1. Introduction
This Privacy Policy explains how DealQ Ltd. (“DealQ,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information when you (“you,” “User”) access or use DealQ and its related websites, applications, and services (collectively, the “Service”).
This Privacy Policy should be read together with our Terms and Conditions. Capitalized terms not defined here have the meaning given in the Terms and Conditions.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service.
DealQ Ltd. is the data controller for personal data processed through the Service.
2. Information We Collect
2.1 Information You Provide to Us
- Account information. When you create an account, we collect information such as your name, email address, password (stored in hashed form), organization name, and role.
- User Content. We collect the content you submit to the Service, including typed or pasted text, uploaded documents, files, attachments, spreadsheets, presentations, and contracts, together with associated file names, folder structures, and tags.
- Voice and meeting data. Where you use voice or meeting features, we collect the audio of the session and the written transcript generated from it (“Transcription Data”). We currently retain the audio recording. If you ask us to delete the audio recording of a session, we will delete it within 72 hours of your request.
- Imported data. We collect structured data — such as CRM records, deal records, and account records — that you or your organization choose to import via API or integration.
- Support communications. When you contact us, we collect the information you provide, such as your messages and contact details.
2.2 Information We Collect Automatically
- Usage data. Information about how you interact with the Service, such as features used, pages viewed, and actions taken.
- Device and log data. Information such as IP address, browser type, operating system, device identifiers, and timestamps.
- Cookies and similar technologies. See Section 12 (Cookies and Tracking).
2.3 Information From Third Parties
- Connected Account Data. If you choose to sign in with, or connect, a third-party identity or integration provider (today: Google, via Sign in with Google and Google Calendar), we receive information from that provider. We call this “Connected Account Data”. It is governed exclusively by Section 3 of this Privacy Policy. Where any other Section of this Privacy Policy could be read to permit a use, sharing, or retention of Connected Account Data that Section 3 does not, Section 3 prevails.
- Other sources. If you or your organization import data through an API or another integration that is not a connected account, we receive that data as authorized by you and as needed to provide the integration.
3. Connected Accounts and Integrations
This Section describes everything DealQ does with Connected Account Data: information received from a third-party identity or integration provider’s APIs when you choose to sign in with that provider or connect it to DealQ. The rules in Sections 3.2 to 3.7 apply to every provider in the same way. Section 3.1 lists, per provider, exactly what is accessed and why, and Section 3.8 records the provider-specific policy commitments we have made.
Providers today. Google is currently the only provider, through two separate and independently optional authorizations: Sign in with Google, and Google Calendar connect. You may use one, both, or neither. If we add another provider (for example, a Microsoft or GitHub sign-in or calendar), its scopes and purposes will be added to Section 3.1 before it is offered, and the same rules will apply to its data.
3.1 Providers, and what we access
Google — Sign in with Google (authentication)
If you choose to sign in or create an account with your Google Account, DealQ requests the following non-sensitive scopes:
| Scope | Google user data accessed | Purpose |
|---|---|---|
openid |
The unique, opaque identifier (sub claim) for your Google Account |
Link your Google identity to a single DealQ account record across sign-ins, so you do not end up with duplicate accounts. |
https://www.googleapis.com/auth/userinfo.email |
Your primary Google Account email address and its verified status | Create or identify your DealQ account by email; send you transactional service emails (e.g., security alerts, account notifications); display your account address in your own profile. |
https://www.googleapis.com/auth/userinfo.profile |
Your basic profile information: name and profile picture URL | Populate your name and avatar in the DealQ interface. |
hd claim of the ID token (present only for Google Workspace accounts) |
The Google Workspace domain your account belongs to (for example, example.com) |
Place you in the DealQ workspace registered for your organization’s domain, and confirm that your organization controls that domain when a workspace owner registers it. It is not stored beyond the workspace record it verifies. |
Google — Google Calendar connect (the meetings integration)
If you choose to connect Google Calendar (Settings → Integrations), DealQ additionally requests the following scopes. calendar.readonly is classified by Google as a sensitive scope.
