Recepsi Privacy Policy
Version 0.11 · Last updated 11 October 2026
This policy explains how Xevix Pte. Ltd. (UEN 202425094Z, a company registered in Singapore), which runs Recepsi ("we", "us"), handles personal data. We've written it in plain English. If anything is unclear, email our Data Protection Officer at dpo@recepsi.com.
1. Two different roles — please read this first
A. When we are in charge (controller / "organisation" / "data controller" under Malaysia's PDPA). We decide how to use personal data about:
- people who sign up for or use Recepsi for their business (our "Customers" or "owners") and their team members;
- visitors to our website and people who contact us.
This policy fully applies to that data.
B. When we act for a business (processor / "data intermediary"). When you chat with a business's Recepsi receptionist — on its website or Telegram (and later WhatsApp) — that business is in charge of your data, and we process it on the business's behalf under a Data Processing Addendum. If you are one of those end-customers:
- the business's own privacy notice applies to you, and you should contact the business to access, correct or delete your data or withdraw consent;
- if you contact us, we'll pass your request to the business (where we can identify it) and help it respond;
- section 9 explains in general terms how we handle chat data for businesses.
C. Telegram is a separate controller. If you chat with a business on Telegram, Telegram stores and handles your messages on its own platform under its own terms and privacy policy. We don't control those copies. (WhatsApp is different: when WhatsApp becomes available, Meta will process WhatsApp messages sent through our integration as a processor on the business's behalf. See section 4.)
2. Personal data we collect (as controller)
| What | Examples | Where from |
|---|---|---|
| Account data | Name, email, password (stored hashed by our database/auth provider), sign-in tokens and sign-in links, business name, phone, opening hours, address, industry, time zone, team members' names and emails | You, at sign-up and in settings |
| Google sign-in data (only if you choose "Continue with Google") | Your name, email address, profile photo and Google account ID | Google, when you sign in with it |
| Hand-over settings | The Telegram chat ID or email address where you want hand-over alerts | You |
| Billing data (paid plans only) | Billing name and address, plan, invoices, payment status, card brand/last 4 digits. Full card details are collected and held by Stripe, not us. | You and Stripe |
| Support requests | Your support messages and any screenshots you send us | You |
| Sign-up source | The referral or campaign tag in the link you used to sign up (for example, a referral code or campaign name) | The sign-up link, automatically |
| Usage metrics | Chat and message counts, model token and spend totals, response times, error/status codes — stored against your business ID, with no chat content | Automatically |
| Technical logs | Request IDs, business and conversation IDs, channel, timings, status codes; IP address and browser type in our hosting provider's (Cloudflare's) request logs. We do not log message content, names, phone numbers or emails. | Automatically |
| Channel connection data | Telegram bot username/token (stored encrypted), and later your WhatsApp Business Account ID and number | You, Telegram and Meta when you connect a channel |
Cookies and analytics: our dashboard uses only the cookies/storage needed to keep you signed in. The chat widget uses browser local storage, not cookies: it stores an anonymous chat ID only after the visitor sends a message, holds only the chat session, and expires after 24 hours without activity. If a visitor looks like a possible bot, the chat window may run a Cloudflare Turnstile security check to block spam; this is for security only, not tracking or advertising. We use no third-party analytics or tracking tools, and no advertising trackers, at launch. We only count sign-up sources internally, in our own database. If we add analytics tools later, they will be cookieless and free of ad trackers, and we'll update this policy first.
We don't ask for sensitive data (such as health information, NRIC/passport numbers or bank account numbers) about you, and we ask that you don't send it to us.
