Privacy policy.
How Facet, LLC collects, uses, shares, and protects personal data, on behalf of site operators, agent operators, and the people whose data transits the Services.
Scope and our role.
1.1 Who we are
This Privacy Policy (the "Policy") is published by Facet, LLC, a Delaware limited liability company ("Facet", "we", "us"), notice address 1 Market St, Suite 100, San Francisco, CA 94105. Facet is the operator of the Services described at facet.llc and its subdomains, including audit.facet.llc and app.facet.llc.
1.2 What this Policy covers
This Policy describes how Facet processes personal data ("Personal Data" or "Personal Information", used interchangeably to accommodate US and EU terminology) when: (a) a website operator ("Customer") signs up for a Facet account, mounts a Terminal, or uses the admin dashboard; (b) an autonomous agent operator ("Agent Operator") presents a Facet KYA token, a KYAPay token, or a DID-based identity claim to a Facet Terminal; (c) visitors interact with the Facet marketing site at facet.llc; and (d) prospective customers request an Agent Traffic Audit. It does not cover Personal Data processed by Customer on Customer's own systems, nor data held by third-party Agent Operators outside Facet's infrastructure.
1.3 Facet’s roles under data-protection law
Under the EU General Data Protection Regulation, Regulation (EU) 2016/679 ("GDPR"), the United Kingdom General Data Protection Regulation and the Data Protection Act 2018 ("UK GDPR"), the Swiss Federal Act on Data Protection of 25 September 2020 in force 1 September 2023 ("Swiss FADP"), and equivalent laws, Facet acts in two distinct roles:
- Controller, for Facet's own commercial-relationship data, including account-owner details, billing information, Customer support conversations, network-wide Agent Reputation Registry signals, and Facet marketing-site analytics. Facet determines the purposes and means of Processing this data.
- Processor, for agent-request metadata and request content flowing through Customer's Terminal. Customer is the Controller of this data; Facet Processes it on Customer's documented instructions under the Data Processing Agreement v2.1 at facet.llc/legal/dpa.html.
Where Facet acts as Processor, data-subject requests must in the first instance be directed to the Customer that operates the Terminal. Facet will assist Customer in responding to those requests on the timelines required by the DPA v2.1 and the applicable law.
1.4 Applicability
This Policy reflects Facet's compliance with: (a) the GDPR; (b) the UK GDPR; (c) the Swiss FADP; (d) the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA", Cal. Civ. Code § 1798.100 et seq.); and (e) the additional U.S. state comprehensive privacy laws identified in Section 14. Specific regional rights are described in Sections 10 and 14.
1.5 Incorporation by title and version
This Policy is referenced by title and version from the Terms of Service v2.1, the Data Processing Agreement v2.1, the Acceptable Use Policy v2.0, the Cookie Policy v2.0, and the Security page v2.0. Version drift between these documents is tracked in the changelog at facet.llc/legal/.
Categories of personal data we collect.
2.1 Customer account data
When Customer registers for Facet or uses the admin dashboard, Facet collects: the account owner's email address and name; organization legal name and mailing address; billing address; Customer's website URL(s); subscription tier; admin-role access controls and authorization tokens issued by Customer's identity provider; and support and sales communications.
2.2 Authentication data
Facet does not store passwords. Admin sign-in uses OpenID Connect through Microsoft Entra ID (multitenant) or Google Workspace, each with OIDC-only scopes. Facet receives and retains the OIDC subject identifier, email, name, and session tokens returned by the identity provider, plus session activity metadata (sign-in timestamp, IP address at sign-in, user-agent).
2.3 Agent identity metadata
For every request reaching a Facet Terminal, Facet processes the signed identity token (kya+jwt, pay+jwt, or kya-pay+jwt) or, where accepted, a DID-based identity claim, and its claims: the agent identifier (aid), agent platform (apd), issuer (iss), audience (aud), expiration (exp), not-before (nbf), and settlement type (stp). Section 13 addresses how Facet treats Agent Identity Data under data-protection law.
2.4 Request and response metadata
Facet processes metadata about each Terminal request: timestamp; route; rate-limit counters; idempotency key; trace identifier; payload schema (not payload content unless Customer has enabled the hosted-ingest path); response size; HTTP status; Ed25519 signature reference; supplier identifier. Metadata does not include end-visitor IP or user-agent except where an authenticated agent has chosen to disclose it as part of an identity claim.
2.5 Schema manifests and Customer content
Customer's facet.yaml manifest, Terminal configuration, catalog metadata submitted through the Schema Auto-Generator, published agents.txt file, and referenced documentation URLs. To the extent these contain Personal Data (for example, a supplier contact email published in agents.txt), Facet processes that data on Customer's instructions.
2.6 Commerce transactions
When an atomic commerce primitive settles (via an x402 or Stripe charge call), Facet records an append-only audit entry comprising: reservation identifier; settlement identifier; settlement rail (stp claim); timestamp; signed-receipt hash; supplier and agent identifiers; and transaction amount. Facet does not receive or store payment card numbers; card and bank data are handled by Stripe, Inc. (for Customer billing and for agent-originated card-rail settlement). Agent-originated USDC settlement occurs non-custodially on-chain via the x402 protocol and Boson escrow and does not pass through Facet's systems.
2.7 Classifier aggregates
For Customers using the Agent Traffic Audit, the @facet/classifier library running inside Customer's environment returns aggregated counts to Facet (per-operator request counts, per-path-category counts, per-time-bucket counts). These aggregates do not include individual request records, IP addresses, or user-agent strings. If a Customer opts into the direct NDJSON upload path, raw log lines are Processed inside Facet's Supabase project per Section 5.
