Privacy Policy

Effective Date: 31 August 2026  |  Version 2.2

1. Introduction

This Privacy Policy explains how Ben Hadad, ID 300107661, trading as "AssistantLabs" ("we", "us", "our"), collects, uses, stores, shares and protects personal data when you use our cloud-based AI assistant platform (the "Service"). The Service enables businesses to build and operate AI-powered assistants across WhatsApp Business, Instagram Direct, Facebook Messenger, website chat and LinkedIn, with an in-app inbox, CRM, analytics and optional integrations. Customers may also connect an external AI assistant, such as Claude, to their workspace through our optional MCP connectors.

We are committed to protecting your privacy and to complying with the Israeli Privacy Protection Law, 5741-1981, the EU General Data Protection Regulation (GDPR) where applicable, and other relevant data-protection legislation.

2. Data Controller & Roles

The controller for account, billing and platform data processed through the Service is:

Ben Hadad / AssistantLabs
Address: Ha'Aniya Arinpura 8, Netanya, Israel
Email: legal@assistantlabs.io

When a Customer (a business) uses AssistantLabs to interact with its own end-users, the Customer is the data controller for end-user personal data and AssistantLabs acts as the data processor on the Customer's behalf, processing that data only on the Customer's documented instructions and to provide the Service.

3. Data We Collect

We collect and process the following categories of personal data:

3.1 Account Data

FieldDescription
idUnique user identifier
displayNameUser's display name
emailEmail address
lastLoginAtTimestamp of last login
profilePictureProfile photo URL (optional)
settings.languagePreferred language

3.2 Billing & Payment Data

FieldDescription
cardHolderNameName on credit card
cardHolderIdID document number of cardholder (Israeli invoicing requirement)
cardTypeCard brand (Visa, Mastercard, etc.)
lastFourDigitsLast 4 digits of card number
expMonth / expYearCard expiration date
tokenTokenized card reference (no full card numbers stored by us)
businessNameCompany or business name for invoicing
businessIdIsraeli business ID or personal ID for tax
receiptEmailEmail for receipts and invoices
Standing order & usage recordsSubscription and usage-charge history for billing

3.3 Assistant Configuration Data

Business information, FAQs, product catalogs, links, guidelines, scenarios, persona settings and other content that Customers provide (directly or via the Logos AI configuration assistant) to configure their AI assistants. Customers may also import content by allowing us to scan a website they provide.

3.4 CRM Contact Data

FieldDescription
firstName / lastNameContact name
phonePhone number
emailEmail address
notesFree-form notes about the contact
customFieldsCustom key-value data
labelsCategorization labels
sourceOrigin channel (WhatsApp, Instagram, Messenger, Web, LinkedIn, Wix, Monday.com, Shopify, WooCommerce, import, manual or API)
consentStatusData-processing consent (granted, denied, pending, unknown)
marketingConsent / optedOutOpt-in status and opt-out flag/timestamp for marketing communications
External IDs & synced ordersIdentifiers and order data from connected integrations (e.g., wixContactId, mondayItemId, WooCommerce/Shopify customer or order records)

3.5 Conversation Data

Messages exchanged between end-users, AI assistants and the Customer's human agents, including text and media content, timestamps, message direction, sender type, read/reaction status, channel metadata and platform message identifiers.

3.6 Analytics & Technical Data

Conversation counts, automated-vs-human classification, message volumes, response metrics, session data, IP addresses, browser type, device information and usage patterns, collected through Firebase Analytics and exported to BigQuery in aggregated form for analytics and billing.

4. Legal Basis for Processing

Legal BasisProcessing Activity
Performance of contractProviding the Service, processing payments, managing accounts, delivering AI assistant functionality
Legitimate interestService improvement (using aggregated/de-identified data), analytics, security monitoring, fraud prevention, debugging
ConsentMarketing communications, optional analytics, cookie placement
Legal obligationTax record keeping, responding to lawful government requests, maintaining billing records

5. How We Use Your Data

We do not sell or rent personal data, and we do not use identifiable Customer Content or end-user conversations to train or fine-tune general-purpose AI models. Only aggregated and anonymized data is used to improve the Service.

6. Sub-Processors

We share personal data with the following sub-processors, strictly as necessary to provide the Service. Integration providers receive data only when the Customer connects the relevant integration.