| Scope | Google user data accessed | Purpose |
|---|---|---|
https://www.googleapis.com/auth/calendar.readonly |
Read-only access to the calendars your Google Account can see, and the events on them. DealQ calls the calendar-list and event-list methods and receives the full event resource for each upcoming event. For the request that renders your meetings list, and only in memory, DealQ uses these fields: the event and calendar identifiers; the title; the start and end times and time zone; the attendees (email address, display name, and response status); the location; the description; the video-conferencing entry-point URL (for example, a Google Meet link); the event type; and the recurring-series identifier. Every other field in the response is discarded with the response and is never sent to your browser or stored. | Show your upcoming meetings inside DealQ; hide entries that are not meetings (all-day events, out-of-office, focus-time, working-location and birthday entries, events you declined, and events with no video link); let you attach a meeting to a negotiation and open live coaching for it; label a meeting as related to a deal or to a known contact by comparing attendee email addresses against your negotiation counterparts, your workspace’s contact book, and company domains; and read the conferencing link so that — only when you explicitly ask for it, meeting by meeting — the DealQ meeting bot can join that call. |
https://www.googleapis.com/auth/userinfo.email |
The email address of the Google Account being connected | Confirm that the Google Account you are connecting is the same account as your DealQ login, and label the connected calendar in the integrations list. |
Read-only, and narrower than it looks. calendar.readonly grants no ability to create, modify, move, or delete events, and DealQ never attempts to. DealQ needs to list the calendars your account can see (work, personal, and shared team calendars) and then read upcoming events on each; the events-only scope does not allow listing your calendars, which is why calendar.readonly is requested. DealQ uses only the calendar-list and event-list methods. It does not read calendar sharing settings, access-control lists, colors, or free/busy information.
3.2 How we use Connected Account Data
We use Connected Account Data only to provide the user-facing features listed below, each of which is prominent in the DealQ interface. We do not use Connected Account Data for any other purpose.
- Sign you in and keep one account. The provider’s account identifier and your email address are used to create or find your DealQ account and to authenticate you.
- Show who you are. Your name and profile picture are shown in your own DealQ interface.
- Show your upcoming meetings. Events from a connected calendar are displayed to you in the meetings view.
- Attach a meeting to a negotiation. When you choose to, an event is linked to one of your negotiations so that you can open live coaching for it and see the meeting on that negotiation’s report.
- Tell deal meetings from other meetings. Attendee email addresses are compared against your negotiation counterparts, your workspace’s contact book, and company domains to label a meeting as related to a deal or to a known contact, and event type, all-day, declined, and no-video-link entries are hidden. This happens in memory for the request that displays the list, and the result is shown to you only; it is not recorded or measured.
- Send the meeting bot to a call you choose. When you switch the bot on for a specific meeting, the video-conferencing link from that event is used to schedule the bot to join that call.
Section 4 (How We Use Your Information) does not apply to Connected Account Data. In particular, we do not use Connected Account Data to monitor or analyze usage of the Service, to generate analytics, to improve our products, or to improve any model.
3.3 What we store, and for how long
- The connected-integration record. For a connected calendar we store: the provider’s access and refresh tokens, encrypted at rest with AES-256-GCM under a key held separately from the database; the connected account’s email address and provider account identifier; the list of scopes you granted; and the timestamp of the last successful sync. This record is deleted immediately when you disconnect the integration or delete your DealQ account.
- Calendar events are not copied. DealQ does not copy, cache, or index your events. Each time you view your meetings, DealQ calls the provider’s calendar API live, uses the response to render that request, and discards it. There is no calendar-event database. Where the interface or our marketing says “sync”, “synced”, or “last checked”, it refers to the last time DealQ read your calendar live to render the meetings view; no copy is kept.
- Two exceptions, each created only by your explicit action:
- When you attach a meeting to a negotiation, the event identifier, its title, and its start time are saved on that negotiation as part of the negotiation’s workspace content — in the same way as a note you type — so that the negotiation can show which meeting it relates to. A negotiation belongs to your organization’s workspace and is shared with its members, so these fields stay with the negotiation for as long as it exists, including after you leave the workspace or delete your account, and are erased when the negotiation is deleted (they are covered by the negotiation’s deletion cascade). You can have them removed earlier by re-linking the negotiation to a different meeting or by asking us (Section 15).
- When you switch the meeting bot on for a calendar meeting, a dispatch record stores the event identifier, the video-conferencing link, and the meeting’s end time, so the bot can join at the right moment and not after the meeting has ended. When you disconnect the calendar or delete your DealQ account, dispatch records for meetings that have not yet started are cancelled and deleted, and those fields are erased from dispatch records for meetings that have finished. A bot that is already in a call at that moment finishes that call (at most four hours), after which the same fields fall within the deletion window in Section 8. Dispatch records are also deleted with the negotiation.
- Sign-in data. Your name, email address, profile picture URL, and provider account identifier from a third-party sign-in are stored on your DealQ account record, encrypted at rest on cloud infrastructure operated by our hosting provider under a data processing agreement, for as long as your account exists.
