Legal
Privacy Policy
Last updated: September 3, 2026
Two kinds of data pass through faberiq: information about you and your business as our customer, and the conversations the front desk handles with your customers on your behalf. Different rules apply to each. This policy covers both, in plain language, and it is the data-processing agreement that our Terms and Conditions refer to.
Contents
- Who we are and who this covers
- What we collect
- How we use it
- How the AI processes conversations
- Who we share it with
- Where it is stored and transferred
- How long we keep it
- How we protect it
- Your rights
- If you are a customer of a business that uses faberiq
- Our role as your processor
- Cookies and similar technologies
- Children
- Changes to this policy
- Contact
1. Who we are and who this covers
faberiq is based in Ontario, Canada. We provide an AI front office for service businesses: it answers customer messages on connected channels, books appointments, and requests payments, and it lets agencies run the same thing for their clients under their own brand. Our privacy contact is hello@faberiq.ai.
This policy applies to three groups of people, and it helps to know which one you are:
- Visitors to faberiq.ai and our other public sites. We collect very little from you.
- Customers: the businesses and agencies that hold a faberiq account, and the people who use it on their behalf. For your account data, we decide how and why it is processed, so we are the “controller”.
- Contacts: the customers, leads and appointment holders of our Customers, whose messages the front desk handles. For your data, the business you are talking to is the controller and we are its service provider or “processor”. Section 10 is written for you.
2. What we collect
Information you give us. When you create an account we collect your name, email address, business name and details, and a password or a link to your Google sign-in. As you set up the service you add configuration: price lists, policies, opening hours, documents and knowledge, workflow rules, branding, and team members' names and emails. When you subscribe, our billing provider collects your payment details; we receive your plan, billing status and the last four digits and expiry of your card, never the full number. When you write to us for support, we keep the correspondence.
Information from connected services. When you connect a channel or tool, we receive the data needed to run the features you enable: for a messaging channel, the messages, sender identifiers and profile names; for a calendar, availability and appointments; for a payment provider, invoices, deposit status and transaction identifiers; for a phone number, call metadata and, if you enable it, voicemail transcripts. We store the access tokens those services issue so we can act on your behalf, encrypted at rest.
Contact Data. On behalf of our Customers we process the content of conversations with their Contacts, the Contacts' names and handles, phone numbers and email addresses, appointment details, service history, and payment records such as a deposit paid or an invoice outstanding. We also generate records about each conversation: the AI's reasoning steps, tools it invoked, handoffs to a human, and outcome.
Information collected automatically. When you use the studio we log the IP address, browser and device type, pages and actions, timestamps, and errors, for security and to keep the product working. Our public website does not run advertising trackers or third-party analytics; the web server keeps standard access logs for a short period.
We do not ask for, and ask you not to store in the service, more sensitive information than a business needs to book and serve an appointment. If your trade legitimately requires more, such as a clinic that records treatment notes, tell us so that we can confirm the right terms are in place.
3. How we use it
We use account data and Contact Data to:
- provide the service: receive messages, generate responses, book appointments, request payments, run workflows, and show you the results;
- keep a complete, replayable record of every conversation so you can supervise, audit and improve the front desk (this is a core feature, not an incidental log);
- authenticate users, secure the service, detect abuse and fraud, and enforce our terms and the rules of connected channels, including opt-out handling;
- bill you, and send transactional messages about your account such as receipts, security alerts and service changes;
- provide support and respond to your requests;
- understand how the product is used, diagnose problems, and improve it, using aggregated or de-identified data wherever that is possible;
- send you product news and offers if you are a Customer, which you can opt out of at any time from the message itself or by writing to us;
- comply with legal obligations and protect our rights and those of our Customers and Contacts.
Where a legal basis is required, we rely on the performance of our contract with you, our legitimate interests in running and securing the service, your consent for optional matters such as marketing email, and legal obligations such as tax and accounting rules. We do not sell personal information, do not share it for cross-context behavioural advertising, and do not use Contact Data to train AI models.
