Notice

Privacy Policy

What personal data we hold, why, where it goes, how long we keep it, and what you can make us do about it. Written for two readers: someone who wants their data back, and a reviewer checking we declared our Google scopes honestly.

Version
2.0
Effective
10 September 2026

1.Who we are, and which hat we are wearing

integrable.cloud provides a platform for adding AI assistants to websites. We operate from India, and we serve customers worldwide.

Whether this policy covers your data depends on who you are, and the distinction matters more than it looks:

If you are…Then we are…And this means
A customer — you have an account with usThe controller (a Data Fiduciary, under Indian law)This policy governs your data, and you can exercise every right in clause 9 directly with us.
A visitor who talked to an assistant on someone else's websiteA processor, acting for that businessThey decide what is collected and why. Ask them first — we will help them answer, and we will point you to them if you write to us. Our commitments to them are in the Data Processing Agreement.

Questions, requests or complaints: privacy@integrable.cloud. If we have not resolved something, see grievance redressal.

2.Our representatives in Europe

We have no establishment in the European Union or the United Kingdom. Where the GDPR or the UK GDPR requires a non-established controller to designate a representative, that appointment is made in writing and named here.

RegionRepresentative
European UnionAppointment in progress. In the meantime, contact us directly at privacy@integrable.cloud — we answer every request from every region on the same terms and the same timescale.
United KingdomAppointment in progress. In the meantime, contact us directly at privacy@integrable.cloud — we answer every request from every region on the same terms and the same timescale.

3.What we collect

  • Account data. Your name, email address, company name, and a hashed password. If you sign in with Google or Microsoft, we receive your email address, name and profile picture from them instead.
  • Content you provide. The pages, documents and text you add to an assistant’s knowledge base, and how you configure it.
  • Conversation data. Messages between your assistants and the people who talk to them, and any details those people choose to give — a name, an email address, a phone number.
  • Technical data. IP address, user agent, page URL and referrer, used for security, rate limiting and the analytics in your dashboard. We store an anonymous visitor identifier so a conversation survives a page reload.
  • Billing data. Your plan, invoices and payment status.

What we never receive

Card details. Subscriptions are sold and processed by Dodo Payments as merchant of record. Card numbers go to them and never touch our infrastructure. We see that an invoice was paid, not how.

4.What we do with it

  • Operate the service — authenticate you, run your assistants, generate answers, store conversations.
  • Send transactional email: activation, password reset, one-time codes, team invitations, and notifications about leads your assistant captures.
  • Enforce quotas, rate limits and abuse protection.
  • Produce the analytics in your dashboard.
  • Bill you, and meet our tax and accounting obligations.
  • Send product and marketing email, only if you opted in, with an unsubscribe link in every message.

Three things we do not do

We do not sell personal data, or share it for cross-context behavioural advertising, as those terms are defined under US state privacy laws.

We do not train AI models on your content — not ours, and the terms we hold with our model providers prohibit them from doing so either. See the AI transparency statement.

We make no solely automated decisions that produce legal or similarly significant effects about anyone. An assistant answers questions; it does not decide who gets a job, a loan or a service. Our Acceptable Use Policy forbids customers using it that way.

6.Google and Microsoft user data

We request Google and Microsoft permissions in three separate, optional contexts. Signing in does not grant calendar or spreadsheet access — each is a distinct consent screen you can decline, and declining only disables that feature.

ScopeRequested whenWhat we do with it
openidYou choose Sign in with GoogleConfirm the sign-in is genuine.
userinfo.emailYou choose Sign in with GoogleYour email address — your account identifier, and how we contact you.
userinfo.profileYou choose Sign in with GoogleYour name and profile picture, shown in the dashboard.
calendar.readonlyYou connect Google CalendarRead your availability so an assistant can offer times that are genuinely free.
calendar.eventsYou connect Google CalendarCreate and update the bookings an assistant makes for you. We do not read or modify events we did not create, beyond reading availability.
drive.fileYou connect Google Sheets as a lead destinationAccess only the specific spreadsheet you select or we create. This scope cannot see the rest of your Drive.
spreadsheetsYou connect Google Sheets as a lead destinationAppend captured leads as rows to that spreadsheet.
Calendars.ReadWriteYou connect Microsoft 365 or OutlookThe Microsoft Graph equivalent — read availability, create and update bookings.
User.ReadYou connect MicrosoftYour name and email, to show which account is connected.

Limited Use

integrable.cloud’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: we do not transfer Google user data to third parties except as necessary to provide or improve user-facing features, comply with law, or as part of a merger or acquisition; we do not use it for advertising; we do not allow humans to read it except with your explicit consent, for security purposes, to comply with law, or where the data has been aggregated and anonymised; and we do not use it to develop, improve or train generalised AI models.

Revoke our access at any time from your Google account permissions or your Microsoft apps, from inside our dashboard, or by deleting your account. Revoking access disables the feature; it does not delete bookings already made.

7.Who else touches it

We use a small number of subprocessors, each for one purpose. The complete, current list — what each does, where it runs, and whether it is in the path always or only if you connect it — is maintained at subprocessors, and customers are notified before it changes.

The most important one to understand: model providers receive message content. To answer a visitor’s question, the question and the retrieved passages from your knowledge base are sent to a model provider. That is not an incidental transfer — it happens on every answered message, and no configuration avoids it. Which providers, and what they may do with it, is in the AI transparency statement.

Beyond subprocessors we disclose personal data only: to comply with a binding legal obligation, on the terms in our government requests policy; to establish or defend legal claims; or to a successor in a merger or acquisition, in which case we will tell you before your data is transferred.