- Operational records. Our security audit log records connection-lifecycle events (connected, disconnected, token refreshed, re-authorization required, read failed) together with the connected account’s email address and provider account identifier. These entries are kept for security and fraud-prevention purposes only, contain no calendar event content, and are not used for anything else. No analytics or telemetry system receives Connected Account Data, and calendar event content is never written to application logs.
Retention is otherwise governed by Section 8. Any Connected Account Data that remains after the deletions described above is deleted within the 90-day window stated there.
3.4 How we share Connected Account Data
We do not transfer Connected Account Data to any third party except:
- Hosting and infrastructure subprocessors (MongoDB Atlas, Railway, and Amazon Web Services), strictly for storing and operating the Service on our behalf, under contractual confidentiality and data-protection obligations. These providers store data; they do not use it.
- DealQ’s own meeting-bot runner. When you switch the bot on for a meeting, the video-conferencing link is passed to the software DealQ operates to join the call. This is part of the Service, not a third party.
- Legal process. Where required to comply with applicable law, legal process, or an enforceable governmental request.
- A merger, acquisition, or sale of assets, and then only after obtaining your explicit prior consent.
Connected Account Data — including calendar event titles, descriptions, attendees, and links — is never sent to any Third-Party AI Provider, speech-to-text provider, email provider, or operational-logging provider listed in Section 5.
3.5 How humans access Connected Account Data
Calendar data. DealQ personnel do not read your calendar data except: (i) with your affirmative consent (for example, to help you with a support request); (ii) to investigate suspected abuse, fraud, or a security incident; (iii) to comply with applicable law; or (iv) in aggregated, anonymized form that cannot identify you, for internal operations.
Sign-in profile data. In addition to (i)–(iv), the name, email address, and profile picture on your account record are visible to the DealQ staff who administer accounts and respond to support requests, in our account-administration console, for those purposes only.
Reads of customer transcripts, recordings, and coaching chats by DealQ staff are recorded in our audit log.
3.6 What we never do with Connected Account Data
We do not:
- transfer, sell, or otherwise make Connected Account Data available to advertising platforms, data brokers, or information resellers;
- use Connected Account Data to serve advertisements of any kind, including retargeted, personalized, or interest-based advertisements;
- use Connected Account Data to determine credit-worthiness or for lending purposes;
- use Connected Account Data for surveillance, or make it available to any entity that conducts surveillance;
- build or maintain any database or dataset of Connected Account Data beyond the per-user records described in Section 3.3;
- use Connected Account Data for analytics, product research, usage measurement, or behavioral profiling;
- sell, rent, license, or broker Connected Account Data.
AI and machine learning. DealQ does not use Google Workspace APIs to develop, improve, or train generalized or non-personalized AI and/or ML models. More generally, DealQ does not use any provider’s APIs, or any data obtained through them (including Google Calendar data), to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models. We also do not use Connected Account Data to train personalized models, to fine-tune, evaluate, or prompt any model, or as training data for any Third-Party AI Provider.
The de-identified meeting transcripts described in Section 6 are produced from the call’s audio, captured by your device or by the DealQ bot as an ordinary call participant (see Section 3.9). They are not obtained through any provider API and are not derived from calendar data. The only role calendar data plays is providing the link used to join a call you have individually chosen. A transcript may naturally contain names or other details spoken during the call; those are removed by the de-identification described in Section 6.1.
3.7 How you revoke access, and what happens then
You can disconnect at any time from Settings → Integrations, or from the provider’s own account settings (for Google: myaccount.google.com/permissions). Disconnecting in DealQ sends a revocation request to the provider for the refresh token and deletes the stored connected-integration record — tokens, connected email, and scope list — immediately, and cancels any meeting-bot dispatches scheduled from that calendar as described in Section 3.3. Deleting your DealQ account runs the same revoke-and-delete steps before the account record is removed.
3.8 Provider policy commitments
- Google. DealQ’s use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
3.9 The meeting bot and Google Meet
The optional DealQ meeting bot joins a video call as a visible, named participant in order to capture the call’s audio. It does this as an ordinary meeting participant, signed in with a Google account owned by DealQ that is not linked to you or your connected accounts. It does not use any provider API scope, the Google Meet API, the Meet Media API, or any other Google Workspace API, and it reads no data from your connected accounts. The only Connected Account Data involved is the video-conferencing link used to schedule it (Section 3.3). Audio and transcripts it captures are “Voice and meeting data” under Section 2.1 and follow the retention and deletion terms stated there, including deletion of a session’s audio within 72 hours of your request.