3. Why we use it and our legal bases
| Purpose | Legal basis (GDPR/UK GDPR) | Singapore / Malaysia PDPA |
|---|---|---|
| Create and run your account, provide the Service, connect channels, send sign-in links and hand-over alerts | Contract | Consent / deemed consent; necessary for our contract with you |
| Count chats, enforce plan limits, bill you | Contract; legal obligation (tax records) | Consent; legal obligation |
| Customer support and service messages (security alerts, plan limits, changes to terms) | Contract; legitimate interests | Consent / deemed consent |
| Understand which channels bring sign-ups, using the sign-up source stored on your account (internal analytics only, never used for ad targeting) | Legitimate interests (you can object) | Consent / deemed consent; legitimate interests |
| Keep the Service secure, prevent fraud and abuse, enforce our terms and platform rules | Legitimate interests; legal obligation | Legitimate interests exception (PDPA SG, First Schedule Part 3) |
| Improve the Service using usage metrics that we aggregate and de-identify | Legitimate interests (you can object) | Business improvement exception (PDPA SG, Second Schedule Part 2) |
| Send product news by email (if you opt in) | Consent; unsubscribe anytime | Consent; we follow the Spam Control Act and the DNC rules — we won't send marketing messages to Singapore numbers on the DNC Registry without clear and unambiguous consent |
| Comply with law, respond to lawful requests, handle disputes | Legal obligation; legitimate interests | Legal obligation |
We do not use your content or your customers' chats to train or fine-tune language models, and our language-model provider must not either (see section 4).
We don't make decisions about you that have legal or similarly significant effects based solely on automated processing.
4. Who we share it with
We don't sell personal data, and we don't share it for cross-context behavioural advertising.
Service providers (sub-processors). We use these providers under contracts that require them to protect personal data and use it only to serve us. Contracting entities are taken from each provider's published terms (checked 10 Oct 2026).
| Provider (contracting entity) | What for | What data | Where processed |
|---|---|---|---|
| Cloudflare, Inc. (Cloudflare Self-Serve Subscription Agreement and Customer DPA v6.4) — Workers and R2 | Website and application hosting on Cloudflare's global edge network; bot and spam protection (Cloudflare Turnstile security checks in the chat window); once live, our nightly backup job (a Cloudflare scheduled Worker) and storage of the backups (R2) | All web/app traffic passes through Cloudflare; once live, backups will contain a full copy of our database, encrypted with our own key before it leaves our database | Global edge network — requests may be processed outside Singapore. Logs are kept briefly (Workers Logs: maximum 7 days) and contain no message bodies. Backups (once live): stored with an Asia-Pacific location hint, which Cloudflare applies on a best-effort basis, so backups may be stored outside Singapore |
| Supabase Pte. Ltd. (Singapore; Supabase Terms of Service — Supabase, Inc. if bought via a cloud marketplace) | Database, sign-in, file and vector storage | Account data; Customers' knowledge sources, transcripts, contacts and bookings | Singapore region (ap-southeast-1). We use Supabase's free plan, which keeps no provider backups. We're setting up our own encrypted backups in Cloudflare R2; until they're live, there are no backup copies. |
| OpenAI OpCo, LLC (USA; OpenAI Services Agreement — contracting party for customers outside the EEA/Switzerland) — our only language-model provider at launch (chat replies and embeddings) | Generating receptionist replies; turning the business's information into searchable "embeddings" | The customer's message, recent chat history and relevant snippets of the business's information | Outside Singapore (US/global). OpenAI does not use API data to train its models; abuse-monitoring logs are kept up to 30 days (longer only where required by law or needed to prevent harm). |
| Plus Five Five, Inc. (USA), trading as Resend (Resend Terms of Service and Data Processing Addendum) | Sending emails from @recepsi.com to business owners only: alerts, hand-over summaries and sign-in links. Never emails end-customers. | Owner email address; hand-over summaries can include a short summary/snippet of a customer's chat and their contact details | United States |
| Stripe Payments Singapore Pte. Ltd. (Stripe Services Agreement §12); Stripe Payments Europe, Limited is the additional party for personal-data processing under Stripe's DPA | Subscription payments (paid plans only; not in use until billing launches after the free beta) | Owner billing data only — never end-customer chat data | Stripe's DPA states that personal data is transferred to Stripe, LLC in the United States and may be transferred globally |
Support requests. Your support messages and any screenshots are stored in our own database (Supabase, Singapore) and handled by our support system. Our code-hosting tool (GitHub) receives only opaque ticket reference IDs, never your messages, screenshots, contact details or business name. Because these IDs reveal no personal data, no personal data is transferred to GitHub.
Possible future sub-processor: we may add Anthropic, PBC (USA) as a fallback language-model provider. It is not used at launch, and we'll update this list and give business customers notice before using it.
