Privacy Policy
How Always Staffed collects, uses, stores, shares, and protects information across the website, dashboard, client agents, connected tools, AI workflows, and managed content operations.
1. Scope
Always Staffed is a service brand operated by NBGallo Enterprises Ltd., a corporation incorporated under the Canada Business Corporations Act under corporation number 1482773-2 and registered to carry on business in Alberta. In this Privacy Policy, “Always Staffed,” “we,” “us,” and “our” mean NBGallo Enterprises Ltd.
This Privacy Policy applies to Always Staffed websites, including alwaysstaffed.com, dashboard.alwaysstaffed.com, lead forms, client dashboards, Telegram-based client agents, AI-assisted workflows, social-content operations, phone or voice-agent demos, and related onboarding or support channels.
If a signed client agreement, statement of work, data processing addendum, or platform-specific authorization applies, that document may add more specific privacy, security, retention, and processing terms for the covered services.
2. Information we collect
We collect information you provide directly, information generated while using our services, and limited technical information needed to operate the sites and workflows.
3. How we use information
- Respond to inquiries, schedule calls, and follow up on workflow or content strategy requests.
- Create, configure, test, and support client dashboards, Telegram agents, AI-assisted workflows, content calendars, media libraries, approval queues, and reporting views.
- Process uploaded media, draft asset descriptions, organize content, prepare captions or post concepts, and improve draft quality from client corrections and approvals.
- Connect approved third party tools, verify account connection status, and operate workflows the client has authorized.
- Keep platform-derived information within the same client and the same platform. No client or platform data is applied to another client or another platform.
- Send operational messages, onboarding emails, payment confirmations, dashboard-ready notices, alerts, summaries, and support responses.
- Maintain security, prevent abuse, debug errors, audit workflow activity, enforce tenant isolation, and protect client accounts and assets.
- Measure site and dashboard performance, form submissions, and high-level service usage.
- Comply with legal, contractual, tax, accounting, and platform-policy obligations.
4. AI processing and human approval
Always Staffed uses AI systems to help summarize, classify, draft, analyze, route, organize, and review work. AI outputs may include captions, summaries, asset tags, post ideas, reply drafts, call summaries, workflow notes, or recommendations.
AI-generated output can be incomplete, inaccurate, or inappropriate for a specific business context. Unless a written agreement says otherwise, client-facing sends, posts, publishing, scheduling, payment actions, customer-impacting actions, deletes, and important record changes require human approval through the configured workflow.
When a client connects a client-owned AI account, such as GPT, ChatGPT, Codex, Grok, or SuperGrok, usage may be subject to that provider's plan limits, terms, privacy policy, retention settings, and account controls.
5. Third party processors and platforms
We use service providers and connected platforms to operate the business and client workflows. These providers receive only the information reasonably needed for the relevant purpose.
- Hosting, routing, security, and analytics: providers such as Netlify, Cloudflare, Google Analytics 4, PostHog, and related infrastructure tools.
- Database, authentication, and storage: database, authentication, and storage providers for dashboard data, private client records, media metadata, and client asset storage.
- Payments: providers such as Stripe for checkout, invoices, subscriptions, and billing portal access.
- Email and notifications: providers such as Resend, Microsoft Outlook, Telegram, and related notification channels.
- AI and voice systems: providers such as OpenAI, ChatGPT/Codex, xAI/Grok, ElevenLabs, Twilio, or similar tools when used for approved workflows.
- Connected app orchestration: connected-app authorization providers used to create or manage approved third party account connections and tool access for client workflows.
- Social and content platforms: platforms connected by the client where supported for the client's approved scope.
- CRM and operations tools: providers such as HubSpot and other client-approved business systems used for follow-up, records, reporting, or workflow execution.
Platform availability, data access, API limits, review requirements, permissions, and policy rules are controlled by the relevant provider. We cannot guarantee that any third party platform will continue to provide the same access, pricing, uptime, or features.
