This Privacy Policy explains how Office Engage AI ("Office Engage AI", "we", "us", or "our") handles information when organizations and their authorized users use our employee engagement, communication, CRM, social publishing, and automation services.
1. Information collected
We may collect account details such as name, work email, company, role, authentication records, preferences, support messages, and activity needed to operate and secure the service. Organizations may provide employee, CRM, campaign, template, and communication information they are authorized to process.
We also collect limited technical data, such as IP address, browser information, timestamps, audit events, and diagnostic records, to protect and maintain the platform.
2. How information is used
We use information to provide requested features, authenticate users, deliver communications, maintain tenant and company isolation, administer integrations, prevent misuse, troubleshoot issues, respond to support requests, and meet legal obligations. We do not use connected provider data for unrelated advertising.
3. OAuth tokens
When an authorized user connects a supported third-party account, we receive OAuth access and, where available, refresh tokens. Tokens are encrypted at rest, access-controlled, and used only to perform authorized actions for the connected organization. We do not display tokens to users or include them in public pages.
4. Gmail and Google user data
Google user data is used only to provide user-requested functionality, such as connecting a selected account and sending or managing communications the user directs through enabled features. Google user data is not sold.
Google Workspace API data is not used to train generalized AI or machine-learning models. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
Users can disconnect Google within Office Engage AI when that option is available and can revoke access at any time from their Google Account settings. Revocation prevents future access but does not automatically remove records we must retain or content already delivered at the user's request.
5. Microsoft Graph data
Microsoft OAuth tokens and Microsoft Graph data are used only for enabled, user-requested functions, such as connecting an approved mailbox or sending communications. Users or administrators can remove app consent in Microsoft account or Entra administration settings, subject to their organization's policies.
6. Meta and social media data
For connected Meta or other social accounts, we process authorized account identifiers, page or profile metadata, tokens, content, publishing results, and analytics needed for requested social publishing features. Access depends on provider permissions and can be revoked through the provider's settings.
8. Data retention
We retain information only as long as needed to provide the service, satisfy organization instructions, resolve disputes, enforce agreements, maintain security and audit records, and meet legal obligations. Retention periods vary by data type and account configuration. Data scheduled for deletion may remain temporarily in protected backups until normal backup rotation completes.
9. Data security
We use administrative, technical, and organizational safeguards appropriate to the data, including access controls, encryption for sensitive integration credentials, audit logging, and tenant-aware authorization. No internet service can guarantee absolute security, so users must also protect their credentials and report suspected misuse promptly.
10. User rights
Depending on location and relationship with the subscribing organization, users may have rights to access, correct, export, restrict, object to processing of, or delete personal information. Requests may need to be directed through the user's organization when it controls the data. We may verify identity and authority before acting.
11. Account disconnection and revocation
Authorized users can disconnect integrations in applicable platform settings or revoke access directly with Google, Microsoft, Meta, or another provider. For permanent deletion requests, follow our Data Deletion Instructions. Disconnecting an integration stops future authorized access but may not delete the Office Engage AI account or all legally retained records.
12. Contact information
Questions or privacy requests can be submitted through our contact page.