Lynxbe Platform — Unified Business Operations
Effective Date: February 13, 2026 | Version 2.0
Lynxbe Platform (the "App") is a unified business operations platform developed by Lynxbe Ltd ("we", "us", "our"), an Israeli software company. The App is available on iOS, Android, and Web.
Lynxbe Platform provides businesses with an integrated system connecting:
Every feature in the platform is interconnected. No capability exists in isolation — communications feed CRM, CRM feeds analytics, analytics feed automation, and compliance governs all.
| Data | Collection | Purpose |
|---|---|---|
| Full name, display name | Required | Account identity, team display |
| Email address | Required | Authentication, notifications, password recovery |
| Phone number | Required | Account verification, voice/SMS features |
| Password | Encrypted | Authentication (bcrypt hashed, never stored in plaintext) |
| Profile photo | Optional | User identity within team |
| Role & team assignment | Automatic | Permission enforcement, data visibility scoping |
| Data | Collection | Purpose |
|---|---|---|
| Business name, address, contact info | Required | Business profile, invoicing, compliance |
| Business logo & branding | Optional | Branded communications |
| WhatsApp Business Account tokens | Encrypted | WhatsApp API connectivity (AES-256 encrypted) |
| Channel configurations (SMS, Voice, Email) | Encrypted | Multi-channel communication delivery |
| Team structure & user assignments | Automatic | Permission enforcement, conversation routing |
| Data | Collection | Purpose |
|---|---|---|
| WhatsApp / SMS / Email messages | Automatic | Conversation management, CRM history |
| Voice call logs & recordings | Automatic | Call history, quality assurance, AI analytics |
| Customer contacts & profiles | Required | CRM, customer relationship management |
| Media files (images, documents, audio, video) | Automatic | Message attachments, document management |
| Conversation metadata (timestamps, delivery status) | Automatic | Analytics, delivery tracking, SLA monitoring |
| CRM deals, pipelines, notes | Required | Sales management, revenue tracking |
| Automation flow configurations | Required | Workflow automation execution |
| Data | Collection | Purpose |
|---|---|---|
| Device model & OS version | Automatic | App compatibility, bug diagnosis |
| App version | Automatic | Feature availability, update prompts |
| IP address | Automatic | Security, audit logging, geo-compliance |
| Push notification token (FCM/APNs) | Automatic | Push notification delivery |
| Crash reports & performance data | Automatic | Stability monitoring, bug fixes |
| Purpose | Legal Basis (GDPR) | Data Used |
|---|---|---|
| Provide platform features (messaging, CRM, analytics, automation) | Contract performance | Account, business, communication data |
| Authenticate users & enforce permissions | Contract performance | Credentials, role, team, JWT tokens |
| Deliver notifications (in-app, push, email, WhatsApp, SMS) | Contract performance | Contact info, push tokens, preferences |
| Generate business analytics & reports | Contract performance | Communication metadata, CRM data |
| Execute automation workflows & triggers | Contract performance | CRM data, communication events, webhook configs |
| AI enrichment (smart routing, suggestions, call intelligence) | Legitimate interest / Consent | Anonymized communication patterns |
| Security monitoring & fraud prevention | Legitimate interest | IP address, device info, access patterns |
| Audit logging & compliance | Legal obligation | All administrative actions, access events |
| Improve platform stability & performance | Legitimate interest | Crash reports, performance metrics |
| HIPAA/GDPR compliance enforcement | Legal obligation | Data classification tags, consent records, access logs |
We never sell your data. We share data only as necessary to operate the platform:
| Provider | Purpose | Data Shared | Their Privacy Policy |
|---|---|---|---|
| Meta (WhatsApp Business API) | WhatsApp messaging | Message content, phone numbers, media | WhatsApp Business Policy |
| SMS Gateway Providers | SMS delivery | Phone numbers, message content | Per provider agreement |
| FreeSWITCH / VoIP Providers | Voice calls | Phone numbers, call audio (when recording enabled) | Per provider agreement |
| SMTP / Email Providers | Email delivery | Email addresses, message content | Per provider agreement |
| Provider | Purpose | Data Shared |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, RDS, S3 storage | All platform data (encrypted at rest & in transit) |
| Google Firebase | Push notifications (FCM), crash analytics | Device tokens, crash data |
| Apple Push Notification Service (APNs) | iOS push notifications | Device tokens, notification payloads |
| OpenAI | AI features (when enabled by admin) | Anonymized/redacted conversation patterns |
Lynxbe Platform is a multi-tenant system where each business organization's data is strictly isolated:
business_id — cross-tenant access is technically impossible at the application layerFor businesses in the healthcare sector or those handling Protected Health Information (PHI), Lynxbe Platform provides HIPAA-compliant data handling capabilities.
