Always Staffed legal

Privacy Policy

How Always Staffed collects, uses, stores, shares, and protects information across the website, dashboard, client agents, connected tools, AI workflows, and managed content operations.

Last updated: July 28, 2026
Client agreements: If you have a signed service agreement, statement of work, order form, or data processing addendum with Always Staffed, that document may add more specific terms for the covered services.

1. Scope

Always Staffed is a service brand operated by NBGallo Enterprises Ltd., a corporation incorporated under the Canada Business Corporations Act under corporation number 1482773-2 and registered to carry on business in Alberta. In this Privacy Policy, “Always Staffed,” “we,” “us,” and “our” mean NBGallo Enterprises Ltd.

This Privacy Policy applies to Always Staffed websites, including alwaysstaffed.com, dashboard.alwaysstaffed.com, lead forms, client dashboards, Telegram-based client agents, AI-assisted workflows, social-content operations, phone or voice-agent demos, and related onboarding or support channels.

If a signed client agreement, statement of work, data processing addendum, or platform-specific authorization applies, that document may add more specific privacy, security, retention, and processing terms for the covered services.

2. Information we collect

We collect information you provide directly, information generated while using our services, and limited technical information needed to operate the sites and workflows.

Website and inquiry dataName, email, company, website, phone number, preferred contact method, business needs, workflow notes, tool details, approval requirements, booking details, and messages sent through forms or email.
Dashboard account dataEmail address, authentication status, setup codes, client membership, account preferences, connection status, billing status, and support or onboarding notes.
Client business contentBrand notes, service descriptions, offers, content calendars, captions, drafts, approval decisions, uploaded photos, videos, files, media metadata, corrected asset details, and performance notes.
Connected platform dataNon-secret authorization metadata, connection state, approved Page or account labels, and platform data needed for the authorized feature. Performance metrics are displayed live by default. We may retain a minimal, expiring derived observation only where the applicable platform policy permits it. We do not normally retain raw API responses, comments, messages, audience identities, person-level reactions, remote account identifiers, post identifiers, or permalinks for performance reporting.
Chat and agent dataTelegram messages, uploaded media, approval responses, edit requests, task instructions, operational summaries, and agent handoff history used to run the client workflow.
Call and voice workflow dataCaller details, call routing data, transcripts, summaries, recordings if enabled, intent classifications, booking notes, and alerts when a phone or voice-agent workflow is used.
Technical dataLog data, IP-derived security signals, device/browser information, cookie or session information, page views, form events, error logs, and analytics used to keep the service working.
Payment and onboarding dataPayment status, Stripe customer or subscription identifiers, invoice status, product plan, onboarding state, and related account setup metadata. We do not store full card numbers on our servers.

3. How we use information

4. AI processing and human approval

Always Staffed uses AI systems to help summarize, classify, draft, analyze, route, organize, and review work. AI outputs may include captions, summaries, asset tags, post ideas, reply drafts, call summaries, workflow notes, or recommendations.

AI-generated output can be incomplete, inaccurate, or inappropriate for a specific business context. Unless a written agreement says otherwise, client-facing sends, posts, publishing, scheduling, payment actions, customer-impacting actions, deletes, and important record changes require human approval through the configured workflow.

When a client connects a client-owned AI account, such as GPT, ChatGPT, Codex, Grok, or SuperGrok, usage may be subject to that provider's plan limits, terms, privacy policy, retention settings, and account controls.

5. Third party processors and platforms

We use service providers and connected platforms to operate the business and client workflows. These providers receive only the information reasonably needed for the relevant purpose.

Platform availability, data access, API limits, review requirements, permissions, and policy rules are controlled by the relevant provider. We cannot guarantee that any third party platform will continue to provide the same access, pricing, uptime, or features.

6. Connected accounts and authorization

Clients may authorize Always Staffed to connect tools, social accounts, AI accounts, phone systems, CRMs, calendars, email tools, or other business platforms. Clients are responsible for having the rights and administrative authority needed to connect those accounts and share the related data.

We store non-secret connection status and operational metadata in the dashboard where possible. OAuth tokens, API keys, bot tokens, and similar secrets should stay in the appropriate provider, client runtime, or secure secret storage. We do not intentionally expose secrets in the browser, public dashboards, Telegram messages, public logs, or marketing pages.

Clients can revoke many connected account permissions through the provider's own account settings. Revoking access may stop related workflows.

6A. Meta, Facebook, and Instagram integrations

Before a Meta, Facebook, or Instagram connection begins, Always Staffed identifies the approved API product, requested permissions, purposes, retention posture, and withdrawal method. The connection begins only after an authorized client user takes an affirmative action.

Approved performance metrics are shown through live display by default and are not retained as exact metric history. If a future approved policy permits a snapshot, the dashboard will identify it as a permitted snapshot and apply the approved expiry. A minimal derived observation may be retained for up to 90 days only where policy permits, and only as a drafting input for the same client and the same platform.

We do not use Facebook observations to influence Instagram, Instagram observations to influence Facebook, any platform information for another client, or platform information for generalized model training. Raw API responses, comments, messages, audience identities, person-level reactions, remote account identifiers, platform post identifiers, and permalinks are excluded from normal performance reporting storage.

