Privacy Policy

Last updated: May 4, 2026
Privacy Policy โ€“ Flyrix
Legal Document
๐Ÿ—“ Effective Date: April 8, 2026๐Ÿข White Rabbit Trading and Consulting Limited ยท Hong Kong ยท flyrix.app
โœ“ GDPR Compliant

At Flyrix, operated by White Rabbit Trading and Consulting Limited ("Company," "we," "us," "our", "White Rabbit"), your privacy is important to us. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have over your information when you use the Flyrix platform ("Service"), available at flyrix.app.

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.

01

Who We Are

White Rabbit is a company incorporated and operating under the laws of Hong Kong, and is the data controller responsible for the personal data you provide when using Flyrix. The Service is operated globally and is accessible to users worldwide.

Because we serve an international user base, we are committed to upholding data protection standards applicable across multiple jurisdictions, including Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO"), the EU/UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act ("CCPA"), and other regional privacy laws where applicable. The most protective standard will apply to your data based on your location.

If you are a Flyrix customer using our platform to manage your own subscribers and contacts, you act as an independent data controller for your end-users' data. White Rabbit acts as a data processor on your behalf in that context, governed by our Data Processing Agreement (DPA), available upon request.

02

Data We Collect

We collect only the data that is necessary to provide and improve the Service. This includes:

Account & Identity Data

  • Full name and email address
  • Password (stored as a one-way encrypted hash)
  • Company name (optional)
  • Profile photo (optional)

Billing & Payment Data

  • Billing address and VAT number (where applicable)
  • Payment method details โ€” processed exclusively by our payment provider; we do not store full card numbers on our servers
  • Transaction history and invoices

Usage & Technical Data

  • IP address and approximate geographic location (country/city level)
  • Browser type, operating system, device type
  • Pages visited, features used, session duration
  • Error logs and crash reports

Customer & Campaign Data

When you use Flyrix to build funnels, manage campaigns, or send emails, you may upload or import contact lists and related data (e.g., subscriber names and email addresses). This data belongs to you. We process it only on your instruction as described in Section 1.

Communications Data

  • Messages you send to our support team
  • Survey responses and feedback submissions
03

How We Collect Data

SourceExamples
Directly from youRegistration forms, billing info, support requests, survey responses
AutomaticallyCookies, server logs, analytics tools when you use the Service
Third partiesPayment processors (e.g., Stripe), OAuth providers (e.g., Google Sign-In)
04

Why We Use Your Data

We use your personal data for the following purposes:

  • Service delivery: To create and manage your account, process payments, and operate the core features of Flyrix.
  • Communication: To send you transactional emails (e.g., invoices, password resets), product updates, and security alerts.
  • Customer support: To respond to your inquiries and resolve issues.
  • Analytics & improvement: To understand how the Service is used, diagnose bugs, and develop new features.
  • Marketing: To send you information about Flyrix features and promotions โ€” only where you have consented or where permitted by applicable law. You may opt out at any time.
  • Security & fraud prevention: To detect and prevent unauthorized access, abuse, and fraudulent activity.
  • Legal compliance: To fulfill our legal obligations, such as tax record-keeping and responding to lawful requests.

We do not sell your personal data to third parties.

06

Sharing Your Data

We do not sell your personal data. We share it only in the following circumstances:

Service Providers (Sub-processors)

We engage trusted third-party companies to help us operate the Service. These providers are bound by contractual obligations to process data only as instructed and to protect it appropriately. Categories include:

  • Cloud hosting and infrastructure providers
  • Payment processors (e.g., Stripe)
  • Transactional email delivery providers
  • Analytics and monitoring tools
  • Customer support software

Legal Requirements

We may disclose your data if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect our rights, your safety, or the safety of others.

Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of our assets, your personal data may be transferred as part of that transaction. We will notify you in advance and ensure that your data remains protected under terms no less protective than this Privacy Policy.

07

International Data Transfers

White Rabbit is incorporated in Hong Kong, and your personal data may be stored and processed in Hong Kong or in other countries where our service providers operate. By using the Service, you acknowledge that your data may be transferred to and processed in countries outside your country of residence, which may have different data protection laws.

Safeguards for EEA / UK Users

When transferring personal data from the EEA or UK to countries not recognized as providing an adequate level of protection (including Hong Kong at present), we rely on appropriate transfer mechanisms such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • The UK International Data Transfer Agreement (IDTA) where applicable;
  • Other legally recognized safeguards under GDPR Chapter V.