6. Connected accounts and authorization
Clients may authorize Always Staffed to connect tools, social accounts, AI accounts, phone systems, CRMs, calendars, email tools, or other business platforms. Clients are responsible for having the rights and administrative authority needed to connect those accounts and share the related data.
We store non-secret connection status and operational metadata in the dashboard where possible. OAuth tokens, API keys, bot tokens, and similar secrets should stay in the appropriate provider, client runtime, or secure secret storage. We do not intentionally expose secrets in the browser, public dashboards, Telegram messages, public logs, or marketing pages.
Clients can revoke many connected account permissions through the provider's own account settings. Revoking access may stop related workflows.
6A. Meta, Facebook, and Instagram integrations
Before a Meta, Facebook, or Instagram connection begins, Always Staffed identifies the approved API product, requested permissions, purposes, retention posture, and withdrawal method. The connection begins only after an authorized client user takes an affirmative action.
Approved performance metrics are shown through live display by default and are not retained as exact metric history. If a future approved policy permits a snapshot, the dashboard will identify it as a permitted snapshot and apply the approved expiry. A minimal derived observation may be retained for up to 90 days only where policy permits, and only as a drafting input for the same client and the same platform.
We do not use Facebook observations to influence Instagram, Instagram observations to influence Facebook, any platform information for another client, or platform information for generalized model training. Raw API responses, comments, messages, audience identities, person-level reactions, remote account identifiers, platform post identifiers, and permalinks are excluded from normal performance reporting storage.
Authorization can be withdrawn through the dashboard, the provider's settings, or by emailing contact@alwaysstaffed.com. Disconnect stops new collection, revokes the local authorization, selectively deletes affected observations and references, and starts any available remote revocation process.
6B. LinkedIn integration
If you connect a LinkedIn account or LinkedIn Page, Always Staffed requests only the official approved API product and permissions identified in the connection notice. LinkedIn features remain unavailable when the required product, permission, account role, or authorization is missing.
Always Staffed may store only aggregate LinkedIn Page and post performance metrics, such as impressions, clicks, reaction counts, and follower trends. We use those metrics solely for reporting and content recommendations for the same Page. They are never used for another client, another Page, advertising targeting, mass messaging, unrelated prospecting, or generalized model training.
Before authorization, we identify the requested information, purpose, expected collection timing, disclosure, and withdrawal method. Authorization requires an affirmative action and is renewed after expiry or a material change where required.
Aggregate Page and post performance metrics may be retained for up to one year while the authorized service remains active. We do not store individual member-level data, member identities, member profiles, member-level reactions, comments, raw API responses, or scraped LinkedIn data for this reporting and recommendation use.
You may withdraw authorization through LinkedIn's connected-app settings, the Always Staffed dashboard, or by emailing contact@alwaysstaffed.com. We stop new collection and delete covered LinkedIn data and tokens within 10 days after the service ends or a verified client deletion request, unless LinkedIn or applicable law requires a shorter period.
LinkedIn information may be disclosed only to the client, authorized users, personnel or contractors supporting the approved service under protective obligations, and service providers needed to host, secure, or operate the integration. LinkedIn also processes information under its own privacy policy and platform terms.
7. Client media, drafts, and platform content
Uploaded photos, videos, files, captions, brand materials, and post drafts may be stored in private client storage and used to prepare content for review. AI-generated descriptions, tags, labels, or recommendations are draft metadata until approved or corrected by the client or operator.
Clients should not upload media, personal information, regulated information, third party content, or customer content unless they have the right to use it for the intended workflow. If a client asks us to delete, correct, reject, or avoid an uploaded asset, we will apply the request where practical, subject to backups, legal obligations, platform retention, and service-continuity needs.
8. Legal bases and business purposes
Depending on the context, we process information to perform a contract, prepare a proposal, operate requested services, comply with law, protect security, support legitimate business operations, or follow consent and authorization given by the client or user.
9. Analytics, cookies, and tracking
We use limited analytics to understand whether the public website and authenticated dashboard work as intended. When optional analytics is enabled with your choice, Google Analytics 4 measures public-site page and conversion events, and PostHog measures allowlisted product events in the authenticated dashboard.
