This is a non-binding English translation provided for your convenience. The legally binding version of this document is the German original („Deutsche Fassung“).

Privacy Policy

1. Data controller

AGAPE INNOVATIONS GROUP INC.
18 King Street East, Unit 1400
Toronto, ON M5C 1C4
Canada
Email: kontakt@hazonlive.com

Corporation incorporated under the laws of the Province of Ontario, Canada. AGAPE INNOVATIONS GROUP INC. is the service provider and the controller within the meaning of Article 4(7) GDPR for the processing of personal data on hazonlive.com.

2. Collection and processing of personal data

We collect personal data when you register, use our services or get in touch with us. This includes:

  • Name and email address (on registration)
  • Usage data (chat histories, uploaded documents)
  • Payment data (processed via the payment service provider Stripe, not stored by us)
  • Technical data (IP address, browser, device)
  • Data of connected channels, for Facebook and Instagram e.g. Page ID, Page name, encrypted access token and the ID and username of the Instagram account, as well as IDs and links of published posts and error messages from Meta (details in section 4c)

3. Legal bases

Processing is carried out on the basis of:

  • Article 6(1)(b) GDPR (performance of a contract)
  • Article 6(1)(a) GDPR (consent)
  • Article 6(1)(f) GDPR (legitimate interests)

4. Use of artificial intelligence

Hazonlive uses AI models for text generation, document analysis and image generation. The AI providers are listed in detail as processors in section 6. The following applies:

  • Your inputs (prompts, conversation histories, image descriptions) are transmitted to the AI providers
  • The AI providers (Anthropic, OpenAI and Google as a backup image model) process the data in the USA; the transfer is based on Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR
  • In accordance with the providers’ API terms, inputs are not used to train the AI models
  • All AI-generated content is labelled as such within Hazonlive; published social media posts carry no automatic AI notice (see section 4c)
  • Further information: AI transparency notice

4a. AI-assisted processing of connected email mailboxes

When you connect an email account (e.g. Gmail) to Hazonlive, the platform regularly retrieves incoming messages and processes them with AI: detecting whether a reply is needed, sorting them into categories (e.g. customer enquiry, appointment, invoice, newsletter) and preparing draft replies. The following applies:

  • The sender's name and address, the subject line and the shortened message text (at most 4,200 characters, including quoted earlier messages) are transmitted to the AI providers; attachments are neither retrieved nor transmitted (data minimisation)
  • To learn your writing style, selected messages you have sent yourself may be read; a shortened excerpt is passed to the AI providers as a style example within the prompt (not to train the models). We delete these examples as soon as you disconnect the mailbox.
  • So that no enquiry is missed that you have already opened in your mailbox, Hazonlive also retrieves opened messages from the last 48 hours, at most 30 per day. Of these, only enquiries, leads and appointment requests are kept; for all others we keep only a content-free identifier so that they are not processed again. Opened messages are neither marked nor moved in your mailbox.
  • To detect whether you have already answered an enquiry directly in your mailbox, Hazonlive reads only metadata of your sent messages (thread identifier, sending time, recipients, reference headers), never the text. Only the identifier and time of the detected reply are stored with the enquiry concerned.
  • Nothing is ever sent, deleted or permanently altered automatically — every reply requires your explicit approval (human-in-the-loop), and automatic sorting can be undone at any time
  • The legal basis vis-à-vis the senders of your emails is Article 6(1)(f) GDPR (legitimate interest in the efficient handling of incoming business communication); every AI categorisation is stored with a justification and is available for you to view
  • Access tokens for your mailbox are stored in encrypted form (AES-256-GCM); content from Google services is used exclusively for the functions described here that are visible to you and is not analysed for advertising purposes (Google API Services User Data Policy, Limited Use)
  • Incoming messages are automatically deleted from Hazonlive after 90 days (answered ones after 24 months); your mailbox itself remains unaffected

4b. Use of Google user data (Gmail and Google Calendar)

When you connect a Google account to Hazonlive, we access only the following Google user data and use it solely for the functions described below that are visible to you:

  • Incoming Gmail messages (read): retrieved so that your AI assistant can detect whether a reply is needed, sort messages into categories and prepare suitable draft replies. Besides unread messages, this also applies, within narrow limits, to messages opened in the last 48 hours (at most 30 per day, not from the Gmail categories Promotions, Social, Updates and Forums); of these, only enquiries, leads and appointment requests are stored permanently. The sender, the subject line and a shortened message text are transmitted to the AI providers, no attachments (data minimisation).
  • Sent Gmail messages (metadata only, read): thread identifier, sending time, recipients and reference headers, never the text. This lets Hazonlive detect whether you have answered an enquiry directly in Gmail, so that it is no longer shown as open.
  • Gmail drafts (create): draft replies are stored as drafts in your mailbox. Nothing is ever sent automatically — sending always requires your explicit approval.
  • Gmail labels and message filing (manage): Hazonlive creates its own label namespace, applies labels to messages and archives them to organise your inbox. Messages are not permanently deleted without your action.
  • Google Calendar events (read and create): when you confirm an appointment (e.g. via telephone reception), Hazonlive adds it to your Google Calendar; existing events are read to check for conflicts.
  • Email address of your Google account: used solely to identify the connected account.

Storage, disclosure and retention: access and refresh tokens are stored in encrypted form (AES-256-GCM, see section 5a); processing takes place on servers in the European Union (Frankfurt). Google user data is disclosed only to the processors listed in section 6, to the extent necessary to provide the functions described, and is never used for advertising or to train AI models. This complies with the Google API Services User Data Policy, including the Limited Use requirements. Incoming messages are automatically deleted from Hazonlive after 90 days (answered ones after 24 months); your Google account itself remains unaffected. You can revoke the connection at any time in the settings.

4c. Facebook and Instagram data (Meta)

When you connect a Facebook Page or an Instagram Business account to Hazonlive under “Integrations” in the settings, we receive the following data via Meta’s programming interface (Graph API). We use it to establish the connection, to publish posts on your Page or Instagram account and to show you the status of your publications. The legal basis is Article 6(1)(b) GDPR (performance of a contract); for error diagnostics, Article 6(1)(f) GDPR (legitimate interest in stable, error-free operation).

  • Sign-in (only while connecting): we exchange Meta’s sign-in token for a long-lived user token. If Meta does not return a list of Pages, we use the “debug_token” interface to read the details of this token, including the permissions granted and the Pages granted. We use the user token and these details only while connecting and do not store them.
  • Pages and linked Instagram accounts (read): for every Page you grant in Meta’s login dialog, we retrieve the Page ID, the Page name and the Page access token, plus the ID and username of an Instagram Business account linked to the Page. Hazonlive has no Page selection of its own; we store these details for all Pages you granted in Meta’s dialog. Facebook and Instagram each get a separate entry, and both contain the same Page access token.
  • What we do not retrieve: Hazonlive does not retrieve or store the name or email address of your Facebook profile. Hazonlive also does not retrieve Page insights, follower data, or posts, comments or messages from other people.
  • Publishing posts (write): Hazonlive sends Meta the post text with hashtags and, where applicable, one or more images (at most 10, together in one post). We pass images as links that Meta retrieves itself. If an image is not publicly accessible, is in an unsuitable format or is too large, we create a publicly accessible copy of it in our storage for this purpose; AI-generated images are held there at a publicly accessible address anyway. For Instagram, we then query the processing status and the link of the post. Hazonlive does not add a notice of AI generation to the published post; Hazonlive shows the “AI-generated” label only in its own interface.
  • When posts are published: we publish what you approve or schedule. The AI assistant can also schedule a post in the chat directly for a specific time; according to its instructions, it does so only when you give it a time. A post scheduled this way is published without a separate approval step. There is also an optional Autopilot. It is off by default, available only on paid plans, and can only be switched on by owners or administrators of a workspace after a confirmation prompt; a newly connected platform is initially excluded and has to be enabled separately. For the enabled platforms, the Autopilot schedules new posts without your individual approval, at the earliest for the following day, and they are published at the scheduled time. Until publishing starts, you can delete or move any scheduled post in the content calendar, or save it as a draft again in the editor. If you switch the Autopilot off, the posts it scheduled whose publishing has not yet started return to approval.
  • Records of publication: for each post we store the ID that Meta assigns to the published post and the link to it; if publishing fails, we store Meta’s error message (at most 600 characters).
  • Comments and messages: Hazonlive does not receive or store comments, mentions or direct messages from Facebook or Instagram via Meta’s interface. The app is not registered with Meta for any such notifications and does not request the permissions used to register a Page for them or to manage comments or messages.

