1. Scope and roles
This policy applies to the AixRR website, workspace application, APIs, and related support interactions (together, the “Service”). It covers information collected directly from an account holder and information that a workspace sends to AixRR through a connected provider or configured workflow.
A team or organization that creates a workspace decides what information to connect and how to use it. For workspace content, that customer generally determines the purpose of processing. AixRR processes that content to operate the Service on the customer’s instructions. AixRR may act as the decision-maker for account administration, service security, product improvement using permitted operational data, and communications about the Service.
Launch item: [Counsel must confirm the legal entity that operates AixRR, the controller/processor allocation for each market, and the jurisdictions covered by this policy.]
2. Information we process
Account and workspace information
We may process your name, email address, sign-in and authentication identifiers, organization or workspace name, role, membership and permission records, subscription or plan details if enabled, and messages you send to support. We also keep configuration such as connected-account aliases, automation definitions, versions, assignments, and workspace preferences.
Connected social-provider data
When a workspace connects a social or messaging provider, we process only the categories made available by that connection and the permissions granted by the workspace administrator. Depending on the provider and feature, those categories may include provider account IDs, handles, display names, profile or page identifiers, conversation and message IDs, message text, attachments or media references, participants, timestamps, delivery state, reactions, labels, and provider capability or rate-limit information. Provider access tokens and refresh credentials are handled as server-side secrets; they are not intentionally displayed in the browser, URLs, or ordinary logs.
Messages, contacts, and operational records
The Service may process contact names, handles, provider identifiers, conversation history, message content, attachments or links, tags, ownership, status, assignment, notes, consent or handoff markers, and other fields a workspace chooses to store. Automation records can include trigger inputs, run state, retry history, delivery intent, provider responses, request IDs, and audit events.
Device, usage, and support data
We may receive IP address, approximate region derived from IP, browser and device type, operating-system and language settings, session identifiers, timestamps, referring pages, feature usage, error details, request IDs, and security events. We may receive additional information when you contact support or report a provider issue.
We do not ask users to submit sensitive personal information through the Service. If a workspace chooses to place sensitive information in messages or contacts, the workspace is responsible for having a lawful basis and appropriate notice for that activity.
3. How we use information
We use information to:
- create and secure accounts, authenticate users, enforce workspace roles, and prevent abuse;
- host, synchronize, search, display, and otherwise provide the inbox, contacts, provider connections, and workspace features;
- run, pause, retry, cancel, and audit automations according to the configuration and permissions selected by the workspace;
- show delivery, freshness, capability, error, and operational signals so teams can make informed decisions;
- respond to support requests, investigate incidents, communicate service changes, and maintain reliability;
- measure and improve the Service using information permitted by the customer agreement and applicable law; and
- comply with legal obligations, enforce terms, protect people and systems, and establish or defend legal claims.
We do not use workspace message content to advertise to a workspace’s contacts. We do not sell personal information. Any additional analytics, model-assisted processing, or product-improvement use must be documented in the final policy and customer terms before it is enabled.
4. Connected providers
AixRR is an independent workspace for coordinating connected accounts. A provider may continue to process information under its own privacy policy and terms. Provider permissions, retention behavior, geographic processing, and deletion behavior can differ from AixRR’s controls.
Before connecting an account, the workspace administrator should review the permissions requested, confirm that the account is authorized, and make sure the intended messages and contacts may be processed. Disconnecting a provider stops new synchronization or delivery requests where the provider supports that control; it does not automatically erase information already copied into the workspace. Use the deletion and export controls described below for stored workspace data.
Workspaces must not use AixRR to evade provider limits, scrape data outside an authorized integration, send prohibited content, or automate actions the provider does not permit. Provider-specific scopes and compliance requirements should be checked for each connection.
6. Retention, deletion, and export
We keep information for as long as needed to provide the Service, maintain security and audit records, meet legal and financial obligations, resolve disputes, and enforce agreements. Workspace administrators can request an export or deletion of workspace data through the available account controls or by contacting the designated privacy contact. Exports may include conversations, contacts, automation definitions and versions, run history, delivery events, and workspace configuration, subject to provider and legal limits.
When a workspace is deleted, we aim to remove active workspace data within the period stated in the final customer agreement. Backups, security logs, fraud-prevention records, and records needed for legal compliance may remain for a limited period and then be deleted or de-identified according to our retention schedule. Removing a record from AixRR does not remove it from a connected provider or from copies lawfully held by other recipients.
Launch item: [Counsel and engineering must set concrete retention periods, deletion SLAs, backup expiry, export format, and the process for verifying an authorized request.]
7. Security
We use administrative, technical, and organizational safeguards designed for the risks of the Service. Current product controls include workspace-scoped authorization, explicit membership checks, server-side handling of provider secrets, typed request and audit context, redacted diagnostic data, and access boundaries between workspaces.
No method of transmission or storage is completely secure. Workspace administrators must use strong credentials, keep membership current, protect connected provider accounts, and report suspected unauthorized access promptly. We will assess and respond to security events using our incident procedures.
AixRR does not claim a security certification or compliance attestation on this page. [Counsel and security must add any verified certifications, audit reports, breach-notice commitments, and security-contact route before making such statements.]
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent where processing relies on consent. You may also have the right to complain to a data-protection authority. Workspace users should first contact their workspace administrator for content controlled by that workspace; we may direct a request to the relevant administrator.
To make a request, contact the address below with enough information for us to verify the request and identify the workspace. We may retain information needed to prevent fraud, protect another person’s rights, or satisfy legal requirements.
Privacy contact: [email protected] (placeholder — counsel must confirm the operating entity, mailbox, response process, and postal contact before launch).
9. Changes and contact
We may update this policy when the Service, law, or data practices change. For a material change, we will provide notice through the Service, email, or another reasonable channel before the change takes effect when required. The version and effective date at the top of this page will be updated.
Operating entity and address: [Counsel to complete; do not rely on the placeholder footer name as a legal entity or service address.]