Summary — the short version
- AnswerWeave is operated by Hazen Technologies Inc. We provide an embeddable AI website assistant to businesses.
- We collect account information from our customers, and, on customers' behalf, we process conversation data from End Users who interact with a customer's assistant.
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
- We do not use your content or End-User conversations to train third-party foundation models.
- You have rights over your personal information, including access, deletion, and correction — see §10.
- Enterprise customers can request our Data Processing Addendum for GDPR/UK GDPR/CCPA-required processor terms.
1. About this policy
This Privacy Policy explains how Hazen Technologies Inc (“we,” “us,” “our”), operator of the AnswerWeave service, collects, uses, discloses, and protects personal information. It applies to information we collect through the AnswerWeave dashboard, the embeddable assistant widget, our marketing website (including answerweave.ai and any subdomain, and answerweave.com, which redirects to it), and any related services or communications (collectively, the “Service”).
“Personal information” means information that identifies, relates to, describes, or could reasonably be linked with an identified or identifiable natural person or household. This term is used interchangeably with “personal data,” “PI,” and similar terms under Applicable Law.
2. Our roles under privacy law
Different privacy laws describe the parties that handle personal information in different ways. In this policy:
- For information about our customers (the businesses that sign up for a AnswerWeave account, and their authorized users), we act as a “controller” (GDPR/UK GDPR) or “business” (CCPA/CPRA). This policy describes our practices in that role.
- For information about End Users who interact with a customer's assistant, we act as a “processor” (GDPR) or “service provider” (CCPA/CPRA) on behalf of the customer, and process such information under the customer's instructions and our Data Processing Addendum. End Users should refer to the privacy policy of the website or property where the assistant is embedded to understand the customer's practices and to exercise their rights against the customer as controller.
3. Information we collect
3.1 Information you provide to us (customers)
- Account information: name, work email address, hashed password, and workspace name provided at registration.
- Team information: names and email addresses of teammates invited to your workspace, and their assigned role.
- Billing information: plan selection, subscription status, promotional code redemptions, and invoice records. Payment card details are collected, tokenized, and stored by our payment processor (Stripe) and are not stored on our servers.
- Content submitted for indexing: URLs, sitemaps, and files (PDF, Word, text, Markdown) you submit for your assistant to answer from, which may include personal information you chose to include.
- Configuration and prompts: the settings, system prompts, greetings, and other configuration you provide for your assistant.
- Communications: content of support tickets, emails, and other messages you send to us.
3.2 Information we collect from End Users (as processor on behalf of the customer)
- Conversation content: messages sent to the assistant, the assistant's responses, feedback (thumbs up/down), and any files or voice input a visitor submits during the conversation.
- Lead information (when the visitor voluntarily provides it): name, email address, phone number, and free-text message.
- Session and technical data: a session identifier stored in the visitor's browser, IP address, user-agent string, referring page, timestamps, and interaction events.
- Voice input (when enabled by the customer): audio is transmitted to a transcription provider, converted to text, and the audio is discarded shortly after transcription. Only the transcribed text is retained as part of the conversation record. Voice input is captured only after the End User affirmatively activates the microphone and, on customer-configured properties in two-party consent jurisdictions (including Florida under Fla. Stat. § 934.03), only where the customer has provided appropriate notice and obtained the End User's consent. The customer is responsible for compliance with all recording-consent laws applicable to the End User's location.
3.3 Information we collect automatically
- Usage data: features you use in the dashboard, actions you take, error and diagnostic events, and aggregate performance metrics.
- Device and network data: IP address, user-agent, browser and operating-system information, timezone, and general location inferred from IP (city or region only).
- Cookies and similar technologies: see §14.
3.4 Information from third parties
We may receive information from third parties, such as payment processors (transaction status, chargeback and refund events), identity or fraud-prevention providers, or single-sign-on providers if you choose to sign in via a federated identity.
3.5 Sensitive information
We do not intentionally collect sensitive personal information (as that term is defined under the CPRA and other laws, including precise geolocation, government identifiers, race or ethnicity, religion, sexual orientation, health information, or genetic or biometric data). You should not submit such information as Customer Content, and you should configure your assistant to avoid soliciting it from End Users.