3.10 New uses require your consent
We will not use Connected Account Data for any purpose not described in this Section 3 without first notifying you and obtaining your consent. Section 14 (Changes to This Privacy Policy) does not allow us to add a new use of Connected Account Data by notice alone.
4. How We Use Your Information
This Section applies to information other than Connected Account Data. Connected Account Data is used only as described in Section 3.
We use the information described in Section 2 to:
- provide, operate, and maintain the Service and generate Outputs for you;
- create and authenticate your account and verify your identity;
- provide customer support and respond to your requests;
- maintain the security and integrity of the Service, and prevent fraud and abuse;
- monitor, analyze, and improve the performance and features of the Service;
- generate aggregated, de-identified analytics that cannot reasonably be re-associated with you or any identifiable individual;
- improve our models as specifically and narrowly described in Section 6;
- communicate with you about the Service, including service-related notices; and
- comply with legal obligations and enforce our agreements.
5. AI Processing and Third-Party AI Providers
The Service operates by sending User-provided inputs (typed text, uploaded documents, attachments, meeting transcripts, metadata, and contextual information, together “User Content”) to third-party large language model and infrastructure providers (“Third-Party AI Providers”) so that we can generate outputs for you. Connected Account Data is not User Content and is never sent to a Third-Party AI Provider (see Section 3.4).
We currently rely on the following categories of service providers and sub-processors:
- AI model providers (OpenAI and Anthropic; we may add Google, Mistral, Cohere, or Microsoft models and will list them here before use): receive User Content to generate preparation guidance and live coaching. None of them receives Connected Account Data.
- Speech-to-text (Deepgram): receives meeting audio to produce real-time transcripts.
- Document processing (Google Cloud Document AI): receives uploaded documents to extract their text.
- Search and embeddings (Voyage AI): receives document and query text to power search inside your workspace.
- Hosting and storage (MongoDB Atlas, Railway, and Amazon Web Services): store your account data, workspace data, and files.
- Transactional email (Postmark): receives your email address and message content to send account and security emails.
- Operational logging (Langfuse): receives model-request metadata, and only where we enable it for debugging, request and response content, to help us monitor reliability.
We keep an up-to-date list of the providers we use and update this Privacy Policy if the categories of recipients change materially.
Third-Party AI Providers operate independent infrastructure governed by their own terms of service, privacy policies, data processing agreements, and security practices, which are outside of our control.
Where Third-Party AI Providers offer them, we configure available endpoints to disable provider-side training and to minimize data retention, including the use of “zero-retention” or “no-training” enterprise modes where available.
6. AI Model Training
This Section governs all uses of User Content for the training, fine-tuning, evaluation, or improvement of any AI model, whether operated by DealQ or a Third-Party AI Provider.
6.1 Data We May Use for Product and Model Improvement (Transcripts and Coaching Tips)
We may use Transcription Data, together with the coaching tips and outputs generated during your sessions, to test, evaluate, train, fine-tune, and improve our own models, prompt systems, and product, and to engage Third-Party AI Providers in supervised fine-tuning or evaluation workflows on our behalf.
Transcription Data is produced from audio captured by your device or by the DealQ meeting bot as an ordinary call participant. It is not obtained through any provider API. No Connected Account Data of any kind — including calendar event titles, descriptions, attendee lists, or sign-in profile data — is included in any training, fine-tuning, or evaluation dataset.
Before any Transcription Data is used for these purposes, we apply commercially reasonable de-identification and redaction processes designed to remove direct identifiers such as names, email addresses, phone numbers, and organization names.
For this limited purpose, you grant DealQ a non-exclusive, worldwide, royalty-free license to use the de-identified Transcription Data. This license is limited to the model-training and evaluation purposes described in this Section, and it ends when you opt out as described below.
Opt-out. You may opt out of training use of your Transcription Data at any time by emailing manuel@dealq.io. Once you opt out, we will stop using your Transcription Data for model training and remove it from the training datasets used for future model versions. Because trained models cannot be selectively reversed, opting out does not affect models that completed training before your request.
6.2 Data We Do Not Use for Model Training
We do not use the following categories of information to train, fine-tune, or evaluate any model, whether ours or a Third-Party AI Provider’s:
- documents, files, attachments, spreadsheets, presentations, contracts, and other artifacts you upload;
- text you paste or type into the Service’s input fields, prompt windows, or workspaces;
- structured customer data, CRM records, deal records, and account records imported via API or integration;
- metadata, file names, folder structures, and tags associated with the above;
- all Connected Account Data described in Section 3, including Google Calendar data and Sign in with Google data.
