1. Who We Are
Refix Inc. (“Refix”, “we”, “us”, or “our”) provides two products:- Refix (formerly called Prism), an AI assistant that works through Slack and the web to answer questions, analyze connected business data, search connected knowledge sources, and run scheduled monitoring; and
- Refix Analytics, our earlier website and product analytics service, including its tracking script and Framer plugin.
2. Our Role
We act as a data controller for personal data we decide how and why to process, such as account, billing, support, and Refix website data. We generally act as a data processor when a customer uses Refix to process data from its Slack workspace, connected services, databases, or knowledge sources, or uses Refix Analytics to collect data about visitors to the customer’s website. The customer is the controller of that data and is responsible for providing required notices, establishing a lawful basis, and honoring requests from its users and visitors. We process that data on the customer’s instructions, the applicable agreement, and this policy.3. Personal Data We Collect
Account, billing, and support data
We may collect:- name, work email address, organization, role, and account identifiers;
- authentication and workspace information;
- subscription, billing, transaction, and invoice information (payment-card details are handled by our payment provider);
- communications with us, including support requests and feedback; and
- service usage, device, browser, IP address, diagnostic, security, and audit logs.
Refix (formerly Prism)
Depending on the features a customer enables, Refix may process:- Slack workspace, channel, thread, and user identifiers, profile details such as name, email, locale, and time zone, and messages or files sent to or made available to Refix;
- prompts, conversations, query history, generated answers, charts, files, feedback, and scheduled watcher configurations and results;
- integration settings, account or project selections, OAuth tokens, API credentials, and other connection information;
- data retrieved from customer-authorized services and databases to answer questions or perform monitoring, such as analytics, advertising, billing, commerce, CRM, support, project-management, and data-warehouse information;
- documents, messages, file metadata, and extracted text or chunks from knowledge sources a customer chooses to connect; and
- organizational context, saved memories, metadata, and generated insights used to provide more relevant answers and continuity between sessions.
Refix Analytics
When a customer installs Refix Analytics on a website, the service may collect:- a randomly generated browser identifier stored locally and associated with that customer’s domain;
- session and page-view information, including page path or URL, page title, referrer, and UTM campaign parameters;
- interactions with links, buttons, and other clickable elements, including automatically generated event labels, and scroll depth; and
- browser, country, device type, operating system, language, and screen resolution.
Our websites and marketing pages
When you visit or sign in to a Refix website, we and our vendors may use cookies, pixels, scripts, local storage, and similar technologies. These may collect device and browser data, IP address, pages viewed, interactions, referral and campaign information, and identifiers. Some vendors may help associate a business visit with a company or business contact record. We use this information to operate our sites, understand traffic, measure marketing, detect fraud and abuse, identify company-level interest, and communicate with relevant business contacts. This website activity is separate from Refix Analytics’ cookie-less customer-site tracking. You can use your browser controls to limit cookies. For supported visitor-identification services, you can also use Retention.com’s opt-out and RB2B’s GDPR opt-out.Data from other sources
We may receive information from your employer or workspace administrator, authentication and integration providers, payment providers, support and marketing vendors, and publicly available business sources.4. How We Use Personal Data
We use personal data to:- provide, personalize, maintain, and secure the Services;
- authenticate users and administer accounts, workspaces, integrations, and subscriptions;
- retrieve customer-authorized data and generate answers, analyses, summaries, charts, alerts, and other requested output;
- operate Refix Analytics and produce website and product analytics for the relevant customer;
- troubleshoot issues, monitor performance, prevent fraud or abuse, and improve reliability;
- provide support and communicate about the Services;
- understand use of our websites and market our business-to-business Services;
- comply with law, enforce our agreements, and protect rights, safety, and property; and
- create aggregated or de-identified information that cannot reasonably identify an individual.
5. Connected Services and Google API Data
Refix accesses a connected service only after a customer or authorized user configures the connection or grants permission. Depending on the integration, Refix may query services such as Slack, Google Analytics, Google Ads, Google BigQuery, Google Drive, databases, data warehouses, analytics tools, CRM systems, support platforms, billing platforms, commerce platforms, and project-management tools. We use connected data to provide the requested Refix feature. We may store connection credentials, selected account and project metadata, query and conversation history, retrieved results, generated outputs, and selected document content or chunks needed for knowledge retrieval and continuity. Refix is not intended to create a permanent copy of an entire connected database or file system, although saved knowledge sources, outputs, memories, and query results may contain portions of connected data. You can disconnect integrations in Refix or through the relevant provider. Disconnecting stops future access but does not automatically delete data already retained in Refix; you or your administrator may request deletion as described below. Refix’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Data obtained from Google Workspace APIs is not used to develop, improve, or train generalized or third-party AI models. You can revoke access through Google Account permissions or Refix’s integration settings.6. AI Processing
Refix uses third-party AI and cloud model providers to understand requests and generate outputs. Depending on configuration and availability, these may include Amazon Web Services (Amazon Bedrock), Anthropic, OpenAI, and Google. We send these providers only the prompts, connected data, conversation context, and instructions needed to provide the relevant feature. We do not permit customer data to be used to train providers’ generalized models where provider controls or contractual terms allow us to prevent that use. AI providers may retain data for limited periods for security, abuse prevention, or legal compliance under their applicable terms. AI-generated output may be inaccurate. Customers and users should review output before relying on it, especially for important decisions.7. How We Share Personal Data
We may share personal data:- with infrastructure, hosting, database, authentication, payment, email, customer-support, analytics, monitoring, integration, and AI providers that process data for us;
- with connected services at a customer’s direction, including when Refix reads from or takes an authorized action in those services;
- with a customer’s workspace administrators and other authorized workspace members;
- with professional advisers, auditors, insurers, and authorities where reasonably necessary;
- to comply with law or protect the rights, safety, and security of Refix, our users, or others; and
- in connection with a merger, financing, acquisition, reorganization, or sale of all or part of our business, subject to appropriate safeguards.
8. International Transfers and Hosting
Our managed core application and analytics infrastructure is hosted in the European Union. We are a United States company, and some service providers may process data in the United States or other countries. Those countries may have different data-protection laws. Where required, we use appropriate safeguards for international transfers, such as contractual protections. For customer-hosted deployments of Refix, the customer determines the hosting location and may directly configure certain infrastructure and model providers.9. Security and Tenant Separation
We use reasonable technical and organizational measures designed to protect personal data, including encryption in transit and at rest where supported, access controls, credential protection, backups, monitoring, and logical separation of customer environments and data. No system is completely secure, and we cannot guarantee absolute security. Customers are responsible for managing their users, integration permissions, credentials, and the data they choose to make available to the Services.10. Retention and Deletion
We retain personal data for as long as reasonably necessary to provide the Services, maintain security and business records, comply with law, resolve disputes, and enforce agreements. Retention varies by the type of data, customer configuration, deployment, and legal requirements. When a customer disconnects a source, closes an account, or requests deletion, we delete or de-identify applicable data within a reasonable period unless we must retain it by law or it remains in backups for a limited period. A customer may have its own retention settings or obligations. If you submitted data through a customer’s website or workspace, contact that customer first; we will assist the customer with a valid request as required by our agreement and applicable law. For request steps and the information to include, see our Data Deletion Instructions.11. Your Privacy Rights
Depending on where you live and subject to legal exceptions, you may have the right to:- access and receive a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion;
- restrict or object to processing;
- receive certain data in a portable format;
- withdraw consent where processing is based on consent; and
- lodge a complaint with your local data-protection authority.