Sub-ProcessorPurposeLocation
Google Cloud Platform (GCP)Cloud infrastructure, Firestore database, Cloud Run, BigQuery analytics, Cloud Tasks, storageIowa, USA
Firebase (Google)Authentication, hosting, analytics, Cloud FunctionsUSA
OpenAIAI language-model processing for assistant responsesUSA
AnthropicAI language-model processing for the Logos configuration assistantUSA
Google (Gemini / Generative AI)AI language-model processingUSA
Meta Platforms Ireland LtdWhatsApp Cloud API, Instagram Messaging API, Messenger PlatformIreland / USA
Meta Platforms Ireland Ltd (Meta Pixel)Measurement and advertising analytics on our own dashboard/marketing web pages (account users only; not applied to end-user conversations). Placed subject to consent where required.Ireland / USA
ResendDelivery of transactional and outreach email (account notifications, onboarding and support mail)USA
Google (Gmail API)Delivery of organisation notification email where the Customer connects a Gmail accountUSA
FlashyWhatsApp template / marketing-message delivery (when used)Israel
Tranzila (InterSpace Ltd)Payment processing, credit-card tokenization, standing ordersIsrael
Customer-enabled integrationsWix, Monday.com, Shopify, WooCommerce, Fireberry, Calendly, Google Calendar/Sheets — contact, order, scheduling and CRM synchronizationVaries by provider

A current sub-processor list is available on request at legal@assistantlabs.io.

An external AI assistant that a Customer connects through an MCP connector is not a sub-processor: it receives data on the Customer's own instruction, under the Customer's own agreement with that AI provider. See the AI Assistant Connectors (MCP) section below.

7. AI Assistant Connectors (MCP)

We publish remote MCP (Model Context Protocol) connectors that let a Customer connect an external AI assistant — such as Claude or ChatGPT — to their own AssistantLabs workspace and then ask it about their business in plain language. Connecting one is optional and entirely Customer-initiated. If a Customer never connects a connector, nothing in this section applies to them.

7.1 What a connection can reach

A single connector address — /mcp — can carry every AssistantLabs product: the assistant and its conversations, the task board, the CRM, Sales and Marketing. Which of them a given connection actually reaches is decided by the permissions the Customer approves, not by the address. A connection approved only for customer replies loads only those tools, and a product the Customer did not approve is never loaded at all. Each product also keeps a dedicated address, for a Customer who prefers to connect one product on its own. Everything is served from https://mcp-server-150134556021.us-central1.run.app.

ProductDedicated addressWhat it can reach
Assistant & conversations/mcp — also the combined address (alias /insights/mcp)Assistant configuration, conversations and their messages, contacts, segments, channels and WhatsApp templates, custom integrations
Tasks/tasks/mcpThe workspace task board — tasks, their contents and views
CRM/crm/mcpCRM contacts and companies, entity schemas, record page layouts
Sales/sales/mcpCustomer groups, journeys and their audiences, participants, journey statistics, WhatsApp templates
Marketing/marketing/mcpMarketing channels, posts and performance, strategy, research and product profile

Each product is resolved independently: approving one does not require approving another, and if one product's service is unavailable that costs only its own tools, not the rest of the connection.

7.2 What a connector collects

A connector collects no new personal data. It exposes data that already exists in the Customer's workspace, and reads it only when the connected AI assistant calls a tool in response to something the Customer asked. Depending on which connectors are authorized and which permissions are granted, the data returned may include:

This data belongs to the Customer. Where it contains personal data about the Customer's end-users, the Customer remains the controller and AssistantLabs remains the processor, exactly as described above — connecting an AI assistant does not change those roles.

7.3 Authorization and permissions

A connector reaches nothing until the Customer authorizes it, in one of two ways:

Permissions are enforced, not advisory. Tools are exposed according to the permissions the credential actually holds, and every request is authorized again by the underlying API. A read-only credential is never offered a tool that writes. Granting read access to conversations does not grant the ability to send messages, change assistant configuration or edit records — those are separate permissions the Customer must approve deliberately.

Where a Customer does grant write permissions, the connected AI assistant can act in the workspace on the Customer's instruction: send a message to a customer, update a contact or CRM record, change assistant configuration, or publish a post. The Customer is responsible for the instructions it gives and for the permissions it approves.

7.4 Use and storage — the connector stores nothing

The connector service is a stateless proxy. It has no database of its own and writes no copy of the data passing through it: each tool call becomes a single authenticated request to the AssistantLabs API, and the response is handed straight back to the AI assistant that asked for it. Nothing is cached, retained or reused once the request completes.

Credentials are never stored by the connector and never written to logs in full — an API key appears in operational logs only as a masked fragment. We keep ordinary operational logs (timestamps, request paths, response codes, tool names and error messages) for reliability, security monitoring and abuse prevention; they are not used to profile end-users. Data reached through a connector is not used to train or fine-tune any AI model.

