Privacy Policy
Last updated: [Date] Effective: [Date]
1. Who we are
AdoptIQ ("we", "us", "AdoptIQ") is a B2B software-as-a-service provided by [AdoptIQ legal entity name], registered at [registered address], company number [number]. This Privacy Policy explains how we handle personal data when you visit our website, sign up, use our service, or contact us.
For questions about this policy or your data, contact us at privacy@adoptiq.io.
2. Roles — controller and processor
We act in two distinct roles depending on the data:
- Controller for: prospect/marketing data, our customers' billing contacts, our employees and contractors, website visitor analytics.
- Processor for: personal data our customers upload or generate within the AdoptIQ service. The customer is the controller; this is governed by our Data Processing Agreement.
This Privacy Policy describes our practices as controller. For processor-role processing, see our DPA.
3. What personal data we collect (controller role)
| Source | Data | Purpose |
|---|---|---|
| Marketing site visitors | IP address (anonymized after [N] days), pages viewed, referrer, device/browser type, cookies (see Cookie Notice) | Operate the site, security, analytics |
| Sign-up / account | Name, business email, company, role, password (hashed by Supabase Auth) | Create your account, authenticate |
| Billing | Name, business email, billing address, VAT ID, last 4 digits of card and brand (full card data is held by Stripe — we never see it) | Invoicing, tax compliance |
| Support requests | Whatever you send us (email, content, logs you attach) | Resolve your request |
| Communications | Your messages, our replies | Communicate with you |
We do not intentionally collect special-category data (health, race, political, biometric, sexual orientation, etc.). Please do not send special-category data via support. [CONFIRM]
4. Lawful bases for processing (GDPR Art. 6)
| Activity | Basis |
|---|---|
| Operating the service for our customers | Performance of contract |
| Billing and invoicing | Performance of contract; legal obligation |
| Marketing communications to existing customers | Legitimate interest (B2B), with opt-out |
| Marketing to prospects | Legitimate interest (B2B) — opt-out always available; consent for non-essential cookies |
| Security, fraud prevention | Legitimate interest |
| Compliance with law | Legal obligation |
You may object to legitimate-interest processing at any time (Section 10).
5. How long we keep data
| Data | Retention |
|---|---|
| Active account & profile | While your contract is active |
| Closed account | 30 days post-termination, then hard delete (see DPA for customer-uploaded data) |
| Content imported from a connected integration (e.g. RFP drafts created from your email) | Until you delete it. Use Delete stored content on any item in your Inbound review queue to erase it permanently, at any time. Items you have confirmed or rejected are automatically stripped of their content 90 days later. Disconnecting the integration deletes the stored credentials but does not by itself remove content already imported. A record of the item — its status and dates, with no message content — is retained. |
| OAuth credentials for connected integrations | Deleted immediately and permanently when you disconnect that integration |
| Billing records | 7 years (tax law) [LEGAL — confirm jurisdiction] |
| Support tickets | 3 years |
| Marketing leads (no opt-in) | 90 days |
| Marketing contacts (opted in) | Until opt-out + 30 days |
| Web analytics | [N] months |
| Audit & access logs | 1 year |
See our internal Data Retention Policy for full detail.
6. Who we share data with (sub-processors)
We use the following sub-processors. The current list is at adoptiq.io/sub-processors.
| Sub-processor | Purpose | Region |
|---|---|---|
| Microsoft Azure | Application hosting | EU |
| Vercel | Frontend hosting | EU + Global with EU SCCs |
| Supabase | Database + Auth | EU |
| GitHub | Source control + CI | USA + Global with EU SCCs |
| Stripe | Payment processing [CONFIRM] | EU + USA with EU SCCs |
| Sentry | Error tracking | EU |
| PostHog | Product analytics — browser (consent-gated) and server-side onboarding-funnel events (no personal data) | EU |
| Zoho | Business email (Zoho Mail) + docs | EU |
| Resend | Transactional email (notifications, onboarding reminders, password resets) | EU + USA with EU SCCs |
We have signed Data Processing Agreements with each. Where data leaves the EEA, transfers rely on Standard Contractual Clauses and Transfer Impact Assessments.
We share personal data with third parties beyond sub-processors only:
- With your consent.
- To comply with a legal obligation or court order.
- To protect the rights, safety, or property of AdoptIQ, customers, or the public.
- In the context of a business transfer (acquisition, merger), with notice.