Storage and disclosure: access tokens are encrypted with AES-256-GCM before they are stored and cannot be retrieved by your browser. The data described here is stored in our database or file storage at Supabase in Frankfurt; for use, the token is decrypted on our servers at Vercel in Frankfurt. A connection applies to the entire workspace: all members can see the connected Pages and accounts, and members with write access can have posts published through it and can disconnect it. If connecting fails, the error message, which may contain an excerpt of Meta’s response, is sent to Sentry (a US provider; data is stored in its EU data region in Frankfurt am Main) for error diagnostics; data we send to Sentry for error diagnostics and stability monitoring may also contain technical details of requests to Meta. We do not transmit Page or account names, IDs, access tokens, links to published posts or error messages from Meta to AI providers; chat notices about failed publications contain only the beginning of your post text, the channel and a reason worded by Hazonlive. The daily email summary is switched on for the person who completes the setup of a workspace, and can be switched off and on in the settings; it lists scheduled posts with a text excerpt, platform and time, and on Mondays also links to the posts published in the previous week, and it is sent via Resend. Sections 6 and 11 list these service providers, where they are based and the basis for transfers to third countries. Meta (for users in the EU: Meta Platforms Ireland Ltd.) is independently responsible for the processing on Facebook and Instagram themselves, including the published posts. We do not sell data from Facebook and Instagram and do not use it for advertising or to train AI models.

Retention and deletion: we store the connection data until you disconnect it or the workspace is deleted. You disconnect Facebook and Instagram separately under “Integrations” in the settings, using the bin icon; because both entries contain the same Page access token, please disconnect both. If you granted several Pages in Meta’s dialog, Hazonlive shows only one connection per platform; repeat the disconnection until no connection is shown for either Facebook or Instagram. Disconnecting deletes the respective entry, including the token, from our database immediately, but does not revoke the permission at Meta; the entry remains in the daily database backups until they are routinely overwritten (see section 9). IDs and links of published posts and error messages from Meta remain stored until you delete the post in Hazonlive or the workspace is deleted; deleting the post removes them from our database immediately. There is currently no fixed deletion period for them. Image copies made specifically for publishing remain until the workspace is deleted. Chat notices about failed publications are deleted with the respective chat history, by default 90 days after the last activity in it; because new notices appear in the same chat, each new notice extends the retention of the older ones, and pinned chats are exempt from this period; chats in the trash are deleted 90 days after being moved there (see section 9). Log entries about connecting, disconnecting and publishing are deleted after 12 months. Deleting a post in Hazonlive does not remove it from Facebook or Instagram. If you delete your user account, the workspaces you own are deleted with all connections, posts and log entries; a connection you set up in a workspace owned by another person remains there until it is disconnected there. Independently of this, you can revoke Hazonlive’s access in the settings of your Facebook account; we are not notified of this, and the data stored with us remains until it is deleted in one of the ways described. All ways to request deletion, including by email, are described on our page Delete your data.

5. Data storage

In our database, master data and usage data are stored on servers in the European Union:

  • Database: Supabase (AWS eu-central-1, Frankfurt)

The application is hosted by Vercel; its serverless functions are configured in the Frankfurt region (fra1), while Vercel’s primary processing facilities are in the USA. Transactional emails (login, password reset, notifications) are sent by Resend via AWS eu-west-1 (Ireland); Resend stores the data, including message content, in the USA.

AI prompts and image descriptions are transmitted for processing to the AI providers in the USA named in section 6 (Standard Contractual Clauses pursuant to Article 46 GDPR). Payment data is processed by the payment service provider Stripe. Vercel and Resend are based in the USA, Supabase in Singapore; for transfers to third countries, see section 11.