Responses are bounded, so that a broad question cannot quietly drain an entire history: a single tool result is capped at 60,000 characters, an analysis call scans at most 300 conversations, and at most 200 messages are read per conversation.

7.5 Third-party sharing — what the AI provider receives

This is the most important thing to understand before connecting one.

When a Customer connects an external AI assistant, the data a connector returns is sent to that AI provider — for the Claude connector, to Anthropic. That is inherent in the request: the assistant cannot answer a question about the Customer's conversations without receiving them. AssistantLabs does not select that provider and does not control what happens to the data once it arrives. Its handling, retention and any human review are governed by the Customer's own agreement with that AI provider and by that provider's privacy policy — not by this one.

We recommend that Customers read the AI provider's terms before connecting, and authorize no permission broader than they need. We do not sell or rent this data, and we disclose it to no recipient other than the AI provider the Customer chose to connect and the infrastructure sub-processors listed above.

Where a Customer is a controller under the GDPR or Israeli privacy law and its end-users' personal data will reach an AI provider through a connector, the Customer is responsible for having a lawful basis for that disclosure and for reflecting it in its own privacy notice.

7.6 Retention

The connector itself retains no conversation, contact, task, CRM or sales content — there is nothing to delete there, because nothing is kept. Operational logs are retained for up to 30 days. The underlying workspace data keeps the retention periods set out in the Data Retention section below. Data delivered to a connected AI provider is retained under that provider's policy, and only the Customer can delete it there.

7.7 Turning a connector off

A Customer may disconnect at any time — by revoking the authorization in their AI assistant or in AssistantLabs, or by deleting the developer API key it uses. Access stops immediately. Because the connector stores nothing, disconnecting leaves no residue with us; anything already delivered into an AI assistant's chat history must be removed in that assistant.

7.8 Questions about a connector

For questions, access requests or complaints specifically about the MCP connectors, contact legal@assistantlabs.io, or use the full contact details in the Contact Us section below. We respond within 30 days.

8. International Data Transfers

Personal data is transferred to and processed in the United States (Google Cloud Platform, Iowa region; OpenAI; Anthropic; Google, including the Gmail API and Meta Pixel measurement; Resend), Ireland/USA (Meta), Israel (Tranzila, Flashy) and other locations depending on the integrations a Customer enables. These transfers are necessary to perform our contract and are safeguarded by:

9. Data Retention

Data CategoryRetention Period
Account dataDuration of active account plus 30 days post-termination
Conversation dataUntil deleted by Customer via dashboard; deleted within 30 days of account termination upon written request
CRM contactsUntil deleted by Customer; removed within 30 days of account termination upon written request
Payment records7 years (Israeli tax law requirements)
Analytics dataAggregated and anonymized; retained for up to 24 months
MCP connectorsNo conversation, contact, task, CRM or sales content is retained by the connector; operational logs up to 30 days
BackupsEncrypted, rolling 30-day window

10. Security Measures

We implement appropriate technical and organizational measures to protect personal data, including:

11. Your Rights

Under the GDPR (where applicable) and Israeli privacy law, you have the following rights:

If you are an end-user of a business that uses AssistantLabs, that business is the controller of your data; please direct your request to it. We will assist our Customer in responding. To exercise rights regarding data for which AssistantLabs is the controller, contact legal@assistantlabs.io. We will respond within 30 days.

12. Cookies & Analytics

The Service uses Firebase Analytics to collect usage data such as page views, session duration and feature interactions. Our own dashboard and marketing web pages also use the Meta Pixel to measure the effectiveness of our marketing and, where relevant, to build advertising audiences for our own promotion of the Service; the Meta Pixel operates only on our web pages visited by account users and prospects, and is never applied to end-user conversations processed on a Customer's behalf. Where required by applicable law, non-essential cookies and the Meta Pixel are set only after consent, and you can withdraw consent or disable them via your browser settings.

The web chat widget may set cookies or local-storage entries for session management. Customers are responsible for obtaining any cookie consent required under applicable law (e.g., the ePrivacy Directive) when embedding the web chat on their websites.

13. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will promptly delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email at least fourteen (14) days before they take effect. The "Effective Date" at the top indicates the most recent revision.

15. Contact Us

If you have questions, concerns or requests regarding this Privacy Policy or our data practices, please contact:

AssistantLabs – Legal & Privacy
Email: legal@assistantlabs.io
Address: Ha'Aniya Arinpura 8, Netanya, Israel

If you are not satisfied with our response, you may lodge a complaint with the Israeli Privacy Protection Authority (PPA) or, for EU residents, your local supervisory authority.