Privacy policy
Effective 12 August 2026 · Lyt Brox Pte Ltd, Singapore
Firavia is operations software for fire protection companies, operated by Lyt Brox Pte Ltd, a company registered in Singapore ("we", "us"). This policy explains what data we collect, why, where it lives, and the rights you have over it. We wrote it to be read, not skimmed past.
Two kinds of data, two roles
Your account and workspace data. When your company signs up, we act as a data controller for the information we need to run your subscription: your name, work email, company details, and billing state.
Your operational data. The customers, sites, contacts, work orders, service reports, photos, signatures, invoices and documents you put into Firavia belong to your company. For this data we act as a processor: we store and process it only to provide the service to you, and your company decides what goes in and who sees it. If your customers' employees use the portal you grant them, their access is governed by your company's relationship with them; we process their login and activity only to provide the portal.
What we collect
- Account data — name, work email, phone (if you add it), role, company name and settings.
- Operational data — everything your team enters to run your operations, including photos and signatures captured on site.
- Billing data — your subscription state, seat count and invoice history. Card numbers never touch our servers: payment runs entirely on Stripe, and we hold only a reference to your Stripe customer record.
- Support conversations — what you write to support, so we can answer and improve the product.
- Technical data — authentication events and server logs (IP address, timestamps, actions) kept for security and debugging.
We use a session cookie to keep you signed in. We do not run advertising trackers on the app, and we do not sell data to anyone, in any form, full stop.
How the AI features handle your data
Some features send the specific text or document you submit to an AI model to structure it: support questions, pasted enquiries, uploaded agreement documents, and scheduling suggestions. This processing runs through Anthropic's API under commercial terms that do not permit training on your data. The AI suggests; a person in your company confirms before anything is saved. We do not feed your operational database to AI models in the background.
Where your data lives
Your data is stored with Supabase on AWS infrastructure in the Asia-Pacific region (Tokyo, ap-northeast-1), with transport encryption (TLS) everywhere and encryption at rest. Backups are managed within the same infrastructure.
Who processes data for us
| Provider | Purpose |
|---|---|
| Supabase (AWS) | Database, authentication, file storage, serverless functions |
| Stripe | Payments, subscriptions, invoices — card data stays with Stripe |
| Resend | Transactional email (invites, password links, notifications) |
| Anthropic | AI processing of text you explicitly submit (no training on your data) |
| Netlify | Hosting of the website and application |
| Optional "Sign in with Google" — only if you choose it |
Each provider processes only what its purpose requires, under its own security and data-processing commitments.
Tenant isolation
Every record in Firavia carries your company's identity, enforced in the database itself, not just hidden by the interface. Another company on Firavia cannot read a single row of yours. We attack this isolation in automated testing on every release, because it is the one property this product cannot exist without.
How long we keep data
- Account and operational data: for the life of your subscription.
- After cancellation: your workspace is retained for 30 days so you can export or reactivate, then deleted. Backups age out on the infrastructure's cycle after that.
- Invoices and records we must keep for tax and accounting law are retained for the legally required period.
Your rights
Under Singapore's Personal Data Protection Act, and equivalent laws where you are, you can ask us to access, correct, export or delete personal data we hold about you, and withdraw consent where processing relies on it. If the data sits inside another company's workspace (for example, you are a portal user of one of our customers), we will route the request to that company, since the data is theirs to control.
Write to sales@lytbrox.com — this address reaches the people who can actually act, usually the same working day.
When something changes
If we materially change this policy, we tell every workspace admin by email before the change takes effect. The date at the top is always the version you are reading.
Contact
Lyt Brox Pte Ltd, Singapore · sales@lytbrox.com