This Privacy Policy explains how Ben Hadad, ID 300107661, trading as "AssistantLabs" ("we", "us", "our"), collects, uses, stores, shares and protects personal data when you use our cloud-based AI assistant platform (the "Service"). The Service enables businesses to build and operate AI-powered assistants across WhatsApp Business, Instagram Direct, Facebook Messenger, website chat and LinkedIn, with an in-app inbox, CRM, analytics and optional integrations. Customers may also connect an external AI assistant, such as Claude, to their workspace through our optional MCP connectors.
We are committed to protecting your privacy and to complying with the Israeli Privacy Protection Law, 5741-1981, the EU General Data Protection Regulation (GDPR) where applicable, and other relevant data-protection legislation.
The controller for account, billing and platform data processed through the Service is:
Ben Hadad / AssistantLabs
Address: Ha'Aniya Arinpura 8, Netanya, Israel
Email: legal@assistantlabs.io
When a Customer (a business) uses AssistantLabs to interact with its own end-users, the Customer is the data controller for end-user personal data and AssistantLabs acts as the data processor on the Customer's behalf, processing that data only on the Customer's documented instructions and to provide the Service.
We collect and process the following categories of personal data:
| Field | Description |
|---|---|
| id | Unique user identifier |
| displayName | User's display name |
| Email address | |
| lastLoginAt | Timestamp of last login |
| profilePicture | Profile photo URL (optional) |
| settings.language | Preferred language |
| Field | Description |
|---|---|
| cardHolderName | Name on credit card |
| cardHolderId | ID document number of cardholder (Israeli invoicing requirement) |
| cardType | Card brand (Visa, Mastercard, etc.) |
| lastFourDigits | Last 4 digits of card number |
| expMonth / expYear | Card expiration date |
| token | Tokenized card reference (no full card numbers stored by us) |
| businessName | Company or business name for invoicing |
| businessId | Israeli business ID or personal ID for tax |
| receiptEmail | Email for receipts and invoices |
| Standing order & usage records | Subscription and usage-charge history for billing |
Business information, FAQs, product catalogs, links, guidelines, scenarios, persona settings and other content that Customers provide (directly or via the Logos AI configuration assistant) to configure their AI assistants. Customers may also import content by allowing us to scan a website they provide.
| Field | Description |
|---|---|
| firstName / lastName | Contact name |
| phone | Phone number |
| Email address | |
| notes | Free-form notes about the contact |
| customFields | Custom key-value data |
| labels | Categorization labels |
| source | Origin channel (WhatsApp, Instagram, Messenger, Web, LinkedIn, Wix, Monday.com, Shopify, WooCommerce, import, manual or API) |
| consentStatus | Data-processing consent (granted, denied, pending, unknown) |
| marketingConsent / optedOut | Opt-in status and opt-out flag/timestamp for marketing communications |
| External IDs & synced orders | Identifiers and order data from connected integrations (e.g., wixContactId, mondayItemId, WooCommerce/Shopify customer or order records) |
Messages exchanged between end-users, AI assistants and the Customer's human agents, including text and media content, timestamps, message direction, sender type, read/reaction status, channel metadata and platform message identifiers.
Conversation counts, automated-vs-human classification, message volumes, response metrics, session data, IP addresses, browser type, device information and usage patterns, collected through Firebase Analytics and exported to BigQuery in aggregated form for analytics and billing.
| Legal Basis | Processing Activity |
|---|---|
| Performance of contract | Providing the Service, processing payments, managing accounts, delivering AI assistant functionality |
| Legitimate interest | Service improvement (using aggregated/de-identified data), analytics, security monitoring, fraud prevention, debugging |
| Consent | Marketing communications, optional analytics, cookie placement |
| Legal obligation | Tax record keeping, responding to lawful government requests, maintaining billing records |
We do not sell or rent personal data, and we do not use identifiable Customer Content or end-user conversations to train or fine-tune general-purpose AI models. Only aggregated and anonymized data is used to improve the Service.