5a. Data security

We protect personal data — in particular sensitive content from connected Google services (Gmail, Google Calendar) — through technical and organisational measures pursuant to Article 32 GDPR:

  • Encryption in transit: All connections to Hazonlive and between our services are exclusively TLS-encrypted (HTTPS).
  • Encryption at rest: Data is stored encrypted in the database (encryption at rest, AWS eu-central-1, Frankfurt). Access and refresh tokens for connected mailboxes and social media channels are additionally encrypted at the application level using AES-256-GCM.
  • Access control and tenant isolation: Access to data is strictly separated by workspace and enforced at the database level through Row Level Security (RLS). Access to your data by our staff occurs only to the extent necessary for operation, support or legal obligations (principle of least privilege).
  • Operator support access: For troubleshooting we can open a time-limited view of your workspace ("view as customer"). This access is bound to a cryptographically signed session proof, requires two-factor authentication, expires automatically after 30 minutes (read mode) or 15 minutes (edit mode), and is logged. No email is sent while it is active.
    Content from connected mailboxes is blocked by default in this mode — message bodies, reply drafts and writing samples learned from your sent folder. It becomes visible only if you explicitly release access in the settings; that release is capped at eight hours, revocable at any time, and appears in your audit log. For Gmail mailboxes the block remains in place even with your release: Google's rules for access to mailbox data provide for no exception based on your consent.
  • Limited use of Google data: Content from Google services is used solely for the functions visible to you described in section 4a, is not disclosed to third parties (other than the processors listed in section 6 for the purpose of providing these functions) and is not used for advertising or to train AI models. This complies with the Google API Services User Data Policy, including the Limited Use requirements.
  • Data minimisation: Only the data required for the respective function is transmitted to AI providers (e.g. for the inbox the sender, subject line and shortened message text, no attachments).
  • Operations and monitoring: We use access logging and error/stability monitoring to detect security incidents. You can revoke mailbox connections at any time in the settings; revoked tokens become invalid and the associated connection is removed.

6. Processors and disclosure to third parties

We use the following service providers as processors (Article 28 GDPR) or as independent controllers:

Anthropic PBC (Claude)

  • Purpose: text AI, AI agents, document analysis, conversation processing, checking and describing images, and web search for the assistants (e.g. lead search, trend research)
  • Data transferred: user prompts, conversation histories, images and documents for checking, description and text recognition; for web search, the search term the assistant derives from your task. Anthropic runs the search with Brave Search as its own sub-processor. Search terms containing direct identifiers (email address, phone number, IBAN, card or tax number) are blocked technically
  • Server location: USA (SCCs pursuant to Article 46 GDPR)
  • Privacy: https://www.anthropic.com/privacy

OpenAI OpCo, LLC (text AI and semantic search)

  • Purpose: text AI as a fallback provider when Anthropic is briefly unavailable, and for assistants for which OpenAI is selected in your workspace; semantic search so that the assistants find relevant content (embeddings)
  • Data transferred: in the fallback or selection case, user prompts and conversation histories; for search, text passages from your knowledge base, summaries of chat conversations, texts of approved social media posts and the assistants' search queries
  • Server location: USA (SCCs pursuant to Article 46 GDPR)
  • Privacy: https://openai.com/policies/privacy-policy

OpenAI OpCo, LLC (image generation)

  • Purpose: AI image generation on user request
  • Data transferred: image prompts (text descriptions); when you have an existing image revised, that image; when an image is to show a person from your media library, the photos you marked as a person reference for this
  • Server location: USA (SCCs pursuant to Article 46 GDPR)
  • Privacy: https://openai.com/policies/privacy-policy

Google LLC (Gemini API)

  • Purpose: backup image model — used only if the primary image model (OpenAI) fails when generating a new image
  • Data transferred: image prompts (text descriptions) and up to three images most recently generated by AI in your workspace as a style reference
  • Server location: USA (SCCs pursuant to Article 46 GDPR)
  • Privacy: https://policies.google.com/privacy

Supabase Pte. Ltd. (Singapore)

  • Purpose: database, authentication and file storage
  • Server location: AWS eu-central-1, Frankfurt am Main; because the contracting party is based in Singapore, Standard Contractual Clauses (Article 46 GDPR) apply in addition
  • Privacy: https://supabase.com/privacy

Vercel Inc.

