Privacy Policy

Last Updated: August 11, 2026 Version 1.3 — synchronized with MSA dated April 17, 2025

1. Overview

We collect and process personal data to deliver our platform, maintain security, comply with law, and improve service quality. This policy applies to all users and customers worldwide.

We are in our SOC 2 Type I program. We will provide audit reports to enterprise customers under NDA when available.

2. Data We Collect

  • Account: Name, email, company, phone, billing address
  • Authentication: Passwords (hashed/encrypted), API keys, OAuth tokens
  • Connected integrations: Data you authorize us to access from third-party services you connect to Surfaice (for example Gmail and Google Drive). See §7 Google User Data for how we access, use, store, and share Google user data.
  • Usage: API requests, logs, files uploaded, agent actions, performance metrics
  • Analytics (with consent on surfaice.pro): Google Analytics, PostHog, Microsoft Clarity, Reb2b, Leadsy — pages visited, features used, device/browser info
  • Support: Support tickets, emails, chat logs
  • Technical: IP address, User-Agent, cookies, crash logs

We do not intentionally collect SSNs, health data, biometrics, or data from children under 13.

3. Prohibited Data

You will not submit the following categories of data to our platform (as defined in our Master Service Agreement):

  • Patient, medical, or other protected health information (HIPAA-regulated)
  • Credit, debit, bank account, or other financial account numbers
  • Social security numbers, driver's license numbers, or other unique government ID numbers
  • Special categories of data as defined in GDPR (race, ethnicity, religion, biometrics, health, sexual orientation, etc.)
  • Other sensitive personal information as defined by Applicable Data Protection Laws

If Prohibited Data is submitted accidentally, we will delete it within 24 hours of discovery. Contact privacy@surfaice.pro to verify deletion.

4. Feedback, Usage Data & Machine Learning

Feedback: You may provide feedback about our platform. We may use feedback freely without restriction or obligation.

Usage Data: We collect data about how you use our platform (system logs, API calls, feature usage, performance metrics). We may use aggregated, non-identifiable Usage Data to maintain, improve, and enhance our products and services.

Machine Learning & AI Training: Usage Data and Customer Content may be used to develop, train, or enhance artificial intelligence or machine learning models that are part of our products and services. However:

  • Usage Data and Customer Content must be aggregated before use for ML purposes
  • We will use commercially reasonable efforts to de-identify data before ML use
  • These commitments do not reduce our obligations regarding Personal Data under Applicable Data Protection Laws
  • If you do not consent to ML training, you may opt out by contacting privacy@surfaice.pro
  • Exception for Google user data: Information received from Google APIs is subject to the additional limits in §7 Google User Data (including Google's Limited Use requirements) and is not used to train generalized AI/ML models.

AI Accuracy & Limitations: Our platform uses artificial intelligence and machine learning to generate outputs, recommendations, and decisions. AI outputs may be incorrect, inaccurate, or hallucinated. You acknowledge that:

  • AI outputs are suggestions only and should not be relied upon without human review
  • You are responsible for validating all AI-generated data before using it for business purposes
  • AI systems are not a substitute for human judgment and decision-making
  • For decisions affecting individuals, you must conduct human review and provide transparent explanations to affected parties (GDPR Article 22 compliance)

Business Continuity: In the event of our business cessation or inability to maintain the Technology Platform, we will provide you with a mechanism to retrieve any data, configurations, or functionality required to continue using the AI Agents independently, subject to de-identification and confidentiality requirements.

5. Legal Basis

We process data under: contract performance (delivering services), legitimate interests (security, fraud prevention, analytics), legal compliance, and your consent (e.g., marketing).

6. Data Sharing & Third Parties

We do not sell your data. We share data only with:

  • Service providers: LLM providers (e.g., OpenAI, Anthropic), cloud hosts (Google Cloud, AWS, Azure), payment processors, analytics tools—all bound by data processing agreements that prohibit unauthorized training or retention of your data without consent
  • Legal/compliance: Law enforcement, courts, regulators (with valid legal process)
  • Business transfers: Merger, acquisition, or bankruptcy (under confidentiality protections)
  • With your consent: Explicit written approval required

We maintain a subprocessor list at privacy@surfaice.pro. We will notify you of new or changed subprocessors at least 30 days in advance.

