Privacy Policy
How Lavix collects, uses, stores, shares and protects data when providing its services.
This document was originally drafted in Vietnamese and has been translated into other languages. In the event of any discrepancy in meaning between the language versions, this English version prevails.
1. Introduction and scope
Lavix is an AI-powered business operations platform that helps stores manage sales conversations, orders, products, inventory, shipping, marketing, finance and AI staff. Lavix is operated by HC Group Sole Co., Ltd, a company registered in the Lao People's Democratic Republic ("Lavix", "we", "us").
This Policy applies to the lavix.io website, the Lavix application and all related services. It describes two different roles that Lavix plays:
- For your account data (name, email, sign-in information, wallets): Lavix is the party that determines the purposes and means of processing.
- For a store's customer data (people who message the store's Page, buyers): Lavix processes such data on behalf of and in accordance with the instructions of the store. The store is responsible for having a lawful basis to collect and use its customers' data, and for providing appropriate privacy information to its customers.
By using Lavix, you confirm that you have read and understood this Policy. This Policy forms part of the Terms of Service.
2. Data we collect
2.1. Account data. Display name, email, password (stored only in hashed form; we cannot read your original password), Lavix ID, store name, and your role and permissions in the store.
2.2. Data when you sign in with Google. When you choose "Continue with Google", Lavix requests only the openid, email and profile scopes, and stores only: your Google account identifier, email address, email verification status and display name. Lavix does not access Gmail, Google Drive, Contacts, Calendar or any other Google data, and does not store your Google profile picture.
2.3. Data from Meta (Facebook, Instagram, Messenger). Only when you actively connect, and only within the scope of the permissions you grant, Lavix may process:
- Information about the Pages and Instagram business accounts you manage (name, identifier, connection status).
- Conversations, messages, attachments and comments that customers send to your Page, together with the sender's public name and profile picture.
- Ad accounts, campaigns, spend and ad performance metrics.
- Conversion events (for example, an order being created) that the store chooses to send to Meta via the Conversions API.
2.4. Store operations data. Orders, recipient information (name, phone number, delivery address), products, inventory, receipts and payment vouchers, financial reports, sales settings, reply scripts and other data that the store creates in or enters into Lavix.
2.5. Wallet and payment data. History of top-ups, fee deductions, commissions, COD collection funds, refund requests, and the refund receiving account details (account holder name, bank, account number) that you provide in order to receive a refund.
2.6. Partner connection data. Connection information for the services you choose (Meta, POS, carriers, Telegram...), including access keys (tokens) issued by those platforms. These keys are used only to operate the connections you have enabled, and are always encrypted at rest (see section 10).
2.7. Technical data. IP address, browser type, access times, error logs and security logs, and the store's settings change log.
2.8. Data when you contact support. When you submit a request through the support form or by email, we receive your full name, email, phone number (if you provide it), store name or Lavix ID, and the subject and content of your request, together with your IP address and browser information for spam prevention. This data is used only to respond to and handle your request.
2.9. Data we do not actively collect. Lavix does not request and does not actively collect sensitive data such as health status, biometric data, religion, political opinions, criminal records, or payment card numbers. If a customer sends such information in a message of their own accord, that data is processed only as part of the store's conversation content.
3. Purposes of use
- Creating and managing accounts, authenticating sign-in, and managing store members and permissions.
- Providing the features you use: the conversation inbox, customer replies, order creation and tracking, POS synchronisation, shipping and reconciliation, reports, advertising and AI staff.
- Charging fees, managing wallets, and processing commissions, collections and refunds.
- Verifying your email address and sending password reset codes when you request them.
- Sending operational notices and security notices, and responding to support requests.
- Securing the system, and detecting and preventing fraud, abuse and unauthorised access.
- Complying with legal and accounting obligations and with valid requests from competent state authorities.
We do not sell personal data, and we do not use your data or the data of a store's customers to advertise for third parties.
4. Processing of data by artificial intelligence (AI)
Some Lavix features use AI models from third-party providers to assist stores, for example: suggesting or drafting replies to customers, detecting orders from conversations, translating messages, and analysing products, advertising and business performance.
- Data that may be sent to AI: conversation and message content, order information, products, and business and advertising figures, only to the extent necessary for the feature being used.
- Data that is never sent to AI: data received from Google at sign-in (section 2.2), passwords, access keys and refund receiving account details.
- Control: stores can turn AI features on or off. Important actions proposed by AI can be configured to require human approval.
- No training of general models: Lavix does not use a store's data to train AI models shared with other customers. Where an AI provider offers the option, we choose the setting that does not allow the provider to use data sent via its API to train its models.
- Accuracy: AI-generated content may be inaccurate. The store is responsible for reviewing it before relying on it for important decisions.
- The list of AI providers and the countries where processing takes place is published in the Subprocessors list.
5. Data received from Google APIs
Lavix's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Lavix's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.Specifically, Google data is used only to sign you in and identify your account in Lavix. This data is not sold, is not transferred to advertisers or data brokers, is not used for advertising, is not used to train AI models, and is not read by Lavix staff unless you consent, it is necessary to investigate a security incident, or it is required by law.
You can revoke Lavix's access at any time on the Google Account permissions page.