2.8 Support, sales, and marketing data
When Customer or a prospect contacts Facet by email, form submission, or a demo request, Facet collects the information submitted plus associated message metadata. On the Facet marketing site, Facet collects anonymous page-view counts for product-improvement purposes; Facet does not deploy advertising cookies (see the Cookie Policy v2.0 at facet.llc/legal/cookies.html).
2.9 Audit logs
Every significant action on the platform, admin sign-ins, configuration changes, key rotations, signature operations, billing events, policy acknowledgments, is recorded in an append-only audit log. Audit-log entries include the actor identifier, timestamp, action, and affected resource, and are retained per Section 8.
2.10 CCPA-defined categories collected in the prior 12 months
For the purposes of Cal. Civ. Code § 1798.110(c), Facet has collected the following CCPA-defined categories of Personal Information in the prior twelve (12) months:
| CCPA category | Collected? | Examples |
|---|---|---|
| Identifiers | Yes | Email, name, OIDC subject, admin-session IP |
| Commercial information | Yes | Subscription tier, invoices, commerce settlement records |
| Internet or network activity | Yes | Terminal metadata, admin audit logs, marketing page-view counts |
| Professional or employment information | Yes | Job title, employer on account-owner profile |
| Inferences | Yes | Agent-reputation signals derived from network-level behavior |
| Sensitive Personal Information (CPRA § 1798.140(ae)) | No | Not knowingly collected |
| Biometric identifiers | No | Not collected |
| Precise geolocation | No | Not collected |
| Characteristics of protected classifications | No | Not collected |
| Audio, electronic, visual, thermal, olfactory, similar information | No | Not collected |
| Education information | No | Not collected |
| Genetic data | No | Not collected |
What Facet does not collect.
Facet's architecture is designed to minimize the Personal Data that reaches our infrastructure. The following categories are deliberately excluded from default Processing:
- Raw visitor IP addresses. The classifier operates at the CIDR-block level and on user-agent patterns. Individual visitor IP addresses are not stored, aggregated, or redistributed by Facet. Agent Traffic Audit reports contain only counts and operator attributions.
- User-agent strings as Personal Data. The classifier matches user-agent strings against published operator patterns (for example, GPTBot/*, ClaudeBot/*) and emits an operator attribution. Raw user-agent strings are not preserved in the classifier output returned to Facet.
- Customer's downstream customer PII. Customer's downstream customer data (orders, shipping addresses, CRM records, ERP records) does not cross into Facet's tenant under default configuration. If a Terminal endpoint is configured in a way that could return such data to an agent, it is Customer's responsibility to restrict it. Facet does not inspect upstream payloads for Personal Data.
- Training-data use by default. Facet does not train foundational artificial-intelligence or machine-learning models on Customer Data, supplier catalog data, or agent traffic. Any such use requires a separate, opt-in Data Licensing Agreement with Customer. This prohibition binds Facet's own models, Facet affiliates, and every subprocessor in Section 6.
- Special categories under GDPR Art. 9. Facet does not knowingly collect or Process data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership; genetic data; biometric data for the purpose of uniquely identifying a natural person; data concerning health; or data concerning a natural person's sex life or sexual orientation. Facet does not knowingly collect data concerning criminal convictions and offences (GDPR Art. 10). Customer will not submit such data through the Services without a prior written supplemental agreement establishing the lawful basis and additional safeguards required by Art. 9 and Art. 10.
- Payment card data. Facet is not a PCI-DSS processor. Customer billing and agent-originated card-rail settlement are handled by Stripe, Inc.; agent-originated USDC settlement is non-custodial on-chain (x402 protocol / Boson escrow) and does not pass through Facet's systems. Facet stores tokenized references, not card numbers, expiration dates, or CVV values.
- Advertising identifiers. Facet does not deploy advertising cookies, does not integrate with advertising identity graphs, and does not sell Personal Data to advertisers.
- Social Security numbers, driver’s license numbers, passport numbers, financial account numbers, or other government-issued identifiers. Facet does not collect any of these on default configuration.
- Children’s Personal Data. The Service is not directed to children. See Section 12 for the triple-threshold children's data policy.
Purposes of processing and legal bases.
Facet Processes Personal Data for the purposes listed below, each supported by a specific legal basis under Art. 6(1) GDPR (and UK GDPR equivalents). Special-category data, if ever Processed under a supplemental agreement, relies on the relevant Art. 9(2) basis identified in that agreement.
| Purpose | Data categories | GDPR Art. 6(1) basis |
|---|---|---|
| Operating the Services (authentication, routing, metering, signing, provenance generation) | Account, authentication, agent identity, request/response metadata | Art. 6(1)(b), performance of a contract with Customer |
| Billing, tax recordkeeping, and financial-regulatory compliance | Account, billing, commerce settlement, tax identifiers | Art. 6(1)(b); Art. 6(1)(c), legal obligation |
| Security, anti-abuse, fraud prevention, and platform integrity | Audit logs, request metadata, admin-session IP, anomaly signals, Agent Reputation Registry | Art. 6(1)(f), legitimate interests in protecting the Services, Customers, Agent Operators, and third parties |
| Support and Customer success | Support communications, account metadata | Art. 6(1)(b) |
| Product improvement using Aggregated or de-identified data only | Aggregated, de-identified metrics | Art. 6(1)(f) |
| Creation and commercialization of Aggregated and De-identified Data Products (benchmarks, indices, market-intelligence) | Aggregated Data, De-identified Data | Art. 6(1)(f) for the derivation; anonymous or aggregated output falls outside the GDPR |
| Marketing communications to existing Customers (“soft opt-in”) | Business contact data | Art. 6(1)(f); PECR Reg. 22(3) soft opt-in where applicable |
| Marketing communications to prospects | Business contact data | Art. 6(1)(a), consent, withdrawable at any time |
| Legal compliance, defense, and regulatory response | All relevant data | Art. 6(1)(c); Art. 6(1)(f) |
| Business transitions (M&A, reorganization, asset sale) | All relevant data | Art. 6(1)(f), subject to protective agreements |
4.1 Legitimate-interest balancing
Where Processing is based on Art. 6(1)(f), Facet has completed a documented Legitimate Interests Assessment ("LIA") confirming that the interests pursued are not overridden by the interests or fundamental rights and freedoms of the data subject. A summary of the LIA is available on request to [email protected].
