Data Protection Policy
Last updated: [set at publication]
This Data Protection Policy explains how BusinessX protects and processes business, customer, and end-customer data across the BusinessX platform and connected services.
1. Purpose and Scope
This policy applies to personal and business data processed through the BusinessX website, application, connected communication channels, customer relationship management tools, AI features, helpdesk, automation, and other available modules. It should be read together with our Privacy Policy and Terms of Service.
2. Roles and Responsibilities
For account, billing, support, and website data collected directly by BusinessX, BusinessX generally acts as the data controller. For data that customers upload or process through the platform—including their end customers' messages, contact details, and CRM records—the BusinessX customer is the controller and BusinessX acts as the processor.
Customers are responsible for establishing a lawful basis for processing, giving any required notices, obtaining necessary permissions or consent, and responding to requests from their own customers. BusinessX processes customer-controlled data only to provide, secure, support, and improve the Service, or as otherwise instructed by the customer and permitted by law.
3. Security Measures
BusinessX applies administrative, technical, and organizational safeguards appropriate to the nature of the data and the risks involved. These safeguards may include:
- Encryption of data in transit and, where supported by the relevant service, at rest.
- Role-based access controls designed to limit access according to job duties and account permissions.
- Restricted production access for authorized personnel with a legitimate operational need.
- Logging, monitoring, backup, and recovery measures appropriate to the Service.
- Security reviews and updates as the platform, threats, and legal obligations evolve.
- Use of payment providers to process payment-card information; BusinessX does not intentionally store full payment-card numbers.
No method of electronic storage or transmission is completely secure. BusinessX therefore cannot guarantee absolute security, but it works to prevent unauthorized access, loss, misuse, alteration, or disclosure using reasonable safeguards.
4. Access Control and Confidentiality
Access to customer data is limited to authorized personnel, contractors, and service providers who need access to operate, support, secure, or maintain the Service. Those parties are expected to follow confidentiality and data-protection obligations. Customers are responsible for managing their own users, permissions, passwords, connected channels, and account access.
5. Data Location and International Transfers
Customer data is stored and processed on infrastructure located in [hosting regions must be confirmed before publication]. Where data is transferred across national borders, BusinessX will use appropriate contractual, organizational, or technical safeguards as required by applicable law.
6. Subprocessors
BusinessX may use carefully selected service providers to support hosting, infrastructure, communications, payment processing, analytics, customer support, and AI functionality. These providers may process limited data only to perform services for BusinessX and are expected to protect it under appropriate contractual terms.
| Subprocessor | Function | Location |
|---|---|---|
| [to be listed] | Hosting and infrastructure | [region] |
| [to be listed] | Payment processing | [region] |
| [to be listed] | AI infrastructure | [region] |
The confirmed subprocessor names, functions, and processing locations must be added before this policy is published.
7. Data Subject Requests
Depending on applicable law, individuals may have rights to request access, correction, deletion, restriction, objection, or a portable copy of their personal data. When a request concerns data controlled by a BusinessX customer, the individual should contact that customer first. BusinessX will provide reasonable assistance to customers through available search, export, correction, and deletion tools.
If BusinessX receives a request concerning customer-controlled data directly, it may forward the request to the relevant customer unless prohibited by law.
8. Incident Response
BusinessX maintains procedures for identifying, assessing, containing, investigating, and responding to security incidents. If a confirmed personal-data breach affects customer-controlled data, BusinessX will notify affected customers without undue delay where required, provide available information needed for their compliance obligations, and document appropriate remediation steps.
9. Retention, Backup, and Deletion
BusinessX retains personal data only for as long as reasonably necessary to provide the Service, maintain security and records, meet contractual commitments, resolve disputes, or comply with legal obligations. Retention periods may vary according to the data type, account status, backup cycle, and applicable law.
After account termination, customer data may remain available for a limited export or wind-down period before it is deleted or anonymized, unless a longer period is legally required. Deleted data may remain temporarily in protected backups until those backups are overwritten according to the normal backup cycle.
10. Data Processing Agreement and Contact
Customers who require a Data Processing Agreement for their compliance obligations may request one by contacting BusinessX.
If you have questions about this policy, data protection, or a suspected security issue, contact us:
- Email: support@businessx.com
- Address: BusinessX, New Baneshwor, Kathmandu, Nepal
Related policies: Privacy Policy, Cookie Policy, and Terms of Service.