Privacy and AI governance at 20X
20X is built and operated by Setoo Solutions Pvt Ltd. This section explains how we approach data protection and responsible AI across the jurisdictions where our customers operate.
What's covered
Three regulatory frameworks shape how we handle personal data and AI on the 20X platform:
- GDPR - the EU/EEA General Data Protection Regulation (2016/679), covering personal data of individuals in the EU and EEA.
- India DPDP Act - the Digital Personal Data Protection Act, 2023, covering digital personal data processed in India.
- EU AI Act - Regulation (EU) 2024/1689, covering how AI systems are provided and used in the EU.
- Data deletion - public instructions for deleting Facebook and Instagram data held by 20X, including for end customers.
Our role
For customer content processed on 20X, customers are the data controller (or Data Fiduciary under India's DPDP Act) and 20X acts as a processor (or Data Processor) on their behalf, under the applicable customer agreement and data processing addendum.
Under the EU AI Act, Setoo Solutions Pvt Ltd is a provider of the 20X AI system. Customers who deploy 20X inside their own operations act as deployers and are responsible for their configuration, prompts, and use.
Shared responsibility
20X provides platform-level controls: access management, role-based permissions, audit logs, human-in-the-loop approval gates, encryption in transit, and configurable retention. Customers are responsible for choosing lawful bases, informing their end users, configuring their agents and workflows, managing user access, and honouring data-subject or data-principal requests they receive.
Contact
Privacy or compliance questions: privacy@20x.business.