6. Data received from Meta
Lavix processes data from Meta in accordance with the Meta Platform Terms and only to provide the features that the store uses in Lavix. We do not sell Meta data, do not use it to build advertising profiles outside the scope of the service, and do not share it with third parties other than the necessary processors described in this Policy.
When a store disconnects a Page or ad account, Lavix stops collecting new data from that asset. Data already collected is handled in accordance with section 9 and the Data deletion instructions page.
7. Sharing of data
We share data only in the following cases:
- Subprocessors that provide infrastructure, security, AI and notification delivery to Lavix, under appropriate contracts or confidentiality terms. The list is published in the Subprocessors list.
- Partners that the store connects itself, such as social media platforms, POS systems or carriers. Data is sent in accordance with the store's instructions to fulfil orders or synchronise data.
- Members of the same store, according to the roles and permissions set by the Store Owner.
- Lavix support staff, only when necessary to provide technical support or resolve an incident. Each support access is time-limited and recorded in the store's change log.
- As required by law or by a competent state authority, or when necessary to protect the rights, property and safety of Lavix, users or the public.
- In a business restructuring (merger, transfer). The recipient must continue to comply with this Policy, and you will be notified in advance.
8. Storage location and transfers of data abroad
Lavix data is stored and processed on servers located in Laos and Vietnam, and may be stored and processed on virtual private servers (VPS) of infrastructure providers when capacity needs to be expanded. Traffic passes through Cloudflare's network for security and load balancing.
When AI features and partner services are used, data may be processed in the countries where the providers operate their infrastructure, including the United States and China. We transfer only the data necessary for the feature and apply the safeguards described in this Policy.
9. Retention periods
| Type of data | Retention period |
|---|---|
| Data of stores and accounts in use | For as long as you use the service |
| After you stop using the service or delete a store | Retained for a maximum of 90 days so that you can restore it, then deleted |
| Verified data deletion requests | Processed within 30 days |
| System backups | Automatically overwritten within 90 days |
| Data received from Google at sign-in | Deleted when you delete your account or unlink Google |
| Support requests | A maximum of 24 months after the request is resolved, for reference if you contact us again; you may request earlier deletion |
| Email verification codes and password reset codes | Stored only in one-way hashed form; expire after 30 minutes and are permanently deleted after 7 days |
| System email delivery logs (recipient, email type, delivery status) | 90 days |
| Payment records, invoices and wallet transactions | For the periods required by accounting and tax laws |
| Security and anti-fraud logs | For as long as necessary for investigation and prevention |
10. Data security
- Each store's data is stored separately. Users can access only the stores of which they are members, within the scope of the permissions granted to them.
- Connections to Lavix are encrypted with HTTPS/TLS.
- Passwords are hashed with the scrypt algorithm. All platform and partner access keys (Meta Page, Messenger, advertising, Conversions API, Pancake, POS, carriers, Telegram, AI providers) are encrypted with AES-256-GCM at rest. Decryption keys are managed separately from the database.
- Store backups are encrypted with AES-256-GCM using a password that you set yourself.
- Role-based permissions within the store, and logging of changes to settings, members and permissions.
- Sign-in with Google and the Facebook connection use the OAuth 2.0 protocol with a single-use anti-forgery code (state); Google additionally uses PKCE, and every Facebook call additionally carries an appsecret_proof signature. Lavix does not store Google access tokens and does not store Facebook user access tokens — it stores only (in encrypted form) the access tokens of the Pages you choose to connect.
No system is absolutely secure. If a security incident affects your data, we will notify the affected stores and the competent authorities in accordance with applicable law, as soon as possible.
11. Your rights
Depending on the applicable law, you have the right to: access your data, correct inaccurate data, delete data, receive a copy of your data (data export or store backup), object to or restrict certain processing activities, and withdraw your consent by disconnecting a platform.
Many of these rights can be exercised directly in Lavix (Settings → Account & Backup, Settings → Data connections). For other requests, please email [email protected]. We may ask you to verify that you are the account holder or the Store Owner before processing your request, and we will respond within 30 days.
If you are a customer of a store that uses Lavix (for example, you messaged the store's Page), please contact that store directly, as the store decides how your data is used. You may also contact Lavix, and we will forward your request to the store and assist within the scope of our role.
13. Age requirement
Lavix is a tool for businesses and is not intended for persons under 18 years of age. We do not knowingly collect account data from persons under 18. If we become aware of such a case, we will delete the account concerned.
14. Changes to this Policy
We may update this Policy when the service or the law changes. For material changes, we will notify you by email or in the application at least 30 days before they take effect. The effective date and version number are always shown at the top of the page.
15. Contact
For any questions about privacy and data, please contact:
- Operator: HC Group Sole Co., Ltd (ບໍລິສັດ ເຮັດຊີ ກຣຸບ ຈຳກັດຜູ້ດຽວ)
- Enterprise Registration Certificate No.: 1464/ຈທວ, issued on 31/07/2024 in Nakhonluang Vientiane
- Enterprise code / tax identification number: 886836352-000
- Address: Ban KhamHuang (Unit 03), Muong Xaythany, Vientiane Capital, Lao PDR
- Email: [email protected]