Privacy Policy

    Effective Date: January 1, 2024

    This Privacy Policy explains how DOO Inc., a Delaware corporation ("DOO," "we," "us" or "our"), collects, accesses, uses, stores, shares and deletes personal information in connection with the DOO CX platform and related products and services, collectively referred to as the "Services."

    By accessing or using the Services, you acknowledge the practices described in this Privacy Policy.

    1. Information We Collect

    1.1 Personal and Account Information

    We may collect personal information that you or your organization provides to us, including:

    1. name;
    2. email address;
    3. telephone number;
    4. job title;
    5. employer or organizational information;
    6. account and authentication details;
    7. subscription and billing information;
    8. payment and transaction information;
    9. support requests; and
    10. communications with DOO.

    1.2 Google User Data and Google API Scopes

    When you connect a Google account to DOO CX, we access Google user data only to the extent authorized by you through the relevant Google OAuth permissions.

    Depending on the features enabled, this may include:

    1. basic Google account information;
    2. primary email address;
    3. profile information, such as name and profile photo;
    4. email metadata, including sender, recipient, subject and timestamps;
    5. email message content;
    6. message, conversation and thread identifiers;
    7. attachments and attachment metadata where required to provide the requested functionality; and
    8. other information specifically authorized through the relevant Google OAuth scope.

    The Gmail integration is intended for organizations connecting authorized business Gmail accounts to manage customer-service communications.

    DOO accesses Google user data only to provide or improve user-facing features that are visible, prominent and relevant to the user.

    DOO's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements.

    We do not use Google user data for:

    1. advertising;
    2. unrelated profiling;
    3. sale or rental to third parties;
    4. credit assessment;
    5. training generalized or non-personalized artificial-intelligence or machine-learning models; or
    6. purposes unrelated to the user-facing functionality requested by the user.

    1.3 Usage and Technical Data

    We may automatically collect technical and usage information, including:

    1. IP address;
    2. device and browser information;
    3. operating-system information;
    4. device identifiers;
    5. login and activity timestamps;
    6. platform usage records;
    7. diagnostic information;
    8. system and security logs;
    9. approximate location derived from IP address;
    10. cookies; and
    11. similar tracking technologies.

    1.4 Third-Party Integrations

    Where you connect third-party platforms, customer relationship management systems, messaging tools, ticketing systems or other integrations, we may access and process information made available through those integrations in accordance with:

    1. your instructions;
    2. the permissions you have granted; and
    3. the configuration of the relevant integration.

    1.5 Information from Customers and Other Users

    Where a business or organization provides you with access to the Services, that organization may provide information about you or authorize DOO to process information relating to you.

    Our business customers may also submit personal information relating to their own customers, employees, contractors or other individuals. In those circumstances, the relevant business customer is responsible for determining the purposes and means of processing and for providing any legally required notices or obtaining any required consents.

    2. How We Use Information

    2.1 Providing the Services

    We may use personal information to:

    • create and manage user accounts;
    • authenticate users;
    • connect authorized business Gmail accounts;
    • receive, read and display customer emails within DOO CX;
    • allow authorized agents to send and reply to communications;
    • maintain conversation threading and historical customer-service context;
    • process authorized attachments;
    • operate enabled third-party integrations;
    • process subscriptions and payments;
    • provide customer and technical support; and
    • otherwise provide requested features.

    2.2 Platform Operation and Improvement

    We may use information to:

    • operate, maintain and improve the Services;
    • diagnose technical problems;
    • monitor performance and reliability;
    • develop and improve user-facing functionality;
    • maintain business continuity;
    • understand how authorized users interact with the Services; and
    • conduct internal analytics.

    Google user data will not be used to train generalized or non-personalized artificial-intelligence or machine-learning models.

    2.3 Communications

    We may use contact information to:

    • send service-related notices;
    • provide security alerts;
    • respond to support requests;
    • communicate administrative or contractual information;
    • provide information about changes to the Services or our policies; and
    • send marketing communications where legally permitted.

    Users may opt out of non-essential marketing communications by using the unsubscribe mechanism provided in the communication or by contacting us.

    2.4 Security and Legal Compliance

    We may process information to:

    • detect, prevent and investigate fraud or abuse;
    • identify and respond to security threats;
    • protect the Services and connected accounts;
    • enforce our Terms of Service and commercial agreements;
    • comply with applicable laws and regulatory obligations;
    • establish, exercise or defend legal claims; and
    • respond to valid legal or governmental requests.

    3. How We Share Information

    3.1 Service Providers and Subprocessors

    We may share personal information with trusted service providers and subprocessors where reasonably necessary to operate, maintain and secure the Services.

    These providers may include:

    • cloud-hosting and infrastructure providers;
    • database and storage providers;
    • email and communications infrastructure providers;
    • payment processors;
    • security-monitoring providers;
    • incident-response providers;
    • analytics and diagnostic providers;
    • customer-support providers; and
    • professional advisers.

    These providers may process personal information only for the authorized purpose and subject to appropriate confidentiality, security and data-protection obligations.

    3.2 Google User Data

    We do not sell or rent Google user data.

    Google user data may be disclosed only:

    1. to service providers where necessary to provide or secure the user-facing functionality requested by the user;
    2. with the user's express permission;
    3. where required by applicable law or valid legal process; or
    4. as otherwise permitted under the Google API Services User Data Policy.