We share personal data with the following sub-processors, strictly as necessary to provide the Service. Integration providers receive data only when the Customer connects the relevant integration.
| Sub-Processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform (GCP) | Cloud infrastructure, Firestore database, Cloud Run, BigQuery analytics, Cloud Tasks, storage | Iowa, USA |
| Firebase (Google) | Authentication, hosting, analytics, Cloud Functions | USA |
| OpenAI | AI language-model processing for assistant responses | USA |
| Anthropic | AI language-model processing for the Logos configuration assistant | USA |
| Google (Gemini / Generative AI) | AI language-model processing | USA |
| Meta Platforms Ireland Ltd | WhatsApp Cloud API, Instagram Messaging API, Messenger Platform | Ireland / USA |
| Meta Platforms Ireland Ltd (Meta Pixel) | Measurement and advertising analytics on our own dashboard/marketing web pages (account users only; not applied to end-user conversations). Placed subject to consent where required. | Ireland / USA |
| Resend | Delivery of transactional and outreach email (account notifications, onboarding and support mail) | USA |
| Google (Gmail API) | Delivery of organisation notification email where the Customer connects a Gmail account | USA |
| Flashy | WhatsApp template / marketing-message delivery (when used) | Israel |
| Tranzila (InterSpace Ltd) | Payment processing, credit-card tokenization, standing orders | Israel |
| Customer-enabled integrations | Wix, Monday.com, Shopify, WooCommerce, Fireberry, Calendly, Google Calendar/Sheets — contact, order, scheduling and CRM synchronization | Varies by provider |
A current sub-processor list is available on request at legal@assistantlabs.io.
An external AI assistant that a Customer connects through an MCP connector is not a sub-processor: it receives data on the Customer's own instruction, under the Customer's own agreement with that AI provider. See the AI Assistant Connectors (MCP) section below.
We publish remote MCP (Model Context Protocol) connectors that let a Customer connect an external AI assistant — such as Claude or ChatGPT — to their own AssistantLabs workspace and then ask it about their business in plain language. Connecting one is optional and entirely Customer-initiated. If a Customer never connects a connector, nothing in this section applies to them.
A single connector address — /mcp — can carry every AssistantLabs product: the assistant and its conversations, the task board, the CRM, Sales and Marketing. Which of them a given connection actually reaches is decided by the permissions the Customer approves, not by the address. A connection approved only for customer replies loads only those tools, and a product the Customer did not approve is never loaded at all. Each product also keeps a dedicated address, for a Customer who prefers to connect one product on its own. Everything is served from https://mcp-server-150134556021.us-central1.run.app.
| Product | Dedicated address | What it can reach |
|---|---|---|
| Assistant & conversations | /mcp — also the combined address (alias /insights/mcp) | Assistant configuration, conversations and their messages, contacts, segments, channels and WhatsApp templates, custom integrations |
| Tasks | /tasks/mcp | The workspace task board — tasks, their contents and views |
| CRM | /crm/mcp | CRM contacts and companies, entity schemas, record page layouts |
| Sales | /sales/mcp | Customer groups, journeys and their audiences, participants, journey statistics, WhatsApp templates |
| Marketing | /marketing/mcp | Marketing channels, posts and performance, strategy, research and product profile |
Each product is resolved independently: approving one does not require approving another, and if one product's service is unavailable that costs only its own tools, not the rest of the connection.
A connector collects no new personal data. It exposes data that already exists in the Customer's workspace, and reads it only when the connected AI assistant calls a tool in response to something the Customer asked. Depending on which connectors are authorized and which permissions are granted, the data returned may include:
This data belongs to the Customer. Where it contains personal data about the Customer's end-users, the Customer remains the controller and AssistantLabs remains the processor, exactly as described above — connecting an AI assistant does not change those roles.
A connector reaches nothing until the Customer authorizes it, in one of two ways:
Permissions are enforced, not advisory. Tools are exposed according to the permissions the credential actually holds, and every request is authorized again by the underlying API. A read-only credential is never offered a tool that writes. Granting read access to conversations does not grant the ability to send messages, change assistant configuration or edit records — those are separate permissions the Customer must approve deliberately.
Where a Customer does grant write permissions, the connected AI assistant can act in the workspace on the Customer's instruction: send a message to a customer, update a contact or CRM record, change assistant configuration, or publish a post. The Customer is responsible for the instructions it gives and for the permissions it approves.
The connector service is a stateless proxy. It has no database of its own and writes no copy of the data passing through it: each tool call becomes a single authenticated request to the AssistantLabs API, and the response is handed straight back to the AI assistant that asked for it. Nothing is cached, retained or reused once the request completes.
Credentials are never stored by the connector and never written to logs in full — an API key appears in operational logs only as a masked fragment. We keep ordinary operational logs (timestamps, request paths, response codes, tool names and error messages) for reliability, security monitoring and abuse prevention; they are not used to profile end-users. Data reached through a connector is not used to train or fine-tune any AI model.