In the event of a breach involving unsecured PHI, Lynxbe will:
For users and businesses in the European Economic Area (EEA) and United Kingdom, Lynxbe Platform fully complies with the GDPR.
| Processing Activity | Legal Basis (Art. 6) | Details |
|---|---|---|
| Providing platform services | Art. 6(1)(b) — Contract | Necessary to perform the service agreement |
| Security & fraud prevention | Art. 6(1)(f) — Legitimate Interest | Protecting users and platform integrity |
| AI-powered features | Art. 6(1)(a) — Consent | Opt-in by business administrator |
| Marketing communications | Art. 6(1)(a) — Consent | Opt-in with easy unsubscribe |
| Audit logging | Art. 6(1)(c) — Legal Obligation | Required for compliance and accountability |
| Analytics & improvement | Art. 6(1)(f) — Legitimate Interest | Improving platform quality (balanced against privacy) |
| Right | Article | How to Exercise |
|---|---|---|
| Right of Access | Art. 15 | Request a copy of all personal data we hold about you |
| Right to Rectification | Art. 16 | Correct inaccurate or incomplete personal data |
| Right to Erasure ("Right to be Forgotten") | Art. 17 | Request deletion of your personal data |
| Right to Restrict Processing | Art. 18 | Limit how we process your data in certain circumstances |
| Right to Data Portability | Art. 20 | Receive your data in machine-readable format (JSON/CSV) |
| Right to Object | Art. 21 | Object to processing based on legitimate interests |
| Right Against Automated Decisions | Art. 22 | Not be subject to decisions based solely on automated processing |
| Right to Withdraw Consent | Art. 7(3) | Withdraw consent at any time without affecting prior processing |
To exercise any right, email privacy@lynxbe.co.il. We respond within 30 days (extendable to 60 days for complex requests with notice).
We maintain Data Processing Agreements (DPAs) with all sub-processors. A list of current sub-processors is available upon request. We notify customers of any changes to sub-processors with 30 days' advance notice.
We conduct DPIAs for high-risk processing activities, including:
For transfers outside the EEA, we rely on:
For California residents under the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA):
As an Israeli company, we comply with the Israeli Privacy Protection Law, 5741-1981 and its regulations:
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| Account data | While active + 90 days after closure | Hard delete from all systems |
| Communication messages | Per business retention policy (configurable) | Soft delete, then hard delete after retention period |
| Voice recordings | Per business retention policy (default: 90 days) | Deleted from S3 storage |
| CRM data | While business active + 90 days | Hard delete with cascade |
| Audit logs | Minimum 12 months (HIPAA: 6 years) | Automated purge after retention |
| Analytics (aggregated) | Indefinite (anonymized) | No personal data retained |
| Encrypted backups | 30 days rolling | Automatic expiration |
| Compliance records | Per applicable regulation (up to 6 years) | Automated purge after legal hold |
Right to Deletion: You may request deletion of your data at any time by contacting privacy@lynxbe.co.il. We process deletion requests within 30 days, subject to legal retention obligations.
Regardless of your location, you have the following rights:
Email: privacy@lynxbe.co.il
We will verify your identity before processing any request. Response time: 30 days (GDPR), 45 days (CCPA).
Business administrators can also manage user data directly through the Lynxbe Platform's compliance dashboard.
The Lynxbe Platform is a B2B business operations tool and is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children under 16 (GDPR) or 13 (COPPA).
If you believe a child has provided us with personal information, contact us immediately at privacy@lynxbe.co.il and we will delete the data promptly.
The App may send push notifications for:
You can disable push notifications at any time through your device's Settings app. Within the Lynxbe app, you can configure which notification types you wish to receive.
| Permission | When Requested | Purpose | Required? |
|---|---|---|---|
| Notifications | First launch | Push notification delivery | Optional |
| Microphone | When making a call | VoIP voice calls, voice messages | For voice features only |
| Camera | When taking a photo | Capture photos for messages | For media features only |
| Photo Library | When attaching media | Send images/videos in conversations | For media features only |
| Background Refresh | After setup | Receive calls and messages when app is in background | Optional |
All permissions can be revoked at any time through your device settings. The app will continue to function with reduced capabilities.
The Lynxbe Platform offers optional AI-powered features that must be explicitly enabled by the business administrator:
Per GDPR Article 22, we do not make decisions that produce legal effects or similarly significant effects based solely on automated processing. AI features provide recommendations only — human review is always available.
The Lynxbe Platform maintains comprehensive audit trails as required by HIPAA and GDPR:
Audit logs are immutable, timestamped, and retained per regulatory requirements. Business administrators can access audit logs through the platform's Audit Log page.
Your data is processed and stored in the following locations:
| Region | Infrastructure | Purpose |
|---|---|---|
| European Union (Frankfurt, Germany) | AWS eu-central-1 | Primary application hosting, database |
| Europe (Ireland) | AWS eu-west-1 | Secondary infrastructure, VoIP services |
| United States | OpenAI API, Firebase | AI processing (when enabled), push notifications |
All cross-border transfers are protected by Standard Contractual Clauses (SCCs), adequacy decisions, and supplementary technical measures (encryption, access controls).
We may update this Privacy Policy periodically. When we make material changes:
Continued use of the app after changes take effect constitutes acceptance. If you disagree with changes, you may delete your account.
| Contact Type | Details |
|---|---|
| Privacy inquiries & data subject requests | privacy@lynxbe.co.il |
| HIPAA compliance & BAA requests | compliance@lynxbe.co.il |
| Security incidents & breach reports | security@lynxbe.co.il |
| General support | info@lynxbe.co.il |
| Company | Lynxbe Ltd, Israel |
| Website | www.lynxbe.co.il |
Our Data Protection Officer (DPO) can be reached at privacy@lynxbe.co.il for any privacy-related concerns, GDPR inquiries, or to exercise your data subject rights.