Privacy Policy
Last updated 24 July 2026 · Yoga on C LLC DBA Xyzios
Xyzios is software for fitness and wellness businesses. A customer — the business that holds a Xyzios account — connects the systems it already uses: its booking platform, and optionally its advertising and analytics accounts. Xyzios reads that data to produce analytics, recommendations, and drafted communications for that customer's own staff.
This policy explains what we handle and why. It covers xyzios.com and the Xyzios application at app.xyzios.com.
The short version
- We hold each customer's business data so they can see and act on their own numbers.
- The customer decides what we connect to, and can disconnect or delete at any time.
- We do not sell data. We do not share it with other customers.
- Data sent to AI models is used to answer that customer's request — not to train anyone's model.
- Every message drafted for a member waits for a human at the business to approve it.
Who controls the data
For the member and business data inside a customer's account, the customer is the controller and Xyzios is the processor. The customer decides what data enters the system and what happens to it; we act on the customer's instructions. If you are a member of a business that uses Xyzios and want to know what it holds about you, or want it removed, contact that business directly — they control that record, and we will support them in honouring your request.
For our own account and billing records — the customer's staff logins, our correspondence with them — we are the controller.
What we handle
| Category | Examples | Why |
|---|---|---|
| Customer business data | Locations, class schedules, membership products and prices, revenue and orders, attendance | The analytics and the agents' recommendations are all reads of this |
| Member records | Name, email, phone, membership status and history, purchase history, visit history | Identifying which members are at risk, which payments failed, who to call |
| Staff account data | Name, work email, role and assigned locations, actions taken in the app | Signing in, permissions, and an audit trail of who approved what |
| Connected marketing data | Ad spend and campaign performance, site analytics, business-profile listings — only where a customer connects those accounts | Reporting cost per lead and channel performance alongside revenue |
| Financial records | Bookkeeping exports a customer chooses to upload | Location-level profit and loss reporting |
We do not ask for, and have no use for, member payment card numbers or government identifiers. Payments are handled by the customer's own booking platform, not by us.
Where it comes from
Data reaches us in three ways: the customer connects its booking platform with credentials it controls and can revoke; the customer optionally connects advertising or analytics accounts through a standard authorisation screen; or the customer uploads a file directly. We do not buy data, scrape it, or obtain it from brokers.
Data from connected platforms
Google user data
Where a customer connects a Google account, Xyzios's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google data only to provide and improve the features the customer connected it for — advertising and analytics reporting inside that customer's account.
- We do not transfer Google data to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition.
- We do not use Google data for advertising.
- We do not allow humans to read Google data, except with the customer's explicit permission for a specific purpose, where required for security or to comply with applicable law, or where the data has been aggregated and anonymised.
Meta platform data
Where a customer connects a Meta account, we read advertising and page performance data to report on it inside that customer's account. We use it for no other purpose, and it is deleted along with the rest of the customer's data on the timeline described below and at Data deletion.
AI models
Xyzios uses large language models to draft communications and written analysis. Two things are worth stating plainly, because they are the questions customers actually ask:
- Customer data sent to a model is used to answer that customer's request and nothing else. Our model providers do not train their models on data submitted through their business APIs.
- Nothing a model drafts reaches a member on its own. Every member-facing message is queued for a person at the business to approve, edit, or reject.
Aggregated and anonymised data
We may use data across customers in aggregated, anonymised form to improve the product and to produce industry benchmarks — for example, the average rate at which first-time visitors return. Aggregated data never identifies a customer, a member, or an individual record, and we do not disclose any single customer's figures to anyone else. This matches the commitment in our written agreements with customers.
Who else touches the data
We use a small number of service providers to run Xyzios — cloud hosting and infrastructure, database and storage, AI model providers, transactional email delivery, and error monitoring. They may process customer data only to provide their service to us, under written terms that prohibit using it for anything else.
We keep the current list of these providers up to date and will send it to any customer on request, and will tell existing customers before adding a new one that would handle their data. Ask us at [email protected].
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
Where data is held
Xyzios is operated from the United States and customer data is stored there. If you connect from elsewhere, you are asking us to process the data in the US.
How long we keep it
We hold a customer's data for as long as its account is active. When an account closes, we delete customer and member data within 30 days, except where we must keep a record to comply with law — invoices and tax records, typically. Backups roll off on their own schedule and are purged within 90 days. Full detail, and how to ask for deletion sooner, is at Data deletion.
Security
Credentials are encrypted, access is scoped by role, and each customer's data is isolated at the database level so one customer cannot read another's. We describe this in more detail on the Security page.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal data, and to object to some processing. If you are a member at a business that uses Xyzios, start with that business — they hold the relationship and the record. If you are a Xyzios customer, write to us at [email protected] and we will respond within 30 days. You will never be charged or given a worse service for exercising these rights.
Children
Xyzios is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 13. Where a customer's own records include a minor, that data is the customer's to manage under its own policies.
Changes
If we change this policy in a way that materially affects how we handle customer data, we will tell account holders by email before it takes effect, not just by editing this page.
Contact
Yoga on C LLC DBA Xyzios
[email protected]