Hong Kong Data Export

Under the PDPO, we take all practicable steps to ensure that personal data transferred outside Hong Kong is protected to a standard at least comparable to that provided under Hong Kong law, in accordance with Data Protection Principle 3.

You may request details of the safeguards applicable to any specific international transfer by contacting us at the address in Section 15.

08

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by law.

  • Active accounts: Data is retained for the duration of your account.
  • Deleted accounts: We delete or anonymize personal data within 90 days of account deletion, except for data we are legally required to retain (e.g., financial records and invoices, which are kept for 7 years in accordance with applicable commercial and tax regulations).
  • Support communications: Retained for up to 3 years to resolve future disputes.
  • Analytics data: Aggregated and anonymized after 24 months.

When personal data is no longer needed, we securely delete or anonymize it.

09

Security

We take the security of your personal data seriously and implement appropriate technical and organizational measures to protect it against unauthorized access, loss, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS/HTTPS) and at rest;
  • Secure password hashing using industry-standard algorithms;
  • Access controls and role-based permissions within our team;
  • Regular security reviews and vulnerability assessments;
  • Incident response procedures and breach notification protocols.

No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.

10

Cookies & Tracking Technologies

We use cookies and similar tracking technologies to operate and improve the Service. Cookies are small text files stored on your device.

TypePurposeCan be disabled?
Strictly necessarySession management, authentication, securityNo โ€” required for the Service to function
FunctionalRemembering your preferences and settingsYes
AnalyticsUnderstanding how users interact with the ServiceYes
MarketingMeasuring the effectiveness of our campaignsYes โ€” requires your consent

You can manage cookie preferences through our cookie consent banner or through your browser settings. Please note that disabling certain cookies may affect the functionality of the Service.

11

Your Rights

Depending on your location, you have specific rights regarding your personal data. We honor these rights for all users globally, in accordance with GDPR (EEA/UK), CCPA (California), PDPO (Hong Kong), and comparable international frameworks.

๐Ÿ‘

Right of Access

Request a copy of the personal data we hold about you.

โœ๏ธ

Right to Rectification

Request correction of inaccurate or incomplete data.

๐Ÿ—‘

Right to Erasure

Request deletion of your personal data ("right to be forgotten").

โธ

Right to Restriction

Request that we limit how we process your data in certain circumstances.

๐Ÿ“ฆ

Right to Portability

Receive your data in a structured, machine-readable format.

๐Ÿšซ

Right to Object

Object to processing based on legitimate interests or for direct marketing.

๐Ÿค–

Automated Decisions

Not to be subject to solely automated decisions with significant effects.

โ†ฉ๏ธ

Withdraw Consent

Withdraw consent at any time where processing is based on consent.

California Residents (CCPA / CPRA)

You additionally have the right to know what categories of personal information we collect and how they are used, to opt out of any sale or sharing of your personal information (we do not sell personal information), and to non-discrimination for exercising your privacy rights.

How to Exercise Your Rights

To submit a request, email us at [email protected] with "Data Subject Request" in the subject line. We will respond within 30 days (or sooner where required by local law). We may need to verify your identity before processing your request.

Right to Lodge a Complaint If you believe we have not handled your personal data lawfully, you may contact the relevant supervisory authority in your jurisdiction. This includes: the Office of the Privacy Commissioner for Personal Data (Hong Kong) at pcpd.org.hk; your national data protection authority within the EU or EEA; or the UK Information Commissioner's Office at ico.org.uk.
12

Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data without parental consent, please contact us immediately at [email protected] and we will take steps to delete such information.

13

Third-Party Links & Integrations

The Service may contain links to third-party websites or integrate with external services. This Privacy Policy applies only to Flyrix. We are not responsible for the privacy practices of third-party sites or services. We encourage you to review the privacy policies of any third parties you interact with through or alongside the Service.

14

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email or by posting a prominent notice on our website, and update the "Effective Date" at the top of this page.

Your continued use of the Service after the updated Privacy Policy takes effect constitutes your acceptance of the changes. If you do not agree, you must stop using the Service.

15

Contact & Data Protection

For any questions, requests, or concerns regarding this Privacy Policy or how we handle your personal data, you may contact us at:

White Rabbit โ€” Privacy Team

Hong Kong ยท We aim to respond to all privacy-related inquiries within 5 business days.

[email protected]

If you wish to exercise a specific data subject right (access, erasure, portability, etc.), please include "Data Subject Request" in the subject line of your email and describe your request clearly so we can handle it promptly.