Privacy Policy
How IMFA Agents collects, uses, shares, and protects personal data.
1. Scope
This Privacy Policy explains how the operator of IMFA Agents ("IMFA," "we," "us," or "our") collects, uses, shares, and retains personal data when you use the IMFA Agents website, dashboard, APIs, agent builder, hosted chat experiences, voice features, and connected channels.
If you create or operate an agent that collects information from visitors, you are responsible for giving those visitors any notices and choices required by law. For that visitor data, you may be the controller and IMFA may process the data on your behalf to provide the service.
2. Personal data we collect
We collect the following categories of information, depending on how you use the service:
- Account and profile data: email address, name, profile image, professional title, biography, country, birthday if provided, authentication records, and account status.
- Agent content and configuration: agent names, prompts, instructions, appearance, model choices, uploaded documents, public webpage sources, tools, channel settings, and publishing state.
- Conversations and lead data: messages, generated replies, session metadata, contact details or other information a visitor chooses to submit, and records needed to manage an inbox.
- Billing and credit data: plan, subscription, customer and transaction references, credit purchases, balances, refunds, and billing events. Payment providers process payment-card details; IMFA does not store complete card numbers in its application database.
- Technical and usage data: request timestamps, feature activity, service errors, agent usage, model and token usage, cost records, credit consumption, IP address or network metadata processed by infrastructure providers, and security signals.
- Files and integrations: uploaded files, public URLs submitted for retrieval, API key hashes, access-token hashes, and credentials needed to connect services such as messaging channels. Secrets are protected using the safeguards implemented by the service.
- Consent records: your current privacy choices and a versioned history of grants, denials, and withdrawals.
- Communications: support requests, verification messages, transactional emails, and related delivery records.
Do not upload sensitive personal data unless it is necessary, lawful, and appropriate for your use case.
3. How we obtain data
We receive information directly from you, from visitors who interact with your agents, from services you connect, from payment and authentication providers, and automatically when the service handles requests. When you ask an agent to use a public webpage as a knowledge source, the service retrieves the URL you supplied.
4. How we use personal data
We use personal data to:
- create and secure accounts;
- provide, host, publish, and maintain agents;
- process conversations, files, knowledge retrieval, voice sessions, and connected-channel messages;
- generate AI responses and embeddings through selected model providers;
- process subscriptions, credit purchases, metering, refunds, and receipts;
- prevent abuse, enforce limits, investigate errors, and protect the service;
- communicate about authentication, transactions, support, and important service changes;
- comply with legal obligations and resolve disputes;
- perform optional product analytics and personalization when you have granted the applicable current consent.
Depending on the context and applicable law, we rely on performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, or consent. Where processing relies on consent, you can withdraw it from Settings > General > Consent manager. Withdrawal does not affect processing that was lawful before withdrawal.
5. AI processing
Content submitted to an agent may be sent through our AI gateway to the AI provider selected for that agent so the provider can generate responses, embeddings, transcriptions, or other requested output. The provider and processing path can vary based on the selected model and the feature being used.
AI output can be incomplete or incorrect. Do not rely on it as the sole basis for legal, medical, financial, employment, credit, housing, or other high-impact decisions.
6. How we share data
We disclose data only as needed for the purposes described above, including to:
- cloud database, hosting, storage, and delivery providers;
- authentication and security providers;
- AI model, speech, and embedding providers selected for a request;
- payment, subscription, and invoicing providers;
- transactional email providers;
- file parsing, public webpage retrieval, and knowledge-processing providers;
- messaging and communication services you connect;
- professional advisers, authorities, or counterparties when required by law or a valid legal process;
- a successor involved in a merger, financing, reorganization, or sale, subject to appropriate protections.
We do not authorize service providers to use personal data for their own unrelated purposes.
7. International processing
Providers may process data in countries other than your own. Where applicable law requires it, we use recognized transfer mechanisms or other appropriate safeguards. The protections available in another country may differ from those in your jurisdiction.
8. Retention
We retain personal data only for as long as reasonably needed for the service, security, legal, accounting, and dispute-resolution purposes described in this policy.
- Account, agent, conversation, and file data is generally retained while the account or relevant content remains active.
- Billing and transaction records may be retained for legally required accounting, tax, fraud-prevention, and dispute periods.
- Consent ledger history is generally retained for up to 365 days, while the current consent state is retained so the service can continue to honor your choice.
- Security logs, backups, delivery records, and deletion workflow records may remain for a limited period after the related live data is removed.
You can start account deletion from Settings > Danger zone. Some information may remain where retention is required by law, needed to complete deletion safely, or necessary to establish, exercise, or defend legal claims.
9. Security
We use technical and organizational safeguards designed to protect data, including authenticated server-side access controls, scoped authorization, protected credentials, rate limits, and audit or operational records where appropriate. No system is completely secure, so you should protect your credentials, use strong authentication practices, and promptly report suspected unauthorized access.
10. Your choices and rights
You can update profile information, manage optional consent, revoke credentials, disconnect integrations, delete agents, and request account deletion through the product.
Depending on your location, you may also have rights to request information about processing, access or correct data, request deletion or restriction, receive portable data, object to certain processing, withdraw consent, and complain to a competent data-protection authority. We may need to verify your identity before acting on a request. Some rights are subject to legal exceptions.
11. Children
IMFA Agents is intended for people who can lawfully enter into a contract for the service. It is not directed to children, and you must not knowingly use an agent to collect children's personal data without all permissions and safeguards required by law.
12. Changes to this policy
We may update this policy when the service, providers, or legal requirements change. We will post the revised policy with a new effective date and provide additional notice when required.
13. Contact
To ask a privacy question or exercise a privacy right, use the Contact link in the website footer or the support channel provided in your account. Include enough information for us to identify your account and understand the request, but do not send passwords, API keys, or other secrets.