Assistyca
Privacy Policy
This Privacy Policy explains how Assistyca collects, uses, stores, discloses, and protects personal information when people use the Assistyca website, portal, Meta and WhatsApp integrations, approval workflows, and related automation and AI-assisted features.
Important Scope Notes
This policy is designed to cover Assistyca’s current business-facing portal and messaging workflows as of July 7, 2026. It is reviewed at least annually and whenever material product, legal, or processing changes require an update.
Assistyca is generally a service provider / processor for customer conversation data that a business customer chooses to submit, and a controller for its own account, billing, security, support, and website administration data. If you are an end user whose information was provided to Assistyca by a business using the service, you should usually direct privacy requests to that business first.
Unless Assistyca expressly agrees otherwise in writing, the service is not intended for child-directed products or for regulated workloads that require sector-specific compliance frameworks such as HIPAA, GLBA, or similar regimes.
Categories of Personal Information
Depending on how the service is used, we may collect the following categories:
- Identifiers and contact details, such as name, email address, phone number, and account identifiers.
- Business and configuration data, such as workspace details, connection settings, and onboarding information.
- Communications content and metadata, such as messages, approval drafts, timestamps, sender details, and delivery or status data.
- Technical and device data, such as IP address, browser type, device signals, error logs, and security events.
- Transaction and service records, such as support history, authentication events, and billing or usage records.
- Integration data from third-party platforms, including Meta or WhatsApp related identifiers, webhook events, and account-linked information.
- Sensitive information only if a user or customer chooses to submit it or an integration transmits it; the service is not designed to invite unnecessary sensitive data.
Sources of Information
We may collect personal information from the following categories of sources:
- Directly from you when you sign in, contact us, configure integrations, or use the service.
- From the business customer that administers the workspace or uploads customer communication data.
- From connected third-party services such as Meta, WhatsApp, email delivery providers, and infrastructure providers.
- Automatically from browsers, devices, and server interactions through logs and security monitoring.
- From publicly available or lawfully obtained sources where needed for business verification, compliance, or fraud prevention.
Purposes and Legal Bases
We use personal information for specific business and operational purposes, including to:
- Provide, authenticate, maintain, secure, and improve the Assistyca service.
- Process messaging, approvals, support workflows, and AI-assisted drafting features requested by users.
- Operate connected integrations, including Meta or WhatsApp related setup, testing, and message routing.
- Prevent abuse, investigate incidents, debug errors, enforce agreements, and protect rights and safety.
- Comply with legal obligations, respond to lawful requests, and keep required records.
- Create aggregated or de-identified insights that do not reasonably identify a person.
Where applicable under laws such as the GDPR or UK GDPR, our legal bases may include contract performance, legitimate interests, legal obligations, and consent where consent is the appropriate basis.
Disclosure to Third Parties
We disclose personal information only as reasonably necessary for the purposes described above, including to the following categories of recipients:
- Hosting, infrastructure, storage, and security providers.
- Email, notification, and communications providers.
- Messaging and platform partners, including Meta and WhatsApp related services.
- AI and automation technology providers that process instructions on our behalf.
- Professional advisers, auditors, insurers, and counterparties involved in corporate transactions.
- Government authorities or other parties when required by law or necessary to protect rights, safety, or the service.
We may also disclose information in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar business transaction, subject to applicable confidentiality and legal requirements.
Sales, Sharing, and Sensitive Information
As of July 7, 2026, Assistyca does not sell personal information for money and does not share personal information for cross-context behavioral advertising as those concepts are used in California privacy law.
If we process sensitive personal information, we do so only as reasonably necessary to provide the requested service, maintain security, comply with law, or for other permitted purposes. We do not intentionally use sensitive personal information to infer characteristics about people unless clearly disclosed and legally permitted.
Because Assistyca does not currently sell or share personal information for cross-context behavioral advertising, a “Do Not Sell or Share My Personal Information” link is not currently provided. If that practice changes, this notice and any required request mechanisms will be updated.
International Transfers
Personal information may be processed in the United States and other countries where Assistyca or its service providers operate. Where applicable law requires safeguards for cross-border transfers, we rely on appropriate measures such as contractual protections, vendor commitments, and related legal transfer mechanisms.
Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including service delivery, security, dispute resolution, recordkeeping, and compliance.
Retention periods vary by category. For example, account data may be kept while an account remains active, security and audit records may be retained longer for abuse prevention and legal compliance, and some information may be kept in backups or archived systems for a limited additional period.
Security and Incident Response
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These measures may include access controls, authentication safeguards, limited internal access, vendor controls, transport security, logging, and monitoring.
No method of transmission or storage is completely secure. If we become aware of a personal data breach, we will investigate, mitigate, and provide notifications where required by applicable law.
Cookies and Similar Technologies
Assistyca and its providers may use server logs, session technologies, local storage, or similar technical mechanisms to support sign-in, security, preferences, fraud prevention, and service functionality.
If we introduce non-essential cookies or similar tracking technologies in a way that requires additional notice or choice under applicable law, we will provide that notice or choice at the relevant time.
Your Privacy Rights
Depending on your location and the context in which Assistyca processes your information, you may have rights that include:
| Right | What it may include |
|---|---|
| Access / right to know | Request details about the personal information we hold and how we use or disclose it. |
| Correction / rectification | Request correction of inaccurate or incomplete personal information. |
| Deletion / erasure | Request deletion of personal information, subject to legal or operational exceptions. |
| Restriction / objection | Request limited processing or object to certain processing, including some marketing or legitimate-interest uses. |
| Portability | Request a copy of certain information in a portable format where required by law. |
| Withdraw consent | Withdraw consent for processing that relies on consent, without affecting prior lawful processing. |
| California-specific requests | Request to know, delete, correct, and if applicable opt out of sale or sharing and limit certain sensitive-information uses. |
| Non-discrimination | Not be unlawfully discriminated against for exercising privacy rights. |
| Automated decision safeguards | Request human review or more information if legally significant automated decision-making applies. |
| Complaint rights | Lodge a complaint with a regulator or data protection authority where applicable. |
We may need to verify identity and authority before responding. Some rights are subject to legal exceptions. If Assistyca acts only as a service provider / processor for data controlled by a business customer, we may direct the request to that customer or ask you to contact them directly.
How to Submit Requests
To submit an access, correction, deletion, objection, portability, or privacy complaint request, email nimrod.shai@gmail.com with enough detail for us to understand and verify the request.
Where permitted by law, authorized agents may submit requests on someone else’s behalf. We may ask for proof of authority and identity verification before responding.
If you are contacting us about a Meta, WhatsApp, or portal data deletion issue, please include the app, account, and workspace details so we can route the request appropriately.
If we deny a request that is subject to an appeal right under applicable law, you may reply to our response and request that we review the decision again.
Automated Tools and AI Features
Assistyca may use automation and AI-assisted tools to help draft responses, summarize communications, classify workflows, and improve service operations. These features are intended to assist users, not to replace their own judgment where human review is appropriate.
Assistyca does not intentionally use solely automated decision-making that produces legal or similarly significant effects on an individual without the safeguards required by applicable law.
Business Customer Responsibilities
If you use Assistyca on behalf of a business, you are responsible for making sure you have the necessary rights, notices, legal bases, and permissions to share customer, employee, prospect, or contact data with the service and with connected platforms such as Meta.
Business customers are also responsible for determining whether they need their own privacy notice, data processing agreement, cookie notice, consumer request workflow, or industry-specific compliance controls.
Children and Regulated Data
Assistyca is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Where local law requires parental consent for certain minors, users should not submit that child data through the service unless they have the necessary authority and legal basis.
Unless expressly agreed otherwise in writing, users should avoid submitting highly regulated information such as medical records, payment card data, government-issued identifiers, or similarly sensitive data that is not necessary for the service.
Changes to This Policy
We may update this Privacy Policy from time to time. Material updates will be reflected by revising the date on this page. We intend to review this policy at least annually so it stays aligned with product and legal changes.
Contact Us
If you have questions about this Privacy Policy or privacy-related requests, contact nimrod.shai@gmail.com.
If you are located in a jurisdiction that provides complaint rights, you may also contact your local privacy or data protection regulator.