Privacy Policy
Effective Date: May 28, 2026
This Privacy Policy explains how Farfatech Inc. ("we", "our", or "us") collects, uses, discloses, and protects personal information when you use our AI SaaS platform (the "Service"). This policy applies to all users of our Service, including business customers and their authorized representatives.
By using the Service, you agree to the collection, use, and disclosure of your personal information as described in this Privacy Policy. If you do not agree with this policy, please do not use the Service.
Identity and Contact Information
- Controller: Farfatech Inc.
- Contact: [email protected]
For any privacy-related questions, requests, or complaints, please contact us at the email above.
Purposes of Processing and Legal Basis
We process personal information for the following purposes, based on the legal bases outlined below:
| Purpose | Legal Basis | Description |
|---|---|---|
| Service Delivery | Contract | Processing necessary to provide the Service, including executing customer contracts. |
| PAF Topic Filtering | Consent | Optional feature allowing customers to improve their AI models using their prompts. |
| Analytics and Improvement | Legitimate Interest | Analyzing usage patterns to improve the Service, ensure security, and optimize performance. |
| Billing and Payments | Legal Obligation | Processing necessary to comply with tax, accounting, and financial regulations. |
Categories of Personal Information Collected
We collect the following categories of personal information:
Account and Organization Information:
- Name
- Email address
- Organization name
- Identity provider details — when using Login with GitHub, Google, or Microsoft, we collect the identifier and profile information returned by that provider
PAF:
- Prompts submitted to the prompt application firewall (PAF)
Usage and Analytics Data:
- Metadata about your interactions
- IP addresses
- Location
- Browser type
- Device information
- Timestamps
- Usage patterns via PostHog
Billing and Payment Information:
- Payment details
- Invoicing information
- Tax Id
- Transaction history
Payment processing is handled by Stripe, Inc. Farfatech does not collect or store full credit card numbers. See the Third-Party Recipients and Subprocessors section for details on Stripe's data handling.
Third-Party Recipients and Subprocessors
We may share personal information with the following third-party service providers to support the operation of the Service:
| Subprocessor | Jurisdiction | Purpose | Data Shared |
|---|---|---|---|
| PostHog | USA | Analytics and usage tracking | Usage and analytics data (e.g., IP addresses, device information, interaction metadata). |
| Cloudflare | USA | Network, CDN and Security | IP addresses, browser information, and metadata to protect against malicious traffic. |
| Cloudflare R2 | USA | Database backups | Backups containing account information, prompts, AI responses, usage data, and billing information. |
| GitHub | USA | Authentication (Login with GitHub) | OAuth profile information (identifier, name, email) returned by the provider. |
| USA | Authentication (Login with Google) | OAuth profile information (identifier, name, email) returned by the provider. | |
| Microsoft | USA | Authentication (Login with Microsoft) | OAuth profile information (identifier, name, email) returned by the provider. |
| Email login | Canada | Authentication (Login with Email) | Email address (to send and verify a one-time login code). No password is stored. Codes expire after 15 minutes. |
| Proton Mail | Switzerland | Email delivery (SMTP) | Email addresses and email content for transactional messages (e.g., notifications, login codes, password resets). |
| Stripe, Inc. | USA | Payment processing | Billing and payment information (e.g., name, email, billing address, payment details, transaction history). Full credit card numbers are not stored by Farfatech and are processed directly by Stripe. |
We ensure that all subprocessors comply with applicable data protection laws and enter into data processing agreements to safeguard your personal information.
Cross-Border Data Transfers
Our Service operates globally, and your personal information may be transferred to, stored, and processed in the following jurisdictions:
- Canada: Hosting and infrastructure (operated by Farfatech) — account information, prompts, AI responses, usage data, and billing information are stored and processed in Canada.
- Switzerland: Email delivery (Proton Mail).
- United States: Analytics (PostHog), Network, CDN, Security, and backups (Cloudflare), authentication (GitHub, Google, Microsoft), and payment processing (Stripe).
Retention Periods
We retain personal information for the following periods:
| Category | Retention Period |
|---|---|
| Prompts and AI Responses | 30 days by default, customizable |
| Account and Organization Information | Duration of the customer contract + 1 year for compliance and record-keeping purposes. |
| Billing and Payment Information | 7 years to comply with tax and financial regulations. |
| Usage and Analytics Data | 12 months rolling, unless otherwise required for security or legal compliance. |
Personal information is securely deleted or anonymized when no longer needed for the purposes outlined in this policy.
PAF Topic Filtering Feature
The PAF Topic Filtering feature allows customers to improve their AI models by training isolated topic classifiers using their prompts and responses. This feature is entirely optional and subject to the following terms:
- Per-Customer Isolation: Trained topic classifiers are isolated to each customer and are never shared, sold, or used by other customers or third parties.
- Opt-In Consent: This feature requires separate, explicit opt-in consent You may enable or disable it at any time in your account settings.
- Commercial Purpose: This feature is used for commercial purposes to improve the Service for your organization.
Automated Processing
Our Service uses AI technologies to process prompts and generate responses. Here's what you should know:
- Prompt Application Firewall (PAF): Prompts are analyzed by AI models to filter, classify, and generate responses. This processing is ephemeral — prompts are not stored beyond the duration of the request.
- Attack Data and Training: When the Service detects a successful attack vector, the anonymized data may be added to our training data to improve detection. Whether this is opt-in or opt-out depends on your service agreement.
Your Rights
To exercise any rights, depending on your jurisdiction, please contact us at [email protected]. We will respond to your request within the timeframes required by applicable law.
Security Measures
We implement the following security measures to protect your personal information:
- Encryption: Data is encrypted in transit using TLS and at rest using industry-standard encryption protocols. This applies to all Customer data on Farfatech-operated hosting infrastructure in Canada, as well as data in transit to and from subprocessors.
- Access Controls: Access to personal information is restricted to authorized personnel and subprocessors on a need-to-know basis.
- Organization Roles: Access to personal information within your organization is controlled through role-based permissions. Administrators can manage members, roles, and organization settings; users have limited access to sensitive data.
- Infrastructure Security: We use secure cloud infrastructure with regular security audits, and vulnerability scanning.
- Data Minimization: We collect and retain only the personal information necessary for the purposes outlined in this policy.
Breach Notification
In the event of a data breach involving your personal information, we will notify the relevant data protection authority based on your jurisdiction within 72 hours.
CCPA/CPRA-Specific Disclosures
This section applies to residents of California under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
- Categories of Personal Information Collected (Past 12 Months): Account and organization information, prompts and AI responses, usage and analytics data, and billing and payment information.
- Sale or Sharing of Personal Information: We do not sell or share personal information with third parties. The PAF Topic Filtering feature uses prompts to train isolated, per-customer classifiers and does not involve sharing or selling data.
- Your Rights Under CCPA/CPRA:
- Right to Know: Request access to the personal information we hold about you.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Non-Discrimination: You will not be discriminated against for exercising your CCPA rights.
To exercise your CCPA rights, please contact us at [email protected]
Technology Collecting Personal Information
The Service collects and process personal information, including prompts and usage data. This technology is deployed to:
- Improve the Service ability to detect attack.
- Analyze usage patterns to improve the Service.
- Train isolated topic classifiers for the PAF Topic Filtering feature.
This disclosure is made before the technology is deployed, as required by law.
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Service offerings. We will notify you of material changes by:
- Posting the updated policy on our website with a new effective date.
- Sending an email notification to the account administrator.
Your continued use of the Service after the updated policy takes effect constitutes your acceptance of the changes.