1. Who this notice is from
This notice is issued by iSolicitude LTD, which operates Priveloq Chat and this website.
Registered address: 27 Savannah Plaza, Halfway Tree St Andrew Jamaica
Privacy enquiries: privacy@priveloq.com
2. Two different relationships, and why the difference matters
Priveloq Chat is a business platform, and this notice covers two situations that are genuinely different in law. Read the one that applies to you.
Our own information. When you read this website, send us an enquiry, ask us about buying the product, or make a privacy request to us, we decide why and how your information is used. This notice describes that in full.
An organisation's workspace. When you use Priveloq Chat because an organisation gave you an account, the business content inside that workspace — your messages, the files you share, your tasks, the knowledge documents you write — is under that organisation's control. They decide what is collected there, who may see it, how long it is kept and when it is deleted. We handle it on their instructions so that the service works. For anything about that content, your organisation is the right place to ask first, and we will support them in answering you.
Where the applicable law uses the words controller and processor, the first situation is normally us acting as a controller and the second is normally us acting as a processor for the customer organisation. The exact allocation for a given customer is the one set out in that customer's written agreement with us, which prevails over this general description.
3. What we collect
Not everything below applies to everyone. What exists for you depends on whether you hold an account, whether you joined as a guest, and how the organisation running your workspace has configured it.
This website
- Ordinary web server request records: the address the request came from, the page asked for, the time, and the browser's own description of itself. This is how a web server is operated and how abuse is investigated.
- If you use the contact form: your name, email address, optional company, subject and message.
- If you make a privacy request: your email address, what you are asking for, and anything you choose to add.
These public pages carry no analytics, no advertising pixel, no session-recording script and no third-party tracker. Nothing on them loads from another company's servers.
Your account
- Your display name, first and last name, and email address.
- Your password, stored only as a hash. We cannot read it and cannot recover it for you.
- Where multi-factor authentication is in use: an authenticator secret and hashed recovery codes.
- Profile information you choose to add, which may include a photograph, a job title and skills.
- Which organisation and which roles, channels and groups you belong to.
- Sign-in and session records, including the address and browser a session was established from, so that you and your administrators can see and revoke active sessions.
- A security audit trail of consequential actions — sign-in attempts, permission changes, administrative acts — which exists so that an organisation can investigate what happened.
- A record that you accepted each version of our legal documents: which document, which version, when, and the address and browser the acceptance was submitted from.
What you put into the product
- Messages you send in direct conversations, channels, groups and temporary conversations, and the reactions and mentions on them.
- Files, images and voice notes you attach, and the technical details needed to store and serve them, such as file name, size and type.
- Posts, comments, reactions and acknowledgements in the Feed.
- Work items — tasks and requests — with their fields, assignments, comments and history.
- Knowledge documents, their versions and who may read them.
- Call records: who took part, when a call started and ended, and its outcome. Call audio and video are not recorded or transcribed by this application.
- Notifications raised for you, and whether you have read them.
Photographs have their embedded metadata — including any location a camera recorded — removed before they are stored.
Guests
Somebody who joins a temporary guest room gives only the display name they type on the way in. The session record holds that name, the address they joined from and when. Guest rooms and their contents are deleted automatically when their retention window closes; see section 7.
4. Why we use it
- To provide the service and make its features work.
- To authenticate you and keep accounts secure.
- To deliver messages, notifications and calls.
- To send transactional email: invitations, password resets, security notices and similar service messages.
- To answer support and sales enquiries you send us.
- To detect, investigate and respond to abuse and security incidents.
- To keep audit records so that an organisation can account for what happened.
- To meet legal obligations, and to establish or defend legal claims.
- To keep the service reliable — diagnosing faults, monitoring performance and capacity.
We do not sell personal information. We do not use your messages, files, Work content or Knowledge documents to train machine-learning models. We do not profile you for advertising, and we run no advertising on this service.
5. The legal basis we rely on
Whether a legal basis is needed at all, and which one applies, depends on the law of the place you are in and on which processing is in question. Where a law of the kind that requires a stated basis applies, these are the ones we would normally rely on.
- Performance of a contract — providing the service to a customer organisation and to the people it authorises.
- Legitimate interests — securing the service, preventing abuse, keeping audit records, and running and improving the product. Where we rely on this, we weigh it against your interests and rights.
- Legal obligation — where we must retain or disclose something by law.
- Consent — for anything genuinely optional, such as browser notifications. Where we rely on consent you may withdraw it at any time, and withdrawing it does not affect what was done beforehand.
Where we handle business content on a customer organisation's instructions, the basis for that processing is the organisation's to determine, not ours.
6. Who it reaches
Conversation content is served only to the people entitled to it. An administrator can manage accounts, roles, sessions and the lifecycle of guest rooms, and can read the security audit trail; the administration area has no route into the contents of a private conversation.
Outside the product, information may reach:
- Service providers we use to run the service — hosting and infrastructure, transactional email delivery, object storage and the conference service that carries call media. The subprocessor list names the ones this installation actually uses, read from its live configuration.
