Privacy policy.
How Dexor handles personal data across the marketing site and the platform.
Plain-language policy
This page describes, in plain language, how we actually handle data today. It is reviewed by counsel. Where a signed order form or a market-specific addendum applies, that agreement governs.
Last updated: July 2026. This policy is operated by [Dexor legal entity], referred to here as "Dexor", "we", or "us". If you have a question about your data, write to hello@dexor.app.
Who we are and the two roles we play
Dexor is a business-to-business platform for consumer goods and distribution companies. Our customers use it to run field sales teams and to collect secondary sales data from their distributors.
We handle personal data in two different roles. For the marketing site and for our own account records, we decide how and why data is used, so we are the controller. For the data that lives inside a customer's workspace, the customer decides how it is used and we process it on their instructions, so we are the processor and the customer is the controller. If you are an employee or a distributor of one of our customers and you have a question about your workspace data, please contact that company; we will support them in answering you.
What the marketing site collects
This site runs a privacy-light page-view counter. It uses no third-party advertising pixels and no cross-site trackers, and we do not sell data to anyone. When you submit a form, such as a quote request or a contact enquiry, we collect what you type, which is usually your name, work email, company, and any figures you choose to share. A person reads it and replies. We do not run drip campaigns or automated marketing sequences off these forms.
What the platform processes
Inside the product we process the data a customer puts into their workspace. Depending on how that customer configures Dexor, this can include user accounts and roles, sales and order records, distributor and outlet records, visit and attendance records, and, where the customer turns it on, field location data and visit photos.
Two points matter for anyone whose data sits in a workspace:
- Location is consent based. A company can set location mode to off, mandatory, or opt-in. A field rep who declines consent under opt-in is not GPS tracked. Route points carry a retention window and are removed after it passes.
- Access is scoped and recorded. Every request reaches storage through a single tenant boundary bound to the signed-in user, so one company cannot read another company's data. Sensitive actions, including reads of personal data, are written to a tamper-evident audit trail.
How our AI uses data
The assistant and the automated insights work from aggregate figures inside the signed-in user's own part of the organisation. Scope comes from the login token, not from anything a user can type, so the assistant cannot read outside that boundary. Prompts sent to the model carry aggregate figures, not raw personal records. The AI tier can be switched off for a workspace without affecting the core product.
We send transactional email only, such as account and workflow messages to users, and replies to people who contact us. We do not send marketing bulk email and we do not email purchased lists. Distributors can email a sales file to an address their company publishes to them; our system reads the file and replies once to the same sender to confirm the rows loaded or to list the errors found. If an address hard-bounces or reports a complaint, we stop sending to it.
Where data is stored
Dexor runs on Amazon Web Services. Our primary hosting region is Singapore (ap-southeast-1). If you are in Pakistan or elsewhere, your data may be processed outside your country on AWS infrastructure. We rely on AWS security controls, encryption in transit and at rest, and point-in-time backups, and we keep access inside the boundaries described above.
How long we keep data
Marketing enquiries are kept for as long as we need them to answer you and for a reasonable follow-up period. Workspace data is kept for as long as the customer's agreement runs, and is handled on their instructions after that. Field location retention windows are set per customer.
Your choices and rights
You can ask us to show you the personal data we hold about you as a controller, to correct it, or to delete it, subject to any legal record-keeping we must follow. For data inside a customer workspace, please raise the request with that company, since they control it; we will help them act on it. To reach us, write to hello@dexor.app.
Security
Isolation, separated identity pools, a fail-closed audit trail, and consent-based field privacy are described on our security page. If you believe you have found a security issue, please contact us so we can look into it.
Children
Dexor is a workplace tool for business use. It is not intended for children, and we do not knowingly collect data from them.
Changes to this policy
We update this page when our practices change and we move the date at the top. Please check back from time to time.
Governing law and contact
This policy is governed by the laws of Pakistan, including the Prevention of Electronic Crimes Act 2016 and applicable data protection law as it comes into force. For any privacy question, write to hello@dexor.app or to [Dexor registered address].