4.2 Withdrawal of consent
Where Processing is based on Art. 6(1)(a) consent, the data subject may withdraw consent at any time by the method specified at the point of collection, and in any event by email to [email protected]. Withdrawal does not affect the lawfulness of Processing before withdrawal.
4.3 No automated decisions with legal or similarly significant effect
Facet does not undertake automated decision-making that produces legal or similarly significant effects on natural persons within the meaning of GDPR Art. 22. The Agent Reputation Registry described in Section 13 affects Agent Operator access to Terminals; because Agent Operators are typically organizations (or software acting for organizations), reputation scoring does not produce legal or similarly significant effects on natural persons. Where a natural person’s interests are implicated by a reputation action, the Agent Operator appeal mechanism under Section 11.4 of the Terms of Service v2.1 applies.
4.4 Aggregated and de-identified data products
Facet creates and may commercialize Aggregated Data and De-identified Data products, including benchmarks, indices, and market-intelligence, as defined and bounded in Section 5.6 of the Terms of Service. These products never identify a Customer, an end customer, or an individual transaction. Facet does not sell or share end-customer Personal Information, and end-customer Personal Data is Processed only on the Customer’s behalf under the Data Processing Agreement. De-identification follows the standard in California Civil Code Section 1798.140(m), so De-identified Data is not personal information, and its use is not a sale or a sharing under the CCPA as amended by the CPRA. Any use of identifiable Customer data for attributable benchmarking is strictly opt-in under Section 5.7 of the Terms of Service.
Sources of personal data.
5.1 Directly from Customer
Most Personal Data Facet holds is submitted directly by Customer in the sign-up flow, the admin dashboard, or a signed Order Form. This includes account-owner details, billing information, site manifests, and configuration choices.
5.2 From Customer’s identity provider
When Customer's admins sign in via Microsoft Entra ID or Google Workspace, Facet receives OIDC claims (subject, email, name) from the identity provider. Facet does not query the identity provider for additional directory data.
5.3 From Agent Operators via Facet KYA, KYAPay, or DID
When an Agent Operator authenticates to a Terminal, Facet receives a signed Facet KYA claim (ES256 JWT with JWKS discovery, Facet's own default), a signed KYAPay claim from an accepted third-party issuer, or, where expressly accepted by the Customer, a DID-based identity claim. Those claims are cryptographically bound to the issuing authority and represent an attestation from the Agent Operator about its own identity.
5.4 From classifier output
The @facet/classifier library runs inside Customer's environment by default (Cloudflare Worker, Vercel Edge, Docker sidecar) and returns aggregated counts to Facet. Raw log lines are Processed inside Facet's Supabase project only where Customer has explicitly opted into direct NDJSON upload.
5.5 From Facet-maintained and public registries
The Fingerprint Registry draws on published operator fingerprints (Anthropic, OpenAI, Google, Perplexity, Meta, and others), on public bot-traffic observatories (including Cloudflare Radar), and on first-party signals contributed back by identity-authenticated operators on an opt-in basis. The registry is a public-interest reference dataset and does not contain Personal Data about individual visitors.
5.6 From subprocessors
Facet's subprocessors (listed in Section 6) may return limited telemetry to Facet, for example, Stripe returns billing events; Supabase returns infrastructure metrics; Netlify returns edge logs; Microsoft Entra ID and Google Workspace return OIDC claims. These returns are governed by Facet's data-processing agreements with each subprocessor.
5.7 From third parties in exceptional circumstances
Where lawfully required, Facet may receive Personal Data from law-enforcement authorities, courts, or regulators responding to a Customer or Agent Operator matter. Any such receipt is logged and handled under Facet's Government Request Policy and Section 9.5.
Data recipients and subprocessors.
6.1 Subprocessors
Facet engages the subprocessors listed in the table below. Each subprocessor is under a written data-processing agreement that imposes data-protection obligations no less protective than those Facet owes Customer (Art. 28(4) GDPR). This list is the canonical list referenced by the DPA v2.1 Annex III and the Security page v2.0 subprocessor section. The three references are kept byte-for-byte in sync.