7. Data from accounts you connect (Google, Microsoft 365, and other integrations)
AdoptIQ lets you connect third-party accounts so the service can bring your existing data into your workspace. You initiate each connection and grant access through the provider's own consent screen, and you can disconnect at any time from Settings → Integrations. When you connect an account we act as a processor on your behalf: the data belongs to you or your organization, and we access it only to provide the specific feature you connected.
| Integration | Access requested | What we do with it |
|---|---|---|
Gmail (gmail.readonly) | Read-only access to messages matching the Gmail label you designate (default: INBOX) | Import Request-for-Proposal (RFP) emails into your private Inbound review queue for you to review. We never send, modify, or delete your mail. |
Google Sheets (spreadsheets) | Read/write access to a spreadsheet you select | Import questionnaire questions from a range you choose and generate draft answers; we write approved answers back to that spreadsheet only after you explicitly review and approve them. Nothing is written without your approval. |
Microsoft 365 (Mail.Read) | Read-only access to the Microsoft 365 folder you designate | Import RFP emails into your Inbound review queue. |
| Salesforce / HubSpot | The CRM opportunity/deal records you authorize | Sync the procurement records you choose to connect. |
| Slack | The channels you authorize | Post notifications to the channels you designate. |
Google API Services — Limited Use
AdoptIQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We access Google user data only to provide the features you explicitly connect — importing RFP emails from a Gmail label you choose into your review queue, and importing and writing back Google Sheets data at your direction.
- We do not sell Google user data, use it for advertising or ad personalization, or use it for any purpose other than providing these features.
- We do not allow humans to read your Google user data, except: with your explicit consent; where necessary for security purposes or to comply with applicable law; or where the data has been aggregated and anonymized for internal operations. No AdoptIQ administrative interface exposes the content of your imported messages — access within the product is restricted to your own organization by database row-level security.
- Google user data is transmitted over encrypted connections (TLS) and stored encrypted at rest, scoped to your own organization by row-level security.
- What happens when you disconnect. Disconnecting an integration immediately and permanently deletes the stored OAuth credentials for that provider, so we can no longer access your account. Disconnecting does not by itself delete content already imported into your workspace: RFP drafts created from your email remain in your Inbound review queue as your working data, so that disconnecting a mailbox does not destroy procurement records you are working on.
- How to delete imported content. Every item in your Inbound review queue has a Delete stored content control that permanently erases the subject and body we stored for that message. The item remains in your queue as a record — its status and dates — but the message content is gone and cannot be recovered. If you already promoted the item into a project, the details you promoted stay in that project as your own record. Confirming or rejecting a draft changes its status only; use Delete stored content to remove the content itself. In addition, any item you have confirmed or rejected is automatically stripped of its content 90 days later, whether or not you ask. See Section 10 to exercise your broader erasure rights.
The same principles apply to data we receive from Microsoft 365 and other connected providers: it is used solely to provide the feature you connected, never sold or used for advertising.
8. International transfers
Where personal data is transferred outside the EEA, we use the European Commission's Standard Contractual Clauses and complete a Transfer Impact Assessment per Schrems II. Copies available on request (privacy@adoptiq.io).
9. Security
We protect personal data with technical and organizational measures including encryption in transit (TLS 1.2+), encryption at rest (AES-256), MFA on all administrative access, role-based access control, RLS on customer data, audit logging, and regular backups. Our internal Information Security Policy describes the full ISMS.
Despite these measures, no system is perfectly secure. We commit to notifying affected customers and supervisory authorities of any breach as required by law.
10. Your rights (GDPR)
Where we are the controller, you have the right to:
- Access the personal data we hold about you (Art. 15).
- Correct inaccurate data (Art. 16).
- Erase your data, subject to legal retention obligations (Art. 17).
- Restrict processing (Art. 18).
- Portability — receive a structured copy of your data (Art. 20).
- Object to processing based on legitimate interest (Art. 21).
- Not be subject to solely-automated decisions with legal effect (Art. 22)
[CONFIRM — n/a today, but say so explicitly]. - Withdraw consent at any time, where consent is the basis.
- Lodge a complaint with your supervisory authority. Lead authority for AdoptIQ is
[CONFIRM — supervisory authority based on main establishment].
To exercise rights: email privacy@adoptiq.io. We respond within 30 days.
If you are an end-user of AdoptIQ's customer (i.e., we are processor), please contact the customer directly. We will assist them as required by our DPA.
11. Cookies
See our Cookie Notice at adoptiq.io/cookies.
12. Children
AdoptIQ is a B2B service not directed at children under 16. We do not knowingly collect data from children. If we learn we have, we will delete it.
13. Changes
We may update this policy. Material changes will be communicated by email to active customers and via a banner on the site at least 30 days before they take effect.
14. Contact
- Email: privacy@adoptiq.io
- Postal: [AdoptIQ legal address]
- EU representative (if AdoptIQ is established outside the EU):
[Name & address — required if no EU establishment]
Lead supervisory authority: [CONFIRM].