4. How we use personal information
We use personal information to:
- provide, operate, secure, and maintain the Service;
- generate answers from customer content using retrieval and language-model inference, and to deliver those answers to End Users;
- capture, summarize, and route sales leads on behalf of the customer to the recipient the customer configures;
- bill customers, process payments, and manage subscriptions and promotions;
- communicate with customers about the Service, including service announcements, security notices, and, where permitted, product updates and marketing (which customers can opt out of);
- respond to support requests;
- improve the reliability, performance, and features of the Service — including diagnostics and aggregated analytics — without using your Customer Content or End-User Data to train third-party foundation models;
- prevent, detect, and investigate fraud, abuse, and security incidents;
- comply with legal obligations, respond to lawful requests from public authorities, and enforce our Terms of Service.
5. Legal bases for processing (EEA and UK)
Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases:
- Performance of a contract — to provide the Service to you or take steps at your request before entering into a contract.
- Legitimate interests — to operate, secure, and improve the Service; to prevent fraud and abuse; and to communicate with you about your account. We balance these interests against your rights and freedoms.
- Legal obligation — where we are required to process personal information by law (for example, tax and accounting records).
- Consent — where required, for example for certain marketing communications or cookies. You may withdraw consent at any time.
6. Automated decision-making and profiling
We do not use personal information to make decisions with legal or similarly significant effects about you based solely on automated processing (within the meaning of Article 22 GDPR). Answers generated by our language models are informational and do not constitute automated decisions about individuals.
7. How we share personal information
We share personal information only in the ways described below. We do not sell personal information and we do not “share” personal information for cross-context behavioural advertising (as those terms are defined under the CCPA/CPRA).
7.1 Service providers and subprocessors
We engage vetted third parties to run the Service. Our current subprocessors include categories such as:
- Language-model and embedding providers — for AI inference and text-embedding generation.
- Payment processing — for subscription billing and invoicing.
- Cloud infrastructure — for application hosting, databases, and file storage.
- Transactional email delivery — for account and lead notifications.
We do not currently use a third-party error-monitoring or log-aggregation service. Application logs remain on our own infrastructure and are not sent to any external provider.
A current list of subprocessors, with names and processing locations, is maintained at answerweave.ai/subprocessors. Enterprise customers may subscribe to notifications of new subprocessors under the DPA. All subprocessors are bound by written data-protection obligations that limit their processing to our documented instructions.
7.2 On instructions from a customer
Where a customer configures a lead-notification email, we deliver the lead — including any contact information the End User provided and an AI-generated conversation summary — to the recipient the customer specifies. We act on the customer's instructions and are not responsible for the customer's handling of that information after delivery.
7.3 Legal, safety, and compliance
We may disclose personal information if we reasonably believe disclosure is required by law or legal process, necessary to protect the rights, property, or safety of AnswerWeave, our customers, or others, or to detect, prevent, or address fraud, security, or technical issues. Where legally permitted, we will notify affected customers before disclosure.
7.4 Corporate transactions
If we are involved in a merger, acquisition, sale of assets, financing, reorganization, or similar transaction, personal information may be transferred as part of that transaction, subject to standard confidentiality protections. We will notify affected users where material changes to this policy result.
8. Data retention
We retain personal information for as long as necessary to provide the Service and to fulfil the purposes described in this policy, and thereafter only as required by Applicable Law. Our default retention periods are:
- Active account data — for the duration of the account, and for a reasonable period after closure to permit reactivation and dispute resolution.
- Closed account data — deleted from active systems within ninety (90) days of a deletion request, subject to legal retention requirements. There is currently no self-service account-deletion control and no automated purge job, so closure and deletion are handled manually on request to support@answerweave.ai.
- Billing and tax records — up to seven (7) years, to meet tax and audit obligations.
- Indexed content, chat transcripts and leads — retained while the customer's workspace is active. Customers can delete indexed sources and whole assistants from the dashboard at any time, and deleting an assistant also removes its transcripts and captured leads. There is currently no control for deleting an individual transcript or lead on its own; ask us and we will do it.
- Voice recordings — never written to persistent storage. Audio is passed to our transcription Sub-processor and discarded; only the resulting text is retained.
- Administrative audit log — records of platform-administrator actions, retained for a defined window and then pruned automatically.
- Backups — up to thirty (30) days. Our managed database service takes automated backups continuously, giving a thirty (30) day point-in-time restore window. Separately, a verified database dump is taken immediately before any schema migration, and those dumps are discarded automatically once they are thirty (30) days old. Both layers expire on the same boundary, so data deleted from active systems persists in backups for no longer than that.
