Privacy Policy · Alebex
Legal / Privacy

Privacy Policy

Privacy notice for ALEBEX websites, accounts, billing, support, security, integrations, and ALEBEX-controlled processing

Version 2.0.0 / Effective August 18, 2026 / Public privacy notice
Privacy Policy and DPA have different functions

This Privacy Policy describes information ALEBEX controls for website, account, billing, support, security, and corporate purposes. When ALEBEX processes customer communications or Customer Personal Data on a Customer’s behalf, the Data Processing Addendum and the Customer’s instructions govern that processing.

01

Scope and ALEBEX roles

This ALEBEX AI Privacy Policy explains how ALEBEX AI Corp. (“ALEBEX,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information through alebex.ai, app.alebex.ai, our Services, support channels, business relationships, integrations, events, and other interactions.

For account, website, billing, security, legal, marketing, procurement, and direct business relationship information, ALEBEX generally acts as the organization, controller, or equivalent role. For Customer Personal Data submitted to the Services for Customer Communications, ALEBEX generally acts as a processor, service provider, contractor, vendor, agent, or subprocessor under the DPA.

A Customer controls the purposes and recipient relationship for Customer Communications. Recipients should direct access, correction, deletion, opt-out, do-not-call, recording, or communication requests to the business that contacted them. ALEBEX may assist that business as required by law and the DPA.

02

Information ALEBEX collects

ALEBEX may collect the following categories, depending on how a person or organization uses the Services:

  • account and identity information, including name, business name, role, email, telephone number, address, username, login and authentication information, and authority details;
  • business, KYC, partner, procurement, and verification information, including registration, ownership where requested, website, industry, use case, countries, tax information, and risk information;
  • billing and transaction information, including plan, currency, invoices, usage, payment status, tax information, and limited payment details received from payment processors;
  • Customer Content and communications data, including contact and CRM fields, messages, email, call audio, recordings, transcripts, summaries, prompts, scripts, knowledge, routing, calendar data, and workflow configuration;
  • service and device information, including IP address, browser, user agent, device, session, cookies, log-in events, Account activity, API usage, errors, traffic patterns, and audit logs;
  • support, security, complaint, and correspondence information, including tickets, call samples, screenshots, abuse reports, opt-outs, legal requests, and incident records;
  • integration information from services a Customer connects, subject to the Customer’s configuration and the integration permissions; and
  • public, professional, business-contact, and event information received from a person, employer, partner, referral source, or legitimate public source.
03

How ALEBEX uses information

ALEBEX may use information to provide, configure, authenticate, operate, secure, monitor, support, maintain, bill, and improve the Services; process transactions and taxes; manage Accounts, partners, and customer relationships; communicate about service, legal, billing, security, and product changes; prevent fraud and abuse; investigate complaints and incidents; enforce agreements; comply with law; protect rights and safety; and perform other purposes disclosed at collection or authorized by the relevant person or Customer.

ALEBEX may use de-identified and aggregated information for security, fraud prevention, capacity planning, analytics, quality control, research, and service development, provided the information does not reasonably identify a Customer, End Client, Recipient, individual, or confidential business record.

ALEBEX does not sell personal information or share it for cross-context behavioral advertising. ALEBEX does not use identifiable Customer Personal Data to train a general-purpose or shared AI model without the Customer’s express opt-in.

04

Customer Content and communications data

Customers may submit information about Recipients, leads, customers, users, employees, applicants, and other persons. ALEBEX processes this information to provide the Services according to the Customer’s instructions, Account configuration, Service Agreement, and DPA.

The Customer is responsible for the lawfulness of its collection and use, including privacy notices, consent or other lawful basis, communication permissions, recording and transcription, retention, and responding to requests. ALEBEX may restrict or suspend processing that appears unauthorized, illegal, insecure, or inconsistent with the Agreement.

05

Service providers, integrations, and disclosure

ALEBEX may disclose information to service providers that support cloud infrastructure, telecommunications, telephone numbers, speech or voice processing, language-model processing, transcription, communications delivery, calendar or CRM integrations, security, monitoring, support, billing, and payment. These providers are authorized to process information for the applicable service and are subject to contractual or legal protections appropriate to their role.

ALEBEX does not publish the full subprocessor list. Customers and prospective customers with a legitimate business need may request it under the ALEBEX AI Subprocessor Information page.

ALEBEX may disclose information to an Affiliate, successor, acquirer, financing party, adviser, auditor, insurer, regulator, carrier, service provider, law-enforcement body, court, or other person where reasonably necessary for a corporate transaction, legal compliance, dispute, collection, security, fraud, safety, recipient protection, service operation, or enforcement. ALEBEX will limit disclosure where reasonably practicable.