Google sign-in (independent controller): if you choose "Continue with Google", Google authenticates you and shares your name, email address, profile photo and Google account ID with us. For users in Singapore, the provider is Google LLC (USA) under the Google Terms of Service and Google Privacy Policy (Singapore country versions; Terms effective 30 Jul 2026, Privacy Policy effective 1 Oct 2026). Google acts as an independent controller, not our sub-processor. You can remove Recepsi's access in your Google Account settings.
Platforms you choose to connect:
- Telegram Messenger Inc. (Telegram Bot Platform Developer Terms; Telegram Privacy Policy). Telegram offers bot developers no data processing agreement and no choice of storage region, so we treat Telegram as an independent controller of messages on its platform. Telegram stores Telegram chats, and any hand-over alerts sent to owners on Telegram, under its own privacy policy, in data centres in several jurisdictions.
- Meta Platforms Ireland Limited (Meta Terms for WhatsApp Business Platform — contracting entity for businesses outside the US/Canada) — later phase only. For WhatsApp messages sent through the Cloud API, Meta acts as a processor (not a separate controller) under the Meta Global Processor Terms. Message content is processed in Meta data centres internationally. We will turn on Meta's local storage in Singapore where it is available for the business's number; message content is then kept at rest in Singapore after a short processing period (up to 60 minutes).
We also share personal data with professional advisers (under confidentiality); authorities where required by law; a buyer or investor in a merger, acquisition or asset sale (with notice); and anyone else with your consent.
5. International transfers
Our database is in Singapore. Personal data is processed outside Singapore by: our language-model provider OpenAI (US/global); Cloudflare's global edge network, which may process requests outside Singapore; once live, our encrypted backups in Cloudflare R2, stored with an Asia-Pacific location hint that Cloudflare applies on a best-effort basis, so they may be outside Singapore; Resend (US) for emails to business owners; once billing launches, Stripe (transfers to Stripe, LLC in the US); Telegram, if connected; and later Meta (WhatsApp), with Singapore local storage where available. For Malaysian businesses and their customers, storing data in Singapore is itself a transfer out of Malaysia. GitHub receives only opaque ticket reference IDs that reveal no personal data, so no personal data is transferred to it.
- Singapore (PDPA s26, Transfer Limitation Obligation): before transferring personal data out of Singapore, we make sure the recipient is bound by legally enforceable obligations (mainly contracts/data-processing terms, or certifications) giving a standard of protection comparable to the PDPA.
- Malaysia (PDPA 2010 s129, as amended in 2024): we transfer only where the destination has laws substantially similar to the PDPA or ensures an adequate level of protection, or another exception applies (for example, the transfer is necessary for our contract with you).
- EU/EEA and UK: where GDPR or UK GDPR applies, we rely on the European Commission's Standard Contractual Clauses (SCCs), with the UK International Data Transfer Addendum for UK data, or on an adequacy decision/approved framework (such as the EU-US Data Privacy Framework where the recipient is certified).
You can ask us for a copy of the relevant safeguards.
6. How long we keep it
| Data | How long |
|---|---|
| Account data | While your account is open; purged within 30 days of account deletion, except marketing consent and opt-out records (see below) |
| Chat transcripts, contacts (including contact-form leads) and bookings (processed for Customers) | As chosen by the business: 30, 90, 180 or 365 days (default 12 months); purged within 30 days of account deletion |
| Unanswered questions (processed for Customers) | Same as the chat transcript they come from; deleted with the conversation or the business's account, or on an erasure request |
| Usage counters (counts and token/spend totals, no content) | 24 months. When an account is deleted, they are reduced to anonymous totals that can't be linked to the business |
| Technical logs | Briefly — Cloudflare Workers Logs up to 7 days; Supabase logs per plan default (≤30 days) |
| Language-model provider copies | OpenAI: abuse-monitoring logs up to 30 days (longer only where the law requires it or to prevent harm); no training |
| Billing and tax records | 5 years (from the end of the relevant financial year / year of assessment), as required by Singapore law: Companies Act 1967 s199 and Income Tax Act 1947 s67; IRAS record-keeping requirements |
| Privacy requests to dpo@recepsi.com | Kept while the request is open. The message, sender's email address and attachments are deleted 12 months after the request is closed. A record with no personal data (reference ID, request type, jurisdiction, dates and outcome) is kept for 24 months as evidence that we responded. |
| Support requests | Ticket text: 12 months, then deleted automatically. Screenshots: automatically deleted after 30 days |
| Sign-up source | Kept with your account; deleted with it |
| Marketing consent and opt-out records | For the life of your account, plus 24 months after your account is purged, so we can prove consent and honour opt-outs. After the purge, each record keeps only a pseudonymous owner ID, a hashed email address, the time, the version of the consent wording, the source, and a keyed hash of the IP address. It keeps no name and no raw IP address. This pseudonymised record is still personal data. We keep it because of our legal obligations and our legitimate interests in showing that we comply with marketing and anti-spam rules. |
| Backups | We're setting up nightly backups of our database, encrypted with our own key before they leave the database, stored in Cloudflare R2 and kept for 8 days. Until they're live, we keep no backup copies, so deleted data is gone once it's deleted from our database. Once live, deleted data will leave backups within about 8 days. |
7. How we protect it
- Encryption in transit (TLS) and at rest (provider-managed AES-256); once our backups are live, they will be encrypted with our own key before they leave our database.
