Always Staffed legal

Privacy Policy

How Always Staffed collects, uses, stores, shares, and protects information across the website, dashboard, client agents, connected tools, AI processing, and managed Content Agent services.

Last updated: September 2, 2026
Client agreements: If you have a signed service agreement, statement of work, order form, or data processing addendum with Always Staffed, that document may add more specific terms for the covered services.

1. Scope

Always Staffed is a registered Alberta trade name of NBGallo Enterprises Ltd., a corporation incorporated under the Canada Business Corporations Act under corporation number 1482773-2 and registered to carry on business in Alberta. The trade-name registration is effective August 5, 2026. In this Privacy Policy, “Always Staffed,” “we,” “us,” and “our” mean NBGallo Enterprises Ltd.

This Privacy Policy applies to Always Staffed websites, including alwaysstaffed.com and dashboard.alwaysstaffed.com, inquiry forms, client dashboards, Telegram-based client agents, AI-assisted Content Agent workflows, social-content operations, and related onboarding or support channels.

If a signed client agreement, statement of work, data processing addendum, or platform-specific authorization applies, that document may add more specific privacy, security, retention, and processing terms for the covered services.

2. Information we collect

We collect information you provide directly, information generated while using our services, and limited technical information needed to operate the sites and workflows.

Website and inquiry dataName, email, company, website, phone number, preferred contact method, business needs, workflow notes, tool details, approval requirements, booking details, and messages sent through forms or email.
Dashboard account dataEmail address, authentication status, dashboard invitation status, client membership, account preferences, connection status, billing status, and support or onboarding notes.
Client business contentBrand notes, service descriptions, offers, content calendars, captions, drafts, approval decisions, uploaded photos, videos, files, media metadata, corrected asset details, and performance notes.
Connected platform dataNon-secret authorization metadata, connection state, approved Page or account labels, and platform data needed for the authorized feature. Where available, aggregate Facebook and Instagram performance snapshots are collected daily and retained for up to 90 days for reporting and same-platform content learning. We do not retain raw API responses, comments, messages, audience identities, person-level reactions, or other member-level data for this use.
Chat and agent dataTelegram messages, uploaded media, approval responses, edit requests, task instructions, operational summaries, and agent handoff history used to run the client workflow.
Technical dataLog data, IP-derived security signals, device/browser information, cookie or session information, page views, form events, error logs, and analytics used to keep the service working.
Payment and onboarding dataPayment status, Stripe customer or subscription identifiers, invoice status, product plan, onboarding state, and related account setup metadata. We do not store full card numbers on our servers.

3. How we use information

4. AI processing, service monitoring, and human approval

Always Staffed uses AI systems to help summarize, classify, draft, analyze, organize, and review Content Agent work. AI outputs may include captions, content plans, summaries, asset descriptions or tags, post ideas, performance notes, draft content, or recommendations.

Authorized Always Staffed personnel and Always Staffed-operated automated agents may access and review client-agent chat messages, media, instructions, approvals, and related operational records when reasonably necessary to operate, supervise, support, troubleshoot, secure, audit, or adjust the service. Review may be routine or incident-driven. Client chat content is not sold, publicly disclosed, used for unrelated marketing, used across clients, or used for generalized AI model training. It may be disclosed only to personnel, contractors, and service providers with a business need and confidentiality obligations, Client-authorized users, or where legally required.

AI-generated output can be incomplete, inaccurate, or inappropriate for a specific business context. Unless a written agreement says otherwise, posts, publishing, scheduling, deletes, and material content or connected-account changes require human approval through the configured workflow.

When a client connects a client-owned AI account, such as GPT, ChatGPT, Codex, Grok, or SuperGrok, usage may be subject to that provider's plan limits, terms, privacy policy, retention settings, and account controls.

5. Third party processors and platforms

We use service providers and connected platforms to operate the business and client workflows. These providers receive only the information reasonably needed for the relevant purpose.

Platform availability, data access, API limits, review requirements, permissions, and policy rules are controlled by the relevant provider. We cannot guarantee that any third party platform will continue to provide the same access, pricing, uptime, or features.

6. Connected accounts and authorization

Clients may authorize Always Staffed to connect social accounts, AI accounts, and other tools required for the agreed Content Agent services. Clients are responsible for having the rights and administrative authority needed to connect those accounts and share the related data.

We store non-secret connection status and operational metadata in the dashboard where possible. OAuth tokens, API keys, bot tokens, and similar secrets should stay in the appropriate provider, client runtime, or secure secret storage. We do not intentionally expose secrets in the browser, public dashboards, Telegram messages, public logs, or marketing pages.

Clients can revoke many connected account permissions through the provider's own account settings. Revoking access may stop related workflows.

6A. Meta, Facebook, and Instagram integrations

Before a Meta, Facebook, or Instagram connection begins, Always Staffed identifies the approved API product, requested permissions, purposes, retention posture, and withdrawal method. The connection begins only after an authorized client user takes an affirmative action.

Where available, Always Staffed collects aggregate Facebook and Instagram performance snapshots daily for reporting and same-platform content learning. These snapshots are retained for up to 90 days and then deleted, or deleted earlier after disconnection, authorization loss, a verified deletion request, or a stricter platform requirement.