Customer-initiated integrations may receive information according to Customer’s configuration and the provider’s own terms. Customers should review integration permissions and revoke access when no longer needed.

06

Cross-border processing

ALEBEX is based in British Columbia, Canada. Information may be processed in Canada, the United States, and other jurisdictions where ALEBEX or authorized service providers operate. Those jurisdictions may have different privacy laws, and information may be accessible to courts, law-enforcement bodies, or regulators under local law.

For Customer Personal Data, cross-border processing is governed by the DPA, enabled territories, and any applicable transfer terms. Customers are responsible for providing required notices and obtaining required consent for their use.

07

Data retention

ALEBEX retains information for the period reasonably necessary for the purposes described in this Policy and as required or permitted for service operation, Customer instructions, security, fraud, billing, tax, audit, dispute, complaint, regulatory, legal hold, and evidence-preservation needs.

CategoryGeneral retention approach
Account and business relationship informationFor the active relationship and a reasonable period afterward for legal, security, billing, tax, support, and recordkeeping needs.
Customer Content and communications dataAccording to Customer configuration, product functionality, the DPA, and any Order Form, subject to lawful backup and preservation exceptions.
Billing, tax, and transaction recordsFor applicable tax, accounting, audit, collection, and legal periods.
Security and standard server logsGenerally up to 90 days for routine monitoring, with longer retention where needed for an incident, fraud, complaint, audit, or legal requirement.
Acceptance and legal recordsFor the duration of the relationship and a period sufficient to establish agreement, authorization, compliance, and dispute history.
Integration tokens and connected-account dataWhile the integration is active and for a limited period needed to complete disconnection, security, and deletion processes.

ALEBEX may de-identify information instead of deleting it where permitted. Backups may be deleted through ordinary rotation.

08

Security

ALEBEX uses administrative, technical, and physical safeguards appropriate to the Services and information, which may include access controls, available multi-factor authentication, encryption in transit, secure storage, credential management, logging, monitoring, vulnerability management, personnel confidentiality, and incident response.

No system is completely secure. Customers must protect their own credentials, devices, networks, integrations, user access, and Customer Content and must report suspected incidents promptly to security@alebex.ai.

09

Privacy choices and rights

Depending on location and relationship, a person may have rights to request access, correction, deletion, portability, withdrawal of consent, objection, restriction, or information about processing and disclosure. Rights may be limited by identity verification, legal exceptions, another person’s rights, privilege, security, fraud prevention, or ALEBEX’s lawful retention obligations.

For ALEBEX-controlled information, submit a request to compliance@alebex.ai. ALEBEX may verify identity and authority and may request enough information to locate the record. For information processed for a Customer, contact the Customer that controls the Account or communication. ALEBEX may forward the request to that Customer.

Recipients may report unwanted or suspicious ALEBEX-powered communications to abuse@alebex.ai. The report should include the telephone number or sender, date and time, calling business if known, and a brief description. ALEBEX may share the report with the responsible Customer to investigate and honor lawful requests.

10

Cookies, analytics, and website technologies

ALEBEX uses essential cookies and similar technologies for authentication, session management, security, preferences, and service operation. ALEBEX may use analytics to understand website and product usage, diagnose errors, improve performance, and measure communications. Browser or Account controls may allow certain choices; disabling essential technologies may prevent use.

11

Calendar and workspace integration data

Where a Customer connects a calendar, workspace, or scheduling account, ALEBEX may access account identity, calendar events or free/busy information, and permissions needed to create, update, or delete events according to Customer instructions. ALEBEX uses this data only to provide the requested integration functionality, secure the integration, and comply with law.

ALEBEX does not use connected-account data for advertising or to train a general-purpose or shared AI model. ALEBEX processes and transfers connected-account data according to the applicable provider terms and permissions. A Customer can disconnect the integration through the Account or revoke access through the provider’s security settings.

12

Children and business use

The Services are designed for business and professional use and are not directed to children. ALEBEX does not knowingly permit a child to create a self-service account. A Customer must not process child or minor data through the Services without an approved use, lawful authority, appropriate notices and consent, and any additional terms ALEBEX requires.

13

Changes and contact

ALEBEX may update this Privacy Policy to reflect law, Services, providers, security, or business practices. ALEBEX will post the updated version and effective date and may provide additional notice for significant changes.

TopicContact
Privacy requests and DPAcompliance@alebex.ai
Legal questionslegal@alebex.ai
Security incidentssecurity@alebex.ai
Abuse and unwanted communicationsabuse@alebex.ai
Registered office570 Dunsmuir Street, Vancouver, British Columbia, Canada