7. Google User Data (Gmail & Google Drive)

Surfaice (Surfaice, Inc. / SURFAICE.PRO Inc.) provides an AI agent workspace (Hugo / Surfaice Pro) that can connect to Google services so your agent can work with your email and documents. When you or your organization connect Google to Surfaice, we access Google user data only to provide those integration features. We do not sell Google user data. We do not use Google user data for advertising, including personalized or retargeted ads.

Surfaice's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7.1 What Google data we access

Gmail (user-authorized OAuth connection). When you connect your Gmail account in Surfaice Settings → Integrations, we request access needed to operate your connected mailbox inside the product. Depending on the features your organization enables, this may include:

  • Read: list, search, and read email messages and threads (including subject, headers, body content, labels/folders, and attachment metadata), and download selected attachments when needed for a workflow you request
  • Send: send new messages and replies on your behalf when you request or approve outbound email in the product
  • Modify mailbox state: apply product actions you request such as archive, trash, star/unstar, mark read/unread, move, and add/remove labels
  • Account identity: your Google account email address so we can identify the connected mailbox

Google Drive (organization-authorized connection). When your organization connects Google Drive to Surfaice, we access Drive content authorized for that workspace so the agent can retrieve project and lease documents and related files. This may include:

  • list Shared Drives and folders available to the connected credentials
  • list, search (including full-text search when enabled), and read file/folder metadata
  • download or export file content into your Surfaice workspace so the agent can analyze documents for tasks you request

Google Drive access in Surfaice is used for read and retrieve workflows (browse, search, download/copy into the workspace). We do not use Google Drive access to upload arbitrary files to your Drive on your behalf unless a future feature is expressly disclosed and authorized.

7.2 How we use Google user data

  • To power Surfaice agent features you request: inbox search and triage, thread summarization, drafting and sending email, document discovery, and copying Drive files into your workspace for analysis
  • To maintain and secure the connection (token refresh, connection status, disconnect/reconnect)
  • To provide support, security monitoring, and abuse prevention related to the connected integration

Google user data may be processed by our AI features and LLM subprocessors (for example OpenAI, Anthropic, or Google Cloud model APIs) solely to fulfill your requests in the Service. That processing is part of providing the user-facing Surfaice product, not a separate secondary use.

We do not use Google user data obtained through Google APIs to develop, improve, or train generalized artificial intelligence or machine learning models. This Limited Use restriction for Google API data controls over the broader Machine Learning language in §4.

7.3 How we store and protect Google user data

  • OAuth access and refresh tokens for Gmail are stored encrypted and used only to call Google APIs for your connected account
  • Email content, attachment content, and Drive file content may be temporarily processed and, when you or the agent copy or save them into Surfaice, retained in your customer workspace / Customer Content under the retention rules in §9
  • We apply the security controls described in §10 (encryption in transit and at rest, access control, monitoring, and incident response)
  • Human access to Google user data is limited to cases needed to operate or secure the Service, comply with law, or with your direction (for example support investigations you request)

7.4 Sharing of Google user data

We share Google user data only as needed to provide the Service:

  • Subprocessors that host or process the Service (cloud infrastructure and LLM providers), under data processing agreements
  • Legal/compliance disclosures when required by valid legal process
  • Business transfers subject to confidentiality protections, as described in §6

We do not sell Google user data or share it for advertising. We do not transfer Google user data to other independent applications except as needed to provide or improve user-facing features of Surfaice, with your consent, for security, or to comply with applicable law—consistent with Google's Limited Use requirements.

7.5 Your controls

  • Disconnect Gmail (and other integrations) at any time in Surfaice Settings → Integrations
  • Revoke Surfaice's access in your Google Account at myaccount.google.com/permissions
  • After disconnect or revoke, we deactivate or delete stored OAuth tokens for that connection; content already saved into your Surfaice workspace remains Customer Content until deleted under §9 / §17
  • Request access, deletion, or other privacy rights for personal data via privacy@surfaice.pro (see §11)

8. International Transfers

We operate globally with servers in multiple jurisdictions. Data may be transferred to the US, EU, and other countries. We use Standard Contractual Clauses (SCCs) for EU/EEA transfers and comply with UK Data Protection Act and Swiss Data Protection Act. See our Data Processing Addendum (DPA) for details on transfer mechanisms and safeguards.