| Subprocessor | Purpose | Location | Transfer mechanism (EU/UK/CH → US) |
|---|---|---|---|
| Supabase, Inc. | Managed PostgreSQL, Edge Functions, object storage | USA (us-east-2) | SCC Dec. 2021/914 Module 3 (P2P); UK IDTA; Swiss FADP addendum; EU-US DPF where Supabase has self-certified (verify current status at dataprivacyframework.gov) |
| Netlify, Inc. | Edge routing, static hosting, host-router for facet.llc, app.facet.llc, audit.facet.llc | USA (primary); global edge | SCC Dec. 2021/914 Module 3; UK IDTA; Swiss FADP addendum; EU-US DPF (Netlify is DPF-certified as of current verification) |
| Cloudflare, Inc. | DNS, WAF, DDoS protection, rate-limiting at the edge for facet.llc properties | USA (primary); global edge | SCC Dec. 2021/914 Module 3; UK IDTA; Swiss FADP addendum; EU-US DPF (Cloudflare is DPF-certified as of current verification) |
| Stripe, Inc. | Subscription and metered billing; tax calculation for Customer invoicing; agent-originated card-rail (Visa, Mastercard) settlement | USA | SCC Dec. 2021/914 Module 3; UK IDTA; Swiss FADP addendum; EU-US DPF (Stripe is DPF-certified as of current verification) |
| Skyfire Systems, Inc. (KYAPay) | KYAPay issuer services; agent identity attestation | USA | SCC Dec. 2021/914 Module 3; UK IDTA; Swiss FADP addendum |
| Microsoft Corporation (Entra ID) | OIDC identity-provider service for admin sign-in (multitenant configuration) | USA (primary); EU regions for EU-tenanted identities | SCC Dec. 2021/914 Module 3; UK IDTA; Swiss FADP addendum; EU-US DPF (Microsoft is DPF-certified as of current verification) |
| Google LLC (Workspace OIDC) | OIDC identity-provider service for admin sign-in (Workspace tenants) | USA (primary); regional replicas | SCC Dec. 2021/914 Module 3; UK IDTA; Swiss FADP addendum; EU-US DPF (Google is DPF-certified as of current verification) |
| GitHub, Inc. (Microsoft) | Source-control, CI/CD, deployment pipeline for Facet code (does not process end-user Personal Data) | USA (primary); global edge | SCC Dec. 2021/914 Module 3; UK IDTA; Swiss FADP addendum; EU-US DPF (GitHub is DPF-certified as of current verification) |
Agent-originated USDC settlement occurs non-custodially on-chain via the x402 protocol and Boson escrow. Funds move directly between the Agent Operator's and Supplier's own addresses; Facet does not hold, custody, or process those funds, and no subprocessor is engaged for that transfer.
Facet will provide Customer with at least thirty (30) days prior written notice before appointing a new subprocessor or replacing an existing one, by updating the canonical list and, for Enterprise Customers, by email to the administrative contact. Customer's objection right is set out in DPA v2.1 § 6. DPF-certification status is verified at dataprivacyframework.gov before Facet relies on the DPF for any specific transfer.
6.2 Other recipients
Facet may disclose Personal Data to:
- professional advisers (legal, accounting, insurance, tax) bound by professional duties of confidentiality;
- auditors conducting SOC 2, ISO/IEC 27001, or similar audits, under non-disclosure agreement;
- actual or prospective acquirers, investors, or counterparties in connection with a merger, reorganization, or asset sale, subject to a protective confidentiality agreement;
- public authorities where required by law, subject to Facet's Government Request Policy, which includes prompt notice to the affected Customer where not prohibited by law, and challenge of overbroad or facially-invalid requests.
6.3 No sale; no sharing for cross-context behavioral advertising
Facet does not sell Personal Information within the meaning of CCPA § 1798.140(ad), Virginia Code § 59.1-575, Colo. Rev. Stat. § 6-1-1303, or any equivalent U.S. state statute, and Facet does not share Personal Information for cross-context behavioral advertising within the meaning of CCPA/CPRA § 1798.140(ah). Because Facet does neither, a “Do Not Sell or Share My Personal Information” link is not required; Facet will nevertheless honor browser Universal Opt-Out Mechanisms ("UOOM") and Global Privacy Control ("GPC") signals as if an opt-out request had been submitted, consistent with the laws of California (Cal. Code Regs. tit. 11 § 7025), Colorado, Connecticut, Montana, New Hampshire, New Jersey, Minnesota, and Maryland.
International data transfers.
7.1 Primary processing locations
Facet's primary Processing location is the United States (Supabase us-east-2 for the Facet database; Cloudflare and Netlify operate globally; Stripe operates in the United States). Facet may cause subprocessors to Process Personal Data in other regions for resilience, support, or operational reasons.
7.2 Transfers from the European Economic Area, the United Kingdom, and Switzerland
Where Facet (or Facet's subprocessors under Facet's instruction) transfers Personal Data from the European Economic Area ("EEA"), the United Kingdom, or Switzerland to a country that does not benefit from an adequacy decision, Facet relies on the following transfer mechanisms, layered as required:
- EU Standard Contractual Clauses. The European Commission's Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 of 4 June 2021, in the Module applicable to the specific transfer: Module 2 (Controller-to-Processor) for transfers where Customer is Controller and Facet is Processor; and Module 3 (Processor-to-Processor) for onward transfers from Facet as Processor to a subprocessor. The specific Module selected for each subprocessor is stated in DPA v2.1 Annex III.
- UK International Data Transfer Agreement (IDTA). The UK Information Commissioner's Office International Data Transfer Agreement or the International Data Transfer Addendum to the EU SCCs, in each case at the version in force at the time of transfer, for transfers subject to UK GDPR.
- Swiss FADP addendum. The Federal Data Protection and Information Commissioner's recognized Swiss addendum to the EU SCCs, for transfers subject to Swiss FADP.
- EU-US Data Privacy Framework. For Personal Data transferred to U.S. subprocessors that have self-certified to the EU-US Data Privacy Framework (DPF) (adequacy decision of 10 July 2023, implementing Commission Decision (EU) 2023/1795), the UK Extension to the DPF, and the Swiss-US DPF, Facet may rely on the applicable DPF framework for so long as the subprocessor remains actively certified at dataprivacyframework.gov. Where DPF certification lapses or the underlying adequacy decision is suspended or invalidated, Facet relies on the SCCs (plus IDTA or Swiss addendum as applicable) as a fallback without gap.
