Xavier
PRIVACY POLICY

What Xavier sees, and what it does with it.

Last updated: August 23, 2026 · Applies to all SlovX accounts and their connected leads/customers

This Privacy Policy explains how SlovX ("we," "us," "our") collects, uses, stores, and shares information in connection with the SlovX platform and its autonomous AI agent, Xavier (the "Service"). It applies both to our direct customers ("Customer," "you") and, where relevant, to the end-customers/leads ("Lead," "End-User") who message a business's Xavier-powered WhatsApp number.

1. Information We Collect

We collect the following categories of information:

  • Account information: business name, owner name, email, phone number, billing details, and Company Configuration (products, pricing, policies) you provide.
  • Conversation data: messages exchanged between Leads and Xavier via WhatsApp (and any additional connected channels), including text and voice-note transcriptions where that feature is used.
  • Derived data: qualification stage, sentiment/intent scores, and enrichment attributes (e.g. estimated company size or revenue tier) generated by the Service to route conversations appropriately.
  • Technical data: IP address, device/browser metadata, and usage logs collected automatically for security, debugging, and service-reliability purposes.
  • Third-party platform data: information received via connected integrations (WhatsApp Business/Meta, Google Calendar, Google Sheets, CRM systems) as authorized by you.

2. How We Use Information

Collected information is used to:

  • Operate the Service — generating conversational responses, qualifying leads, scheduling meetings, and syncing data to your connected tools.
  • Maintain conversation continuity across sessions (so Xavier can reference earlier context within an ongoing lead relationship).
  • Monitor and improve service reliability, including automated error monitoring and abuse/rate-limit detection.
  • Communicate with you regarding your account, billing, or material changes to the Service.
  • Comply with legal obligations and enforce our Terms & Conditions.

3. AI Processing Disclosure

Conversation text is processed by third-party large language model providers (such as Anthropic) to generate Xavier's responses, and may be processed by third-party transcription or embedding providers where voice-note transcription or semantic caching features are enabled. These providers process data under their own applicable data-processing terms. We select providers that offer contractual data-handling commitments, but we do not control their infrastructure directly.

4. Data Retention

Conversation and account data is retained for as long as your account is active, and for a limited period afterward as reasonably necessary for legal, billing, or dispute-resolution purposes. You may request deletion of your account data as described in Section 8, subject to any retention obligations imposed by applicable law or active integrations (e.g. records already synced to your own CRM).

5. Data Sharing

We do not sell personal information. We share data only in the following circumstances:

  • Payment processing: billing name, email, and payment details are shared with Paddle.com Market Limited, our Merchant of Record, solely to process your subscription payment, calculate applicable tax, and handle refunds. SlovX does not store your full card details — Paddle handles this directly.
  • With sub-processors and infrastructure providers (hosting, database, AI model providers) strictly to operate the Service.
  • With integrations you explicitly connect (e.g. your CRM, Google Workspace) — data flows to these tools based on your configuration and permission.
  • Where required by law, legal process, or to protect the rights, safety, or property of SlovX, our customers, or the public.
  • In connection with a merger, acquisition, or asset sale, subject to continued protection under an equivalent privacy policy.

6. Data Security

Data in transit between your systems, End-Users, and SlovX infrastructure is encrypted using industry-standard protocols (HTTPS/TLS). We apply reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, alteration, or loss. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. End-User (Lead) Notice

If you are messaging a business's WhatsApp number that uses Xavier, your messages are being processed by an automated AI system on that business's behalf, as described in this Policy. The business (our Customer) is responsible for the content and configuration of its own Company Configuration and for its own direct relationship with you as its customer or prospect. To stop automated messages from a specific business, reply "STOP" — this is honored automatically.

8. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, export, or request deletion of your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at privacy@slovx.com. We will respond within the timeframe required by applicable law.

9. International Data Transfers

Depending on your location and the infrastructure providers used, information may be processed in countries other than your own. Where required, we rely on appropriate legal mechanisms (such as standard contractual clauses) to safeguard cross-border transfers.

10. Children's Privacy

The Service is intended for business use and is not directed at individuals under the age of 18. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the dashboard or your account email at least 14 days before taking effect.

12. Contact

Questions about this Privacy Policy or data-related requests can be directed to privacy@slovx.com. For payment or billing data questions specifically, contact billing@slovx.com.

This document is a general-purpose template and does not constitute legal advice. Bracketed fields must be completed, and this Policy should be reviewed by a qualified lawyer familiar with your operating jurisdiction (e.g. GDPR, CCPA, or other applicable data-protection frameworks) before publication.