Privacy Policy
How Ash handles personal information — yours, and that of the people who call, text and email your business.
Last updated 2026-08-01
Who this policy is from.
Hubify Solutions Inc. operates Ash, an AI assistant for businesses, at hiash.ai. This policy explains what personal information we handle, why we handle it, and what you can ask us to do about it.
It covers two different relationships, and the difference decides who is answerable for what. When you visit hiash.ai or become a customer, we are the organisation responsible for your information. When Ash answers calls and messages for your business, we handle your clients' information on your behalf and under your instructions — you remain the organisation your clients deal with, and the one accountable to them.
We operate in British Columbia, Canada and are subject to the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and to British Columbia's Personal Information Protection Act (PIPA).
What this website collects.
Almost nothing, and that is deliberate. hiash.ai sets no cookies, runs no analytics, and loads nothing from a third party — the typefaces are served from this domain, and no script, pixel or font is fetched from anywhere else when you open a page. There is no cookie banner because there is nothing to consent to.
The server that serves this site keeps ordinary request logs, which include IP addresses, for security and diagnostics. Cloudflare sits in front of the site and keeps its own logs for the same reasons.
If you email us, we keep that correspondence so we can reply to it and so we have a record of what was agreed.
What Ash handles when it works for a business.
When a business connects Ash to its phone number, calendar, email and CRM, Ash handles information about the people who contact that business. What it handles depends on what those people say and send.
- Calls
- Audio recordings of calls Ash answers, and written summaries of them.
- Messages
- Text messages and emails sent to the business, and the replies Ash sends or drafts.
- Contact details
- Names, phone numbers and email addresses given during a conversation.
- What was discussed
- Appointments, enquiries, timelines, budgets and other details a caller volunteers.
- Lead source
- Which channel produced the enquiry.
Call recordings.
Ash records the calls it answers. This is the most sensitive thing it handles, so it is set out separately rather than left inside a list.
Recordings are kept for 30 days and then deleted automatically. We do not keep an archive beyond that period, and we cannot retrieve a recording once it has passed.
Within that window, a recording is available to the business the call was placed to — its owner and the people they have authorised. It is not shared with other customers, and we do not listen to recordings except where it is necessary to investigate a fault or a security incident, or where the law requires it.
Who is responsible for obtaining consent.
Under Canadian privacy law an organisation must have meaningful consent to collect personal information, and a person must know that a call is being recorded and why.
The business using Ash is the organisation with the relationship to its callers, and it is responsible for ensuring that its callers are informed and that recording is permitted where it and its callers are located. Our Terms of Service place that obligation on the customer explicitly. We provide the tools and the retention limits; we are not in a position to know what a given business has told its clients.
If you have called a business that uses Ash and you want to know what was recorded or ask for it to be deleted, contact that business directly. They control the record. If you cannot reach them, write to us at [email protected] and we will help you find the right route.
Why we handle this information.
To answer calls and messages on behalf of a business, to book appointments in its calendar, to keep a record of its clients in its own CRM, to send its daily summary, and to let its owner review what happened. We also use information to operate, secure and support the service itself.
We do not sell personal information. We do not share it with advertisers. We do not use the content of a customer's calls, messages or client records to train machine learning models.
Service providers.
Ash is built on services provided by other companies, and running it means information passes through them. Each is used for a specific purpose and is bound by its own agreement with us.
Several of these providers operate outside Canada, primarily in the United States. That means information may be stored or processed outside Canada and may be accessible to foreign courts and law enforcement under the laws of those countries. This is disclosed here because British Columbia's PIPA requires it.
- Telephony and messaging
- To receive and place calls and text messages.
- Voice assistant
- To hold a spoken conversation and produce a transcript.
- Calendar and email
- To read availability, write bookings and handle email, using the accounts a customer connects.
- CRM
- To write client records into the customer's own HubSpot or Follow Up Boss account.
- Payments
- To take subscription payments. Card details are handled by the payment provider and never reach us.
- Infrastructure
- Hosting, network protection and transactional email.
How long we keep things.
Call recordings are deleted after 30 days, automatically.
Client records written into a customer's CRM belong to that customer and live in their account — we do not control how long they are kept there, and deleting a business's Ash account does not delete what has already been written into their own systems.
Account and billing records are kept for as long as the account is open and afterwards for the period Canadian tax and corporate law requires. Correspondence is kept while it is useful for support.
Your rights.
You may ask what personal information we hold about you, ask for a copy of it, ask us to correct it if it is wrong, and withdraw consent for its use — subject to legal and contractual limits, and noting that withdrawing consent may mean we can no longer provide the service.
Write to [email protected]. We will respond within 30 days, which is the period PIPEDA sets. We may need to verify who you are before disclosing anything, because handing personal information to the wrong person is itself a breach.
If you are not satisfied with our answer, you may complain to the Office of the Privacy Commissioner of Canada, or to the Office of the Information and Privacy Commissioner for British Columbia.
Security.
Credentials for connected accounts are encrypted. Each business's data is kept separate from every other business's. Access to production systems is limited to the people who need it to operate the service.
No system is perfectly secure, and we would rather say so than imply otherwise. If a breach occurs that creates a real risk of significant harm, we will notify the affected customers and the Privacy Commissioner as the law requires.
Changes to this policy.
We will update this page when what we do changes, and the date at the top will change with it. If a change materially affects how personal information is handled, we will tell customers directly rather than relying on them to notice.
Contact.
Questions about this policy, or a request about your own information: [email protected].
Hubify Solutions Inc. is incorporated in British Columbia, Canada and operates from Coquitlam. We are a small company and do not publish a street address. If you need one in writing — to serve a formal notice, or to support a complaint to a regulator — ask at [email protected] and we will give it to you.