- Adequacy decisions. Where an adequacy decision applies to a destination (for example, Japan private-sector adequacy, Republic of Korea adequacy, UK adequacy for Swiss/EU exports), Facet relies on the adequacy decision.
- Art. 49 derogations. Facet does not rely on Art. 49 derogations for systematic transfers. Where a one-off transfer depends on a derogation (for example, Art. 49(1)(b) contract performance with the data subject), Facet documents the basis in its records of Processing activities under Art. 30.
7.3 Transfer Impact Assessments
Facet conducts Transfer Impact Assessments ("TIAs") using the methodology in European Data Protection Board Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of Personal Data, as updated. TIAs consider: the legal regime at the destination (government-access laws, FISA 702 and EO 12333 context for U.S. destinations); the likelihood of access requests; the nature, sensitivity, and volume of the data; the technical and organizational supplementary measures applied (including encryption in transit via TLS 1.3, encryption at rest via AES-256, pseudonymization, key management, and zero-anon-grant RLS on public schemas); and compensating contractual and procedural measures (transparency reporting, challenge of overbroad requests, customer-notice commitments). TIAs are reviewed annually and whenever a destination's legal regime materially changes.
7.4 Right to receive a copy of safeguards
On request to [email protected], Facet will provide data subjects and Customers with a copy of the applicable transfer safeguards (SCCs, IDTA, or Swiss addendum) with commercially sensitive information redacted. Requests are handled under Section 11.
Retention periods.
Facet retains Personal Data only as long as necessary for the purposes in this Policy and as required or permitted by law. Retention periods are set by category below, subject to extension where required by legal hold, regulatory obligation, or dispute resolution:
| Category | Retention | Reason |
|---|---|---|
| Audit logs (admin sign-ins, configuration changes, key rotations, signature operations) | Seven (7) years after event | SOC 2 control evidence; financial-record retention; regulatory defense |
| Customer account data and billing records | Seven (7) years after termination of Customer's last Order | U.S. IRS recordkeeping; HMRC six-year retention for UK-taxable flows; contract-dispute defense |
| Raw agent-call metadata | Ninety (90) days | Operational troubleshooting; abuse detection |
| Classifier aggregates (where Facet holds them) | Eighteen (18) months | Product benchmarking; fraud-trend analysis |
| Directly-uploaded NDJSON (Agent Traffic Audit hosted path) | Thirty (30) days in hot storage, then deletion | Audit-report generation only |
| Commerce settlement records | Seven (7) years after settlement | Financial-record retention; chargeback dispute; potential tax-authority audit |
| Support conversations | Three (3) years after close | Customer history; troubleshooting patterns |
| Marketing contact data | Twenty-five (25) months from last engagement, or until opt-out, whichever is earlier | PECR / ePrivacy soft-opt-in recency window |
| Security, access, and incident logs | Thirteen (13) months hot storage; up to seven (7) years cold storage if required for incident investigation or compliance | Incident forensics; regulator and law-enforcement cooperation |
| Backups | Thirty (30) days rolling, then overwritten | Disaster recovery |
| Aggregated and de-identified data | Indefinitely, without re-identification | Benchmarking; public-interest reporting (e.g., agent-traffic observatory) |
Where Customer or a data subject requests deletion, Facet deletes the identifiable record from production within thirty (30) days and overwrites backups in the ordinary course within ninety (90) days, except for records subject to legal hold. Aggregated data that cannot be re-identified is retained beyond these windows. Legal hold, government request, or open claim may require Facet to retain specific records longer than the default period; Facet documents the reason.
Security measures and breach notification.
9.1 Technical and organizational measures
Facet implements technical and organizational measures designed to protect Personal Data against unauthorized or unlawful Processing, accidental loss, destruction, or damage, as required by GDPR Art. 32. Measures include: TLS 1.3 in transit; AES-256 encryption at rest (managed by Supabase); Ed25519 response signing with quarterly key rotation; per-supplier PostgreSQL tenant isolation; row-level security with zero anonymous grants on public schemas; MFA-enforced admin sign-in; append-only audit logs; automated backups with point-in-time recovery; WAF and DDoS protection at the edge; rate limiting; and an incident-response program with 24×7 engagement for P1 events. Full documentation of controls, certifications roadmap, vulnerability-disclosure program, and the canonical subprocessor list is maintained in the Security page v2.0 at facet.llc/legal/security.html.
9.2 No security control is perfect
Facet does not guarantee that Personal Data will never be subject to unauthorized access. Where a Personal Data Breach (GDPR Art. 4(12)) occurs, the notification timelines and contents in Section 9.3 apply.
9.3 Breach notification timelines
Where Facet confirms a Personal Data Breach affecting Personal Data under Facet's control as Controller, Facet will notify the competent supervisory authority without undue delay and, where feasible, not later than seventy-two (72) hours after becoming aware of the breach, in accordance with GDPR Art. 33(1), UK GDPR Art. 33(1), and the Swiss FADP, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the breach is likely to result in a high risk, Facet will notify the affected data subjects without undue delay, in accordance with Art. 34(1).
Where Facet acts as Processor on behalf of Customer, Facet will notify Customer of a confirmed Personal Data Breach affecting Customer Personal Data within forty-eight (48) hours of confirmation, in accordance with DPA v2.1 § 8, together with the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to mitigate the breach.
