Privacy Policy
Last updated: 6 August 2026
Vinyard is a trade name used by Sagi Kirma, an individual sole proprietor registered in Israel as an exempt dealer (עוסק פטור) (“Vinyard”, “we”, “us”, “our”). Sagi Kirma operates the AI-assisted customer-messaging platform available at getviny.com and its applications (the “Service”). This Privacy Policy explains what personal data we process, why we process it, who receives it, how long we keep it, and the rights available to you. The controller can be contacted at privacy@getviny.com.
1. Our two roles
Vinyard handles personal data in two capacities:
- As a controller — Sagi Kirma determines how and why we use information about business-account users, website visitors, prospective customers, and people who contact us.
- As a processor — for the customer conversations a business manages through Vinyard (messages, contact details, etc.). Here the business is the controller and decides how that data is used; we process it on their behalf under our agreement with them. If you are an end-customer of a business that uses Vinyard, please see “If a business uses Vinyard to talk to you” below.
2. Information we collect
Account, business & integration information
- Account details such as name, email address, role, preferred language, and a hashed password.
- Business profile and settings you configure (business name, hours, AI instructions, knowledge-base content, automation flows, notification settings, and team members).
- Identifiers and credentials for services you connect, such as WhatsApp channel identifiers and access tokens, and Google Calendar identifiers, OAuth tokens, and connection status. WhatsApp access tokens are encrypted at the application layer before storage. Integration credentials are used only to provide and maintain the connection you request.
Conversation data (processed on our customers’ behalf)
- Message content, attachments and media references exchanged between a business and its customers, and related metadata such as timestamps, sender, message type, platform identifier, and delivery status.
- Customer contact records, such as name, phone number, email address, language, notes, tags, and messaging-platform identifiers.
- When supported by a connected WhatsApp configuration, synced names and phone numbers from the business owner’s saved contacts. We use these to keep the AI from replying to personal contacts.
- Automation-flow state and information a person supplies while interacting with a flow.
Calendar & AI-operation data
- If Google Calendar is connected, availability information and event data needed to view, create, reschedule, cancel, or send invitations for appointments. Calendar events created by Vinyard may contain the customer’s name, phone number, email address, appointment details, and Vinyard-specific event identifiers.
- AI and calendar audit information such as model and request identifiers, generated output, confidence and escalation results, tool actions, calendar action logs, errors, latency, and token-usage information.
Usage & technical data
- Log, request, and device data such as IP address, browser type, timestamps, authentication events, and actions taken in the Service.
- Information submitted through our marketing site, including name, email address and/or phone number, when you ask us to contact you.
3. How information is collected and whether you must provide it
We collect information directly from account users and website forms, automatically when the Service is used, and from services a business chooses to connect, including Meta/WhatsApp and Google Calendar. Business customers also provide or direct us to process information about their own customers and team members.
Unless we say otherwise at the point of collection, you are not legally required to provide personal data; providing it is voluntary. However, required account information is necessary to create and secure an account, contact information is necessary for us to respond to a request, and relevant customer and integration information is necessary to provide messaging, automation, AI, and scheduling features. If you do not provide it, the corresponding account, response, or feature may not be available. End-customers choose what to include in their messages, although the messaging platform automatically supplies the identifiers and metadata needed to deliver those messages.
4. Why we use information
- To create and administer accounts and provide, operate, troubleshoot, and secure the Service.
- To receive, organize, and send customer communications and run automation flows according to the business customer’s instructions.
- To generate AI-assisted suggestions or automated responses based on the conversation and the business’s instructions and knowledge base.
- To check calendar availability and carry out appointment actions when a business enables scheduling and the conversation requests such an action.
- To send transactional messages (e.g. password resets, escalation alerts, calendar invitations, and lead notifications).
- To respond to inquiries and requested demonstrations.
- To provide support, measure performance, maintain audit trails, prevent abuse and fraud, enforce our terms, and comply with legal obligations.
- To analyze and improve the Service, using aggregated or de-identified data where reasonably possible.
Our legal bases (where GDPR applies) include performance of a contract, legitimate interests (operating and securing the service), consent (where required), and compliance with legal obligations. Where we act as a processor, the business customer determines the lawful basis for processing its customer data.
5. Artificial intelligence and automated actions
When AI features are enabled, relevant conversation history, business instructions, knowledge-base content, and, when needed, limited calendar availability or appointment context are sent to OpenAI through its API. We configure the API so that this content is not used to train OpenAI’s models. Vinyard records the resulting reply and operational audit information.
Depending on the business’s settings, AI-generated replies may be sent automatically and the Service may propose and carry out appointment actions in Google Calendar. Business customers decide whether to enable these features, configure their instructions and escalation threshold, and can take over a conversation. AI output can be inaccurate, so businesses remain responsible for their configuration and communications. Vinyard is not intended to make solely automated decisions that produce legal or similarly significant effects about individuals.