4. How the AI processes conversations
To answer a message, the service sends the relevant parts of a conversation, together with the configuration and knowledge you have provided, to a large language model. By default that is a model provided by Google (Gemini), accessed under commercial terms that prohibit the provider from using the content to train its models and that limit its retention to what is needed to provide the API and enforce abuse policies. Customers can instead configure their own model provider, including Google Cloud Vertex AI, Anthropic, OpenAI, Microsoft Azure, Amazon Bedrock and OpenAI-compatible hosts; in that case the content goes to the provider you chose under your agreement with it.
To make your documents searchable by the agent, we convert them into numerical embeddings using an embedding model and store those in our vector database. Embeddings are derived data that stay in our infrastructure and are deleted with the source document.
The AI acts only within the permissions and guardrails you configure. Every automated decision, such as offering a slot or requesting a deposit, is recorded and can be reviewed and reversed by a person on your team. Contacts can ask for a human at any time and the conversation is handed to you.
5. Who we share it with
We share personal data only with the categories of service providers below, only to the extent needed to run the service, and under contracts that require them to protect it and use it only on our instructions. We will update this list before adding a new category of subprocessor and, for Customers who ask to be notified, give at least thirty days' notice.
| Purpose | Provider | Location | What they receive |
|---|---|---|---|
| Cloud hosting, databases, storage | Amazon Web Services | United States | All service data, encrypted at rest |
| Sign-in and identity | Amazon Cognito (AWS) | United States | Account email, name, hashed credentials, sign-in events |
| AI responses (default) | Google (Gemini API) | United States | Conversation content and configuration needed to respond; no training |
| AI responses (bring your own) | Provider you configure | Per your provider | Same as above, under your agreement |
| Subscription billing | Stripe | United States | Your billing name, email, payment method, plan |
| Messaging, calendar, payment and business channels you connect | Meta (Instagram, WhatsApp, Messenger), Twilio, Telegram, Google, Microsoft, Stripe, Square, Calendly, Shopify and others you choose | Per provider | Messages and records exchanged through that channel, under the provider's own policy |
| Transactional email | Amazon SES (AWS) | United States | Recipient address and message content |
Beyond service providers, we disclose personal data only: to an agency that manages your workspace under our agency programme, because they act for you; to a successor if we sell or merge the business, with notice to you; to professional advisers under confidentiality; and when the law requires it, in response to a valid legal process, or to protect the safety of a person or the security of the service. Where we are legally permitted, we will tell you about a request for your data before we respond to it.
6. Where it is stored and transferred
The service runs on Amazon Web Services in the United States. If you are in Canada, the European Economic Area, the United Kingdom, or elsewhere, your data is transferred to and processed in the United States and in the countries where the connected services you choose operate. Where the law requires a transfer mechanism we rely on the provider's standard contractual clauses or an equivalent recognised safeguard, and we contractually require our subprocessors to do the same. Canadian Customers should note that data stored outside Canada may be subject to the laws of the country in which it is held.
7. How long we keep it
- Account and configuration data: for as long as your account is open.
- Conversations and Contact Data: for as long as your account is open, because replay and audit of every conversation is part of the product. You can delete individual Contacts and conversations at any time from the studio, and we will delete them from live systems within thirty days.
- After you close your account: your data stays available for export for thirty days, is then deleted from live systems within a further thirty days, and ages out of encrypted backups on a rolling schedule of at most ninety days after that.
- Trial workspaces that never convert are deleted ninety days after the trial ends.
- Billing and tax records: seven years, as Canadian law requires.
- Security and access logs: up to twelve months.
- Website server logs: thirty days.
- Support correspondence: three years after the case closes.
8. How we protect it
Data is encrypted in transit with TLS and at rest with provider-managed encryption. Access to production systems is limited to the small number of people who need it, protected by multi-factor authentication, and logged. Connected-service credentials are stored encrypted and are never shown back in full. Every business's data is separated by tenant in our databases and every request is checked against the tenant it belongs to. We test changes against replays of real conversations before releasing them, and we design the agent to hand off rather than guess when it lacks permission or information.
No system is perfectly secure. If we discover a breach that affects your data we will notify you without undue delay, and within seventy-two hours where the law requires, with what we know and what we are doing about it, so that you can meet your own obligations to your Contacts and regulators. Report security concerns to hello@faberiq.ai.