We may retain personal information for longer where required by law, to enforce our Terms, to establish, exercise, or defend legal claims, or where a customer instructs us to do so under the DPA.
9. Security
We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, or destruction. These include HTTPS/TLS for data in transit, one-way hashing of account passwords, role-based access controls, a single public entry point with application and database services not directly exposed to the internet, rate-limiting on sensitive endpoints, peer review of every change before it reaches production, and an audit log of platform-administrator actions. Card details never reach our servers.
We think it is more useful to tell you what we do not yet have than to imply otherwise. We do not currently operate centralised security logging or monitoring, automated vulnerability scanning, third-party penetration testing, a formal incident-response or disaster-recovery plan, or formal personnel security training, and we hold no SOC 2 or ISO 27001 certification of our own. Annex 2 of our Data Processing Addendum sets out both lists in full. No system is completely secure; we cannot guarantee the absolute security of information transmitted to or stored by us.
We will notify affected customers of a personal-data breach involving their data without undue delay after becoming aware of it, and will provide the information reasonably necessary for the customer to meet its own notification obligations. Where we are required to notify affected individuals directly, we will do so in accordance with Applicable Law, including where applicable the Florida Information Protection Act (Fla. Stat. § 501.171) — which generally requires notice to affected Florida residents within thirty (30) days of determination of the breach — and Article 33/34 of the GDPR and UK GDPR. Further processor obligations are described in the DPA.
10. Your rights
Depending on where you live, you may have rights over your personal information. This section summarizes those rights. To exercise a right, contact us at support@answerweave.ai. We will respond within the timeframe required by Applicable Law. We may require you to verify your identity before acting on a request.
10.1 Rights common across most jurisdictions
- Access — request a copy of the personal information we hold about you.
- Correction — request that we correct inaccurate or incomplete personal information.
- Deletion — request that we delete personal information about you, subject to legal exceptions.
- Portability — receive a copy of your personal information in a structured, commonly used, machine-readable format.
- Objection or restriction — object to, or ask us to restrict, certain processing.
- Withdraw consent — where processing is based on consent, withdraw it at any time (without affecting the lawfulness of prior processing).
- Non-discrimination — we will not discriminate against you for exercising your rights.
10.2 California residents (CCPA/CPRA)
In addition to the rights above, if you are a California resident:
- You have the right to know the categories and specific pieces of personal information we have collected about you, the sources, the business or commercial purpose for collecting or sharing it, and the categories of third parties to whom it is disclosed.
- You have the right to limit the use and disclosure of “sensitive personal information.” We do not use sensitive personal information for purposes that would trigger this right.
- We do not sell your personal information and we do not “share” it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA.
- Because we neither sell nor share personal information, there is no sale or sharing for an opt-out to apply to, and we therefore do not operate an opt-out mechanism. We do not currently detect the Global Privacy Control (GPC) browser signal. If we ever begin selling or sharing personal information, we will implement GPC handling and a “Do Not Sell or Share My Personal Information” link before doing so.
- An authorized agent may submit a request on your behalf, subject to verification.
- To exercise any right, email support@answerweave.ai with the subject line “CCPA Request.”
Categories of personal information we have collected in the preceding twelve months are: identifiers (name, email); commercial information (subscription details); Internet or other network activity (usage data); geolocation data (general, IP-based); professional or employment-related information (from account and workspace details); and inferences drawn from the foregoing for legitimate business purposes.
10.3 Other U.S. state privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, and others)
Residents of U.S. states with comprehensive privacy laws (including the VCDPA, CPA, CTDPA, UCPA, TDPSA, and equivalents) have rights substantially similar to those in §10.1 above, including access, correction, deletion, portability, and — where applicable — opt-out of targeted advertising, sale, or profiling with legal effects. We do not engage in those activities in a way that triggers the corresponding opt-out rights, but we honour any opt-out request without discrimination.
Florida residents. Florida's Digital Bill of Rights (Fla. Stat. §§ 501.701–501.721) applies to certain large controllers meeting statutory revenue and processing thresholds. Where applicable to us, Florida residents have rights substantially similar to those in §10.1 above, including the right to opt out of the sale of personal information, the processing of personal information for targeted advertising, and profiling in furtherance of decisions producing legal or similarly significant effects. Regardless of statutory applicability, we do not sell personal information about Florida residents and we honour opt-out requests without discrimination. Florida residents may also have rights under the Florida Information Protection Act with respect to breach notification.