Facebook information is used only for the same client's Facebook service, and Instagram information only for the same client's Instagram service. We do not use platform information for another client, another platform, advertising targeting, unrelated outreach, or generalized AI model training. We do not retain raw API responses, comments, messages, audience identities, person-level reactions, or other member-level data for this use.

Authorization can be withdrawn through the dashboard, the provider's settings, or by emailing contact@alwaysstaffed.com. Disconnect stops new collection, revokes the local authorization, selectively deletes affected observations and references, and starts any available remote revocation process.

6B. LinkedIn integration

If you connect a LinkedIn account or Company Page, Always Staffed uses the official approved connection and permissions available for the enabled service, including approved Company Page publishing. Features remain unavailable when the required access, account role, or authorization is missing.

For the current publishing service, Always Staffed processes the content, Page authorization information, connection status, approval records, and delivery results needed to prepare and publish approved Company Page posts. LinkedIn performance reporting and learning are not enabled unless the required product access is approved and implemented.

You may withdraw authorization through LinkedIn's connected-app settings, the Always Staffed dashboard, or by emailing contact@alwaysstaffed.com. Withdrawal stops future LinkedIn activity and begins disconnection and deletion of eligible connection information under the applicable service and legal retention rules.

7. Client media, drafts, and platform content

Uploaded photos, videos, files, captions, brand materials, and post drafts may be stored in private client storage and used to prepare content for review. AI-generated descriptions, tags, labels, or recommendations are draft metadata until approved or corrected by the client or operator.

Clients should not upload media, personal information, regulated information, third party content, or customer content unless they have the right to use it for the intended workflow. If a client asks us to delete, correct, reject, or avoid an uploaded asset, we will apply the request where practical, subject to backups, legal obligations, platform retention, and service-continuity needs.

8. Legal bases and business purposes

Depending on the context, we process information to perform a contract, prepare a proposal, operate requested services, comply with law, protect security, support legitimate business operations, or follow consent and authorization given by the client or user.

9. Analytics, cookies, and tracking

We use limited analytics to understand whether the public website and authenticated dashboard work as intended. When optional analytics is enabled with your choice, Google Analytics 4 measures public-site page and conversion events, and PostHog measures allowlisted product events in the authenticated dashboard.

Optional analytics is off until you make an affirmative analytics choice. You may decline without losing access to the public site or dashboard, and you may change your choice later through the persistent Analytics settings control.

Google Analytics may use first-party analytics cookies after consent. Our initial PostHog configuration uses manual events without autocapture, session replay, user identification, person profiles, or cross-session analytics cookies.

Analytics events may include a normalized page or feature label, CTA category, form-start or successful-submit status without field values, onboarding-step status, connection-flow status, sanitized error code, browser or device category, and consent state. We exclude names, email addresses, phone numbers, company names, form values, free-text messages, client content, social-platform data, Telegram content, uploaded media, prompts, dashboard invitation tokens, OAuth data, billing identifiers, full URLs with query strings, and unknown event properties.

Google signals, advertising personalization, remarketing, Google User-ID, PostHog autocapture, heatmaps, session replay, network capture, console capture, and person identification are disabled in the initial analytics configuration.

Connected platforms may use their own cookies, tracking, or account data when you authenticate with them or use their services. Their privacy policies apply to their handling of that data.

10. Data retention

Retention depends on the data category, approved purpose, platform policy, authorization status, client instructions, and legal obligations.

11. Security

We use reasonable technical and operational safeguards, including least-privilege access, tenant isolation, private storage, signed URLs where appropriate, role-based access, approval gates, separate client runtime boundaries where practical, and secret-handling controls. No internet-connected service is completely secure, and we cannot guarantee absolute security.

12. International processing

Always Staffed and its providers may process information in Canada, the United States, or other locations where we or our providers operate. Google may process analytics information in locations where it operates. The initial PostHog project is hosted in PostHog Cloud US. By using the site, dashboard, or services, you understand that information may be transferred and processed outside your province, state, or country and may be subject to the laws of those locations.

13. Your choices and requests

You may ask us to review, correct, export, restrict, or delete information you submitted, close your dashboard login, or request closure and deletion of a Client workspace by emailing contact@alwaysstaffed.com. We may need to verify your identity and authority before acting. Closing one user's login does not automatically delete a shared Client workspace or information needed by other authorized users.

A verified full Client account closure request covers eligible records under Always Staffed control, including the dashboard workspace, client-agent runtime, scheduled jobs, connected-account authorizations, uploaded media, drafts, and ordinary working records. Some information may be retained for security, legal, accounting, contract, dispute, audit, backup, or service-continuity reasons. Records held only in a Client-owned third party account must be removed through that provider when Always Staffed lacks authority or technical ability.

You may decline or withdraw optional analytics through the Analytics settings control. Withdrawal stops future optional collection and clears available first-party analytics identifiers where practical. Some deliberately anonymous analytics events cannot be reliably linked to a requester.

For connected third party accounts, you may also need to manage access, deletion, retention, or export requests directly with the relevant provider.

14. Children's data

Always Staffed services are intended for businesses and are not directed to children. Do not submit information about children unless it is necessary for an authorized Content Agent workflow and the client has the required legal authority and consent.

15. Changes to this policy

We may update this policy as our services, providers, legal requirements, or workflows change. The updated date above shows when the latest version was posted.

16. Contact

Questions or privacy requests can be sent to contact@alwaysstaffed.com.