Back to account creation

Privacy policy — Musaed

Operational Pilot contract · v0.1 · effective 2 August 2026

This is an operational Pilot document and is not final legal advice. Legal, commercial, backup/DR, and production notification approval remain required before production.

Scope and roles

Musaed is a multi-tenant SaaS platform for conversations, widgets, knowledge, AI, and human support. The customer organization determines the purposes for visitor data; Musaed processes it to provide, secure, and operate the service under the final agreement. Subprocessors and data regions require approval before production.

Data categories and purposes

Data may include accounts and memberships, organization settings, visitors and customers, conversations and messages, knowledge and embeddings, operational/security records, and privacy requests. It is used for authentication, conversation delivery, grounding, security, necessary measurement, and ACCESS/ERASURE fulfillment. Customer data is not used to train a general model without a separate contractual basis and consent.

Isolation and security

Isolation uses organization_id, PostgreSQL RLS, composite foreign keys, and separate roles. Object keys are server-generated; the read-only API and the worker that uploads/deletes ACCESS exports use separate capabilities. Secrets, tokens, and raw export contents are excluded from logs.

Retention and ACCESS

Pilot retention defaults are proposed, not final legal periods: closed conversations 24 months, raw files 90 days after successful processing, old knowledge versions 90 days, AI evidence 12 months, inactive anonymous visitors 90 days, and idempotency records 72 hours subject to contract alignment. Live ACCESS exports default to 7 days with a 25 MiB technical limit; after expiry downloads return 410, the worker deletes the object, and records EXPORT/REMOVED. Deleting the live copy does not prove deletion from backups or WAL.

Data-subject rights

Depending on law and the final agreement, rights may include access, a copy, correction, restriction, objection, and deletion. An organization administrator submits ACCESS or ERASURE after identity and tenant-scope checks. ACCESS is proven on staging; each ERASURE branch and production retention period needs separate acceptance.

Backups and status

Off-host backup/PITR and delivery from Alertmanager to an external receiver are not proven in this release. There is no final RPO/RTO or legal-compliance promise. A DR, subprocessors, and retention addendum must be approved before production.

Changes and contact

This version is PRIVACY-PILOT-AR-0.1. Changes to categories, purposes, subprocessors, or periods require a new version. Requests go through the customer organization’s support channel or designated privacy contact.