Responses are bounded, so that a broad question cannot quietly drain an entire history: a single tool result is capped at 60,000 characters, an analysis call scans at most 300 conversations, and at most 200 messages are read per conversation.
This is the most important thing to understand before connecting one.
When a Customer connects an external AI assistant, the data a connector returns is sent to that AI provider — for the Claude connector, to Anthropic. That is inherent in the request: the assistant cannot answer a question about the Customer's conversations without receiving them. AssistantLabs does not select that provider and does not control what happens to the data once it arrives. Its handling, retention and any human review are governed by the Customer's own agreement with that AI provider and by that provider's privacy policy — not by this one.
We recommend that Customers read the AI provider's terms before connecting, and authorize no permission broader than they need. We do not sell or rent this data, and we disclose it to no recipient other than the AI provider the Customer chose to connect and the infrastructure sub-processors listed above.
Where a Customer is a controller under the GDPR or Israeli privacy law and its end-users' personal data will reach an AI provider through a connector, the Customer is responsible for having a lawful basis for that disclosure and for reflecting it in its own privacy notice.
The connector itself retains no conversation, contact, task, CRM or sales content — there is nothing to delete there, because nothing is kept. Operational logs are retained for up to 30 days. The underlying workspace data keeps the retention periods set out in the Data Retention section below. Data delivered to a connected AI provider is retained under that provider's policy, and only the Customer can delete it there.
A Customer may disconnect at any time — by revoking the authorization in their AI assistant or in AssistantLabs, or by deleting the developer API key it uses. Access stops immediately. Because the connector stores nothing, disconnecting leaves no residue with us; anything already delivered into an AI assistant's chat history must be removed in that assistant.
For questions, access requests or complaints specifically about the MCP connectors, contact legal@assistantlabs.io, or use the full contact details in the Contact Us section below. We respond within 30 days.
Personal data is transferred to and processed in the United States (Google Cloud Platform, Iowa region; OpenAI; Anthropic; Google, including the Gmail API and Meta Pixel measurement; Resend), Ireland/USA (Meta), Israel (Tranzila, Flashy) and other locations depending on the integrations a Customer enables. These transfers are necessary to perform our contract and are safeguarded by:
| Data Category | Retention Period |
|---|---|
| Account data | Duration of active account plus 30 days post-termination |
| Conversation data | Until deleted by Customer via dashboard; deleted within 30 days of account termination upon written request |
| CRM contacts | Until deleted by Customer; removed within 30 days of account termination upon written request |
| Payment records | 7 years (Israeli tax law requirements) |
| Analytics data | Aggregated and anonymized; retained for up to 24 months |
| MCP connectors | No conversation, contact, task, CRM or sales content is retained by the connector; operational logs up to 30 days |
| Backups | Encrypted, rolling 30-day window |
We implement appropriate technical and organizational measures to protect personal data, including:
Under the GDPR (where applicable) and Israeli privacy law, you have the following rights:
If you are an end-user of a business that uses AssistantLabs, that business is the controller of your data; please direct your request to it. We will assist our Customer in responding. To exercise rights regarding data for which AssistantLabs is the controller, contact legal@assistantlabs.io. We will respond within 30 days.
The Service uses Firebase Analytics to collect usage data such as page views, session duration and feature interactions. Our own dashboard and marketing web pages also use the Meta Pixel to measure the effectiveness of our marketing and, where relevant, to build advertising audiences for our own promotion of the Service; the Meta Pixel operates only on our web pages visited by account users and prospects, and is never applied to end-user conversations processed on a Customer's behalf. Where required by applicable law, non-essential cookies and the Meta Pixel are set only after consent, and you can withdraw consent or disable them via your browser settings.
The web chat widget may set cookies or local-storage entries for session management. Customers are responsible for obtaining any cookie consent required under applicable law (e.g., the ePrivacy Directive) when embedding the web chat on their websites.
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will promptly delete it.
We may update this Privacy Policy from time to time. We will notify you of material changes by email at least fourteen (14) days before they take effect. The "Effective Date" at the top indicates the most recent revision.
If you have questions, concerns or requests regarding this Privacy Policy or our data practices, please contact:
AssistantLabs – Legal & Privacy
Email: legal@assistantlabs.io
Address: Ha'Aniya Arinpura 8, Netanya, Israel
If you are not satisfied with our response, you may lodge a complaint with the Israeli Privacy Protection Authority (PPA) or, for EU residents, your local supervisory authority.