Legal

Privacy Policy

Last updated July 11, 2026Effective July 11, 2026
On this page Overview At a glance Information we collect How we use data Legal bases Sharing & subprocessors Governed data & operators Retention Security Your rights (GDPR) Your rights (US states) International transfers Cookies Changes Contact

This policy explains what personal data Fibric Inc. ("Fibric," "we") processes, why, and the choices you have. It covers fibric.io, BearScope, and managed deployments that we provide under a customer agreement. The generalized Fibric kernel described in public materials is a reference architecture unless a customer agreement says otherwise. Customer Data that we process on a customer's behalf is governed by the applicable customer agreement and, where incorporated, our Data Processing Addendum.

Overview

We generally act as a data controller for personal data about website visitors, authorized users, and prospective customers. We act as a data processor only when and to the extent an applicable customer agreement requires us to process Customer Data on the customer's behalf. This policy describes our controller activities; the applicable agreement and incorporated DPA describe processor obligations.

At a glance: our privacy label

The short version, in the style of a nutrition label. The full detail follows below.

Privacy Factsfibric.io, BearScope & managed deployments
Data used to identify youName, work email, company, and account identifiers you or your organization provide
Data linked to youAccount activity, support messages, usage telemetry
Data not linked to youAggregate site analytics (consent-based)
Sold to third partiesWe do not currently sell personal data or share it for cross-context behavioral advertising.
Used to train shared modelsCustomer Data is not used to train a shared model unless the customer expressly agrees in writing.
TrackingWhere consent is required, non-essential analytics are used only after a valid choice. We honor recognized browser opt-out signals where required by law.
RetentionBased on purpose, law, and the applicable customer agreement; supported action records follow the contracted retention schedule
Your controlsAccess, correct, delete, export, object — email privacy@fibric.io

Information we collect

You give us

  • Account & contact: name, work email, company, role when you sign up, request access, or contact us.
  • Operation setup: the systems you connect and the intents and guardrails you configure during onboarding.
  • Communications: messages you send to support, sales, or community channels.

We collect automatically

  • Usage & device: pages viewed, actions taken, IP address, browser, and similar telemetry, used to operate and improve the service.
  • Cookies: see Cookies below.

How we use data

We use personal data to provide and secure our current services, authenticate provisioned accounts, respond to you, send service and (with consent where required) marketing communications, meet legal obligations, and improve the product. We do not currently sell personal data or share it for cross-context behavioral advertising. Customer Data is not used to train a shared model unless the customer expressly agrees in writing.

Legal bases

Where the GDPR or similar laws apply, we rely on: contract (to deliver the service you requested), legitimate interests (to secure and improve the platform), consent (for optional marketing and non-essential cookies), and legal obligation (to comply with law).

Sharing & subprocessors

We may share personal data with service providers used to deliver, secure, or support the applicable website or contracted Service, subject to appropriate terms and only for the relevant purpose. We may also disclose data where required by law or necessary to protect rights and safety. The Subprocessors page is a public category summary; the named provider schedule for Customer Data is contract-specific.

Governed data & operators

Supported BearScope and contracted managed-deployment paths use tenant-scoped controls appropriate to those paths. Current BearScope production data tables use reseller and tenant identifiers and row-level access controls where implemented, and supported governed actions can produce attributable action records with duplicate-suppression controls. These controls do not mean that every reference-kernel component is deployed, that every event or row has identical enforcement, or that a downstream action can always be reversed. Any compensating recovery depends on the connected system and the applicable customer agreement. Where we process Customer Data as a processor, we do so on documented customer instructions and under the applicable agreement.

Retention

We keep personal data for as long as reasonably needed for the purposes above, to meet legal obligations, and to resolve disputes. For Customer Data, export, deletion, backup-cycle, and supported action-record retention are governed by the applicable customer agreement and any incorporated DPA. We then delete or anonymize data where required and technically feasible, subject to lawful retention requirements.

Security

For supported production services, we use technical and organizational measures designed to protect data, including encryption in transit and at rest, access controls, authentication, logging, and tenant-scoped controls where implemented. Measures vary by product, connected system, and contracted deployment; reference-architecture descriptions are not representations that every control is deployed on every path. No method is perfectly secure. See Security and our Responsible Disclosure policy.

Your rights (GDPR / UK GDPR / EEA)

If you are in the EEA, UK, or Switzerland, you may have the following rights over your personal data, subject to applicable conditions and exceptions. To exercise a right, email privacy@fibric.io. We respond within the period required by applicable law and will tell you if a lawful extension applies. We do not charge for a request or treat you adversely except where applicable law permits a reasonable fee or other limitation.

  • Access (Art. 15) — get a copy of the personal data we hold about you.
  • Rectification (Art. 16) — correct inaccurate or incomplete data.
  • Erasure (Art. 17) — ask us to delete your data ("right to be forgotten").
  • Restriction (Art. 18) — limit how we process your data while a dispute is resolved.
  • Portability (Art. 20) — receive your data in a structured, machine-readable format.
  • Objection (Art. 21) — object to processing based on legitimate interests, and to direct marketing at any time.
  • No automated decisions (Art. 22) — we do not make legal or similarly significant decisions about you by solely automated means.
  • Withdraw consent — where processing is based on consent, withdraw it at any time (for cookies, use Cookie preferences in the footer).

You may also lodge a complaint with your local supervisory authority. We'd appreciate the chance to resolve it first, but you don't have to give us one.

Your rights (California and other US states)

If you are a resident of California (CCPA/CPRA), Colorado, Connecticut, Virginia, Utah, or another state with a comprehensive privacy law, you may have some or all of the following rights, subject to applicable conditions and exceptions:

  • Know / access — what personal information we collect, use, and disclose, and to receive a copy.
  • Delete — ask us to delete personal information we collected from you.
  • Correct — fix inaccurate personal information.
  • Opt out of sale or sharing — we do not currently sell personal information or share it for cross-context behavioral advertising. Where required by law, we treat a recognized opt-out preference signal, such as Global Privacy Control, as a request to opt out.
  • Limit sensitive personal information — as of this policy's effective date, we do not use sensitive personal information for purposes that require offering this right.
  • Non-discrimination — we will not unlawfully discriminate against you for exercising an applicable privacy right.

Submit requests to privacy@fibric.io. We verify requests using information appropriate to the request and respond within the period required by applicable law. You may use an authorized agent; we may ask for proof of authorization. As of this policy's effective date, we have not sold or shared personal information as those terms are defined by the CCPA during the preceding 12 months.

International transfers

We may process data in countries other than yours. Where applicable law requires a transfer mechanism, we use the mechanism specified in the relevant customer or service-provider agreement, which may include Standard Contractual Clauses.

Cookies

We may use strictly necessary storage to operate the site and analytics technologies to understand usage. Where applicable law requires consent, we seek it before using non-essential analytics and provide a way to change that choice. Where required, we treat recognized browser opt-out signals as privacy requests. See the Cookie Policy for additional detail.

Changes to this policy

We may update this policy as the product and law evolve. We will post the new version here and update the date above; material changes will be communicated where appropriate.

Contact

Questions about this policy or your data? Email privacy@fibric.io, or write to Fibric Inc., Attn: Privacy. For data-processing matters, see the DPA.