This Privacy Policy describes how we collect, use, and disclose your information when you use the Service, and explains your privacy rights and how the law protects you. We use your Personal Data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
Interpretation and Definitions
Words with initial capital letters have meanings defined under the following conditions. The following definitions have the same meaning whether they appear in singular or plural.
- Account means a unique account created for you to access our Service or parts of our Service.
- Affiliate means an entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest, or other securities entitled to vote for election of directors or other managing authority.
- Company (referred to as either "the Company", "we", "us", or "our") refers to Allyos Technologies, Dubai, United Arab Emirates.
- Cookies are small files placed on your device by a website, containing details of your browsing history among other uses.
- Country refers to United Arab Emirates.
- Device means any device that can access the Service, such as a computer, a cellphone, or a digital tablet.
- Personal Data is any information that relates to an identified or identifiable individual.
- Service refers to the Website and the associated web application (the Allyos CRM).
- Service Provider means any natural or legal person who processes data on behalf of the Company.
- Third-party Integration refers to any external service you connect to the Service, for example Google, Microsoft 365/Outlook, or WhatsApp, to enable features such as contact, calendar, or email synchronization.
- Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself, for example the duration of a page visit.
- Website refers to Allyos, accessible from https://allyos.ai.
- You means the individual accessing or using the Service, or the company or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Types of data we collect
While using the Service, we may ask you to provide personally identifiable information, including but not limited to:
- Email address
- First and last name
- Phone number
- Address, state/province, ZIP/postal code, city
- Workspace and team information
We also collect Usage Data automatically when you use the Service, including IP address, browser type, pages visited, time and date of visit, time spent on pages, and device identifiers.
We use cookies and similar technologies to operate the Service and understand usage:
- Necessary or essential cookies, for authentication, security, and core functionality.
- Cookies policy / notice acceptance cookies, to record your consent choices.
- Functionality cookies, to remember preferences such as language and time zone.
- Analytics cookies, if you consent, to help us analyze usage. See Google Analytics below.
Information from third-party integrations
You may connect Third-party Integrations such as Google, Microsoft 365/Outlook, or WhatsApp. If you connect Gmail, Outlook, or WhatsApp, we create a profile for each contact in your account. The data elements imported depend on the provider and your permissions, and typically include identifiers such as name, email, phone, organization, and profile photo. Any feature that relies on message content is clearly disclosed and requires additional consent.
Google User Data
When you connect your Google Account to the Service, we request only the minimum scopes necessary for the features you choose. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Scopes we request and why:
- `userinfo.email` and `userinfo.profile`, to authenticate you and display your account details.
- `contacts.readonly`, to read Google Contacts and create or update profiles in your Allyos workspace.
- `gmail.metadata` (or `gmail.readonly` if required by a feature), to read Gmail headers and labels so we can show interactions on contact timelines. We do not store email bodies by default.
- `gmail.send`, to send emails you initiate from the Service via your Gmail account.
- `calendar.readonly`, to read Calendar events and display meetings alongside contacts.
Our Limited Use commitments:
- We use Google user data only to provide or improve user-facing features in Allyos.
- We do not use Google data for advertising or to build advertising profiles.
- We do not sell Google user data.
- We do not allow human access to Google user data except with your explicit consent, for security or abuse investigations, or to comply with applicable law.
- We do not use Google user data to train generalized AI/ML models.
Storage, security, and retention of Google data:
- OAuth tokens are stored encrypted and rotated. We revoke them within 24 hours of disconnect.
- Contacts (the Google-sourced fields you choose to sync) are stored to power your workspace. The cache is refreshed, and deletions propagate within 24 hours.
- Gmail headers, message/thread IDs, and labels (no bodies by default) are retained up to 7 days for timeline rendering and troubleshooting.
- Calendar event IDs and timestamps are retained up to 30 days for timeline rendering.
- After you disconnect Google or delete your Account, Google-derived data we persist is deleted from active systems within 7 days, unless longer retention is required by law or to defend legal claims. Backups purge within 7 days, and security logs within 14 days.
You can revoke the Service's access to your Google Account at any time at myaccount.google.com/permissions, or by disconnecting Google from within the Service under Settings > Integrations. Revoking access may limit functionality that relies on Google data.
Microsoft User Data (Outlook / Microsoft 365)
If you connect Microsoft 365/Outlook, we request substantially equivalent scopes, such as `Contacts.Read`, `Mail.ReadBasic`/`Mail.Read`, `Mail.Send`, and `Calendars.Read`, to create contact profiles, show interactions on timelines, send emails you initiate, and display events. We apply the same use, sharing, security, and retention principles described above for Google data.
If you connect a WhatsApp integration that you authorize, we import contact identifiers, such as name, phone number, and profile metadata that WhatsApp makes available via your integration, to create profiles. We do not process message content for contact creation.
AI features: Ally and the Note Taker
Ally, the AI assistant built into Allyos, reads workspace data, including records, notes, synced messages, and the instructions you give it at the workspace, object, or view level, to answer questions and take actions you authorize. We do not use your workspace content to train generalized AI/ML models, and the same Limited Use commitments described above for Google data apply to any Google or Microsoft sourced data Ally accesses.