  • Purpose: hosting and delivery of the application
  • Server location: USA (the provider’s primary processing facilities); the application’s serverless functions are configured in Frankfurt (fra1). The transfer is based on the provider’s certification under the EU-U.S. Data Privacy Framework (adequacy decision, Article 45 GDPR)
  • Privacy: https://vercel.com/legal/privacy-policy

Plus Five Five, Inc. (Resend)

  • Purpose: sending transactional emails (sign-up confirmation, password reset, system notifications, and call notifications if the telephone feature is activated)
  • Data transferred: email address, user name, mail content; for call notifications also the caller’s name and phone number, the AI summary of the call (including urgency and action items) and the note
  • Server location: USA (storage, including message content and delivery logs); emails are sent via AWS eu-west-1, Ireland. The transfer is based on the Standard Contractual Clauses in its data processing addendum (Article 46 GDPR), which alone govern transfers from Switzerland; in addition, the provider is certified under the EU-U.S. Data Privacy Framework (Article 45 GDPR; re-certification currently under review)
  • Privacy: https://resend.com/legal/privacy-policy

Functional Software, Inc. (Sentry)

  • Purpose: error diagnostics and stability monitoring of the application on the basis of Article 6(1)(f) GDPR (see section 8). With your consent (cookie banner: „Alle akzeptieren“ / “Accept all”) additionally session replay for error analysis — text inputs are masked and media blocked in the process.
  • Data transferred: technical error and performance data (browser, device, error message); for errors on our servers also details of the request concerned, including the IP address, and error messages that may contain excerpts of responses from connected services; from your browser, with consent, additionally IP address and masked session recordings
  • Server location: Sentry’s EU data region in Frankfurt am Main; because the provider is based in the USA, Standard Contractual Clauses (Article 46 GDPR) apply in addition
  • Privacy: https://sentry.io/privacy/

Twilio Inc.

  • Purpose: telephone reception (incoming calls, call notes) — only relevant if the telephone feature is activated in your workspace
  • Data transferred: caller’s phone number, call metadata and call content — the caller’s speech is processed by Twilio for speech recognition and responses are spoken via text-to-speech; calls are not recorded
  • Server location: USA; the transfer is based primarily on the provider’s certification under the EU-U.S. Data Privacy Framework (Article 45 GDPR), alternatively on its Binding Corporate Rules (BCRs) or Standard Contractual Clauses (Article 46 GDPR) under its data processing addendum
  • Role: Twilio acts as a processor for providing the telephone service and as an independent controller for its own purposes (including operating as a communications provider, security and abuse detection, legal obligations, product improvement); this concerns connection and usage data and, to that extent, also call content
  • Privacy: https://www.twilio.com/legal/privacy

Stripe (payment service provider)

  • Purpose: technical payment processing (card payment, SEPA direct debit and others) on behalf of the provider
  • Data transferred: name, email address, billing address, payment data (PCI-DSS-compliant via Stripe)
  • Provider: Stripe Payments Canada, Ltd. (master agreement) and Stripe, LLC (processing), USA
  • Role: Stripe acts as a processor for payment processing and as an independent controller for its own purposes (including towards banks and payment method providers, fraud and risk checks, anti-money laundering and identity checks, legal obligations, product improvement)
  • Server location: among others the USA; the transfer is based primarily on Stripe, LLC’s certification under the EU-U.S. Data Privacy Framework (Article 45 GDPR), alternatively on Standard Contractual Clauses (Article 46 GDPR)
  • Personal data may be transferred, processed and stored outside of Canada and, as a result, may be subject to disclosure as required by applicable law
  • Privacy: https://stripe.com/privacy
  • Note: The purchase contract for paid plans is concluded with the provider (AGAPE INNOVATIONS GROUP INC.); Stripe handles the payment technically. For details, see Terms and Legal notice (Imprint).

