Legal
Privacy Policy
Effective September 10, 2026
This Privacy Policy explains how Fabstech LLC (“Fabstech,” “we,” “us,” or “our”) collects, uses, and shares information in connection with CyberGuardIntel AI (the “Service”), including our marketing site and the application used by our customers (“Customers”) and their authorized users.
1. Scope of this policy
This policy covers information we collect through our website, the CyberGuardIntel AI application, and related communications. It does not cover the content of Customer Data itself (the policies, evidence, and compliance records you store in the Service), which is governed by our Terms of Service and, where applicable, a separate data processing or Business Associate Agreement with your organization.
If you are an individual whose information appears in a Customer’s account (for example, as a named control owner or BAA contact), that Customer is responsible for that data and you should direct privacy requests to them; we act on their instructions with respect to that content.
2. Information we collect
Account and identity information
When you or your organization sign up, our identity provider, Clerk, collects your name, work email address, and authentication details, including OAuth identifiers if you sign in with Google, Microsoft, or GitHub, and multi-factor authentication metadata (MFA is required on every account).
Billing information
Subscription and billing details (plan, seat count, billing contact) are processed through Stripe, our payment processor. Stripe collects and stores your payment card details directly; we do not store full card numbers ourselves.
Content you provide
This includes uploaded evidence files, AI-drafted and approved policies and risk assessments, PHI system map entries, BAA tracker records, and other information you enter into the Service.
Integration data
When you connect a third-party tool (for example, a cloud provider, identity provider, or engineering tool) we collect the metadata needed to map evidence to compliance controls, limited to the scopes you authorize during that connection.
Usage and device information
We collect standard technical information such as IP address, browser type, device information, pages visited, and timestamps, primarily through server logs and the audit log we maintain for HIPAA-relevant actions in your account.
Support and other communications
If you email us, request a demo, or contact support, we collect the information you provide, including inbound emails processed through our email provider, Resend.
3. How we use information
- Provide, operate, and maintain the Service;
- authenticate accounts and enforce multi-factor authentication and organization-level access controls;
- process payments and manage subscriptions through Stripe;
- generate AI-assisted drafts of policies and risk assessments from the information you provide (see AI processing);
- maintain the audit log required for HIPAA-relevant actions in your account and to help you demonstrate compliance;
- send transactional email such as verification codes, invitations, BAA expiration reminders, and billing notices;
- respond to support requests and, if you opt in, send product updates or marketing communications;
- detect, investigate, and prevent fraud, abuse, and security incidents; and
- comply with legal obligations.
4. AI processing
To draft policies, risk assessments, and similar content, the Service sends the relevant portions of your input to a third-party AI provider (Anthropic) under that provider’s business-tier terms, which by default do not permit use of your prompts or outputs to train their models. AI output is stored as part of your Customer Data and always begins in draft status, requiring human review before it is finalized. See AI-generated content in our Terms for more detail on how draft content is handled.
6. Protected health information
The Service is built to help you document your organization’s HIPAA posture — for example, mapping which of your systems touch protected health information (“PHI”) — without needing you to store actual PHI in the Service. We ask Customers not to upload real patient data or other regulated PHI into the Service unless we have a Business Associate Agreement in place covering that data, as described in our Terms of Service. If your organization needs a BAA with us, contact privacy@notifications.cyberguardintel.ai.
8. Security
We apply layered technical and organizational safeguards, including:
- multi-factor authentication enforced on every account and plan;
- encryption of evidence files at rest (AES-256 / SSE-KMS) and in transit;
- time-limited, signed download links for evidence files, which expire shortly after they are issued;
- encrypted storage of third-party integration credentials, never stored in plaintext;
- tenant isolation, so every query is scoped to your organization; and
- an audit log recording HIPAA-relevant actions taken in your account.
No system is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your information, we will notify you in accordance with applicable law.
9. Data retention
We retain account and Customer Data for as long as your organization has an active subscription, plus a limited period afterward to allow for export or reactivation, after which we delete or anonymize it unless a longer period is required. Because compliance records such as audit logs, approved policies, and evidence often need to remain available to satisfy HIPAA documentation requirements, we retain those categories for up to six years from creation, consistent with HIPAA’s own documentation-retention standard, unless you request earlier deletion and no legal or contractual obligation requires us to keep it longer.
10. Your rights and choices
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing. You can exercise most of these rights directly within the Service (for example, updating your profile, or an organization admin removing a member). Otherwise, contact privacy@notifications.cyberguardintel.ai and we will respond within the time required by applicable law. You can opt out of marketing email using the unsubscribe link in any such message; you cannot opt out of transactional or security-related email needed to operate your account.
11. Children's privacy
The Service is a business tool intended for use by adults acting on behalf of an organization. It is not directed to children, and we do not knowingly collect personal information from children.
12. International data transfers
We and our service providers may process information in the United States and other countries where our infrastructure or subprocessors operate. Where required, we rely on appropriate safeguards, such as standard contractual clauses, to cover transfers of personal information out of the European Economic Area, the United Kingdom, or other regions with similar requirements. Contact privacy@notifications.cyberguardintel.ai if you need more detail about a specific transfer.
13. Changes to this policy
We may update this policy from time to time. For material changes, we will update the “Effective” date above and, where appropriate, notify the account owner by email or in-app notice before the change takes effect.
14. Contact us
Questions about this Privacy Policy or how we handle your information can be sent to privacy@notifications.cyberguardintel.ai. For Enterprise data-processing or security questionnaires, contact sales@notifications.cyberguardintel.ai. Fabstech LLC is the operator of CyberGuardIntel AI.