DRAFT: have a lawyer review before publishing.
Privacy Policy
BuildAi Agency ("we", "us") runs a marketing platform for small businesses in Trinidad and Tobago and the wider Caribbean. This policy explains what personal information we handle, why, who we share it with, how long we keep it, and your rights. We follow the general privacy principles of the Trinidad and Tobago Data Protection Act 2011 and, where they apply, the EU/UK GDPR and the California CCPA/CPRA.
1. Two roles
- Our clients' account data (the business owners and staff who use BuildAi: name, business details, login email, billing contact). Here we are the controller.
- Our clients' customer data (the people a client emails, chats with, or who visit a client's website). Here the client is the controller and we are their processor: we only handle it on the client's instructions, under our data processing terms. If you are one of a client's customers and want to use your rights, you can contact us and we will pass the request to the client, or help them act on it.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Client account | Business name, owner name, email, phone, logo, plan, login details | You, when you sign up or are onboarded |
| Customer and contact lists | Name, email, phone, website, social handle, tags, where the contact came from | The client; sign-up forms on client websites; lead search (see §4) |
| Chat messages | Messages and phone number or messaging ID on WhatsApp, Instagram, Facebook Messenger and website chat; the AI assistant's replies | The person chatting |
| Email activity | Whether an email was opened or a link clicked | Our tracking pixel and links in the emails we send for clients |
| Website visitor data | Pages viewed, time on page, referring source or campaign, a random visitor ID kept in the browser's local storage, and a contact ID if the visitor arrived from a link in a client's email | The small script we add to client websites |
| Advertising data | Ad impressions, clicks and spend for ads we run on a client's behalf | Meta |
| Technical data | IP address, browser type, timestamps, security logs | Our servers |
We do not knowingly collect sensitive information (health, religion, etc.) and ask clients not to send it through the platform.
3. How we use it, and why
- To provide the service a client signed up for: sending marketing emails, running the AI chat assistant, tracking website and campaign results, managing ads, building websites, and producing reports (performing our contract with the client).
- To keep the platform secure and prevent abuse: rate limiting, fraud and spam prevention, logs (our legitimate interest).
- To comply with the law and answer legal requests.
- To improve the service, using aggregated usage information.
We do not sell personal information, and we do not use it to advertise to you for anyone but the client who collected it.
4. Finding new customers (lead search)
A client can ask the platform to find businesses that might want to hear from them. We look for business contact details (business name, business phone, business website and business email) in public business listings and on the businesses' own websites. We do not collect personal social media profiles. Each contact keeps a record of where it was found and when. Anyone who tells us they don't want to be contacted is added to a suppression list and is not contacted or re-added.
5. AI processing
We use artificial intelligence (Anthropic's Claude models) to draft emails, ads, website pages and reports, and to power the chat assistants. The text needed for the task (for example a business description, a draft, or a customer's chat message) is sent to Anthropic for processing. Chat assistants tell people at the start of a conversation that they are talking to an AI assistant, and a person can step in on request. People review AI-written emails, ads and pages before they go live.
6. Who we share it with (sub-processors)
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, file storage, client sign-in | Region of our Supabase project |
| Railway | Hosting the platform | United States |
| Anthropic | AI text generation and chat assistants | United States |
| Resend | Sending email | United States |
| Twilio | WhatsApp messaging | United States |
| Meta Platforms (Facebook, Instagram, WhatsApp) | Messenger and Instagram messaging, ad delivery and reporting | United States / Ireland |
We also disclose information when the law requires it, or to protect our users and platform. If we change providers we will update this list.
7. International transfers
Our providers are mostly in the United States. Where the law requires safeguards for data leaving Trinidad and Tobago, the EU or the UK, we rely on contractual protections such as standard contractual clauses and on our providers' security commitments.
8. How long we keep it
| Data | Kept for |
|---|---|
| Chat transcripts | 24 months |
| Website visitor events | 13 months |
| Lead search results not added to a client's contacts | 24 hours |
| Email send and engagement logs | 24 months |
| Do-not-contact (suppression) records | Kept as a one-way hash, so we can keep honouring the request |
| Security and audit logs | 12 months |
| A closed client account | Deleted within 30 days of closing, unless the law requires us to keep something |
Retention periods are being put into the platform in stages; until each one is automated we apply them manually on request.
9. Cookies and similar technologies
Our own apps use browser storage only to keep you signed in and remember display settings. The script on client websites stores a random visitor ID in the browser's local storage (not an advertising cookie). It does nothing if the visitor's browser sends a Do Not Track or Global Privacy Control signal. Client websites built on BuildAi show a short notice about this and link to the site's own privacy page.
10. Email, and unsubscribing
Every marketing email we send for a client names the business, shows its address and contains an unsubscribe link and a one-click unsubscribe option in your email app. Unsubscribing stops all further marketing email from that business through BuildAi, including automated follow-ups.
11. Security
We use encrypted connections, access controls, signed sessions, rate limiting and abuse detection, database access restricted to our servers, and providers that encrypt data at rest. No system is perfectly secure; if there is a breach affecting your information we will tell the affected client and, where required, the authorities, without undue delay.
12. Your rights
Depending on where you live you may have the right to access your information, correct it, delete it, restrict or object to how it is used, receive a copy in a portable format, and withdraw consent you gave. You may also complain to the data protection authority where you live.
13. Deleting data you shared through Facebook, Instagram or WhatsApp
If you messaged a business that uses BuildAi through Facebook Messenger, Instagram or WhatsApp, you can have those messages deleted by (a) removing the BuildAi app in your Facebook settings (Settings → Apps and websites), which sends us an automatic deletion request, or (b) emailing privacy@mybuildai.agency with your name and the business's name or the phone number you used. After a Facebook-initiated request we show a confirmation page with a status code you can keep.
14. Children
The platform is for businesses. It is not directed at children under 16 and we do not knowingly collect their information.
15. Changes
We will post changes here and change the version date. For material changes we will notify our clients by email.
16. Contact
BuildAi Agency, sole trader registered in Trinidad and Tobago under the Registration of Business Names Act, business registration certificate no. B2026062600001.
Trinidad and Tobago
Privacy: privacy@mybuildai.agency · Security: security@mybuildai.agency