9. Your rights
Wherever you are, you can ask us to tell you what personal data we hold about you, correct it, delete it, give you a copy in a portable format, stop using it for marketing, or restrict or object to particular processing. Customers can do most of this themselves in the studio; for anything else, write to hello@faberiq.ai. We will verify your identity, respond within thirty days, and tell you if we need longer or if a legal exception applies. We never discriminate against you for exercising a right.
Canada. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial law. You can complain to the Office of the Privacy Commissioner of Canada, but we ask that you write to us first; we fix things faster.
European Economic Area and United Kingdom. The rights above are those under the GDPR and UK GDPR, including the right to withdraw consent where we rely on it and the right to lodge a complaint with your local supervisory authority. Our legal bases are described in section 3.
California and other U.S. states. Residents of states with comprehensive privacy laws have the rights to know, delete, correct and port their data and to opt out of sale, sharing and targeted advertising. We do not sell or share personal information for advertising and we have not done so in the preceding twelve months. You can use an authorised agent to make a request; we will verify the agent's authority.
10. If you are a customer of a business that uses faberiq
If you messaged a business, booked an appointment or paid a deposit and the conversation was handled by faberiq, the business you dealt with is responsible for your data, and its privacy policy applies to how it is collected and used. We process your messages, contact details and booking and payment records only on that business's instructions, to run its front desk. We do not use your information for our own marketing, do not sell it, and do not use it to train AI models. Card details you enter go directly to the business's payment provider and never reach us.
To access, correct or delete your information, contact the business you dealt with; they have the tools to do so in the product and we will act on their instruction. If you cannot reach them, or you believe we hold your data in a way they did not authorise, write to hello@faberiq.ai and we will help. You can stop automated messages on any channel by replying STOP or using the channel's own block or unsubscribe function, and you can ask for a person at any point in the conversation.
11. Our role as your processor
For Contact Data, this section is the data-processing agreement between faberiq and each Customer, and it applies whenever data-protection law requires one. We will: process Contact Data only on your documented instructions, which include the configuration you set and the features you enable; ensure the people who access it are bound by confidentiality; apply the security measures in section 8; use only the subprocessors listed in section 5, remain responsible for them, and let you object to a new one with thirty days' notice, in which case you may terminate without penalty; help you respond to Contacts' requests and to your obligations on security, breach notification and impact assessments, taking into account the nature of the processing; delete or return Contact Data at the end of the service as described in section 7; and make available the information needed to demonstrate compliance, and allow audits by you or an auditor you appoint, on reasonable notice and no more than once a year unless a regulator requires otherwise or a breach has occurred. If we believe an instruction breaks the law, we will tell you. Customers established in the EEA or UK may request our standard data-processing addendum incorporating the applicable standard contractual clauses by emailing us.
12. Cookies and similar technologies
Our public website sets no cookies and loads no third-party trackers or analytics; fonts, images and scripts are served from our own domain. The studio and customer portals use strictly necessary cookies and browser storage to keep you signed in, protect against cross-site request forgery, and remember interface preferences such as a selected workspace. These cannot be switched off without breaking sign-in, and they do not track you across other sites. If we ever add analytics, we will describe it here and ask for consent where the law requires.
13. Children
The service is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16 as a Customer. Businesses that serve minors, such as a barber booking a child's haircut through a parent, are responsible for handling any such data lawfully. If you believe we hold a child's data without appropriate authority, write to us and we will delete it.
14. Changes to this policy
We will update this policy as the service and the law change. The date at the top tells you when it was last revised. For material changes, such as a new category of data, a new purpose, or a new category of subprocessor, we will notify Customers by email at least thirty days before the change takes effect. Earlier versions are available on request.
15. Contact
Write to hello@faberiq.ai for anything to do with privacy, including rights requests, subprocessor notifications, data-processing addenda, and security reports. We are based in Ontario, Canada; our postal address is available on request for formal notices. If you are in a jurisdiction with a privacy regulator you also have the right to complain to it, but write to us first; we fix things faster.