For U.S. state law, Facet complies with notification timelines applicable to the affected resident, including: Cal. Civ. Code § 1798.82 (California, notification “in the most expedient time possible and without unreasonable delay”); N.Y. Gen. Bus. Law § 899-aa (New York); the breach-notification provisions of each of the U.S. state comprehensive privacy laws listed in Section 14; and sectoral federal regimes (HIPAA, GLBA) where applicable. Facet notifies U.S. state attorneys general and consumer reporting agencies where statutorily required.
9.4 Content of breach notices
Breach notices include: (a) the nature of the breach; (b) the categories and approximate number of data subjects and records concerned; (c) the name and contact details of Facet's security contact at [email protected]; (d) the likely consequences of the breach; (e) the measures taken or proposed to address the breach and mitigate its possible adverse effects; and (f) where required by law, remediation steps and identity-protection offers available to data subjects.
9.5 Government and law-enforcement requests
Facet's Government Request Policy requires Facet to: (a) verify the legal validity of the request; (b) challenge overbroad, facially invalid, or legally impermissible requests; (c) narrow the scope of disclosure to what is legally required; (d) where not legally prohibited, give prompt notice to the affected Customer or data subject so they may challenge; and (e) report aggregate statistics in a periodic transparency report. Facet treats U.S. national-security process under EO 12333 and FISA 702 as within scope of this policy and is committed to publishing a periodic transparency report consistent with U.S. legal constraints.
Your rights.
Depending on your jurisdiction and the data in question, you may have the following rights with respect to Personal Data Facet holds about you. Rights applicable in specific U.S. states are additionally summarized in Section 14.
- Access (GDPR Art. 15; UK GDPR Art. 15; Swiss FADP Art. 25; CCPA § 1798.110; VCDPA § 59.1-577(A)(1); analogous provisions in other states). Obtain confirmation that we Process Personal Data about you, a copy of the Personal Data, and information about the Processing.
- Rectification / correction (GDPR Art. 16; CPRA § 1798.106; state-law analogues). Have inaccurate Personal Data corrected or incomplete data completed.
- Erasure / deletion (GDPR Art. 17; CCPA § 1798.105; state-law analogues, subject to exceptions).
- Restriction of processing (GDPR Art. 18).
- Portability (GDPR Art. 20; CCPA § 1798.100(d); state-law analogues). Receive Personal Data you provided in a structured, commonly used, machine-readable format and transmit it to another Controller.
- Objection (GDPR Art. 21). Object to Processing based on Art. 6(1)(e) or (f), including profiling; Facet will cease Processing unless we can demonstrate compelling legitimate grounds that override your interests.
- Withdrawal of consent (GDPR Art. 7(3)). Where Processing is based on Art. 6(1)(a) consent, withdraw at any time without affecting lawfulness of prior Processing.
- Opt-out of sale, sharing, and targeted advertising (CCPA/CPRA; VCDPA; CPA; CTDPA; OCPA; TDPSA; and all U.S. state comprehensive privacy laws). Facet does not sell or share for cross-context behavioral advertising; UOOM and GPC are honored as described in Section 6.3.
- Opt-out of profiling with legal or similarly significant effects (VCDPA; CPA; CTDPA; OCPA; TDPSA; Minnesota CDPA right to question automated decisions).
- Limit use of sensitive Personal Information (CPRA § 1798.121). Facet does not collect Sensitive Personal Information; the right nevertheless applies and Facet will honor requests.
- Right to appeal (VCDPA, CPA, CTDPA, OCPA, TDPSA, and other U.S. state laws that provide a statutory appeal mechanism; see Section 11.4).
- Shine the Light (Cal. Civ. Code § 1798.83). California residents may request information about Facet's disclosure of Personal Information to third parties for those third parties' direct-marketing purposes in the prior calendar year. Facet does not disclose Personal Information for third-party direct-marketing purposes. Requests may be sent to [email protected].
- Complaint (GDPR Art. 77). Lodge a complaint with your local data-protection supervisory authority, including the supervisory authority of the Member State of your habitual residence, place of work, or place of the alleged infringement; the UK Information Commissioner's Office (ICO); the Swiss Federal Data Protection and Information Commissioner (FDPIC); or your U.S. state attorney general.
- Non-discrimination (CCPA § 1798.125; state-law analogues). Facet will not deny services, charge different prices, or provide different-quality services because you exercised a privacy right.
Where Facet acts as Processor on behalf of Customer, Facet will route your request to Customer and assist Customer in responding, on the timelines required by the DPA v2.1 and applicable law. You may also address your request to Facet directly and Facet will coordinate with the Controller.
How to exercise your rights.
11.1 Submitting a request
Email [email protected] with a clear description of your request, the nature of your relationship with Facet or with a Customer (account owner, Agent Operator, visitor to the marketing site, or person whose data was submitted by a Customer), and enough information to verify your identity. Authorized agents may submit requests on your behalf with proof of authorization and independent verification of the data subject's identity.
11.2 Verification
To protect data subjects, Facet takes reasonable steps to verify identity before acting on a rights request. Verification may involve: a reply to the email address already on file; a signed challenge from a cryptographic identifier you previously bound to an account; or, where necessary, a government-issued identification document handled under strict confidentiality and retained only as long as needed to complete verification. Verification methods are proportionate to the sensitivity of the data at issue.
11.3 Response times
Facet will acknowledge your request within five (5) business days and respond substantively within thirty (30) days. Where a request is complex or where Facet receives a high volume of requests, Facet may extend the response period by a further thirty (30) days and will notify you of the extension and its reasons within the original thirty-day window. No fee applies to reasonable requests; where a request is manifestly unfounded or excessive, Facet may charge a reasonable fee or decline to act, and will explain why.
