Privacy Policy
1. Overview
This Privacy Policy explains how Rulebase Technologies Inc. (“Rulebase”, “we”, “us”) collects, uses, and protects personal information when you visit our website or use our services. We build for regulated financial services, and we treat data protection as a core product requirement, not an afterthought.
2. Information we collect
We collect information you provide directly — such as your name, work email, and company details when you request a demo or contact us. When you use the platform, we process the customer-interaction data your organization connects to the services on your organization’s behalf and under its instructions. We also collect standard technical information such as browser type, device information, and usage analytics.
3. How we use information
We use information to provide and secure the services, respond to inquiries, improve product performance, and meet our legal obligations. We do not sell personal information. Customer-interaction data processed through the platform is used solely to deliver the services to your organization.
4. Data security
We maintain administrative, technical, and physical safeguards designed to protect personal information — including encryption in transit and at rest, access controls, and continuous monitoring. Rulebase maintains SOC 2 compliance and aligns with GDPR requirements.
5. Data retention
We retain personal information only as long as necessary for the purposes described in this policy, to comply with legal obligations, or as instructed by the organization that controls the data. Customer Data is deleted or returned in accordance with our contractual commitments upon termination of services.
6. Sharing
We share information only with service providers who process it on our behalf under contractual confidentiality obligations, when required by law, or in connection with a corporate transaction. We require all subprocessors to meet security standards consistent with our own.
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict the processing of your personal information. If your data is processed on behalf of one of our customers, we will direct your request to that organization. To exercise your rights, reach out through the contact page.
8. Cookies and analytics
We store one necessary privacy-preference record in your browser’s local storage. It records which optional tools you allowed, when you chose, and when the choice expires. We keep that preference for 180 days so we do not ask on every visit.
Product analytics. If you opt in, PostHog measures page views and interactions so we can improve the website. Our implementation uses PostHog’s EU service endpoint, keeps its visitor identifier in memory rather than a cookie or local storage, respects Do Not Track, and disables session recording.
Visitor insights. If you separately opt in, Mesh by Avina records session and form interactions and technical data such as device and IP information. Depending on the vendor settings enabled for Rulebase, it may use providers such as Vector or RB2B to identify a business or business visitor. The SDK may store browser identifiers, including a Mesh visitor identifier for up to 30 days.
Scheduling. The Cal.com booking embed is loaded only when you select a demo or get-started button. At that point, Cal.com processes the booking information you submit and the technical data needed to provide the booking service.
These optional tools remain off until you choose them. You can accept, reject, or select them individually, and you can withdraw consent at any time using Cookie Settings in the footer. Withdrawing consent stops future collection on this website.
9. Changes to this policy
We may update this policy from time to time. We will post the revised version on this page and update the date above. Material changes will be communicated with reasonable notice.
10. Contact
For privacy questions or requests, contact us through the contact page.