7. Your rights

You have the right to:

  • Access to your stored data (Article 15 GDPR)
  • Rectification of inaccurate data (Article 16 GDPR)
  • Erasure of your data (Article 17 GDPR)
  • Restriction of processing (Article 18 GDPR)
  • Data portability (Article 20 GDPR)
  • Objection to processing (Article 21 GDPR)
  • Withdrawal of consent given (Article 7(3) GDPR)

To exercise your rights, please contact us at: kontakt@hazonlive.com

8. Cookies and consent

We use technically necessary cookies for authentication. Error diagnostics via Sentry (see section 6) are based on Article 6(1)(f) GDPR (legitimate interest in stable, error-free operation) and do not depend on your consent: we report errors on our servers as well as technical error and performance data from your browser. Only with your consent (“Accept all” in the cookie banner) do error diagnostics in your browser additionally transmit your IP address and further request data, and do we enable session replay (text inputs are masked, media blocked). We do not use marketing or advertising cookies. You can change your choice at any time via “Cookie settings” in the footer.

9. Retention period

Personal data is deleted as soon as the purpose of storage no longer applies. If you delete your user account, we delete it immediately together with the workspaces you own and all data stored in them. In workspaces owned by other people, content and log entries you created may remain without being linked to your account; for connections to Facebook and Instagram, see the last paragraph of this section.

We automatically delete chat histories with the agents, including attached images, 90 days after the last activity in them. Chats you move to the trash are permanently deleted 90 days after being moved; until then you can restore them or delete them permanently at any time. Pinned chats are exempt from automatic deletion as long as they are pinned and not in the trash.

Backups: our hosting provider Supabase backs up the database automatically every day. Data we delete from the database remains in these backups until they are routinely overwritten; on our current plan, Supabase keeps the backups of the last 7 days. Files from our file storage (e.g. images) are not included in these database backups.

Results of the legal assistant (contract traffic light, GDPR check, DPA draft, legal question) are stored as a history so you can review them again. Only the structured results and metadata are kept, never the full contract or input text. They are deleted automatically after 90 days, and every entry can also be deleted manually at any time.

We store connection data for Facebook and Instagram (IDs, names, encrypted access tokens) until you disconnect the respective connection or the workspace is deleted. IDs and links of published posts and error messages from Meta remain stored until you delete the post in Hazonlive or the workspace is deleted; deleting the post removes them from our database immediately. There is currently no fixed deletion period for them. Image copies made specifically for publishing remain until the workspace is deleted. Log entries about connecting, disconnecting and publishing are deleted after 12 months. If you delete your user account, connections you set up in a workspace owned by another person remain there until they are disconnected there. Details in section 4c.

10. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority.

11. Transfer of data to third countries

Personal data is transferred to the USA in the context of AI processing (Anthropic, OpenAI, Google as a backup image model), telephone reception (Twilio) and payment processing (Stripe); this includes the search terms of the web search, which runs via Anthropic. For Twilio and Stripe, the transfer is based primarily on their certification under the EU-U.S. Data Privacy Framework (Article 45 GDPR), alternatively on the mechanisms named in section 6. For error diagnostics (Sentry), the provider is a company based in the USA; the data is stored in Sentry’s EU data region in Frankfurt am Main. The contracting party for database and file storage (Supabase) is a company based in Singapore; the data is stored in Frankfurt am Main. The other transfers are based on the Standard Contractual Clauses of the European Commission pursuant to Article 46(2)(c) GDPR, together with supplementary technical and organisational measures of the respective providers.

Hosting (Vercel) and email delivery (Resend) are provided by companies based in the USA. The application’s serverless functions are configured in the Frankfurt am Main region, while Vercel’s primary processing facilities are in the USA; emails are sent via the Ireland region, and Resend stores the data in the USA. Transfers to Vercel are based on its certification under the EU-U.S. Data Privacy Framework and the European Commission’s adequacy decision for it (Article 45 GDPR). Transfers to Resend are based on the Standard Contractual Clauses in its data processing addendum (Article 46(2)(c) GDPR), which alone apply to transfers from Switzerland; in addition, Resend is certified under the EU-U.S. Data Privacy Framework (Article 45 GDPR; re-certification currently under review).

In addition, the operator AGAPE INNOVATIONS GROUP INC., based in Toronto, Canada, has access to personal data as the controller. This transfer is based on the adequacy decision of the European Commission for Canada (Article 45 GDPR), which applies to commercial organisations subject to the Canadian data protection act PIPEDA.


As of: 28 September 2026.