1. Our Commitment
CollaboPoint is committed to full compliance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR 2016/679), and the Data Protection Act 2018. We treat data protection as a core business function, not an afterthought.
2. Data Controller
CollaboPoint acts as the Data Controller for personal data processed when you use our platform. Our Data Protection Officer (DPO) can be contacted at privacy@collabopoint.com. Where you process personal data of your own users or employees through CollaboPoint, you act as the Controller and we act as a Data Processor on your behalf.
3. Lawful Bases for Processing
- Contract (Art. 6(1)(b)): processing necessary to provide the service you signed up for, including account management, authentication, and delivering features.
- Legitimate Interests (Art. 6(1)(f)): fraud prevention, security monitoring, product improvement, and direct marketing to existing customers.
- Legal Obligation (Art. 6(1)(c)): compliance with UK and EU laws, responding to lawful government requests.
- Consent (Art. 6(1)(a)): optional marketing emails and analytics cookies — you may withdraw consent at any time.
4. Data Subject Rights
- Right of Access (Art. 15): request a copy of all personal data we hold about you.
- Right to Rectification (Art. 16): have inaccurate personal data corrected without undue delay.
- Right to Erasure (Art. 17): request deletion of your personal data where it is no longer necessary for the purpose collected.
- Right to Restrict Processing (Art. 18): request that we limit processing of your data in certain circumstances.
- Right to Data Portability (Art. 20): receive your personal data in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21): object to processing based on legitimate interests or for direct marketing.
- Rights related to Automated Decision-Making (Art. 22): not be subject to decisions based solely on automated processing that produce legal or significant effects.
- Submit requests to: privacy@collabopoint.com. We will respond within 30 days.
5. Data Processing Agreement (DPA)
Where you use CollaboPoint to process personal data of your customers, employees, or other data subjects, a Data Processing Agreement governs our role as your Processor. Our standard DPA is available on request at privacy@collabopoint.com and incorporates the UK International Data Transfer Agreement and EU Standard Contractual Clauses where applicable.
6. Sub-processors
- Google Cloud Platform (GCP) — Infrastructure hosting and storage. EU/UK data centres available.
- Firebase (Google) — Authentication, Firestore database, Cloud Storage, Cloud Functions, FCM push notifications.
- Resend — Transactional email delivery. EU-based (London).
- Stripe — Payment processing. PCI-DSS Level 1 certified.
- Agora — Real-time video and audio calls. Media is processed through Agora infrastructure. We are pursuing a Data Processing Agreement with Agora.
- Groq — AI-powered writing assistance (free tier) and audio transcription. US-based. We are pursuing a Data Processing Agreement with Groq.
- OpenAI — AI writing assistance (paid tier). US-based. Data Processing Agreement available.
- Anthropic — AI model inference via personal API key (no training on customer data). DPA available.
- Expo — Mobile push notification delivery. We are pursuing a Data Processing Agreement with Expo.
- CloudConvert — Optional document format conversion (DOCX, XLSX, PPTX → PDF/HTML). Germany-based.
- Unsplash / Pexels — Stock image search for presentations. Search queries only; no personal data.
- We maintain an up-to-date list of sub-processors and will notify you of material changes 30 days in advance.
7. International Data Transfers
Where personal data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place: Standard Contractual Clauses (SCCs) under EU GDPR, and International Data Transfer Agreements (IDTAs) under UK GDPR. All our primary infrastructure is operated by Google, which maintains binding corporate rules and SCCs. Real-time video and audio calls use Agora infrastructure, which may route media through non-EEA servers; we are actively pursuing contractual safeguards with Agora. AI features (Groq, OpenAI) transfer document content to US-based servers under applicable SCCs or adequacy mechanisms.
8. Data Minimisation and Purpose Limitation
We only collect personal data that is necessary for the purposes described in our Privacy Policy. We do not use your data for purposes incompatible with those for which it was collected. We regularly review data holdings and delete data that is no longer required.
9. Security Measures (Art. 32)
- Encryption of personal data in transit (TLS 1.3) and at rest (AES-256).
- Pseudonymisation of analytics data where possible.
- Ongoing confidentiality, integrity, availability, and resilience of processing systems.
- Regular testing, assessment, and evaluation of security measures.
- Access controls: role-based access, multi-factor authentication, and principle of least privilege.
10. Data Breach Notification
In the event of a personal data breach, we will notify the Information Commissioner's Office (ICO) within 72 hours where the breach is likely to result in a risk to individuals' rights and freedoms. We will notify affected data subjects without undue delay if the breach is likely to result in a high risk to their rights. We maintain an internal breach register and incident response procedure.
11. Privacy by Design and Default
We incorporate data protection principles into all new features and services from the outset. By default, we apply the most privacy-friendly settings, collect the minimum amount of data necessary, and restrict access to personal data on a need-to-know basis.
12. Retention Schedules
- Active account data: retained for the duration of the account.
- Deleted account data: purged within 90 days.
- Financial records: retained for 7 years (UK legal requirement).
- Support communications: retained for 3 years.
- System logs and security logs: retained for 12 months.
- Anonymised analytics: retained indefinitely.
13. Supervisory Authority
The supervisory authority for UK GDPR compliance is the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. You have the right to lodge a complaint with the ICO at ico.org.uk if you believe we have not handled your personal data in accordance with applicable law.
14. Contact our DPO
Data Protection Officer: privacy@collabopoint.com. We aim to respond to all GDPR-related requests within 30 days. In complex cases we may extend this by a further 60 days, in which case we will inform you of the extension and the reasons for it.