Privacy Policy

Last updated: 6 August 2026

Vinyard is a trade name used by Sagi Kirma, an individual sole proprietor registered in Israel as an exempt dealer (עוסק פטור) (“Vinyard”, “we”, “us”, “our”). Sagi Kirma operates the AI-assisted customer-messaging platform available at getviny.com and its applications (the “Service”). This Privacy Policy explains what personal data we process, why we process it, who receives it, how long we keep it, and the rights available to you. The controller can be contacted at privacy@getviny.com.

1. Our two roles

Vinyard handles personal data in two capacities:

2. Information we collect

Account, business & integration information

Conversation data (processed on our customers’ behalf)

Calendar & AI-operation data

Usage & technical data

3. How information is collected and whether you must provide it

We collect information directly from account users and website forms, automatically when the Service is used, and from services a business chooses to connect, including Meta/WhatsApp and Google Calendar. Business customers also provide or direct us to process information about their own customers and team members.

Unless we say otherwise at the point of collection, you are not legally required to provide personal data; providing it is voluntary. However, required account information is necessary to create and secure an account, contact information is necessary for us to respond to a request, and relevant customer and integration information is necessary to provide messaging, automation, AI, and scheduling features. If you do not provide it, the corresponding account, response, or feature may not be available. End-customers choose what to include in their messages, although the messaging platform automatically supplies the identifiers and metadata needed to deliver those messages.

4. Why we use information

Our legal bases (where GDPR applies) include performance of a contract, legitimate interests (operating and securing the service), consent (where required), and compliance with legal obligations. Where we act as a processor, the business customer determines the lawful basis for processing its customer data.

5. Artificial intelligence and automated actions

When AI features are enabled, relevant conversation history, business instructions, knowledge-base content, and, when needed, limited calendar availability or appointment context are sent to OpenAI through its API. We configure the API so that this content is not used to train OpenAI’s models. Vinyard records the resulting reply and operational audit information.

Depending on the business’s settings, AI-generated replies may be sent automatically and the Service may propose and carry out appointment actions in Google Calendar. Business customers decide whether to enable these features, configure their instructions and escalation threshold, and can take over a conversation. AI output can be inaccurate, so businesses remain responsible for their configuration and communications. Vinyard is not intended to make solely automated decisions that produce legal or similarly significant effects about individuals.

6. Service providers and connected services

We use the following categories of recipients to operate the Service. They receive only the information reasonably needed for their role:

ProviderPurpose
Meta Platforms (WhatsApp Business Platform)Connected-channel synchronization and delivery of messages and notifications
OpenAIAI reply generation and optional media transcription or understanding when enabled
Google CalendarOptional calendar connection, availability checks, event management, and invitations
RailwayApplication, database, cache, and queue hosting
CloudflareDNS, content delivery, security, and marketing-site hosting
ResendTransactional email delivery
Google WorkspaceBusiness email

Connected services also process information under their own terms and privacy policies. A business may configure an automation webhook that sends flow data to a destination it selects; that business is responsible for the destination and its use of the information. We do not sell or rent personal data.

Google API data. Vinyard’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google Calendar data only to provide the user-facing scheduling features the connected-account user requests, maintain security, and comply with law. We do not use Google Calendar data for advertising, sale, credit decisions, or to train a generalized AI or machine-learning model. Human access is limited to cases where the user has given permission (including for a specific support request), access is necessary for security, or access is required by law.

7. Other sharing and disclosure

We may also disclose personal data to the business account that controls a conversation and its authorized users; to professional advisers subject to confidentiality; when required by law, regulation, legal process, or a competent authority; when reasonably necessary to protect rights, safety, security, and the integrity of the Service; or in connection with a financing, reorganization, sale, or transfer of all or part of the business, subject to appropriate safeguards.

8. International transfers

Some of our providers are located outside Israel and the EEA (e.g. in the United States). We use a lawful transfer mechanism and obtain applicable contractual privacy and security commitments for transfers from Israel. Where the GDPR or UK GDPR applies, we rely on an adequacy decision or appropriate safeguards such as approved standard contractual clauses, as applicable.

9. Data retention

We keep personal data only for as long as reasonably necessary for the purposes described above. The applicable period depends on the type of data:

After a verified account-deletion request, we delete or de-identify the relevant active-system data within the timeline stated on our Data deletion page. Residual copies may remain in backups until they rotate out. We may retain limited records for longer when required by tax, accounting, fraud-prevention, dispute, or other legal obligations.

10. Security

We use technical and organizational measures designed to protect personal data, including encryption in transit, application-layer encryption of WhatsApp access tokens, password hashing, access controls, tenant isolation, credential redaction, and security logging. No method of transmission or storage is 100% secure.

11. Your rights

Under Israel’s Privacy Protection Law, you have the right to inspect personal data about you held in a database and to request correction if it is incorrect, incomplete, unclear, or outdated. Depending on the law that applies to you, you may also have rights to request deletion or a copy of your data, object to or restrict certain processing, and withdraw consent where processing is based on consent. Withdrawal does not affect processing already carried out lawfully.

To exercise a right, email privacy@getviny.com. If your data is processed by Vinyard on behalf of a business (as a processor), we will refer your request to that business or act on its instructions. We may request information reasonably necessary to verify your identity and protect the data. You may also have the right to complain to the Israel Privacy Protection Authority or another competent supervisory authority.

12. If a business uses Vinyard to talk to you

If you messaged a business that uses Vinyard, that business is the controller of your conversation and its own privacy policy governs how it uses your data. For access or deletion, contact that business directly, or email us at privacy@getviny.com and we will route your request. See Data deletion for how to request removal of your data.

13. Browser storage and cookies

The dashboard uses browser local storage for the authentication token and functional preferences such as language and dismissed notices. The marketing site uses local storage to remember the selected language. These features are necessary to provide the requested experience. We do not currently use advertising cookies. Cloudflare may process basic request and security data when serving the site.

14. Communications

We use contact information submitted through the marketing site to respond to the requested inquiry or demonstration. We do not send unrelated promotional communications unless we have consent or another lawful basis. You can ask us to stop promotional communications at any time by replying to the message or emailing privacy@getviny.com. We may still send non-promotional account and security messages.

15. Children

Vinyard accounts are intended for adults acting for a business and are not directed to children. The Service may process a minor’s message only when a business customer uses Vinyard to communicate with that person. The business customer is responsible for determining whether that processing is lawful and for providing any notice or obtaining any consent required for minors.

16. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here and revise the “Last updated” date; material changes will be communicated as appropriate or as required by law.

17. Contact

The controller and Service operator is Sagi Kirma, an Israeli sole proprietor registered as an exempt dealer (עוסק פטור), trading as Vinyard. Questions and privacy requests can be sent to privacy@getviny.com.