10.4 EEA, UK, and Switzerland (GDPR/UK GDPR)
You have the rights in §10.1 above, and additionally the right to lodge a complaint with your local supervisory authority. A list of EEA authorities is available at edpb.europa.eu. In the UK, the supervisory authority is the Information Commissioner's Office (ico.org.uk). We nonetheless encourage you to contact us first so we can try to resolve your concern.
10.5 Other jurisdictions
Individuals located in Brazil (LGPD), Canada (PIPEDA and provincial equivalents), Australia (Privacy Act), Japan (APPI), and other jurisdictions have rights substantially similar to those in §10.1 above. Contact us at support@answerweave.ai to exercise them.
10.6 If you are an End User
If you interacted with an assistant on a customer's website, the customer is the controller of your data. Please contact that customer to exercise your rights. We will support the customer in responding to your request as required under our DPA.
11. International data transfers
We are based in the United States, and our subprocessors may operate in multiple jurisdictions. When we transfer personal information from the EEA, UK, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on lawful transfer mechanisms, including the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable), and we implement supplementary technical and organizational measures where necessary. Copies of the applicable safeguards are available on request from support@answerweave.ai.
12. Children's privacy
The Service is intended for use by businesses and is not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 where applicable under local law, including the UK, certain EEA member states, or where the customer's configuration so requires). If you believe a child has provided personal information to us, please contact us at support@answerweave.ai and we will take steps to delete it. Customers deploying assistants on sites directed to children are responsible for complying with COPPA, the GDPR's children's data rules, and equivalent laws.
13. Direct marketing and communications
We may send you service-related communications (such as security notices, billing information, and material changes to our policies) that are not subject to opt-out. Where permitted by law, we may also send you marketing communications about our products and services; you may opt out of those at any time using the unsubscribe link included in the message or by contacting us. Opting out of marketing does not affect service communications. We comply with applicable email-marketing laws, including the CAN-SPAM Act (15 U.S.C. §§ 7701 et seq.), Canada's Anti-Spam Legislation (CASL), and the ePrivacy Directive in the EEA/UK. For telephone or text communications, we comply with the Telephone Consumer Protection Act (TCPA) and the Florida Telephone Solicitation Act (Fla. Stat. § 501.059) where applicable, and we do not initiate such communications without the consent required by law.
14. Cookies and similar technologies
We use cookies and similar technologies (such as browser localStorage) for the following purposes:
- Strictly necessary — to authenticate signed-in users, to keep the dashboard secure, and to preserve an End User's conversation across page loads on a customer's site.
- Preferences — to remember your interface preferences.
- Analytics — to understand which pages people read, where they get stuck, and whether the site works. On our public marketing site at answerweave.ai we use two providers for this:
- Google Analytics 4 (Google LLC) — aggregate traffic and page measurement. Google Privacy Policy
- Microsoft Clarity (Microsoft Corporation) — heatmaps and session replay of interactions such as scrolling and clicks, used to find usability problems. Clarity masks page text and images by default, and we have left that masking enabled. Microsoft Privacy Statement
Where required by law, we obtain consent before setting non-essential cookies. Visitors in the EEA, the United Kingdom and Switzerland are asked before either analytics provider above is loaded, and no request is made to Google or Microsoft until that choice is given. Declining changes nothing about how the site works. You can change your answer by clearing this site's data in your browser, and you can control cookies generally through your browser settings; disabling strictly necessary cookies may impair the Service.
15. Third-party links and services
The Service, and content submitted to it, may contain links to or integrate with third-party websites or services. This policy does not apply to those third parties. We are not responsible for the privacy practices of any third party; we encourage you to review their privacy policies.
16. Changes to this policy
We may update this policy from time to time. If we make material changes, we will provide notice by email or a prominent notice in the Service before the changes take effect, and we will update the effective date at the top of this policy.
17. How to contact us
For questions about this policy, or to exercise a privacy right, contact us at support@answerweave.ai or by mail at:
Hazen Technologies IncAttn: Privacy
7957 N University Dr #1004, Parkland, FL 33067, USA
Enterprise customers requiring a Data Processing Addendum, Standard Contractual Clauses, or a security questionnaire response may request one at the address above. An EU/UK representative under Article 27 GDPR/UK GDPR will be appointed when required and identified here.