This Privacy Policy explains how Lyberty Labs FZCO d/b/a Lyberty ("Lyberty," "we," "us," or "our") processes personal data when we operate lyberty.ai, provide the Lyberty Services, communicate with users, and process customer-configured integrations, sites, tracking, AI workflows, agent runtime actions, and support requests. It does not override any executed Data Processing Addendum ("DPA"), Master Subscription Agreement, or order form, which prevail in case of conflict on data-protection matters they govern.
Who we are and how to contact us
- Controller: Lyberty Labs FZCO
- Registered address: Premises Number 23201, IFZA Business Park, Dubai, UAE
- Privacy email: privacy@lyberty.ai
- Support email: support@lyberty.ai
- Data Protection Officer: Not appointed at this time. Privacy inquiries are handled by the Lyberty privacy function reachable at the email above.
UK representative (UK GDPR Art. 27): R&Co Solutions LLP. UK-resident data subjects may contact us at privacy@lyberty.ai; we route Article 27 representative requests as appropriate.
EU/EEA representative (GDPR Art. 27): to the extent Article 27 GDPR requires Lyberty to maintain an EU/EEA representative, Lyberty will identify that representative in this Privacy Policy. Where Article 27 does not require appointment for a particular processing context, EEA data subjects may contact Lyberty directly at privacy@lyberty.ai. Lyberty periodically reviews its EEA processing activities and will update this Policy if its representative status changes.
Where this Policy refers to Lyberty Written Authorization, it means the formal authorization standard defined in the Terms. Chat responses, AI-generated responses, support suggestions, documentation, product UI text, automated messages, and informal communications do not authorize Restricted Data, high-risk AI, children's data, or other restricted uses unless confirmed through that formal authorization standard.
The Services
Lyberty provides a graph-centered execution runtime for venture building and scaling. The Services help customers model business objects and relationships, connect operational systems, collect and reconcile first-party site and event data, run analytics and experiments, coordinate workflows and approvals, generate and review AI-assisted outputs, manage artifacts and operational records, and publish or synchronize customer-approved changes to customer-selected destinations. Features may include sites, campaigns, relationships, finance, operations, artifacts, governance, integrations, first-party tracking, AI-assisted planning, research, content generation, and agent runtime workflows.
Scope
This Policy covers personal data we process:
- when you visit lyberty.ai or other sites we control;
- when you create an account, authenticate, or use the Services;
- when you connect integrations, configure sites, run tracking, or upload content;
- when you use AI-assisted features, agent workflows, approvals, artifacts, or analytics;
- when we communicate with you for support, sales, security, or service administration.
It does not apply to third-party sites, destinations, or customer properties except where we process data through the Services as described here or in a DPA. Where Lyberty acts as a processor on a customer's behalf, the customer's privacy notice — not this Policy — governs the customer's collection and use of personal data.
Personal data we process
We process the following categories depending on how the Services are used.
Account, workspace, and billing data
Names, business email addresses, authentication identifiers, workspace membership, roles, permissions, organization details, subscription tier, billing metadata, invoices, payment confirmations, and related account records. Payments are processed by Stripe; we do not store full payment-card numbers.
Customer content and operational records
Customer-provided content, artifacts, files, documents, spreadsheets, images, briefs, prompts, chat messages, AI inputs and outputs, approvals, workflow and run records, graph nodes and relationships, configuration files, publishing records, and revision metadata.
Integrations and connected-system data
Provider names, OAuth scopes, account or property IDs, access or refresh tokens, connected objects, and data retrieved from customer-configured systems such as advertising, analytics, commerce, CRM, finance, content, search, support, productivity, storage, and development platforms. The available connector set changes over time and is governed by product configuration and customer authorization.
First-party website, SDK, and event data
When enabled on Lyberty-controlled sites or customer-configured properties, Lyberty may process pseudonymous or session identifiers, page URLs, referrers, UTM parameters, gclid/fbclid and similar campaign parameters, device, browser, and OS information, approximate location derived from IP, IP-derived signals, page views, page leaves, clicks, changes, submits, scroll, error and performance events, experiment assignments, feature flag and pathway assignments, consent state, bot and internal-traffic signals, and related event metadata.
AI and model-operation data
Prompts, messages, attachments, retrieved context, tool calls, model and provider metadata, model responses, token and cost telemetry, evaluation traces, and safety and reliability records needed to provide and improve AI-assisted features. We do not use Customer Personal Data or Customer Content to train general-purpose AI models for other customers (see "AI, model training, and automations").