8.Where it goes, and how it is protected in transit

We operate from India and our infrastructure is largely in the United States. If you are in Europe, your data leaves the EEA.

  • Standard Contractual Clauses. India has no adequacy decision. Transfers from the EEA rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914), incorporated into our DPA. UK transfers rely on the UK Addendum to those clauses.
  • A transfer impact assessment. We have assessed the laws of the countries we transfer to, including Indian government access powers, and the supplementary measures that mitigate them — principally per-tenant envelope encryption and database row-level security, described at security architecture.
  • Encryption. In transit with TLS, at rest with per-tenant keys.

Under India’s DPDP Act, transfers out of India are permitted except to countries the Government restricts by notification. We monitor that list.

Which region your data sits in, and what we can and cannot offer on residency, is at data residency.

9.How long we keep it

Specific periods, not “as long as necessary” — that phrase usually means nobody has decided.

DataKept forWhy
Conversations and messagesFor as long as your account is openYou can delete any conversation at any time, and deletion is immediate rather than a soft flag.
Leads and contact recordsFor as long as your account is openExportable at any time. These are yours, and the point of them is that they also live in your CRM.
Knowledge base contentUntil you remove itRemoving a source removes its embeddings in the same operation.
Account and billing records7 years after closureIndian tax and companies legislation requires books to be retained. This is a legal obligation, not a preference.
Security and access logs180 daysSet by the CERT-In Directions 2022, which require logs to be retained for 180 days.
Everything else, after account closure30 days, then erasedThe window exists so an account closed by mistake can be recovered. After it, erasure is permanent and irreversible.

10.Your rights, wherever you live

We do not run a two-tier privacy programme. The strongest right in any of these regimes is offered to everyone.

India — DPDP Act 2023Data Principals in India

  • Access a summary of the personal data we process about you and what we do with it
  • Correction, completion, updating and erasure of your personal data
  • Nominate someone to exercise these rights if you die or become incapacitated
  • Readily available grievance redressal, which you must use before approaching the Board

If we do not resolve your grievance, you may complain to the Data Protection Board of India.

EEA, UK and Switzerland — GDPR and UK GDPRData subjects in Europe

  • Access, rectification and erasure
  • Restriction of processing, and objection to processing based on legitimate interests
  • Data portability in a structured, commonly used, machine-readable format
  • Withdraw consent at any time, without affecting processing already carried out
  • Not be subject to a decision based solely on automated processing with legal or similarly significant effects — we make no such decisions

You may lodge a complaint with your local supervisory authority, or the UK Information Commissioner.

United States — state privacy lawsResidents of California, Virginia, Colorado, Connecticut, Texas and other states with comprehensive laws

  • Know what personal information is collected, and access a copy
  • Delete personal information, subject to legal retention obligations
  • Correct inaccurate personal information
  • Opt out of sale, sharing, and targeted advertising — we do none of these
  • Non-discrimination for exercising any of these rights

We do not sell or share personal information as those terms are defined under state law, and we run no targeted advertising.

Everywhere elseAnyone

  • The rights above are offered to everyone, regardless of where you live
  • Splitting people into those who get privacy rights and those who do not is a choice, and we have made the other one

Write to privacy@integrable.cloud. We respond within 30 days.

How to exercise any of them

Email privacy@integrable.cloud. We will acknowledge within 48 hours and respond within 30 days. We may need to verify your identity — we will ask for the minimum that does the job, and we will not use what you send for anything else. There is no charge unless a request is manifestly unfounded or excessive.

If you talked to an assistant on someone else’s website, that business decides. Tell us which site and we will identify the customer and pass your request on the same day.

11.Security, and what happens if it fails

Tenant isolation is enforced in the database with row-level security, content is encrypted at rest with per-tenant keys, and access to production is limited and logged. The detail, without marketing adjectives, is at security architecture. What we are not certified for is stated just as plainly at compliance.

If there is a personal data breach:

  • Where we are the controller, we notify the relevant supervisory authority within 72 hours where the GDPR requires it, and the Data Protection Board of India as the DPDP Act requires.
  • Where we are your processor, we notify you without undue delay, with what we know, what we are doing, and what we recommend you do — so that you can meet your own deadline.
  • We notify affected individuals directly where the risk to them is high.
  • We report qualifying incidents to CERT-In within the timescale the Indian directions require.

Our incident process, including what we commit to telling you and when, is at incidents.

12.Children

The service is for businesses, and it is not directed at children. We do not knowingly collect personal data from a child.

If you deploy an assistant, this is your obligation

India’s DPDP Act treats anyone under 18 as a child and requires verifiable parental consent before processing their data — a higher threshold than the GDPR’s 13 to 16, or COPPA’s 13. Our Acceptable Use Policy therefore prohibits deploying an assistant on a service directed at children, and prohibits tracking, behavioural monitoring or targeted advertising directed at them.

If you believe a child has given us personal data, write to privacy@integrable.cloud and we will delete it.

13.Cookies

This website sets none — no analytics, no tag manager, no advertising pixel, which is why you have not seen a consent banner. The dashboard sets a strictly necessary session cookie. The chat widget stores one identifier so a conversation survives a page reload. Full detail, and whose job it is to disclose the widget’s storage on your own site, is in the cookie policy.

14.Changes to this policy

This page carries a version number and an effective date at the top. If we make a change that materially affects how we handle your personal data, we will email account holders at least 30 days before it takes effect. Smaller corrections take effect when published.

See what it drafts from your site. Free to start, no card, live in minutes.

Start free