- Row-level security so each business can only see its own data; only the business owner and team members it invites can read its customers' transcripts.
- No routine Recepsi access to transcripts. Admin/database access is limited to a service account and logged. Secrets (API keys, bot tokens) are kept server-side; Telegram bot tokens are stored encrypted.
- No message content in logs.
- Rate limiting and abuse controls on the chat widget.
- Our security team requires multi-factor authentication on admin and provider accounts and reviews access regularly.
8. Data breaches
If we have a data breach affecting personal data we control, we'll assess it quickly; the PDPC expects this within 30 days of becoming aware. If the breach is notifiable under the Singapore PDPA (likely to cause significant harm, or affecting 500 or more people), we'll notify the PDPC as soon as practicable and within 3 calendar days of that assessment. Where there's likely significant harm, we'll also notify affected individuals, at the same time or after notifying the PDPC. Where the Malaysian PDPA applies, we'll notify the Personal Data Protection Commissioner as soon as practicable and within 72 hours, and affected individuals within 7 days after that where the breach is likely to cause significant harm. Where GDPR/UK GDPR applies, we'll notify the supervisory authority within 72 hours. For data we process for a business, we'll tell that business without undue delay and within 48 hours of becoming aware, so it can meet its own deadlines. Our security team runs a documented breach response plan.
9. Chat data we process for businesses (end-customers)
When you chat with a business's Recepsi receptionist, we process — for that business — your messages and the receptionist's replies, any contact details you share (such as name, phone number, Telegram username/ID), booking requests, and an anonymous chat session ID. We use it only to reply to you, qualify your enquiry, make booking requests and alert the business when a human needs to take over. If the receptionist is busy, it asks for your contact details and question instead. We store what you submit as a lead for the business and keep it like other contacts (section 6). On the website, your first message (up to 500 characters) stays in your browser until you submit the form and is included in the lead only then. On Telegram, we only store what you send after you've seen our notices. Phone numbers, email addresses and NRIC numbers typed into the name or question are masked, and your phone number is kept only in its own field.
- You're told it's automated. A fixed notice, which the business cannot edit or remove, says you're chatting with an automated Super Intelligent assistant. It is shown in the website widget and on the hosted chat page, and sent at the start of Telegram chats. If you ask whether you're talking to a human, you'll get an honest answer, and you'll be told when a person from the business takes over.
- Please don't share sensitive details such as NRIC/passport numbers, card or bank details, or health information in the chat.
- Who else handles it: your messages are sent to our language-model provider, OpenAI, to generate replies (outside Singapore, US/global; it doesn't train on them; abuse-monitoring logs are kept up to 30 days). If the business is alerted to take over, a short summary of your chat and your contact details may be sent to the business owner by email (sent via Resend, in the US; we never email you directly) or Telegram. Telegram also keeps its own copies of messages sent on its platform.
- Website widget: the chat stores an anonymous chat ID in your browser's local storage (not a cookie) so the conversation continues across pages. It is saved only after you send a message, holds only the chat session, and expires after 24 hours without activity. It is not used for tracking or advertising.