11.4 Appeals
If you are dissatisfied with Facet's response to a rights request, you may appeal by replying to the original request thread within forty-five (45) days and asking for a second-level review, which will be conducted by a reviewer who was not involved in the original decision. Facet will respond to an appeal within sixty (60) days of receipt. Residents of Virginia, Colorado, Connecticut, Oregon, Texas, Montana, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Iowa, Indiana, Delaware, Rhode Island, and Kentucky may additionally exercise the statutory appeal mechanism on the timelines their laws require. Residents of the EEA, UK, or Switzerland may lodge a complaint with their supervisory authority at any time.
Children’s data.
The Service is not directed to children and is designed for business and enterprise use. Facet does not knowingly collect Personal Data from children. The applicable age of digital consent differs by jurisdiction:
- United States: COPPA (15 U.S.C. §§ 6501 to 6506; 16 CFR Part 312). Facet does not knowingly collect Personal Information from children under the age of thirteen (13) without verifiable parental consent. If Facet learns it has collected Personal Information from a child under 13 without the required parental consent, Facet will delete that information promptly as required by 16 CFR § 312.10.
- European Economic Area: GDPR Art. 8. Facet does not knowingly collect Personal Data from children under the applicable age of digital consent. The default age is sixteen (16), which individual Member States may reduce to not lower than thirteen (13). Facet recognizes each Member State's specific threshold where the Member State has set a lower age.
- United Kingdom: UK GDPR § 9 of the Data Protection Act 2018. The applicable age of digital consent is thirteen (13).
- Other jurisdictions. Facet applies the higher of the COPPA or the jurisdiction-specific age of digital consent where applicable.
If you believe a child has provided Personal Data to Facet in violation of the applicable threshold, email [email protected] and Facet will delete the data promptly. This Policy does not cover Processing by Customers through their own services, for which Customers remain solely responsible.
Agent Identity Data.
Facet operates an agent-commerce protocol in which autonomous agents, software acting on behalf of an organization or, less commonly, on behalf of a natural person, interact with Facet Terminals. The data generated by these interactions includes cryptographic identifiers, tokens, and behavior logs that do not map cleanly to the traditional Personal-Data / non-Personal-Data distinction. This Section 13 sets out Facet's current framing, a regulatory-risk acknowledgment, and a fallback position, consistent with the novel-framing disclosure requirement under the Terms of Service v2.1 § 11.6(a).
13.1 Framing
Agent identifiers, Facet KYA tokens, KYAPay tokens, DID records, agent configuration, and agent-behavior logs (collectively, "Agent Identity Data") are treated as Customer Content of the Customer whose Terminal the agent interacts with, not as Personal Information of a natural person, unless the data is reasonably linkable to a specific natural person (for example, where an identity token embeds a natural-person email as the sub claim). Where Agent Identity Data is reasonably linkable to a natural person, Facet treats the linkable subset as Personal Data and applies this Policy, the DPA v2.1, and the GDPR where applicable.
13.2 Regulatory-risk acknowledgment
The legal treatment of machine-generated, agent-attributed data under GDPR, UK GDPR, Swiss FADP, CCPA/CPRA, and analogous regimes is unsettled. A competent authority, an EU Data Protection Authority, the UK ICO, the Swiss FDPIC, the California Privacy Protection Agency, a state attorney general, or a court, may determine that some or all Agent Identity Data constitutes Personal Information; or that the persistence of agent identifiers across sessions creates profiling risks under GDPR Art. 22; or that principal-agent attribution makes natural-person operators identifiable through behavioral linkage. Facet will monitor regulatory developments and adjust its framing accordingly.
13.3 Fallback position
If a competent authority determines that Agent Identity Data (or a subset of it) constitutes Personal Information, Facet will, from the date of notice: (a) treat the affected data as Personal Data under this Policy and the DPA v2.1, including applying retention (Section 8), transfer-mechanism (Section 7), and data-subject-rights (Section 10 & 11) obligations; (b) provide affected Customers and Agent Operators with written notice of the re-classification; and (c) where applicable, publish a material-change notice under Section 15.
Customer may terminate the affected Services on thirty (30) days written notice if the re-classification materially increases Customer's compliance obligations, on the terms set out in Terms of Service v2.1 § 1.3 (modification) and § 8.3 (termination).
13.4 Cross-site Agent Reputation Registry
Facet maintains a cross-site Agent Reputation Registry recording network-wide behavioral signals attributed to each Agent Identity. Registry entries are keyed to Agent Identity (not to a natural person). Where a registry entry becomes linkable to a natural person under Section 13.1, the entry is treated as Personal Data. Agent Operators may appeal registry actions under Terms of Service v2.1 § 11.4; natural persons whose identities are reasonably linked to an Agent Identity may additionally exercise the rights in Section 10 of this Policy.
U.S. state privacy rights.