For these categories, we configure available Third-Party AI Provider endpoints to disable training, model improvement, and extended retention to the maximum extent commercially offered. This data is processed solely to generate Outputs for you in real time.
6.3 Caveats
You acknowledge that: (a) de-identification is a probabilistic process and cannot eliminate all theoretical risk of re-identification; (b) Third-Party AI Providers may independently retain inputs and outputs for limited periods for trust-and-safety, abuse-detection, and legal-compliance purposes, even where training is disabled; and (c) we may modify the scope of this Section prospectively upon notice, with no retroactive effect on User Content already processed.
7. How We Share Your Information
We share information only as described below. Connected Account Data is shared only as described in Section 3.4.
- Service providers and subprocessors. With the hosting, infrastructure, and processing providers listed in Section 5, who process data on our behalf to operate the Service under contractual confidentiality and data-protection obligations. We use no analytics provider.
- Third-Party AI Providers. As described in Section 5.
- Legal and safety. Where required to comply with applicable law, legal process, or enforceable governmental request, or to protect the rights, property, or safety of DealQ, our users, or others (for Connected Account Data, only as permitted by Section 3.4).
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Privacy Policy — and, for Connected Account Data, only after obtaining your explicit prior consent.
- With your consent. Where you have directed or authorized us to share information (for Connected Account Data, only as permitted by Section 3.4).
No sale of personal data. We do not sell, rent, license, or broker User Content or personal data to advertisers, data brokers, or other third parties for commercial gain, and we do not engage in cross-context behavioral advertising.
8. Data Retention
We retain personal data for as long as needed to provide the Service and fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
Account data is retained for as long as your account remains active. Provider access and refresh tokens are deleted immediately when you disconnect an integration; other Connected Account Data is deleted as described in Section 3.3. When you delete your account, or request deletion, we delete or de-identify the associated personal data within 90 days, except where retention is required for legal, security, or fraud-prevention purposes. Connected Account Data is always deleted rather than de-identified, with two stated exceptions: a meeting title attached to a shared negotiation stays with that negotiation as workspace content (Section 3.3), and security audit-log entries recording that an integration was connected or disconnected are kept for security and fraud-prevention purposes only.
9. Data Security
We take reasonable and appropriate technical and organizational measures designed to protect personal data against unauthorized access, use, alteration, loss, or disclosure. These include: TLS encryption for all data in transit; encryption at rest on our hosting providers’ infrastructure; provider access and refresh tokens additionally encrypted with AES-256-GCM under a key held outside the database; role-based access to production systems limited to DealQ staff who need it; short-lived, HttpOnly session cookies; and an audit log of security-relevant events and of staff access to customer content. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. International Data Transfers
DealQ and its service providers may process personal data in countries other than your own, including outside the United Kingdom and the European Economic Area. Where we transfer personal data internationally, we rely on appropriate safeguards, such as the UK International Data Transfer Agreement, the UK Addendum, or the European Commission’s Standard Contractual Clauses.
11. Your Privacy Rights
11.1 United Kingdom and EEA (UK GDPR / GDPR)
If you are in the UK or the EEA, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, the right to data portability, and the right to withdraw consent where processing is based on consent. We process personal data on the lawful bases of performance of a contract, our legitimate interests, your consent, and compliance with legal obligations.
You also have the right to lodge a complaint with a supervisory authority, such as the UK Information Commissioner’s Office (ICO).
11.2 California (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect, to access and delete it, to correct inaccurate information, and to opt out of the sale or sharing of personal information. As stated in Section 7, we do not sell or share personal information. We will not discriminate against you for exercising your rights.
11.3 Exercising Your Rights
To exercise any of these rights, contact us at manuel@dealq.io. We will respond within the timeframes required by applicable law. We may need to verify your identity before fulfilling your request.
12. Cookies and Tracking
We use first-party cookies and similar technologies only to operate the Service, remember your preferences, and maintain sessions. We use no analytics or advertising cookies. You can control cookies through your browser settings; disabling some cookies may affect the functionality of the Service. For details on the specific cookies and storage we use, see our Cookie Policy.
13. Children’s Privacy
The Service is not directed to children under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by other reasonable means. A new use of Connected Account Data additionally requires your consent, as stated in Section 3.10. Any modification operates prospectively only and will not retroactively change the treatment of User Content already processed. The “Last Updated” date above indicates when this Policy was last revised.
15. Contact Us
For questions about this Privacy Policy, to exercise your data rights, or to opt out of training use of Transcription Data, contact us at:
DealQ Ltd. Email: manuel@dealq.io