1. Information We Collect
We collect information directly from you when you register an account, configure support channels, upload knowledge base materials, or communicate with our team.
Account & Profile Data: Full name, business email address, workspace name, encrypted credentials, and billing contact details.
Support & Channel Data: Chat conversation logs, ticket history, end-user feedback, and customer metadata transmitted through our live-chat widget or connected messaging channels.
Knowledge Base Assets: Documentation, support articles, FAQ lists, and file uploads supplied to configure your workspace retrieval index.
Technical & Diagnostic Logs: IP address, browser type, device information, access timestamps, and error traces necessary for platform security and debugging.
2. How We Use Information
We use the collected information exclusively to fulfill our contractual commitments and operate our service:
- To route customer inquiries to assigned autonomous support agents or human operators.
- To generate context-aware conversational replies using your workspace knowledge base.
- To maintain multi-turn conversational memory within customer sessions.
- To monitor system health, detect abuse, and prevent unauthorized account access.
- To process recurring subscription charges and manage billing transactions.
3. AI Processing & Foundation Model Boundaries
Customer conversations are processed through configured large language model providers (including OpenAI, Anthropic, or private inference endpoints selected in your workspace settings).
Zero Training on Customer Data: We enforce strict contractual and API-level data boundaries. Neither LayBuild AI nor our third-party LLM providers use your customer conversations, support tickets, or proprietary knowledge-base materials to train or fine-tune public foundation models. Your data remains strictly isolated to your tenant.
4. Guardrails, PII Redaction & Data Isolation
To protect consumer privacy before data reaches inference models, LayBuild AI incorporates configurable data protection controls:
- Automatic Personally Identifiable Information (PII) redaction: Email addresses, phone numbers, and payment cards can be masked before routing to language models.
- Prompt-injection defense: User inputs are evaluated against guardrail policies to block adversarial prompts.
- Multi-tenant tenant segregation: Workspace data, embeddings, and conversation histories are partitioned at the database layer with strict tenant identifiers.
5. Data Security & Storage
We apply security controls across all storage and computing tiers:
- Encryption in transit: All web and API traffic is encrypted using TLS 1.3.
- Encryption at rest: Database stores, backups, and vector embeddings are encrypted using AES-256.
- Access controls: Administrative access to production databases requires multi-factor authentication, audit logging, and principle-of-least-privilege approval.
- Infrastructure: Our systems are hosted in ISO 27001 and SOC 2 compliant cloud facilities.
6. Subprocessors & Third-Party Service Providers
We partner with specialized third-party infrastructure providers to support our platform operations. All subprocessors are vetted for data protection compliance and bound by written data processing agreements:
- Cloud hosting and databases: AWS, Supabase, Neon (PostgreSQL, vector index).
- Language model inference: OpenAI, Anthropic (API agreements with zero-retention or zero-training terms).
- Payment processing: Stripe, PayU, Razorpay (PCI-DSS Level 1 compliant processors; we never store raw payment card credentials).
- Transactional messaging: Resend, SendGrid (email notifications and invitation delivery).
7. Data Retention & Account Deletion
We retain account data, knowledge-base documents, and conversation logs for as long as your workspace subscription remains active.
Upon account cancellation or formal deletion request, we purge your workspace conversation history, uploaded files, and vector indices from production databases within 30 days. Immutable system backups are overwritten following a 90-day retention cycle. Aggregated, non-identifiable telemetry may be retained strictly for system reliability monitoring.
8. International Data Transfers
If you access the Service from the European Economic Area (EEA), United Kingdom, or Switzerland, your data may be transferred to and processed in countries outside your jurisdiction. Where cross-border transfers occur, we rely on standard contractual clauses approved by the European Commission, UK International Data Transfer Agreements, or equivalent recognized safeguards to ensure appropriate protection.
9. Your Rights & Privacy Choices
Depending on your location (including rights under the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA)), you may exercise the following rights:
- Right to Access: Request a copy of the personal information we hold about you.
- Right to Rectification: Correct inaccurate or incomplete account details.
- Right to Erasure ("Right to Be Forgotten"): Request the deletion of your personal data.
- Right to Restriction & Portability: Receive your conversation data in a structured, machine-readable format or limit processing.
- Right to Opt-Out: We do not sell or share personal information for cross-context behavioral advertising.
To exercise any of these rights, contact us at [email protected].
10. Cookies & Tracking Technologies
We use strictly necessary session cookies to maintain user authentication and security tokens. We also use functional cookies to remember UI preferences (such as dashboard layout settings). We do not deploy third-party advertising cookies or cross-site tracking scripts on authenticated customer workspaces.
11. Security Incident Notification
In the event of a confirmed security incident resulting in unlawful access to, disclosure of, or alteration of personal data, LayBuild AI will notify affected workspace administrators without undue delay, and within 72 hours of becoming aware of the incident, providing details regarding the nature of the event, affected data scope, and remediation measures.
12. Children's Privacy
The Service is intended exclusively for commercial use by organizations and individuals aged 18 and older. We do not knowingly collect or solicit personal data from children under the age of 16. If we become aware that we have collected information from a minor without verified consent, we will promptly delete that data.
13. Changes to This Policy
We may modify this Privacy Policy to reflect updates in our technical architecture, legal obligations, or product features. For material changes, we will provide advance notice via email or a prominent notification within the workspace console. Continued use of the Service following published updates constitutes acknowledgment of the revised terms.
14. Contact & Inquiries
If you have questions, feedback, or concerns regarding this Privacy Policy or our data handling practices, please contact us:
Email: [email protected]
Security & Vulnerability Reports: [email protected]
Address: LayBuild AI Platform, Data Protection Office