Residents of the U.S. states listed below have the rights provided by their state comprehensive privacy statute, in addition to the rights generally available under Section 10 of this Policy. The table summarizes applicability thresholds, key rights, and whether the state mandates recognition of Universal Opt-Out Mechanism ("UOOM") / Global Privacy Control ("GPC") signals.
| State | Statute | Effective | Key rights beyond Section 10 baseline | UOOM/GPC |
|---|---|---|---|---|
| California | CCPA as amended by CPRA (Cal. Civ. Code § 1798.100 et seq.) | Jan 1, 2020 / Jan 1, 2023 | Access; Delete; Correct; Portability; Opt-out of Sale/Sharing; Limit Use of Sensitive PI; Non-Discrimination; Shine the Light (§ 1798.83) | Mandatory (GPC) |
| Virginia | VCDPA (Va. Code § 59.1-575) | Jan 1, 2023 | Access; Delete; Correct; Portability; Opt-out of targeted advertising, sale, profiling with legal/significant effects; statutory appeal | Permissive |
| Colorado | CPA (Colo. Rev. Stat. § 6-1-1301) | Jul 1, 2023 | Same as VCDPA + mandatory UOOM recognition | Mandatory |
| Connecticut | CTDPA (Conn. Gen. Stat. § 42-515) | Jul 1, 2023 | Same as VCDPA + sixty (60)-day erasure; UOOM mandatory from Jan 1, 2025 | Mandatory |
| Utah | UCPA (Utah Code § 13-61-101) | Dec 31, 2023 | Access; Delete; Portability; Opt-out of targeted advertising and sale (narrower than VCDPA) | Not required |
| Texas | TDPSA (Tex. Bus. & Com. Code § 541) | Jul 1, 2024 | VCDPA-style; broader applicability (no revenue threshold) | Not required (permissive) |
| Oregon | OCPA | Jul 1, 2024 | VCDPA-style + derived-data disclosure on request | Permissive |
| Montana | MCDPA | Oct 1, 2024 | VCDPA-style; UOOM mandatory | Mandatory |
| Delaware | DPDPA | Jan 1, 2025 | VCDPA-style; lower applicability threshold (35,000 consumers or 10,000 + 20% revenue from sale) | Permissive |
| Iowa | ICDPA | Jan 1, 2025 | Access; Delete; Portability; Opt-out of sale (narrower scope) | Not required |
| New Hampshire | NHPA | Jan 1, 2025 | VCDPA-style; UOOM mandatory | Mandatory |
| New Jersey | NJ Data Privacy Act | Jan 15, 2025 | VCDPA-style + expanded sensitive-data list; UOOM mandatory | Mandatory |
| Tennessee | TIPA | Jul 1, 2025 | VCDPA-style with affirmative defense for NIST-aligned privacy programs | Not required |
| Minnesota | MCDPA (Minnesota Consumer Data Privacy Act) | Jul 31, 2025 | VCDPA-style + right to question results of automated decisions; UOOM mandatory | Mandatory |
| Maryland | MODPA | Oct 1, 2025 | Data-minimization duty; prohibition on sale of Sensitive PD and minors’ data; UOOM mandatory | Mandatory |
| Indiana | INCDPA | Jan 1, 2026 | VCDPA-style | Not required |
| Rhode Island | Data Transparency and Privacy Protection Act | Jan 1, 2026 | VCDPA-style | Not required |
| Kentucky | KY Consumer Data Protection Act | Jan 1, 2026 | VCDPA-style | Not required |
14.1 Sectoral state laws
- Illinois BIPA (740 ILCS 14). Biometric-identifier privacy with a private right of action. Facet does not collect biometric data from Illinois residents.
- Washington My Health My Data Act. Health-data-specific with private right of action. Facet does not knowingly Process consumer health data.
- New York SHIELD Act. Reasonable-security and breach-notification obligations. Facet complies with N.Y. Gen. Bus. Law § 899-aa where applicable.
14.2 How Facet applies the strongest standard
For operational simplicity, Facet applies the strongest applicable U.S. state standard to all U.S. residents where operationally feasible. Where a state law provides broader protection than Section 10 of this Policy, Facet will honor the state-law right. Where a state law provides narrower protection, Facet will not use it to restrict the Section 10 baseline.
14.3 Verification of currency
U.S. state privacy law continues to be enacted and amended at a rapid cadence. This Section 14 is current as of the Effective Date of this Policy (2026-04-23). Before relying on Section 14 for regulatory purposes, Customer or a data subject should verify whether a new state comprehensive privacy law has been enacted or an existing law has been amended.
Changes to this Policy and how to contact us.
15.1 Changes
Facet may update this Policy from time to time. The version number and Effective Date in the eyebrow reflect the current version. For material changes, any change to data categories, Processing purposes, legal bases, recipients, international-transfer mechanisms, retention periods, data-subject rights, or breach-notification practices, Facet will provide at least thirty (30) days prior written notice by (a) posting a notice in the admin dashboard and on the Facet marketing site at facet.llc/legal/, and (b) emailing the administrative contact on each active Customer account. Non-material changes (clarifications, formatting corrections, typographical corrections, contact-detail updates) may be made without notice and take effect on posting. An archive of historical versions is maintained at facet.llc/legal/ and is available on request to [email protected].
15.2 Contact
For privacy questions, rights requests, or complaints, contact Facet's privacy team:
Email: [email protected]
Postal: Facet, LLC, Attn: Privacy, 1 Market St, Suite 100, San Francisco, CA 94105
Security matters: [email protected]
Legal counsel: [email protected]
15.3 EU / UK representatives and DPO
Facet has not yet appointed an EU Representative under GDPR Art. 27 or a UK Representative under UK GDPR Art. 27, because Facet's current EU/UK offering is B2B and has not crossed the thresholds that trigger mandatory appointment. Where the thresholds are crossed, Facet will appoint a representative and publish the contact details on this page. Facet has not appointed a Data Protection Officer under GDPR Art. 37; Facet's privacy lead is contactable at [email protected].
15.4 Supervisory authorities
EU data subjects may lodge a complaint with the supervisory authority of the Member State of habitual residence, place of work, or place of the alleged infringement; as a B2B platform without a single EU establishment, Facet does not rely on a lead supervisory authority. UK data subjects may lodge a complaint with the ICO at ico.org.uk. Swiss data subjects may contact the FDPIC at edoeb.admin.ch.