1. Scope and our role
This policy applies to visitors to our website, prospective and current customers, authorized users of customer workspaces, and people who contact us for support, sales, or security matters.
A customer organization generally decides why and how the personal information in its workspace is processed. For that customer-controlled information, the customer is the controller or business and we act as its processor or service provider. We act as a controller or business for information used to administer accounts, operate our own website, manage billing and customer relationships, secure the Service, and meet our legal obligations.
2. Information we collect
Information you or your organization provide
- Account and identity information, such as your name, business email address, password credentials handled by our authentication provider, company membership, role, permissions, and account-verification status.
- Customer Data, meaning information submitted to a workspace, including seller and buyer contacts, phone numbers and email addresses, property and lead details, tasks, appointments, notes, offers, contracts, documents, import files, team activity, and related records.
- Communications, including sales requests, support messages, feedback, and other correspondence with us. Please do not send passwords, authentication tokens, or Customer Data through public sales or support forms unless we specifically request it through an approved secure channel.
- Commercial information, such as subscription plan, billing contact, transaction status, and invoices. Payment-card details, when payments are offered, are handled by the applicable payment provider rather than stored as complete card numbers by us.
Information collected through use of the Service
- Device, browser, operating-system, IP address, session, referral, and approximate location information derived from the IP address.
- Product and security events, such as sign-ins, invitations, permission changes, feature interactions, errors, request timestamps, audit events, and diagnostic data.
- Cookies or similar local technologies needed for authentication, session continuity, security, preferences, and any analytics described in our Cookie Policy.
AI Help Assistant information
If you use the AI Help Assistant, we process your question, approved Help Center content, page context, role or permission names, and limited safe diagnostics needed to answer the question. The assistant is read-only: it has no tools that can create, change, or delete CRM records. Customer CRM records are excluded from model context by default, and provider-bound text is minimized and scrubbed for common personal-data patterns. Because no automated scrubber is perfect, do not place seller, buyer, property, contract, financial, document, credential, or other sensitive information in an assistant prompt.
3. How we use information
We use personal information to:
- provide, maintain, troubleshoot, and improve the Service;
- create and verify accounts and administer company workspaces;
- enforce company-level tenant boundaries, server-side permissions, protected file access, and other security controls;
- send transactional messages about accounts, invitations, security, imports, billing, and other service activity;
- answer support, privacy, security, and sales requests;
- measure reliability and understand feature use using minimized operational data;
- prevent fraud, abuse, unauthorized access, and violations of our terms; and
- comply with law, enforce agreements, and protect legal rights.
Where applicable law requires a legal basis, we rely on performance of a contract, legitimate interests such as operating and securing the Service, compliance with legal obligations, or consent. You may withdraw consent at any time, but withdrawal does not affect processing already performed lawfully.
4. How we disclose information
We may disclose personal information in the following circumstances:
- At a customer’s direction. Workspace owners and authorized users can grant access, assign permissions, export records, and otherwise direct processing within their company workspace.
- Service providers and subprocessors. We use providers for cloud infrastructure, Supabase authentication, managed Postgres database services, protected file storage, transactional email delivery, AI model inference for assistant prompts and minimized safe context, monitoring, customer support, and other operations. They may process information only to provide contracted services to us and are subject to appropriate confidentiality and data-protection obligations.
- Legal and safety reasons. We may disclose information when reasonably necessary to comply with law or valid legal process, enforce our agreements, investigate abuse, or protect the rights, safety, and security of our customers, users, the public, or the Service.
- Business transactions. Information may be disclosed in connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to customary confidentiality protections and applicable law.
We do not sell Customer Data. We do not use Customer Data for third-party advertising. Our current subprocessor information is available on the Subprocessors page.
5. Multi-tenant workspaces and access
A&A DealFlow is a multi-tenant service. Customer records are associated with a company identifier and protected through application-level scoping, server-side permission checks, and Postgres row-level security. Documents use company-scoped storage paths and protected access flows. These safeguards reduce the risk of unauthorized cross-company access, but no system can guarantee absolute security.
Customer workspace administrators control membership and permissions within their company. If your account was provided by an organization, that organization may access, manage, export, restrict, or delete information in the workspace according to its own policies and your assigned permissions.
6. Retention and deletion
We retain personal information for as long as reasonably necessary to provide the Service, maintain an account or customer relationship, meet the purposes described in this policy, comply with law, resolve disputes, enforce agreements, and protect the Service. The period depends on the type of information, customer instructions, contractual commitments, sensitivity, operational need, and legal requirements.
After account closure or contract termination, Customer Data is deleted, returned, or de-identified in accordance with the applicable agreement and our then-current deletion process. Limited copies may remain temporarily in backups, security records, audit logs, or records we must keep by law and will remain protected while retained. Any committed post-termination retention or deletion period will be stated in the applicable agreement or service documentation after the relevant operational process is verified. Aggregated or de-identified information may be retained where it cannot reasonably identify an individual.
7. Security
We use administrative, technical, and organizational safeguards appropriate to the nature of the Service. Current product controls include verified-account authentication, company-level tenant isolation, database row-level security, server-side permission checks, protected document storage paths, input validation, and audit logging for implemented sensitive events. Access is limited according to role and operational need.
No security program eliminates all risk. We do not claim SOC 2, ISO, HIPAA, GDPR, or any other certification. Please review the Security page for control-by-control implementation status, and notify us promptly if you believe an account or Customer Data may have been compromised.
8. Your choices and privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to request access to, correction of, deletion of, or a copy of your personal information; to object to or restrict certain processing; to withdraw consent; or to appeal a decision on a request. You may also update certain account information in the Service or through your workspace administrator.
If your information is in a customer-controlled workspace, contact that customer first. We will support the customer’s verified request as required by contract and law. For information we control, email us using the contact details below. We may verify your identity and authority before acting. Authorized agents may submit requests where allowed by law. You also may complain to your local data-protection authority.
9. International processing
We and our service providers may process information in countries other than the one in which it was collected. Where required, we use contractual or other recognized safeguards for international transfers. Customers with specific data-location or transfer requirements should raise them before purchasing the Service.
10. Children
The Service is intended for business users and is not directed to children under 13 or the higher minimum age required by local law. We do not knowingly collect personal information directly from children through the Service. Contact us if you believe a child has provided information to us without appropriate authorization.
11. Changes to this policy
We may update this policy to reflect changes in the Service, law, or our practices. We will post the revised version and update its date. If a change materially affects how we use personal information, we will provide additional notice when required by law or contract.
12. Contact us
Send privacy questions or requests to the contact below. Do not include passwords, authentication tokens, or unnecessary Customer Data in your message.
A&A Development LLC
Email: support@aadealflow.com
5900 Balcones Drive STE 100, Austin, TX 78731