6. Service providers and connected services
We use the following categories of recipients to operate the Service. They receive only the information reasonably needed for their role:
| Provider | Purpose |
|---|---|
| Meta Platforms (WhatsApp Business Platform) | Connected-channel synchronization and delivery of messages and notifications |
| OpenAI | AI reply generation and optional media transcription or understanding when enabled |
| Google Calendar | Optional calendar connection, availability checks, event management, and invitations |
| Railway | Application, database, cache, and queue hosting |
| Cloudflare | DNS, content delivery, security, and marketing-site hosting |
| Resend | Transactional email delivery |
| Google Workspace | Business email |
Connected services also process information under their own terms and privacy policies. A business may configure an automation webhook that sends flow data to a destination it selects; that business is responsible for the destination and its use of the information. We do not sell or rent personal data.
Google API data. Vinyard’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google Calendar data only to provide the user-facing scheduling features the connected-account user requests, maintain security, and comply with law. We do not use Google Calendar data for advertising, sale, credit decisions, or to train a generalized AI or machine-learning model. Human access is limited to cases where the user has given permission (including for a specific support request), access is necessary for security, or access is required by law.
7. Other sharing and disclosure
We may also disclose personal data to the business account that controls a conversation and its authorized users; to professional advisers subject to confidentiality; when required by law, regulation, legal process, or a competent authority; when reasonably necessary to protect rights, safety, security, and the integrity of the Service; or in connection with a financing, reorganization, sale, or transfer of all or part of the business, subject to appropriate safeguards.
8. International transfers
Some of our providers are located outside Israel and the EEA (e.g. in the United States). We use a lawful transfer mechanism and obtain applicable contractual privacy and security commitments for transfers from Israel. Where the GDPR or UK GDPR applies, we rely on an adequacy decision or appropriate safeguards such as approved standard contractual clauses, as applicable.
9. Data retention
We keep personal data only for as long as reasonably necessary for the purposes described above. The applicable period depends on the type of data:
- Account, configuration, integration, and customer-content data are normally kept while the account is active and until the business deletes them or makes a verified account-deletion request.
- Marketing leads and correspondence are kept for as long as needed to respond, follow up on the requested demonstration or inquiry, maintain an appropriate business record, and honor opt-out requests.
- Security, delivery, AI, and calendar audit records are kept for as long as reasonably needed to secure the Service, investigate incidents, resolve disputes, and maintain reliable operations.
After a verified account-deletion request, we delete or de-identify the relevant active-system data within the timeline stated on our Data deletion page. Residual copies may remain in backups until they rotate out. We may retain limited records for longer when required by tax, accounting, fraud-prevention, dispute, or other legal obligations.
10. Security
We use technical and organizational measures designed to protect personal data, including encryption in transit, application-layer encryption of WhatsApp access tokens, password hashing, access controls, tenant isolation, credential redaction, and security logging. No method of transmission or storage is 100% secure.
11. Your rights
Under Israel’s Privacy Protection Law, you have the right to inspect personal data about you held in a database and to request correction if it is incorrect, incomplete, unclear, or outdated. Depending on the law that applies to you, you may also have rights to request deletion or a copy of your data, object to or restrict certain processing, and withdraw consent where processing is based on consent. Withdrawal does not affect processing already carried out lawfully.
To exercise a right, email privacy@getviny.com. If your data is processed by Vinyard on behalf of a business (as a processor), we will refer your request to that business or act on its instructions. We may request information reasonably necessary to verify your identity and protect the data. You may also have the right to complain to the Israel Privacy Protection Authority or another competent supervisory authority.
12. If a business uses Vinyard to talk to you
If you messaged a business that uses Vinyard, that business is the controller of your conversation and its own privacy policy governs how it uses your data. For access or deletion, contact that business directly, or email us at privacy@getviny.com and we will route your request. See Data deletion for how to request removal of your data.
13. Browser storage and cookies
The dashboard uses browser local storage for the authentication token and functional preferences such as language and dismissed notices. The marketing site uses local storage to remember the selected language. These features are necessary to provide the requested experience. We do not currently use advertising cookies. Cloudflare may process basic request and security data when serving the site.
14. Communications
We use contact information submitted through the marketing site to respond to the requested inquiry or demonstration. We do not send unrelated promotional communications unless we have consent or another lawful basis. You can ask us to stop promotional communications at any time by replying to the message or emailing privacy@getviny.com. We may still send non-promotional account and security messages.
15. Children
Vinyard accounts are intended for adults acting for a business and are not directed to children. The Service may process a minor’s message only when a business customer uses Vinyard to communicate with that person. The business customer is responsible for determining whether that processing is lawful and for providing any notice or obtaining any consent required for minors.
16. Changes to this Policy
We may update this Policy from time to time. We will post the updated version here and revise the “Last updated” date; material changes will be communicated as appropriate or as required by law.
17. Contact
The controller and Service operator is Sagi Kirma, an Israeli sole proprietor registered as an exempt dealer (עוסק פטור), trading as Vinyard. Questions and privacy requests can be sent to privacy@getviny.com.