- Spam protection: if a visitor looks like a possible bot, the chat window may run a Cloudflare Turnstile security check to block spam. It is used for security only, not for tracking or advertising.
- Unanswered questions: when the receptionist can't answer a question, we store the question as you typed it, with the conversation ID, the business ID and the time, but no contact fields. The business owner receives a digest of these questions to improve the receptionist's answers. They are kept for the same period as chat transcripts, and are deleted with the conversation or the business's account, or when you ask for erasure.
Hosted chat
Hosted chat pages (recepsi.com/c/<business>). Some businesses use a chat page hosted by Recepsi at recepsi.com/c/<business> instead of the website widget. It works like the widget: an anonymous chat ID is kept in your browser's local storage (not a cookie), saved only after you send your first message and deleted after 24 hours without activity. A Cloudflare Turnstile spam check runs only if you are challenged. The page is not used for tracking or advertising. The conversation belongs to the business named on the page, which is responsible for it, and Recepsi processes it on that business's behalf (see the business's own privacy notice, if linked on the page). Recepsi is responsible for the page's own storage and security check.
- How long: as set by the business — 30, 90, 180 or 365 days (default 12 months) — and deleted within 30 days if the business deletes its account.
- Children: businesses that serve children (such as tuition centres) must get any parental consent the law requires and collect only contact and booking details.
- Your rights: contact the business. It can search, export, correct or delete your chats from its dashboard, and we'll help.
10. Your rights
Depending on where you are, you may have the right to:
- access your personal data and learn how it's used and disclosed;
- correct inaccurate data;
- withdraw consent (for example, to marketing);
- delete your data, or restrict or object to processing (GDPR/UK GDPR; Malaysia PDPA in some cases);
- data portability (GDPR/UK GDPR; Malaysia PDPA as amended in 2024, once in force);
- complain to a regulator: Singapore PDPC; Malaysia Personal Data Protection Commissioner; your EU/EEA supervisory authority; the UK ICO.
California (CCPA/CPRA): if and when the CCPA applies to us, you may know, access, correct and delete personal information and opt out of "sale" or "sharing". We do not sell or share personal information as defined, and we don't use sensitive personal information to infer characteristics. We won't discriminate against you for using your rights. Categories, sources, purposes and recipients are in sections 2–4.
To make a request, email dpo@recepsi.com. We'll verify your identity and respond within 30 days (Singapore — we'll tell you if we need longer), 21 days (Malaysia), one month (GDPR) or 45 days (CCPA). We may charge a reasonable fee for access requests where the law allows, and will tell you first.
How we handle privacy requests: messages to dpo@recepsi.com are received by our own email system on Cloudflare and stored in our database (Supabase, Singapore), where only restricted service access can reach them. Our DPO reads and replies through a secure admin view protected by multi-factor authentication, and replies are sent through Resend. Privacy requests aren't processed by Gmail or any Google service.
11. Children
Recepsi is a business service; owners must be 18 or over. Some businesses that use Recepsi (for example, tuition centres) may chat with students who are minors. In that case the business is responsible for having any parental consent the law requires and for configuring its receptionist appropriately. Receptionists must not be set up to collect more than the contact and booking details needed. If you believe a child has given us personal data inappropriately, contact us or the business and it will be deleted.
12. Data Protection Officer and representatives
- Data Protection Officer (Singapore and Malaysia PDPA): Sky Fam, dpo@recepsi.com. We publish our DPO's business contact here, as the Singapore PDPA allows, and may also list it on the PDPC's DPO Registry.
- EU/UK representatives (GDPR/UK GDPR Art. 27): not appointed. Recepsi is currently offered to businesses in Singapore and Malaysia; we'll appoint representatives before actively offering the Service in the EU or UK.
13. Changes to this policy
We'll post updates here and change the "Last updated" date. For significant changes we'll tell Customers by email or in the dashboard before they take effect.
14. Contact us
Xevix Pte. Ltd. (Recepsi) · UEN 202425094Z · Privacy and DPO: dpo@recepsi.com · General: support@recepsi.com
Languages: this policy is currently published in English only. A Bahasa Malaysia version is available on request from dpo@recepsi.com. If we publish a translation, the English version prevails where the two differ.