Support, sales, and communications data
Messages you send to us, scheduled meeting records, support tickets, diagnostic details, and related metadata.
Special-category, sensitive, and regulated data
The Services are not designed for special-category personal data (GDPR Art. 9), biometric or genetic data used for identification, children's personal data, health or medical records, payment-card numbers (PAN), financial-account credentials, full government-issued identifier numbers, criminal-offense data, or other categories regulated as highly sensitive (collectively, "Restricted Data") unless Lyberty Written Authorization in a signed addendum, order form, business associate agreement, DPA exhibit, or other executed agreement expressly authorizes the specific Restricted Data category and safeguards. Customers must not upload or route Restricted Data without that signed authorization. Lyberty may use automated and manual controls designed to detect, block, quarantine, or remove Restricted Data, but Lyberty does not guarantee detection of all Restricted Data.
Lawful basis matrix (EEA / UK / Switzerland)
| Processing activity | Lawful basis (GDPR / UK GDPR) |
|---|---|
| Providing accounts, subscriptions, integrations, support, and the Services you request | Contract — Art. 6(1)(b) |
| Operating sites, tracking, analytics, experiments, approvals, workflows, artifacts, publishing | Contract or Legitimate interests — Art. 6(1)(b) / 6(1)(f) |
| Securing the Services, preventing abuse, fraud, and platform misuse | Legitimate interests — Art. 6(1)(f) |
| Service-administration telemetry, reliability, cost, and product-improvement signals | Legitimate interests — Art. 6(1)(f) |
| AI-assisted features (planning, drafting, research, agent workflows) on customer instructions | Contract — Art. 6(1)(b); customer-controller-side basis as applicable |
| Permitted business marketing to existing customers and prospects who have opted in | Legitimate interests / Consent — Art. 6(1)(f) / 6(1)(a) |
| Optional cookies, analytics, session-replay, and advertising technologies | Consent — Art. 6(1)(a) and ePrivacy / PECR |
| Compliance with accounting, tax, sanctions, anti-money-laundering, regulatory, and court obligations | Legal obligation — Art. 6(1)(c) |
| Establishing, exercising, or defending legal claims; corporate transactions | Legitimate interests — Art. 6(1)(f) |
Where we rely on legitimate interests, we have conducted (or will conduct on request) a balancing assessment that takes into account data-subject rights and reasonable expectations. You may withdraw consent at any time without affecting processing that occurred before withdrawal.
How we use personal data
We use personal data to:
- provide, administer, secure, and troubleshoot the Services;
- authenticate users and manage workspaces, permissions, and billing;
- connect integrations, ingest data, normalize records, and maintain the execution graph;
- operate sites, tracking, analytics, experiments, approvals, workflows, artifacts, and publishing;
- provide AI-assisted planning, research, drafting, analysis, search, and agent workflows;
- generate telemetry, audit logs, reliability metrics, cost records, and security signals;
- communicate about support, product changes, security, billing, and permitted marketing;
- enforce agreements, prevent fraud and abuse, comply with law, and protect rights and safety.
Our roles
- Processor / service provider. For Customer Personal Data that customers submit, connect, upload, collect through customer properties, or instruct us to process through the Services, Lyberty acts as a processor or service provider under the DPA and customer instructions.
- Independent controller. For account administration, billing, security, service telemetry, marketing-site analytics, product improvement, legal compliance, and our own communications, Lyberty acts as an independent controller.
Some third-party integrations and destinations may act as independent controllers under their own terms. Customers are responsible for choosing, configuring, and lawfully using those services.
Service Data does not include Customer Content except to the limited extent Customer Content is incidentally reflected in logs, support tickets, security records, or telemetry necessary for the purposes described in this Policy. Where the same data element is processed both as Customer Personal Data and Service Data, Lyberty processes it in each role only for the corresponding purposes and legal bases. Lyberty does not use Service Data to identify or profile Customer's end users for Lyberty's own advertising purposes.
Service Improvement
"Improve the Services" means using Customer Content and Customer Personal Data only to maintain, debug, secure, operate, measure, and enhance the functionality, reliability, safety, performance, and user experience of the Services for Customer and similarly situated customers. Service Improvement does not include training, fine-tuning, or otherwise improving general-purpose AI models or foundation models for use by other customers, unless Customer expressly opts in under a separate written agreement.
Lyberty may use aggregated or de-identified telemetry derived from use of the Services for analytics, benchmarking, reliability, security, capacity planning, and product development, provided such data does not identify Customer, Customer's users, or any individual and is not reasonably capable of re-identification.
