General Data Protection Regulation (GDPR)
How 20X handles personal data of individuals in the EU and EEA under Regulation (EU) 2016/679.
Controller and processor roles
When customers use 20X to process personal data of their end users, employees, or leads, the customer is the data controller and Setoo Solutions Pvt Ltd (operator of 20X) acts as a data processor. When we process limited data to run our own business (billing, account administration, security telemetry, marketing to prospects), we act as an independent controller for that data.
Lawful bases we rely on
- Contract (Art. 6(1)(b)) - to provide the 20X service to account holders.
- Legitimate interests (Art. 6(1)(f)) - service security, fraud prevention, product analytics, and direct outreach to business prospects, balanced against user rights.
- Consent (Art. 6(1)(a)) - optional cookies, marketing emails to individuals, and any special-category processing customers configure.
- Legal obligation (Art. 6(1)(c)) - tax, accounting, and lawful information requests.
Customers choose their own lawful basis for content they process through 20X and must inform their end users accordingly.
Data-subject rights
Individuals in the EU/EEA can exercise the following rights against a controller: access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making (Art. 15-22).
If your data is processed by 20X on behalf of a customer, contact that customer first - they control the data. If you contact us directly, we will forward the request to the relevant customer and assist them in responding. For data 20X controls itself, email privacy@20x.business. We will respond within one month, extendable by two further months for complex requests (Art. 12(3)).
International transfers
Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses (2021/914) with supplementary measures where required by the Schrems II guidance, and on adequacy decisions where they apply. Customers can request the current list of transfer mechanisms and destination countries by writing to privacy@20x.business.
Security of processing (Art. 32)
- Encryption in transit (TLS) for all customer traffic.
- Role-based access control, least-privilege administration, and audit logs of privileged actions.
- Human-in-the-loop approval gates for sensitive agent actions, configurable per workflow.
- Regular backups and disaster-recovery procedures.
- Vendor review for sub-processors handling personal data.
Retention
Customer content is retained for the duration of the customer agreement and deleted or returned on termination, subject to the timelines set out in the applicable DPA. Account, billing, and security records are retained for the period required by law or by our legitimate interests in defending claims.
Sub-processors and DPA
20X uses vetted sub-processors for cloud hosting, communications, analytics, and AI model inference. For AI replies — including replies sent through a customer’s connected Facebook Page or Instagram account — we use OpenAI and Google Gemini. Under our current API terms those providers do not train their models on 20X customer data.
Production marketing analytics uses Google Tag Manager and Google Analytics 4. Customers processing personal data through 20X can request our current Data Processing Addendum and sub-processor list from privacy@20x.business.
Breach notification
If 20X becomes aware of a personal-data breach affecting customer data, we will notify the affected customer without undue delay so they can meet their 72-hour supervisory-authority notification obligation under Art. 33.
EU representative and complaints
Setoo Solutions Pvt Ltd has not appointed an Art. 27 EU representative or a Data Protection Officer at this time; our processing does not currently meet the thresholds that require one. This will be reviewed as our processing evolves.
Individuals in the EU/EEA have the right to lodge a complaint with their local supervisory authority (Art. 77).