Last updated August 31, 2026
Data Processing Agreement
This agreement applies whenever you use Faber to process personal data about other people: your colleagues, your customers, the people in your inbox. It forms part of the Terms of Service and takes effect when you accept those terms. Nothing here needs signing separately; if your organisation requires a countersigned copy, write to admin@getfaber.co.
1. Who is who
You are the controller of the personal data your tasks read and write. You decide what a task does, which accounts it connects to, and whose data it touches.
Joshua Young, operating Faber, is the processor of that data. We process it to carry out your instructions and for no purpose of our own. We do not use it to train models, to build profiles, or for advertising, and we do not sell it.
Separately, we are a controller of your own account information: your name and email, your billing details, your support messages, and the product analytics about how you use Faber. Those are covered by the Privacy Policy, not by this agreement.
2. What we process, and on whose instructions
Subject matter and duration. Providing the Faber service, for as long as your account exists.
Nature and purpose. Reading from and writing to the applications you connect, generating drafts and summaries with AI models, and keeping a record of what each run checked and changed.
Categories of data. Whatever your connected accounts contain and your tasks reach: message content, calendar entries, contact and customer records, files, issue and project data, and the names, email addresses and account identifiers attached to them.
Categories of data subject. Your employees, contractors, customers, prospects, and correspondents.
Your instructions. Writing a task, arming it, and approving a held write are your documented instructions. So is a request sent to us in writing. We will tell you if we believe an instruction breaches data protection law.
3. Retention
Run records are kept for the life of your account. A run record is what makes the work auditable, so it is retained for as long as the account exists rather than on a rolling window.
On your instruction we erase a person from those records by redaction. We remove the person's name wherever it appears and leave the rest of the record intact: what happened, when, and to which item. If you require deletion of the whole record rather than redaction, tell us and we will do that instead.
On termination, everything goes. Deleting your account disconnects every application, stops every task, and cancels any subscription immediately. Your data is retained for thirty days so the account can be restored on request, and is permanently deleted after that. Run artifacts are deleted immediately.
4. Confidentiality and security
Everyone with access to your data is bound by confidentiality obligations. We maintain technical and organisational measures appropriate to the risk, including encryption of connected-app credentials at rest with AES-256-GCM, TLS for all traffic in transit, access controls, and audit logging of administrative access to customer content.
5. Subprocessors
You give general authorisation for us to engage the subprocessors listed on our subprocessor page, 11 companies as of today, each named with what they do and what they can see. Each is bound by written terms no less protective than these.
We will update that page before a new subprocessor starts processing. Write to admin@getfaber.co to be told of changes in advance. You may object to a new subprocessor on reasonable data protection grounds; if we cannot accommodate the objection, you may terminate and receive a refund of any prepaid fees for the unused term.
6. Data subject requests
You can read your run records in the app at any time and export them from Settings, and you can ask us to redact a named individual from them. Where a request reaches us directly we will pass it to you rather than act on it ourselves, and we will help you respond.
7. Personal data breaches
We will notify you without undue delay after confirming a breach affecting your data, with what we know about what happened, who is affected, and what we are doing about it.
8. International transfers
Faber is hosted in the United States, and your data is processed there. If European, UK or Swiss data protection law applies to you, write to admin@getfaber.co.
9. Audits
On written request, and no more than once a year unless a supervisory authority requires otherwise, we will provide the information reasonably needed to demonstrate compliance with this agreement, including answering a security questionnaire.
10. Changes
We may update this agreement as the service or the law changes. The date at the top says when. We will give notice of material changes before they take effect.
Contact
Anything about this agreement goes to admin@getfaber.co.