Lyberty personnel will not access Customer Content except as necessary to provide support requested by Customer, investigate security or abuse issues, comply with law, maintain the Services, or as otherwise authorized by Customer. Access is logged and limited to personnel with a need to know.
AI, model training, and automations
We do not use Customer Personal Data or Customer Content to train general-purpose AI models for other customers. We may process Customer Content through AI providers selected by Lyberty or configured by Customer to provide the Services. AI outputs may be inaccurate, incomplete, biased, outdated, hallucinated, fabricated, non-unique, unprotectable, infringing, or unsuitable for a particular use; Customer is solely responsible for human review, approvals, validation, and lawful use before relying on, publishing, or acting on AI outputs or enabling automations. Customer must not present AI outputs as reviewed, verified, endorsed, or approved by Lyberty unless a Lyberty Written Authorization expressly says so.
Where enabled by Customer, automations may make customer-configured changes such as workflow actions, publishing steps, experiment decisions, routing updates, or destination synchronizations. Customers remain responsible for monitoring automations, maintaining required approvals, and ensuring lawful use, including under the EU AI Act, FTC AI guidance, and equivalent regulations in their operating jurisdictions.
Automated decision-making, profiling, and high-risk AI uses
Lyberty supports profiling, segmentation, analytics, recommendations, experiments, and automation for operational, marketing, and execution workflows. Lyberty does not intend the Services to be used as the sole basis for decisions that produce legal or similarly significant effects concerning individuals (GDPR Art. 22), nor for "high-risk" AI uses regulated under the EU AI Act, the Colorado AI Act, NYC Local Law 144, or comparable laws — including hiring, performance evaluation, dismissal, credit, insurance, housing, education admissions or grading, healthcare diagnosis or triage, legal services, criminal-justice decisioning, biometric identification, or essential public services — unless Lyberty has expressly authorized that use in a signed addendum AND the required impact assessments, notices, opt-outs, human oversight, accuracy testing, bias testing, and regulator-facing safeguards are in place under Customer's responsibility. Lyberty may require a use-case questionnaire, risk assessment, or high-risk AI addendum before enabling or continuing a regulated AI use case.
Cookies, tracking, and privacy choices
We use necessary cookies and similar technologies for security, session continuity, consent state, and site functionality. We may use optional analytics, session-replay, advertising, and similar technologies only according to your consent choices where required.
Our marketing site uses Microsoft Clarity only when analytics consent is granted and no applicable browser opt-out signal blocks analytics loading. Clarity may collect page interaction data such as clicks, scrolling, session-replay signals, device or browser information, approximate location, and visited URLs to help us understand site use and improve the website. Session-replay and interaction-analytics tools are configured, where available, to mask or suppress sensitive fields, passwords, payment information, authentication credentials, and other Restricted Data. We do not intentionally use session-replay tools to collect the contents of private messages, payment-card numbers, passwords, government identifiers, or health information.
Customer sites may use Lyberty first-party tracking configured by the customer. Customers are responsible for providing legally sufficient notices, consent mechanisms, opt-out handling, preference-signal handling, and platform permissions on their own properties. Customers are responsible for determining whether Lyberty technologies constitute cookies, tracking technologies, sales, sharing, targeted advertising, profiling, or similar activities under applicable law, and for configuring consent and opt-out controls accordingly. Lyberty excludes consent-denied, bot, and internal traffic from eligible decisioning where those signals are available, but customer configuration and legal compliance remain the customer's responsibility.
Manage preferences at https://lyberty.ai/privacy/choices. Cookie details are in our Cookie Policy.
"Do Not Sell or Share" and targeted advertising
If marketing cookies or similar technologies on lyberty.ai constitute a "sale" or "sharing" for cross-context behavioral advertising under California, Colorado, Connecticut, Texas, Virginia, Utah, or comparable US state law, residents of those states may opt out at https://lyberty.ai/privacy/choices. Where applicable, we honor Global Privacy Control (GPC) signals as opt-out requests.
Disclosures and subprocessors
We disclose personal data to:
- vendors and subprocessors that host, secure, transmit, store, analyze, support, or help provide the Services;
- AI and model providers and infrastructure providers needed for selected AI features;
- customer-configured third-party integrations and destinations;
- payment, email, security, support, analytics, observability, and professional-services providers;
- authorities, courts, counterparties, or advisers when required for legal, safety, regulatory, compliance, or corporate transaction purposes.
Our current subprocessor list is at https://lyberty.ai/trust/sub-processors.
