Who we are and what this covers
Fasha is operated by Fasha LLC, a Delaware limited liability company (“we,” “our,” or “us”). This policy covers the Fasha website and application, including our ERP and real estate services previously branded fwdERP. It explains what information we collect, why we use it, how we share and retain it, and the choices available to you.
Information we collect
We collect information you provide when you create an account, request a demo, or use Fasha: your name and contact details, organization and role, account credentials, billing information, and the business records you enter or upload. We also collect technical and usage information such as IP address, browser and device details, pages visited, feature activity, and security logs.
When you authorize an integration, we receive the data and permissions needed for the features you enable. Connected services may provide email messages and attachments, calendar events, financial transactions, contact information, connection identifiers, and access credentials. The specific Google data we use is described below.
How we use information
- Provide the accounting, real estate, communication, document, and agent workflows you request or enable.
- Process transactions; keep related records; and provide support, administrative notices, and security alerts.
- Maintain integrations and improve the reliability, security, and usability of the service.
- Comply with legal obligations and enforce our terms.
Google: Gmail and optional Calendar
When you connect a Google account, Fasha uses the permissions you grant for connected features. A Google connection does not automatically enable every automation: mailbox access, memberships, agent assignments, and workflow settings determine what runs.
- Gmail: Fasha may read message content and attachments, senders, recipients, subjects, labels, and timestamps to show and search mail, create communication records, prepare or send replies and drafts, and process documents or agent workflows you enable. The Gmail permission may allow reading, sending, and changing messages; Fasha uses those capabilities according to your settings and actions.
- AI processing with consent: When you enable AI features, Fasha may send email content, metadata, and attachments to OpenAI and Anthropic for summaries, classification and routing, document extraction, writing-style analysis, draft replies, and agent workflows you request or enable.
- Calendar is separate: Fasha accesses Google Calendar event data only when you enable Calendar permissions. Event titles, times, descriptions, locations, and attendees support availability, scheduling, and event management. With your consent to agent assistance, those details may also be sent to OpenAI and Anthropic for enabled features.
- Limited use: We use Google user data, including data derived from it, for these user-facing features. We do not sell it, use it for advertising, or use it to develop or train generalized AI models.
Fasha’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Sharing and service providers
We do not sell personal information. We share information with providers that help us host, store, secure, and operate Fasha, and with OpenAI and Anthropic for enabled AI features as described above. Within your organization, workspace users and mailbox members may see information according to their permissions and sharing settings. We may also disclose information when required by law or needed to investigate abuse and security incidents, subject to the restrictions that apply to Google user data. Other sharing occurs with your consent.
If a business transfer involves Google user data, we will obtain any prior consent required by Google’s Limited Use requirements.
Security
Fasha uses authenticated access and permissions for company and mailbox data, encrypts stored OAuth access and refresh tokens, and uses HTTPS for browser and Google API connections. No security measure eliminates every risk.
Disconnecting, revoking access, and retention
You can remove a workspace’s Google connection in Fasha’s email settings. To avoid disrupting other Fasha connections to the same Google account, provider access may be retained when you disconnect one workspace. You can review or revoke Fasha’s access in your Google Account connections; revocation may affect other Fasha workspaces using that account. If a provider revocation attempt fails, Fasha disables the connection and retains it for retry rather than representing it as successfully disconnected.
Disconnecting or revoking access stops future authorized access but does not automatically delete data already stored in Fasha. Imported bills and documents, communication records, calendar data, agent tasks, and other business records may remain to support the organization’s workflows and legal obligations. To request deletion of stored personal or connected-service data, contact your workspace administrator or privacy@fwdap.io. We will review the request and explain any records that must be retained.
Your choices and rights
Depending on your location, you may have rights to access, correct, delete, or obtain a copy of your personal information, to object to or restrict processing, and to withdraw consent. Contact us to exercise these rights. You can also manage enabled workflows in Fasha and manage Google permissions through your Google Account.
Children and policy changes
Fasha is not intended for people under 18. We do not knowingly collect children’s personal information. We may update this policy as our services or practices change; the date above shows when it was last updated.
Contact us
Fasha LLC
Email: privacy@fwdap.io