1. Scope and data controller
This Privacy Policy describes how Firetech Corp (“Firetech”, “we”, “us”, “our”), the data controller, processes Personal Data in connection with the Firetech CRM platform and related websites and services (collectively, the “Service”). It applies to visitors, account holders, and the people whose information is entered into a workspace.
Where your organization administers a workspace, that organization acts as the controller of the content it uploads and Firetech acts as its processor; this policy then describes our own data practices and supplements the agreement between Firetech and your organization.
2. Definitions
- Personal Data — any information relating to an identified or identifiable person.
- Process / Processing — any operation performed on Personal Data (collection, storage, use, disclosure, deletion).
- Customer Data — content you or your team upload to a workspace (boards, tasks, files, comments).
- Sub-processor — a third party we engage to process data on our behalf.
- Service — the Firetech CRM platform and related sites.
3. Personal data we collect
We collect the following categories of Personal Data, depending on how you use the Service:
| Category | Examples | Source |
|---|---|---|
| Account & profile | Full name, email, phone and mobile number, location, job position/title, work anniversary, birth date, profile photo | You / your administrator |
| Authentication | Email and a securely hashed password; session and refresh tokens | You |
| Workspace content | Boards, tasks, groups, columns, comments, file attachments, uploaded PDFs/documents, quotes, purchase orders | You / your team |
| Voice recordings | Short audio clips for dictation — transient, deleted after transcription (see §10) | You |
| AI assistant | Messages you send to the assistant and the workspace context needed to answer | You |
| Usage & activity | Server logs, IP address, browser type, and an audit trail of actions taken in your workspace | Automatic |
We do not intentionally collect special-category data (health, biometrics, etc.). Please do not enter such data into free-text fields.
4. How and why we use data (legal bases)
Where the EU/UK GDPR applies, we rely on the following legal bases. Elsewhere, we process data for the equivalent legitimate purposes described below.
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide, operate, and secure the Service; authenticate you; deliver the features you use (boards, automations, AI assistant, voice dictation, document-to-task extraction) | Performance of a contract (Art. 6(1)(b)) |
| Send transactional email (invitations, notifications, password resets, security alerts) | Performance of a contract (Art. 6(1)(b)) |
| Improve, troubleshoot, and protect the Service against abuse using aggregate usage data | Legitimate interests (Art. 6(1)(f)) |
| Comply with legal obligations and respond to lawful requests | Legal obligation (Art. 6(1)(c)) |
| Optional features that require it (e.g. connecting a Google account) | Consent (Art. 6(1)(a)) |
5. AI processing
Certain features — the Sidekick assistant, document-to-task extraction, and group classification — send relevant workspace content (such as board and task text, or the contents of an uploaded document) to large-language-model providers (Google Gemini and Anthropic Claude) through the Vercel AI Gateway, solely to generate the output you request. A redaction layer is applied to assistant data where applicable.
This content is processed for inference only. It is not used by us, or by these providers, to train their generally available models. AI output can be inaccurate and should be reviewed before you rely on it.
8. Google user data
If you connect a Google account, our access to, use of, and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. For the full disclosure of what Google data we request, why, how we store and protect it, and how to revoke access, see our Google API Disclosure.
9. International data transfers
Firetech operates from the Dominican Republic and the United States, and our sub-processors process data in various regions, including the United States. Where Personal Data is transferred out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) together with the contractual and technical protections offered by our sub-processors. You may request more information about these safeguards using the contact details below.
10. Data retention
We retain Personal Data for as long as your account is active and as needed to provide the Service. Voice-dictation audio is deleted immediately after transcription and is not stored. Tasks and boards are soft-deleted and can be recovered for a limited window before permanent removal. After an account is closed, we retain limited data only as required for legal, accounting, security, and dispute-resolution purposes, after which it is deleted or anonymized.
11. Security
We apply reasonable technical and organizational measures, including:
- Passwords stored as salted hashes; enforced password strength and login rate limiting.
- Encryption in transit (TLS) and at rest.
- Role-based access control and least-privilege access to production systems.
- Audit logging of changes within workspaces.
No system is completely secure. If a breach affects your Personal Data, we will notify you and the relevant authorities as required by applicable law.
12. Your privacy rights
Subject to your jurisdiction, you may have the right to:
- Access the Personal Data we hold about you and obtain a copy (portability).
- Correct inaccurate or incomplete data.
- Delete your data (“right to be forgotten”).
- Restrict or object to certain processing, including profiling.
- Withdraw consent at any time where processing is based on consent.
- Opt out of any sale or sharing of personal information — note we do not sell or share it. We do not discriminate against you for exercising your rights.
To exercise any right, email devteam@airobotix.net or contact your workspace administrator. We will respond within the timeframe required by law (generally within 30 days). We may verify your identity before acting. You may authorize an agent to act on your behalf. Account deletion removes your login credentials and profile; some collaboration history (for example, your name on past activity) may be retained where necessary for the integrity of shared records.
If you are in the EEA, UK, or Switzerland, you also have the right to lodge a complaint with your local data-protection supervisory authority.
13. Children’s privacy
The Service is a business tool and is not directed to children. We do not knowingly collect Personal Data from anyone under the age required by applicable law (16 in much of the EEA; 13 in the US). If you believe a child has provided us data, contact us and we will delete it.
14. Changes to this policy
We may update this policy to reflect changes to the Service or applicable law. We will post the updated version with a new “Last updated” date and, for material changes, notify you by email or within the platform. Your continued use of the Service after an update means you accept the revised policy.
15. Contact
For privacy questions or to exercise your rights, contact our team at devteam@airobotix.net.
Firetech Corp
Calle Mauricio Báez #262, Ensanche La Fe, Santo Domingo, Distrito Nacional, Dominican Republic
7442 NW 55th Street, Miami, FL 33166, United States
See our Contact & Support page for more ways to reach us.