International transfers
We may process and transfer personal data internationally, including to the United Arab Emirates, the United States, the United Kingdom, the EEA, and other countries where our infrastructure, subprocessors, personnel, or customer-selected providers operate. Where required, we use appropriate safeguards including the EU Standard Contractual Clauses (Decision (EU) 2021/914), the UK International Data Transfer Addendum or IDTA, the Swiss-FDPIC supplementary terms, transfer impact assessments, and supplementary technical and organizational measures. UAE PDPL transfers rely on adequacy decisions or appropriate safeguards as recognized by the UAE Data Office. Where customer-configured integrations transfer data to additional jurisdictions (e.g. PRC under PIPL, India under DPDPA), the customer is the controller responsible for those transfers under its own program.
Retention
We retain personal data only as long as reasonably necessary for the purposes described in this Policy, the DPA, customer configuration, and applicable law.
| Category | Default retention |
|---|---|
| Account, billing, contract, and legal records | Account term + statutory accounting / tax / limitation periods (typically 6–10 years) |
| Customer Content and graph or workspace records | Subscription term, until deleted by Customer, or as otherwise agreed in writing |
| Integration tokens and OAuth grants | Until revoked, disconnected, expired, or no longer needed |
| Security logs, audit trails, and reliability telemetry | 12–24 months unless a longer period is required for security, investigation, or law |
| Marketing-site analytics events | Up to 13 months |
| Cookie and consent records | Lifetime needed to remember choices and demonstrate compliance, typically up to 13 months |
| Backups | Rolling backup window; backed-up data is purged on expiry of the backup cycle |
Security
We use administrative, technical, and organizational safeguards designed to protect personal data, including access controls, encryption in transit, encryption at rest where supported by the underlying storage or service, least-privilege practices, secrets management, environment separation, network protections, monitoring, logging, alerting, vulnerability management, secure development practices, and incident response procedures. No system is perfectly secure. If we become aware of a Personal Data Breach affecting your data, we will notify affected customers or users as required by applicable law and our agreements. Any notice may be preliminary and supplemented as more information becomes available.
Your rights
Depending on where you live, you may have rights to:
- access and obtain a copy of your personal data;
- correct inaccurate or incomplete data;
- delete personal data, subject to legal exceptions;
- restrict or object to certain processing;
- data portability in a structured, commonly used, machine-readable format;
- withdraw consent at any time;
- opt out of targeted advertising, sale, share, or certain profiling;
- appeal a refusal of a privacy request;
- non-discrimination for exercising privacy rights;
- lodge a complaint with a supervisory authority.
To exercise rights, email privacy@lyberty.ai or use https://lyberty.ai/privacy/choices for cookie and opt-out choices. We may verify your identity proportionate to the request. Where Lyberty acts as processor, we will direct the request to the relevant Customer-controller and assist them in responding.
Supervisory authorities you may contact include (non-exhaustive): the UK ICO (ico.org.uk), the Irish DPC (dataprotection.ie), other EU/EEA national authorities listed at edpb.europa.eu, the Swiss FDPIC (edoeb.admin.ch), the UAE Data Office, the California Privacy Protection Agency (cppa.ca.gov), and equivalent state attorneys general.
Children
The Services are intended for users 18 and older and are not directed to children. We do not knowingly collect personal data from children. Customers must not deploy Lyberty technologies on websites, applications, or services directed to children, or where Customer has actual knowledge that children's personal data will be processed, unless a signed addendum authorizes that use and specifies required safeguards. If you believe a child provided personal data to us, contact privacy@lyberty.ai and we will take appropriate steps including deletion.
Customer responsibilities
Customers are responsible for ensuring they have all necessary rights, notices, consents, lawful bases, platform permissions, and third-party authorizations before connecting integrations, uploading content, enabling tracking, sending data to destinations, publishing outputs, or instructing Lyberty to process personal data. Customers are also responsible for compliance with sector-specific laws applicable to their industry (financial services, healthcare, education, employment, advertising, etc.) when using the Services. If Customer becomes aware that Restricted Data has been submitted without Lyberty Written Authorization, Customer must promptly notify Lyberty, stop further submission, and cooperate in remediation, deletion, isolation, and required notices.
Changes
We may update this Policy from time to time. We will post changes on this page and update the "Last updated" date. Material changes will be communicated where appropriate (in-product notice, email to account administrators, or both).
Additional documents
Contact
privacy@lyberty.ai Lyberty Labs FZCO Premises Number 23201, IFZA Business Park, Dubai, UAE