Privacy Policy
This Privacy Policy outlines how Desynthic collects, uses, processes, stores, protects, and deletes personal and business data across our web and mobile applications.
Table of Contents
- 1. Developer & Entity Identity
- 2. Information We Collect
- 3. How We Use Your Information
- 4. Third-Party Subprocessors & Sharing
- 5. Data Security & Storage Controls
- 6. AI Processing & Gemini Intelligence
- 7. Data Retention & Deletion Rights
- 8. GDPR, CCPA & Global User Rights
- 9. Children's Privacy
- 10. Contact & Data Protection Officer
1Developer & Application Identity
This application (Ventrexs AI) is owned and operated by Desynthic ("Desynthic", "we", "us", or "our"), a commercial software enterprise specializing in multi-tenant accounts receivable automation, invoicing, customer relationship management, and ethical financial operations.
Application Name: Ventrexs AI
Operating Entity: Desynthic
Headquarters: Delaware, United States
Primary Support & Inquiries: support@ventrexs.com
Data Protection Officer (DPO): privacy@ventrexs.com
2Information We Collect
We strictly collect information necessary to deliver, authenticate, secure, and maintain accounts receivable management services:
A. Account & Profile Credentials
When creating an account, we collect your full name, business email address, company/trade name, role (e.g., owner, admin), and encrypted authentication tokens managed through Supabase Auth.
B. Business & Invoicing Data
Customer contact records (client name, client email, phone number, physical address, communication opt-in status), invoice numbers, issue dates, due dates, itemized line items, subtotal, original amounts due, payments recorded, and remaining balances.
C. Communication & Telephony Records
When sending payment reminders or statement notices via Email, SMS, or WhatsApp with affirmative consent, we log provider message identifiers, transmission timestamps, delivery statuses, and opt-out/STOP events. We do not inspect or sell message contents.
D. Technical & Security Audit Logs
IP addresses, request headers, browser user agent, session timestamps, and security audit events strictly used to detect unauthorized cross-tenant access attempts, brute-force anomalies, and rate-limiting enforcement.
3How We Use Your Information
We process your data under the following legitimate legal and contractual grounds:
- Service Delivery: To generate invoices, record payments, calculate outstanding aging balances, and maintain customer accounts.
- Payment Settlement: To facilitate card and ACH checkout links via integrated payment processors (Stripe Connect).
- Consensual Notifications: To dispatch payment confirmation receipts, approaching due notices, and overdue follow-ups upon your review and approval.
- Security & Tenant Isolation: To enforce cryptographic webhook verification, Row Level Security (RLS), and prevent cross-tenant data leakage.
- Legal & Tax Compliance: To generate audit trails, tax summaries, and maintain statutory accounting records Net 7 years where required by law.
4Third-Party Subprocessors & Data Sharing
Ventrexs AI does not sell, rent, monetize, or trade your personal or customer data to third parties, data brokers, or advertising networks. We share data exclusively with verified technical infrastructure subprocessors under strict Data Processing Addenda (DPAs):
| Subprocessor | Purpose | Data Transmitted | Location |
|---|---|---|---|
| Supabase Inc. | Managed PostgreSQL Database & Auth Engine | User profiles, encrypted auth credentials, business invoices, customer metadata | US / EU |
| Stripe Inc. | Payment Processing & Subscription Billing | Customer email, billing addresses, invoice payment amounts (PCI-DSS Level 1 managed by Stripe; Ventrexs never stores raw card numbers) | United States |
| Resend Inc. | Transactional Email Dispatch | Recipient email address, invoice PDF links, email delivery status | United States |
| Twilio Inc. | SMS Reminders & TCPA Opt-Out Routing | Recipient phone number, reminder text, opt-out status | United States |
| Meta Platforms Ireland | WhatsApp Cloud API Communication | Opted-in customer WhatsApp number, template notification metadata | Ireland / US |
| Google LLC (Gemini) | Read-Only Financial Intelligence & Copilot | Aging invoice balances, overdue days, customer communication tone parameters | United States |
5Data Security & Technical Controls
Ventrexs AI implements robust, multi-layered technical and organizational safeguards:
Postgres Row Level Security (RLS)
Enforces zero cross-tenant leakage at the database engine layer. Every query requires verified business membership.
Encryption in Transit & At Rest
All data in transit is encrypted using modern TLS 1.3. Database volumes and backups are encrypted with AES-256.
Cryptographic Webhook Validation
Inbound Stripe webhooks are verified using HMAC SHA-256 signatures with timestamp tolerance barriers.
Server-Side Authorization
Client mutation inputs are never trusted directly. Role-based membership is evaluated server-side before execution.
6AI Processing & Gemini Copilot Governance
Ventrexs AI utilizes Google Gemini models strictly in an advisory, read-only copilot capacity:
- Zero Ledger Mutation: AI models cannot modify invoice balances, trigger payments, or mutate financial state. Remaining balance calculations are strictly computed via deterministic database arithmetic (
remaining_balance = original_amount - payments_received). - Human-in-the-Loop: No reminder, SMS, or WhatsApp message generated by the AI copilot is ever dispatched without explicit human approval.
- No Foundation Model Training: Your business data and customer invoices are never used to train public LLM models or shared across commercial AI pools.
- Halal-First & Ethical Debt Safeguards: Our deterministic validation layer rejects all prompt outputs attempting usurious interest calculations, compounding late fees, predatory financing, or deceptive debt-collection notices.
7Data Retention & Deletion Rights
In full accordance with the Google Play Data Safety Mandate, GDPR Article 17 (Right to Erasure), and CCPA/CPRA, users have full autonomy to delete their account and associated personal data:
- In-App Self-Service Deletion: Authenticated users can navigate to Settings > Danger Zone to permanently delete their account profile, customer lists, and business workspace in real-time.
- Public Unauthenticated Deletion Portal: Anyone who previously created an account or wishes to purge their contact details can submit a request via our public Account Deletion Page (/account-deletion) without requiring active login.
*Note: Historical finalized tax invoices and statutory audit logs are retained up to statutory accounting retention horizons (Net 7 years) where mandated by commercial tax laws, after which they are permanently destroyed.
8GDPR, CCPA & Global Privacy Rights
Depending on your jurisdiction, you are entitled to the following enforceable privacy rights:
- Right of Access: Request a complete export of personal data held about you in standard JSON or CSV format.
- Right to Rectification: Update inaccurate business credentials or customer contact information via Settings.
- Right to Erasure / Deletion: Permanently delete your profile and personal data.
- Right to Object & Opt-Out: Withdraw consent for SMS/WhatsApp notices at any time (e.g., reply STOP).
- Right to Non-Discrimination: We will never degrade service quality or deny access for exercising privacy rights.
9Children's Privacy
Ventrexs AI is a commercial B2B financial software platform designed exclusively for business entities and professional operators. We do not knowingly market to, collect, or process information from individuals under the age of 18. If you believe a minor has created an account, contact privacy@ventrexs.com immediately for expedited removal.
10Contact & Data Protection Officer
For any questions, compliance audits, GDPR/CCPA inquiries, or data deletion requests, contact our Data Protection Team:
Desynthic — Data Protection Office
Email: privacy@ventrexs.com
Legal Inquiries: legal@ventrexs.com
Physical Notice Address: Desynthic, Corporation Trust Center, 1209 Orange St, Wilmington, DE 19801, USA
© 2026 Desynthic. All rights reserved.