- Your organisation — if you use the product through an organisation's workspace, its administrators can see account, membership, session and audit information about your use of it.
- Professional advisers — lawyers, accountants and auditors, where they need it and are bound to keep it confidential.
- Authorities — where we are legally required to disclose, or where disclosure is necessary to establish or defend legal claims, or to protect somebody's safety.
- A successor — if the business or part of it is reorganised, merged or sold, information may transfer as part of that, subject to this notice continuing to apply.
7. Where it is processed
Where information is processed depends on how this installation is deployed and which providers it is configured to use. The subprocessor list states the processing location for each provider where it is known.
Where information moves between countries and the applicable law requires a transfer safeguard, we put an appropriate one in place with the provider concerned. Business customers can ask us for the details that apply to their deployment.
8. How long it is kept
We keep information for as long as it is needed for the purpose it was collected for, and then delete it or stop being able to associate it with you. In practice:
- Temporary guest rooms are deleted automatically when their retention window closes — the messages, the files, the stored objects behind them, the call record and the guest's ephemeral identity. What survives is the administrative record that the room existed, who opened it and when it ended, never what was said in it. The window is set by the organisation running the installation.
- Notifications that have been read or dismissed are swept after a configurable period. An unread one is kept.
- Account and workspace content — messages, files, Work items, Knowledge documents — is kept until it is deleted, and by whom and on what schedule is the customer organisation's decision. The product provides retention policies and retention runs for organisations that set them.
- Security and audit records are kept longer than the content they describe, because their whole purpose is to remain available after the fact.
- Legal acceptance records are kept for as long as the agreement they evidence could matter, which is normally the life of the relationship plus the period in which a claim could still be brought.
- Contact and privacy-request records are kept long enough to answer you and to show that we did.
- Anything under a legal hold is kept until the hold is released, even where it would otherwise have been deleted.
We have deliberately not printed a fixed number of days against every category. Retention periods here are configurable per installation, and stating a figure this product does not actually enforce would be a commitment nobody could keep. Business customers can ask for the periods configured for their deployment.
9. How it is protected
We use technical and organisational measures designed to protect the service and the information in it: encrypted transport, role-and-capability-based access control, optional multi-factor authentication, session management and revocation, a security audit trail, password hashing, validation and scanning of uploaded files, and removal of embedded metadata from photographs.
No service can promise that information can never be breached, and we do not make that promise. The security page sets out what the product does and, just as importantly, what it does not claim — including that message content is readable by the server and that this is not an end-to-end encrypted product.
10. Cookies and local storage
This installation sets only strictly necessary cookies, and runs no analytics or advertising technology. The cookie notice lists every one of them and explains why there is no consent banner.
11. Your rights
Depending on where you live and which law applies to you, you may have some or all of the following rights. Not every right applies to every person in every situation, and some can be limited — for example where another person's rights are engaged, or where we are legally required to keep something.
- To ask for a copy of the personal information we hold about you.
- To have inaccurate information corrected.
- To ask for information to be deleted.
- To ask us to restrict how we use it.
- To object to processing we base on legitimate interests.
- To receive information you gave us in a portable form.
- To withdraw a consent you gave, at any time.
- To appeal a decision we make about your request, where the applicable law provides for that.
- To complain to your data protection regulator. We would rather you came to us first, but this right does not depend on that.
We verify identity before acting on a request. That is not an obstacle put in your way: acting on an unverified request is itself a disclosure, and somebody asking for a copy of your data in your name is the most obvious attack on a rights process. We verify through the account's own registered address wherever we can, and we do not ask you to send identity documents unless there is no other way.
Deleting an account
Closing an account does not necessarily erase everything connected to it, and it would be misleading to imply otherwise. Content you contributed to an organisation's workspace — messages in shared conversations, Work items, Knowledge documents — may belong to or be controlled by that organisation and may legitimately remain after your account is gone. Security and audit records are retained because their purpose is to survive the events they describe. Anything under a legal hold is retained until the hold is released. Where content remains, we remove or sever the personal identifiers we are able to remove without destroying the records the organisation is entitled to keep.
12. If your account came from an organisation
There is no public registration for Priveloq Chat. An account exists because an administrator issued an invitation and somebody redeemed it. That means the organisation decides who has access, what they may do, and when access ends — and it is the first place to take a question about the content inside its workspace. If you ask us something we hold on that organisation's behalf, we will normally refer you to them and tell you we have done so.
13. Age
Priveloq Chat is a business product, intended for use by organisations and the adults they authorise. It is not directed at children, and we do not knowingly collect information from a child. The eligibility requirement is set out in the Terms of Service.
14. Changes to this notice
This notice is versioned. The version and effective date are shown at the top of this page, and the version you accepted — where acceptance applied — is recorded against your account. When we make a change that materially affects you, we will bring it to your attention rather than relying on you noticing a new date, and where it is appropriate we will ask you to acknowledge the revised version before you continue.
15. How to reach us
Privacy and data-rights enquiries: privacy@priveloq.com
Security reports: insight@priveloq.com
Anything else: the contact page.
By post: 27 Savannah Plaza, Halfway Tree St Andrew Jamaica