Privacy Policy
Last updated: 2026-08-08
This Privacy Policy describes how GHEXIT, operated by Vukori Holdings [registered entity name, address, and jurisdiction to be confirmed by Vukori Holdings / legal counsel before this page is treated as final], collects, uses, and discloses information in connection with the GHEXIT communications platform (the “Service”). This policy covers both data about our Customers(organizations with a GHEXIT account) and data about individuals Customers communicate with through the Service (“End Users”, e.g. SMS/call/email recipients) that GHEXIT processes on the Customer’s behalf.
1. Information We Collect
Account & billing information (Customers)
- Name, email address, and password (hashed — GHEXIT never stores plaintext passwords) via Supabase Auth.
- Organization details: company name, tax ID, billing address, and Stripe customer/subscription identifiers.
- API keys and their usage metadata (last used, permissions, environment).
- Optional TOTP multi-factor authentication secrets and single-use backup codes, stored encrypted, used only to verify sign-in.
Communications content & metadata (End Users)
- SMS/MMS and WhatsApp message bodies, media attachments, and sender/recipient phone numbers.
- Voice call metadata (duration, status, from/to numbers) and, only where a Customer has explicitly enabled recording, call recordings.
- Email content, recipients, and delivery/open/click tracking where a Customer has enabled it.
- Video room session metadata and, only where recording is explicitly enabled by the Customer, video recordings.
- Verification codes (OTPs) — stored as salted hashes, not plaintext, and auto-expire.
Technical & usage data
- API request logs, IP address, user agent, and audit-log entries (action, resource, timestamp) for security and compliance purposes.
- Carrier delivery-status callbacks (e.g., Twilio, Telnyx, SignalWire, Africa’s Talking status webhooks), authenticated via each carrier’s documented request-signing scheme before being accepted.
- Cookies strictly necessary for authenticated dashboard sessions (Supabase Auth session cookies). We do not use third-party advertising trackers.
2. How We Use Information
- To provide, operate, and secure the Service — routing messages/calls/emails through the correct carrier, authenticating requests, and enforcing per-organization data isolation.
- To bill for usage and manage subscriptions via Stripe.
- To detect fraud, abuse, and security incidents, including maintaining audit logs and (where applicable) HIPAA-relevant access logs.
- To provide customer support and respond to inquiries.
- To comply with legal obligations, including data-subject and law-enforcement requests where legally required.
We do not sell personal information, and we do not use End User communications content for advertising.
3. Sub-processors & Third Parties
To deliver the Service, GHEXIT shares the minimum necessary data with:
- Carrier partners (Twilio, Telnyx, SignalWire, Africa’s Talking) — to actually transmit SMS, voice, and WhatsApp traffic.
- Resend — to transmit email traffic sent through the Service.
- LiveKit — to host video room sessions.
- Stripe — to process payments; GHEXIT does not store full payment card numbers.
- Supabase (self-hosted infrastructure) — for authentication and database hosting.
We do not permit sub-processors to use Customer or End User data for any purpose other than providing services to GHEXIT.
4. Data Isolation & Security
Each Customer organization’s data is logically isolated at the database level (row-level security scoped to the organization) in addition to application-level access controls, so one Customer cannot read or write another Customer’s messages, calls, billing records, or API keys. Backend service operations use credentials that never leave our server-side environment. We maintain audit logs of access to sensitive resources.
5. Data Retention
We retain Customer account data for as long as the account is active, and communications content/metadata for the period needed to provide the Service, resolve disputes, and meet legal/audit retention requirements, after which it is deleted or anonymized. Customers may request earlier deletion of specific records subject to any legal retention obligations (e.g., billing records, HIPAA audit trails where applicable).
6. Your Rights (GDPR / CCPA and equivalents)
Depending on your location, you may have rights to access, correct, export, or delete your personal data, or to object to or restrict certain processing. GHEXIT supports these requests — including access, rectification, erasure, portability, and objection requests — through our compliance tooling. To exercise a right, contact [email protected], or ask your Customer organization if you are an End User (they are typically the data controller for communications they send through GHEXIT; GHEXIT acts as a processor on their behalf).
7. HIPAA
For Customers processing protected health information, GHEXIT maintains HIPAA-relevant audit logging capability, but PHI may only be processed through the Service under a signed Business Associate Agreement (BAA). Contact us before sending PHI through the Service if a BAA is not already in place.
8. International Transfers
GHEXIT serves customers across multiple regions, including African markets, and works with Carriers that may process data in other countries in order to deliver messages/calls locally. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers.
9. Children
The Service is intended for business use and is not directed to children under 16.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via the dashboard or the email address on your account at least 14 days before taking effect.
11. Contact
Privacy questions or data-subject requests: [email protected]. General support: [email protected].