9. Data Retention

  • Account data: Duration of subscription + 30 days
  • Billing: 7 years (tax/legal compliance)
  • Support logs: 3 years (dispute resolution)
  • Analytics: 12-24 months
  • Backups: Up to 180 days (disaster recovery)
  • Legal holds: As required by litigation/investigation

Upon your request, we will delete your Customer Content within 60 days, except as required by law or where retention is necessary for legal/compliance reasons.

Data used for analytics and service improvement is anonymized and aggregated so it cannot be traced to you. Anonymized data may be retained indefinitely.

10. Security & SOC 2 Type I

  • Encryption: TLS 1.2+ in transit, AES-256 at rest
  • Key management: Dedicated KMS with role-based access control
  • Access control: Multi-factor authentication (MFA), role-based access (RBAC), audit logging of all data access
  • Data isolation: Multi-tenant architecture with tenant boundaries at database, API, and application layers
  • Monitoring: Firewalls, intrusion detection, DDoS protection
  • Incident response: Documented plan, breach investigation protocol, 72-hour customer notification (or as required by law)
  • Testing: Annual penetration testing, quarterly security assessments, continuous vulnerability scanning
  • Disaster recovery: RTO 4 hours, RPO 1 hour, geographic redundancy, quarterly testing

11. Your Rights

GDPR, CCPA/CPRA, and equivalent laws grant you the right to:

  • Access: Request a copy of your data (30 days)
  • Rectify: Correct inaccurate information (10 days)
  • Erase: Request deletion (30 days, subject to legal exceptions)
  • Portability: Export your data in machine-readable format (30 days)
  • Restrict: Limit how we use your data
  • Object: Opt out of direct marketing, analytics, or AI model improvement
  • Withdraw consent: For optional processing like marketing emails
  • Automated decisions: Right to human review of solely automated decisions that significantly affect you (GDPR Article 22)
  • Cookie/Tracking control: Adjust preferences via our cookie banner, footer links, or browser settings; we honor Global Privacy Control (GPC) signals

To exercise any right, contact privacy@surfaice.pro with your name, email, and request details. We respond within 30 days.

12. California & State Privacy Rights

If you live in California, Virginia, Colorado, Connecticut, or Utah, you have additional rights: right to know, delete, correct, opt out of sales/sharing, and limit use of sensitive personal information. We do not discriminate against you for exercising these rights. We do not sell or share your personal information for cross-context behavioral advertising.

13. Data Processing Agreements & Processor Obligations

If you are located in the EU/EEA or process personal data under GDPR, you act as the "controller" and we act as the "processor" of your data. We will execute a Data Processing Addendum (DPA) with Standard Contractual Clauses (SCCs) within 10 days of this Agreement's Effective Date. The DPA governs our data processing obligations, subprocessor management, customer rights assistance, and audit procedures. For customers outside EU/EEA, equivalent data protection agreements apply where required by local law.

14. Breach Notification

If we become aware of a breach of your personal data or Customer Content, we will:

  • Notify you within 72 hours of discovery (or sooner if required by Applicable Data Protection Laws)
  • Provide details of the breach, including types of data affected, scope, and remedial actions taken
  • Cooperate with your notification obligations to regulators and affected individuals
  • Provide forensic investigation results within 15 days

15. Contact & Complaint

Privacy inquiries: privacy@surfaice.pro

Security concerns: security@surfaice.pro

If you believe we violated your rights, you can file a complaint with your data protection authority:

  • EU/EEA: Your national data protection authority
  • UK: Information Commissioner's Office (ico.org.uk)
  • Switzerland: Federal Data Protection Authority (edoeb.admin.ch)
  • California: California Privacy Protection Agency (cppa.ca.gov)
  • Other US states: Your state Attorney General

16. Updates

We may update this policy. Material changes will be posted here with a new date, and we will notify you by email 30 days in advance. Continued use of our platform indicates acceptance of the updated policy.

17. Term & Data Upon Termination

Upon termination or expiration of your subscription agreement:

  • You will no longer have access to the platform
  • We will facilitate transfer or independent use of AI Agents to minimize disruption to your internal business
  • Upon your written request, we will delete your Customer Content within 60 days
  • Confidential Information will be returned or destroyed within 90 days unless required by law to be retained
  • We will submit a final invoice for all outstanding fees

Effective: August 11, 2026 | Version 1.3 | Synchronized with MSA dated April 17, 2025 | Updated for Google API Services User Data Policy (Gmail & Google Drive)