Optional analytics is off until you make an affirmative analytics choice. You may decline without losing access to the public site or dashboard, and you may change your choice later through the persistent Analytics settings control.
Google Analytics may use first-party analytics cookies after consent. Our initial PostHog configuration uses manual events without autocapture, session replay, user identification, person profiles, or cross-session analytics cookies.
Analytics events may include a normalized page or feature label, CTA category, form-start or successful-submit status without field values, onboarding-step status, connection-flow status, sanitized error code, browser or device category, and consent state. We exclude names, email addresses, phone numbers, company names, form values, free-text messages, client content, social-platform data, Telegram content, uploaded media, prompts, setup codes, OAuth data, billing identifiers, full URLs with query strings, and unknown event properties.
Google signals, advertising personalization, remarketing, Google User-ID, PostHog autocapture, heatmaps, session replay, network capture, console capture, and person identification are disabled in the initial analytics configuration.
Connected platforms may use their own cookies, tracking, or account data when you authenticate with them or use their services. Their privacy policies apply to their handling of that data.
10. Data retention
Retention depends on the data category, approved purpose, platform policy, authorization status, client instructions, and legal obligations.
- Live platform metrics are discarded after the live display request and are not kept as exact metric history.
- A permitted snapshot is retained only when the applicable platform policy expressly allows it, and it is labeled and assigned an expiry.
- Minimal Facebook or Instagram derived observations may be retained for up to 90 days for the same client and the same platform, then deleted earlier on disconnect, authorization loss, policy change, or verified deletion request.
- Aggregate LinkedIn Page and post performance metrics may be retained for up to one year for reporting and content recommendations for the same Page. Individual member-level data is not stored. Covered data is deleted within 10 days after service end or a verified client deletion request.
- Authorization, deletion, and retention-run records may retain counts, timestamps, policy versions, and proof of action without preserving the deleted platform content.
- Client dashboard, media, workflow, approval, billing, security, and legal records follow their applicable service, contract, and legal retention periods.
- Google Analytics user-level and event-level exploration data is configured for two months with user-data reset on new activity disabled. Standard aggregated reports may remain available under Google's product behavior.
- PostHog product events follow the configured PostHog Cloud US project retention and deletion controls. The actual project setting is recorded in our internal retention schedule before collection begins.
- Withdrawing analytics consent stops new optional analytics collection. Provider-side deletion may be asynchronous. Deliberately anonymous events may not be linkable to an individual request.
- Third party platforms retain information under their own policies and controls.
11. Security
We use reasonable technical and operational safeguards, including least-privilege access, tenant isolation, private storage, signed URLs where appropriate, role-based access, approval gates, separate client runtime boundaries where practical, and secret-handling controls. No internet-connected service is completely secure, and we cannot guarantee absolute security.
12. International processing
Always Staffed and its providers may process information in Canada, the United States, or other locations where we or our providers operate. Google may process analytics information in locations where it operates. The initial PostHog project is hosted in PostHog Cloud US. By using the site, dashboard, or services, you understand that information may be transferred and processed outside your province, state, or country and may be subject to the laws of those locations.
13. Your choices and requests
You may ask us to review, correct, export, restrict, or delete information you submitted by emailing contact@alwaysstaffed.com. We may need to verify the request and may retain some information where needed for security, legal, accounting, contract, dispute, backup, or service-continuity reasons.
You may decline or withdraw optional analytics through the Analytics settings control. Withdrawal stops future optional collection and clears available first-party analytics identifiers where practical. Some deliberately anonymous analytics events cannot be reliably linked to a requester.
For connected third party accounts, you may also need to manage access, deletion, retention, or export requests directly with the relevant provider.
14. Children's data
Always Staffed services are intended for businesses and are not directed to children. Do not submit information about children unless it is necessary for an approved client workflow and the client has the required legal authority and consent.
15. Changes to this policy
We may update this policy as our services, providers, legal requirements, or workflows change. The updated date above shows when the latest version was posted.
16. Contact
Questions or privacy requests can be sent to contact@alwaysstaffed.com.