The Allyos Note Taker joins meetings you invite it to and produces recordings, transcripts, and summaries that are logged against the relevant record. It only joins meetings you explicitly add it to, and you can remove it from your workspace at any time under Settings > Integrations.
How we use your data
- To provide and maintain the Service, including syncing contacts and, if you choose, related interactions from connected integrations.
- To manage your Account and deliver the features you request.
- To perform our contract with you.
- To contact you about updates or security notices.
- To send product updates and newsletters, which you can opt out of at any time.
- To manage support requests.
- For business transfers, as permitted by law.
- For analytics and other purposes needed to improve the Service.
We do not sell Personal Data, and we do not use Customer workspace content to serve ads.
Legal bases for processing (GDPR)
Where GDPR applies, we rely on performance of a contract to run the Service you signed up for, legitimate interests for product security, improvement, and fraud prevention, consent when you connect WhatsApp or the Note Taker, and legal obligation for tax, accounting, and regulatory requirements.
Sharing of your Personal Data
- With Service Providers who process data on our behalf, including hosting, authentication, email, payments, analytics, support, and bug tracking.
- With Affiliates, subject to this Privacy Policy.
- With business partners, for non-Google/Microsoft data only, where permitted and with your consent where required. Data obtained via Google APIs or Microsoft Graph is never used for advertising or shared with business partners, except with Service Providers acting on our behalf, for legal compliance, or with your direction.
- With other users in your workspace, per your workspace settings.
- With your consent, or as otherwise required by law.
Sub-processors
We use carefully selected Service Providers, referred to as sub-processors, to help deliver the Service, under data processing agreements that require appropriate security and confidentiality commitments. Contact us for the current list and to subscribe to updates.
| Processor | Type of data | Purpose | Region | Opt-out |
|---|---|---|---|---|
| AWS | PII, contact data | Hosting (servers / databases / storage) | EU (Stockholm) | No |
| AWS Cognito | PII | Authentication and user management | EU (Stockholm) | No |
| SendGrid | Contact data | Transactional email | USA | Yes |
| Stripe | PII | Billing and payments | USA/EU | No |
| Linear | PII (support/bug context) | Bug tracking and issue management | USA/EU | No |
| Google Analytics | Usage data | Analytics (per cookies/consent) | Global | Yes |
User-connected integrations such as Google Workspace, Microsoft 365/Outlook, and WhatsApp are not our sub-processors. They are independent services you choose to connect and can disconnect at any time under Settings > Integrations. See the Google, Microsoft, and WhatsApp sections above.
Security
We use administrative, technical, and physical safeguards appropriate to the data's sensitivity, including encryption in transit and at rest, least-privilege access controls, logging and monitoring, and vulnerability management. Production access is restricted and reviewed. Our primary processing region is the EU (Stockholm).
Retention and deletion
- Contact sync cache: 30 days, rolling.
- Gmail/Outlook headers, message/thread IDs, and labels (no bodies by default): 7 days.
- Calendar event IDs and timestamps: 30 days.
- OAuth tokens: encrypted and rotated, revoked within 24 hours of disconnect.
- Security logs: 14 days, then deleted or anonymized unless we're legally required to retain them longer.
- Backups: purged within 7 days.
You can close your Account at any time from within the Service or by contacting us. After deletion, your Personal Data is removed from active systems within 7 days and from backups within 7 days thereafter, except where we're required to retain it longer by law, or for legitimate purposes such as fraud prevention, security, or legal claims.
International data transfers
Your information may be processed in countries other than where you reside, including our primary processing region, the EU (Stockholm), and wherever our sub-processors operate. Where we transfer Personal Data out of the EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your Personal Data, restrict or object to certain processing, and withdraw consent you've previously given, for example by disconnecting Google, Microsoft, WhatsApp, or the Note Taker. If you're a Customer's contact rather than a direct Allyos user, please start with that organization, since it controls its workspace, and we'll assist as needed. To exercise these rights directly with us, contact privacy@allyos.ai and we'll respond within the time required by applicable law.
Disclosure of your Personal Data
If the Company is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. We'll provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.
We may also disclose your Personal Data if required to do so by law, in response to valid requests by public authorities such as a court or government agency, or to protect rights, safety, and security.
Children's privacy
Our Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you're a parent or guardian and believe your child has provided us with Personal Data, contact us and we'll remove it as required by law.
Communication
We may email you about Service changes or technical/administrative information. You can opt out of marketing emails via the unsubscribe link in those emails. We may still send transactional or administrative messages related to the Service even after you've opted out of marketing.
Links to other websites
Our Service may contain links to websites we don't operate. We strongly advise you to review the privacy policy of every site you visit. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We'll notify you by posting the new version on this page and updating the "Last updated" date, and where required by law, we'll notify you via email or through the Service before the change takes effect.
Contact us
If you have any questions about this Privacy Policy, contact us by email at privacy@allyos.ai.