Privacy Policy
1. Who this policy covers
This Privacy Policy describes how Huz AI ("Huz," "we," "us") collects, uses, and protects information in connection with the Service. Huz AI is built for business (B2B) use: accounts are created by, and workspaces belong to, businesses and the individuals who work for them, not by members of the general public acting as consumers.
2. Information you provide
Account information: work email address, password (stored only as a salted cryptographic hash, never in plain text), and, if provided, your full name.
Workspace/business information: company name, industry, company size, country/region, website, description of your operations, timezone, language, and currency preferences, and the answers you give during onboarding about your team, role, and the operational problem you want Huz to help with.
Agent and Job configuration data: the plain-language operational responsibilities you describe, and the Agent name, purpose, and Job details Huz derives from them.
Data Space content: business records you explicitly upload or import (for example, CSV data) for an Agent or Job to use, and the dataset schemas you define.
Connections/integration metadata: the name, service type, and connection status of systems you authorize Huz to work with (for example, a connected company email account). Where a Connection uses OAuth, Huz receives only the access authorization and account identifiers necessary to operate the Connection you approved — not your third-party account password.
Support and other communications: information you send us when you contact support or otherwise correspond with Huz.
3. Information collected automatically
Operational and activity logs: records of what Huz has done in your workspace — Agent and Job creation, test runs and their outcomes, resolution/requirement evidence, and Production deployment events — kept so that your team has a truthful, auditable account of Huz's actions.
Authentication and session data: session tokens (stored only as hashes), sign-in timestamps, and rate-limiting records used to protect your account from abuse.
Technical data: standard web request metadata (such as IP address and browser user agent) processed by our hosting and security infrastructure as part of operating the Service securely.
Cookies/session technologies: Huz uses a session cookie required to keep you signed in. This cookie is essential to the Service; we do not use third-party advertising or cross-site tracking cookies.
4. How we use information
We use information to: authenticate you and maintain your session; enforce workspace/tenant isolation so that one Customer can never see another Customer's data; operate the Agents and Jobs your workspace has configured, including planning, resolving, and safely testing them; send required transactional communications (such as email verification codes and password-reset links); investigate and prevent abuse, fraud, and security incidents; provide support you request; and comply with legal obligations.
We do not use your Customer Data to train general-purpose AI models that are not part of delivering the Service to you.
5. Service providers and subprocessors
Delivering the Service requires sending limited, purpose-specific information to infrastructure and service providers acting on our behalf, including: a database and hosting provider for storing workspace data; an application hosting/deployment provider; an AI language-model provider used to interpret operational requests and to power test-time capability generation; a transactional email provider used to deliver verification codes and account notices; and, only where your workspace has explicitly configured a Job that needs them, workflow-automation and voice/telephony test-infrastructure providers, and OAuth-connected providers such as your email provider. Each provider receives only the information necessary to perform its specific function and is not authorized to use it for its own independent purposes.
6. AI providers
Where an Agent or Job you configure requires it, portions of your request text and relevant workspace context may be sent to a third-party AI language-model provider to generate or evaluate a plan. We do not send your Data Space content or Connection credentials to an AI provider except where a specific, workspace-authorized capability is designed to do so as part of fulfilling your request (for example, drafting a reply using content you have explicitly connected).
7. Data retention
We retain account and workspace data for as long as your account is active, and for a limited period afterward as needed to comply with legal obligations, resolve disputes, and enforce our agreements. Activity and test-run evidence is retained to preserve an accurate operational record. Verification codes and password-reset tokens expire quickly and, once used or expired, are retained only as already-consumed hash records, not as usable credentials.
8. Security and tenant isolation
Every read and write in the Service is scoped to your authenticated workspace; the Service is designed so that a workspace identifier alone, without a valid authenticated session, cannot be used to access another Customer's data. Passwords use salted, iterated cryptographic hashing. Verification codes and password-reset tokens are stored only as hashes. Session cookies are set with security flags appropriate for the hosting environment. Connection secrets are not exposed in product responses, logs, or customer-visible screens. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. International processing
Our hosting and service providers may process data in countries other than your own. [Placeholder: specific data-hosting regions and any cross-border transfer safeguards (such as standard contractual clauses) will be documented here once finalized.]
10. Your rights and choices
Subject to applicable law, you may request access to, correction of, or deletion of personal information we hold about you, and you may object to or request restriction of certain processing. Workspace administrators can also directly manage, update, or remove much of your workspace's own data (Agents, Jobs, Connections, Data Space content) through the Service itself. To make a request we cannot fulfil directly in the product, contact us as described in Section 13.
11. Deletion requests
Where you request deletion of personal information and no legal or legitimate business reason requires retention (such as active fraud prevention or a legal hold), we will delete or anonymize it within a reasonable period. Some records — for example, hashed evidence of a consumed security token — are retained only in non-reversible form and do not represent recoverable personal information.
12. Children and minors
Huz AI is a business-to-business service intended for use by working professionals on behalf of their employer. It is not directed to, and we do not knowingly collect personal information from, children.
13. Changes to this policy and contact
We may update this Privacy Policy from time to time. Material changes will be issued under a new version number shown at the top of this page. Privacy questions or requests can be sent to Huz Global AI through the official support channel published for your account. [Placeholder: a dedicated privacy contact address will be published here once designated.]
14. Effective date
This Privacy Policy is effective as of the version and date shown above and remains in effect until superseded by a later version.
Back to registration