Trust, Privacy & Legal Terms
Review the legal agreements, data processing boundaries, and security safeguards that govern the LayBuild AI Customer Support Platform.
Effective as of September 24, 2026
Primary Legal Agreements
Select a document to read our complete terms and operational policies.
Terms of Service
Updated: September 24, 2026
Our customer agreement governing platform access, customer intellectual property ownership, acceptable use guardrails, liability caps, and dispute resolution.
- Customer retains 100% IP ownership of uploaded documents and chats
- Mutual 12-month trailing liability limitation
- Explicit acceptable use and prompt-injection guardrails
- Standard Delaware governing law and dispute procedures
Privacy Policy
Updated: September 24, 2026
Detailed breakdown of how we handle account details, chat transcripts, customer metadata, and technical logs, with zero model training on customer data.
- Zero model training on proprietary customer data or knowledge bases
- Configurable PII redaction prior to language-model routing
- Full GDPR and CCPA privacy rights with 30-day data purging
- 72-hour security incident notification commitment
Cookie Policy
Updated: September 24, 2026
Clear documentation of how we use strictly necessary session tokens, UI preference cookies, and diagnostic telemetry with zero third-party advertising tracking.
- Strictly necessary JWT authentication and CSRF session security
- Zero third-party advertising tracking scripts or behavioral ad pixels
- Transparent retention schedules from session-only to 1 year
- Step-by-step guidance for managing cookies in all major browsers
Cancellation & Refund Policy
Updated: September 24, 2026
Clear, predictable rules for subscription billing cycles, prorated upgrades, self-serve cancellations, and error dispute resolutions.
- Advance monthly and annual billing with no hidden fees
- One-click self-serve cancellation from billing settings
- 14-day dispute notification window for duplicate or erroneous charges
- Immediate prorated billing for mid-cycle tier upgrades
Data Governance & Security Standards
We treat customer privacy and technical security as foundational requirements. Here is how we safeguard your organization’s support conversations and data assets.
Zero Model Training
Your customer interactions and uploaded knowledge bases are strictly isolated. We enforce contractual API boundaries ensuring no customer data is used to train public foundation models.
AES-256-GCM Encryption
Stored API keys, secrets and uploaded knowledge files are encrypted with AES-256-GCM. Web and API traffic is served over HTTPS.
Multi-Tenant Data Isolation
Workspace data, vector indices, and conversation histories are segregated at the database schema level with strict tenant identifiers preventing cross-tenant leakage.
Prompt Injection Defense
Incoming inputs pass through automated guardrail filters and heuristic anomaly detectors to protect your support agents from adversarial prompts and data exfiltration.
Authorized Subprocessors
To provide reliable, high-availability customer support, we utilize vetted third-party infrastructure providers bound by contractual data protection agreements.
| Subprocessor | Service Category | Operational Role | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud Hosting & Storage | Core compute infrastructure, data hosting, and backup management | United States & EU |
| Neon / Supabase | Relational & Vector Database | Serverless PostgreSQL storage and pgvector indexing for workspace retrieval | United States |
| OpenAI / Anthropic | Language Model Inference | Commercial inference APIs governed by zero-training and data protection agreements | United States |
| Stripe / PayU / Razorpay | Payment Processing | Secure PCI-DSS Level 1 payment gateway processing and recurring billing | Global / Regional |
Need a Customized Enterprise DPA or Security Questionnaire?
Email us for a data processing agreement or help with your vendor security questionnaire.