HoosAI Privacy Notice
Effective: 2026-05-06 · Last updated: 2026-05-06 · Contact: privacy@hoosai.biz
At a glance
- HoosAI operates a multi-tenant CRM platform on behalf of business customers ("tenants").
- For personal data about your contacts inside HoosAI, the tenant you work with is the data controller. HoosAI is a service provider / processor.
- HoosAI does not sell or share personal data, run advertising, or train AI models on customer data without explicit per-tenant opt-in.
- Audit logs retained at least 365 days for security and compliance.
- Data is stored in the United States by default; EU hosting available on request.
1. What we collect
From staff users: name, work email, MFA factor metadata, login history, and audit-log actions. From your tenant's CRM: whatever your tenant chooses to record (typically contact name, email, phone, address, communication history, transaction history). From your browser: functional cookies only — no advertising, analytics, or behavioral tracking.
2. Gramm-Leach-Bliley Act (16 CFR Part 313) disclosures
This section applies when your tenant has been flagged as a "financial institution" under §314.2(h) or as a service provider to one. The substantive disclosures below apply to nonpublic personal information ("NPI") HoosAI processes on your tenant's behalf.
2.1 Categories of NPI we collect
Per the platform's NPI inventory:
- Transaction history: invoice amounts, payment dates, status
- Contract financial terms: agreement values, schedules, fees
- Contact PII: name, email, phone, address (when associated with financial activity)
- Mixed free-form fields: email bodies, contract text, notes — to the extent these contain NPI based on tenant use
- Account identifiers: none currently stored; a CI guard (per §313.12) blocks introduction without explicit compliance review
2.2 How we use NPI
HoosAI uses NPI exclusively to provide the CRM service to your tenant under their direction. We do not use NPI for our own purposes, do not aggregate it across tenants, and do not provide it to subprocessors except as required to deliver the service (database hosting, email delivery, etc.) under contractual confidentiality and use-restriction terms.
2.3 Categories of NPI we disclose, and to whom
HoosAI does not disclose NPI to non-affiliated third parties for those parties' own purposes. The only disclosures are:
- Subprocessors (Supabase, Vercel, Doppler, Google Workspace) — each under a Data Processing Agreement that prohibits secondary use of NPI
- To your tenant's authorized users — under the tenant's configured access controls
- As required by law — subpoena, court order, regulatory request
2.4 §313.12 — account-number protection
HoosAI does not disclose customer account numbers or access codes to non-affiliated third parties for telemarketing, direct mail, or email marketing. A platform-level CI guard blocks new code paths that would do so.
2.5 Opt-out
Because HoosAI does not share NPI with non-affiliated third parties for those parties' own purposes, no §313.7 opt-out is required. If this changes for any tenant, an opt-out mechanism will be made available before the sharing begins.
2.6 Annual notice — §313.5 alternative delivery
HoosAI delivers the annual privacy notice required by §313.5 via this posted version, relying on the alternative-delivery exception (the conditions of which are documented in HoosAI's internal privacy policy). The page is updated at least annually; the "Last updated" date reflects the most recent material change. Material changes are also communicated via in-app notice for all affected users.
3. How we protect personal information
- Encryption at rest: AES-256-GCM via Supabase + AWS EBS
- Encryption in transit: TLS 1.2+ enforced via Vercel and Supabase
- Access control: per-tenant row-level security in the database; multi-factor authentication required for privileged roles; least-privilege role-based access control
- Logging: immutable audit log of privileged actions, retained 365 days minimum
- Testing: annual penetration test; semi-annual vulnerability scans
- Incident response: documented written incident response plan with a 30-day FTC notification commitment per §314.4(j)
4. Your rights
You may request access, correction, portability, or deletion of personal data we hold. Contact your tenant administrator or email privacy@hoosai.biz. We respond within 30 days (extended to 90 days for complex requests, with notice).
5. Changes to this notice
Material changes will be communicated via in-app notice for staff users on tenants flagged as GLBA-covered, and via this page for all readers. The "Last updated" date above reflects the most recent material change.
6. Contact
privacy@hoosai.biz · HoosAI · Qualified Individual: Nik Zufall