question instead. We store what you submit as a lead for the business and keep it like other contacts (section 6). On the website, your first message (up to 500 characters) stays in your browser until you submit the form and is included in the lead only then. On Telegram, we only store what you send after you've seen our notices. Phone numbers, email addresses and NRIC numbers typed into the name or question are masked, and your phone number is kept only in its own field.

Hosted chat

Hosted chat pages (recepsi.com/c/<business>). Some businesses use a chat page hosted by Recepsi at recepsi.com/c/<business> instead of the website widget. It works like the widget: an anonymous chat ID is kept in your browser's local storage (not a cookie), saved only after you send your first message and deleted after 24 hours without activity. A Cloudflare Turnstile spam check runs only if you are challenged. The page is not used for tracking or advertising. The conversation belongs to the business named on the page, which is responsible for it, and Recepsi processes it on that business's behalf (see the business's own privacy notice, if linked on the page). Recepsi is responsible for the page's own storage and security check.

10. Your rights

Depending on where you are, you may have the right to:

California (CCPA/CPRA): if and when the CCPA applies to us, you may know, access, correct and delete personal information and opt out of "sale" or "sharing". We do not sell or share personal information as defined, and we don't use sensitive personal information to infer characteristics. We won't discriminate against you for using your rights. Categories, sources, purposes and recipients are in sections 2–4.

To make a request, email dpo@recepsi.com. We'll verify your identity and respond within 30 days (Singapore — we'll tell you if we need longer), 21 days (Malaysia), one month (GDPR) or 45 days (CCPA). We may charge a reasonable fee for access requests where the law allows, and will tell you first.

How we handle privacy requests: messages to dpo@recepsi.com are received by our own email system on Cloudflare and stored in our database (Supabase, Singapore), where only restricted service access can reach them. Our DPO reads and replies through a secure admin view protected by multi-factor authentication, and replies are sent through Resend. Privacy requests aren't processed by Gmail or any Google service.

11. Children

Recepsi is a business service; owners must be 18 or over. Some businesses that use Recepsi (for example, tuition centres) may chat with students who are minors. In that case the business is responsible for having any parental consent the law requires and for configuring its receptionist appropriately. Receptionists must not be set up to collect more than the contact and booking details needed. If you believe a child has given us personal data inappropriately, contact us or the business and it will be deleted.

12. Data Protection Officer and representatives

13. Changes to this policy

We'll post updates here and change the "Last updated" date. For significant changes we'll tell Customers by email or in the dashboard before they take effect.

14. Contact us

Xevix Pte. Ltd. (Recepsi) · UEN 202425094Z · Privacy and DPO: dpo@recepsi.com · General: support@recepsi.com

Languages: this policy is currently published in English only. A Bahasa Malaysia version is available on request from dpo@recepsi.com. If we publish a translation, the English version prevails where the two differ.