Authorization can be withdrawn through the dashboard, the provider's settings, or by emailing contact@alwaysstaffed.com. Disconnect stops new collection, revokes the local authorization, selectively deletes affected observations and references, and starts any available remote revocation process.

6B. LinkedIn integration

If you connect a LinkedIn account or LinkedIn Page, Always Staffed requests only the official approved API product and permissions identified in the connection notice. LinkedIn features remain unavailable when the required product, permission, account role, or authorization is missing.

Always Staffed may store only aggregate LinkedIn Page and post performance metrics, such as impressions, clicks, reaction counts, and follower trends. We use those metrics solely for reporting and content recommendations for the same Page. They are never used for another client, another Page, advertising targeting, mass messaging, unrelated prospecting, or generalized model training.

Before authorization, we identify the requested information, purpose, expected collection timing, disclosure, and withdrawal method. Authorization requires an affirmative action and is renewed after expiry or a material change where required.

Aggregate Page and post performance metrics may be retained for up to one year while the authorized service remains active. We do not store individual member-level data, member identities, member profiles, member-level reactions, comments, raw API responses, or scraped LinkedIn data for this reporting and recommendation use.

You may withdraw authorization through LinkedIn's connected-app settings, the Always Staffed dashboard, or by emailing contact@alwaysstaffed.com. We stop new collection and delete covered LinkedIn data and tokens within 10 days after the service ends or a verified client deletion request, unless LinkedIn or applicable law requires a shorter period.

LinkedIn information may be disclosed only to the client, authorized users, personnel or contractors supporting the approved service under protective obligations, and service providers needed to host, secure, or operate the integration. LinkedIn also processes information under its own privacy policy and platform terms.

7. Client media, drafts, and platform content

Uploaded photos, videos, files, captions, brand materials, and post drafts may be stored in private client storage and used to prepare content for review. AI-generated descriptions, tags, labels, or recommendations are draft metadata until approved or corrected by the client or operator.

Clients should not upload media, personal information, regulated information, third party content, or customer content unless they have the right to use it for the intended workflow. If a client asks us to delete, correct, reject, or avoid an uploaded asset, we will apply the request where practical, subject to backups, legal obligations, platform retention, and service-continuity needs.

8. Legal bases and business purposes

Depending on the context, we process information to perform a contract, prepare a proposal, operate requested services, comply with law, protect security, support legitimate business operations, or follow consent and authorization given by the client or user.

9. Analytics, cookies, and tracking

We use limited analytics to understand whether the public website and authenticated dashboard work as intended. When optional analytics is enabled with your choice, Google Analytics 4 measures public-site page and conversion events, and PostHog measures allowlisted product events in the authenticated dashboard.

Optional analytics is off until you make an affirmative analytics choice. You may decline without losing access to the public site or dashboard, and you may change your choice later through the persistent Analytics settings control.

Google Analytics may use first-party analytics cookies after consent. Our initial PostHog configuration uses manual events without autocapture, session replay, user identification, person profiles, or cross-session analytics cookies.

Analytics events may include a normalized page or feature label, CTA category, form-start or successful-submit status without field values, onboarding-step status, connection-flow status, sanitized error code, browser or device category, and consent state. We exclude names, email addresses, phone numbers, company names, form values, free-text messages, client content, social-platform data, Telegram content, uploaded media, prompts, setup codes, OAuth data, billing identifiers, full URLs with query strings, and unknown event properties.

Google signals, advertising personalization, remarketing, Google User-ID, PostHog autocapture, heatmaps, session replay, network capture, console capture, and person identification are disabled in the initial analytics configuration.

Connected platforms may use their own cookies, tracking, or account data when you authenticate with them or use their services. Their privacy policies apply to their handling of that data.

10. Data retention

Retention depends on the data category, approved purpose, platform policy, authorization status, client instructions, and legal obligations.

11. Security

We use reasonable technical and operational safeguards, including least-privilege access, tenant isolation, private storage, signed URLs where appropriate, role-based access, approval gates, separate client runtime boundaries where practical, and secret-handling controls. No internet-connected service is completely secure, and we cannot guarantee absolute security.

12. International processing

Always Staffed and its providers may process information in Canada, the United States, or other locations where we or our providers operate. Google may process analytics information in locations where it operates. The initial PostHog project is hosted in PostHog Cloud US. By using the site, dashboard, or services, you understand that information may be transferred and processed outside your province, state, or country and may be subject to the laws of those locations.

13. Your choices and requests

You may ask us to review, correct, export, restrict, or delete information you submitted by emailing contact@alwaysstaffed.com. We may need to verify the request and may retain some information where needed for security, legal, accounting, contract, dispute, backup, or service-continuity reasons.

You may decline or withdraw optional analytics through the Analytics settings control. Withdrawal stops future optional collection and clears available first-party analytics identifiers where practical. Some deliberately anonymous analytics events cannot be reliably linked to a requester.

For connected third party accounts, you may also need to manage access, deletion, retention, or export requests directly with the relevant provider.

14. Children's data

Always Staffed services are intended for businesses and are not directed to children. Do not submit information about children unless it is necessary for an approved client workflow and the client has the required legal authority and consent.

15. Changes to this policy

We may update this policy as our services, providers, legal requirements, or workflows change. The updated date above shows when the latest version was posted.

16. Contact

Questions or privacy requests can be sent to contact@alwaysstaffed.com.