Who this notice is from
Firehoz is a lead-capture and engagement platform operated by [LEGAL ENTITY NAME] (“Firehoz”, “we”, “us”), registered at [REGISTERED ADDRESS]. For any privacy question or to exercise a right, contact [PRIVACY CONTACT EMAIL] (grievance officer: [NAME], [CONTACT]).
Two different roles — read this first
Firehoz processes personal data in two distinct roles, and your rights differ by which one applies:
- For a Firehoz customer’s website visitors — when you fill in a form on a site that runs the Firehoz beacon, Firehoz acts as a processor on behalf of that customer (the controller). Your relationship is with that business; they decide why your data is collected and how long it is kept. Requests about that data should go to the business whose site you used, though we help them action them (see Your rights).
- For Firehoz customers (the operators who sign up) — for your own account data, Firehoz is the controller.
What the beacon captures — and what it deliberately does not
The drop-in beacon is built to capture leads, not to surveil. In the product’s own code it:
- Respects Do Not Track. If your browser sends the DNT signal, the beacon does nothing at all.
- Never captures password, hidden, or payment fields, and skips login / sign-in / password-reset / OTP forms entirely — those are recorded as a bare event with no field contents.
- Does not load third-party trackers, fingerprint the canvas, or use cross-site cookies.
When you do submit a genuine lead form, it captures the fields you entered (typically name, email, phone, and your message), the page URL, and a short interaction trail (which pages on that one site you viewed) so the business can gauge intent.
What we store
Against a customer’s workspace we may hold: contact records (name, email, phone, company), the submissions you sent (including the raw form fields), the resulting lead and its status, any messages exchanged, behavioural events, and a derived “intent” score. For account holders we store your name, email, and workspace settings.
Isolation between customers
Each customer’s data is isolated at the database level, not merely by application logic: the request-serving database role cannot bypass row-level security, and every query is scoped to a single tenant. One customer cannot read another customer’s data.
Who else processes the data (sub-processors)
We rely on a small number of infrastructure providers to run the service. This list must be confirmed and kept current: [HOSTING PROVIDER] (application + database hosting), [OBJECT STORAGE] (media), and [EMAIL PROVIDER] (transactional sign-in email). Where you connect your own mailbox to send replies, your outbound email goes through the provider you choose, and the credentials for it are stored encrypted. We do not sell personal data to anyone.
Retention
Short-lived behavioural events are automatically pruned on a rolling basis (currently after about seven days). Contact, submission and lead records are retained until the controlling business deletes them or closes the workspace. [Confirm the retention periods your business commits to.]
Your rights
The product is built so these can actually be honoured, not just promised:
- Access & portability — a workspace can export its contacts and leads as CSV.
- Erasure — a person can be erased on request. Erasure clears the contact record and the personal content that would otherwise let them be reconstructed, including the raw form payloads, message bodies, drafts and behavioural signals — not just the obvious columns.
- Deletion of a whole workspace — a workspace owner can purge all of a workspace’s captured data.
Because for website-visitor data the business whose site you used is the controller, please direct such requests to them; we support them in carrying the request out. For your own Firehoz account, contact [PRIVACY CONTACT EMAIL].
Legal basis, transfers & governing law
[State the lawful basis you rely on, any cross-border transfer mechanism, the governing law and the applicable data-protection regime — e.g. India’s DPDP Act 2023 and/or the GDPR — for your jurisdiction. This section is a placeholder and must be completed by counsel; nothing here should be read as a claim of compliance with any specific regime.]
Changes
We may update this notice; material changes will be reflected in the “last updated” date above.