    Human access to Google user data is restricted unless:

    1. the user has expressly authorized access for a specific purpose;
    2. access is necessary to provide user-requested support;
    3. access is necessary for security or abuse investigation;
    4. access is required to comply with applicable law; or
    5. the data has been appropriately aggregated or anonymized where permitted.

    3.3 Corporate Transactions

    Information may be transferred as part of a merger, acquisition, financing, corporate restructuring, bankruptcy, sale of assets or similar corporate transaction, subject to applicable legal requirements and appropriate confidentiality protections.

    3.4 Legal Requirements and Protection of Rights

    We may disclose information where reasonably necessary to:

    • comply with applicable law or regulation;
    • respond to a valid subpoena, court order, regulatory request or legal process;
    • enforce our agreements;
    • protect the rights, property, safety or security of DOO, our users or others;
    • investigate fraud, abuse or unlawful activity; or
    • establish, exercise or defend legal claims.

    3.5 With Your Direction or Consent

    We may disclose personal information to other parties where you direct us to do so, enable an integration or otherwise provide consent.

    4. Sale and Sharing of Personal Information

    DOO does not sell personal information for monetary consideration.

    DOO does not sell or share Google user data for advertising purposes.

    Certain cookies, analytics technologies or integrations may be considered a "sale," "sharing" or use for targeted advertising under some state privacy laws, depending on how those technologies are configured.

    Where required by applicable law, we will provide an appropriate method for users to opt out of such processing.

    5. Data Storage and Security

    We maintain reasonable administrative, technical and organizational safeguards designed to protect personal information against unauthorized access, unlawful processing, accidental loss, alteration, destruction or disclosure.

    Depending on the applicable system and information, these safeguards may include:

    • encryption in transit;
    • encryption at rest;
    • role-based access controls;
    • access based on the principle of least privilege;
    • secure management of OAuth credentials and tokens;
    • authentication and account-security controls;
    • system monitoring and security logging;
    • vulnerability-management procedures;
    • incident-response procedures; and
    • confidentiality requirements for employees, contractors and service providers.

    No electronic system, online platform or storage method can be guaranteed to be completely secure.

    Users are responsible for protecting their own credentials, devices, authorized users and connected third-party accounts.

    6. Data Retention and Deletion

    We retain personal information only for as long as reasonably necessary to fulfill the purpose for which it was collected or subsequently processed.

    Once the relevant purpose has been completed, the personal information will be deleted, securely disposed of or irreversibly de-identified unless continued retention is reasonably necessary or required for:

    1. compliance with applicable law or regulation;
    2. a valid court, regulatory or governmental order;
    3. accounting, tax, audit or statutory recordkeeping requirements;
    4. fraud prevention or security investigations;
    5. establishing, exercising or defending legal claims;
    6. enforcing our agreements; or
    7. maintaining limited backup and disaster-recovery systems.

    Retention periods may vary depending on:

    • the nature and sensitivity of the information;
    • the purpose for which it was collected;
    • the duration of the Customer's account or subscription;
    • applicable legal obligations; and
    • technical backup and deletion cycles.

    Google user data will be retained only for as long as necessary to provide the Google-connected functionality authorized by the user or for an additional period where required by applicable law.

    6.1 Account Closure and Disconnection

    When a user:

    • disconnects a Google integration;
    • revokes DOO's Google access;
    • closes an account; or
    • submits a verified deletion request,

    DOO will stop accessing the connected Google account and delete the relevant Google user data within a reasonable operational period, unless continued retention is legally required.

    Information remaining temporarily within protected backup or disaster-recovery systems will:

    1. remain secured and access-restricted;
    2. not be used for ordinary business purposes; and
    3. be deleted or overwritten through the applicable backup-management cycle.

    6.2 Data Deletion Requests

    Users may request deletion of their personal information by contacting:

    hello@doo.ooo

    We may request reasonable information to verify the identity and authority of the person making the request.

    Users may also revoke DOO CX's access to their Google account through their Google Account security settings. Revoking access may prevent Google-connected features from continuing to operate.

    7. Privacy Rights

    Depending on your state or country of residence and subject to applicable law, you may have the right to:

    • request access to personal information we maintain about you;
    • request correction of inaccurate or incomplete personal information;
    • request deletion of personal information;
    • obtain a portable copy of certain personal information;
    • object to or request restriction of certain processing;
    • opt out of the sale or sharing of personal information;
    • opt out of certain targeted advertising;
    • withdraw consent where processing is based on consent;
    • appeal a decision relating to a privacy request; and
    • receive equal service and pricing without unlawful discrimination for exercising a privacy right.

    Requests may be submitted to:

    hello@doo.ooo

    We may need to verify your identity and authority before completing a request. Where a request is made through an authorized agent, we may require evidence that the agent is authorized to act on your behalf.

    Certain requests may be restricted, denied or subject to exceptions where permitted or required by applicable law.

    To appeal a decision concerning a privacy request, reply to our decision or contact us using the email address above and state that you are submitting a privacy appeal.

    8. Cookies and Similar Technologies

    We may use cookies and similar technologies to:

    • authenticate users;
    • maintain sessions;
    • remember preferences;
    • protect account security;
    • operate essential platform functionality;
    • diagnose technical issues;
    • measure platform performance; and
    • understand how the Services are used.

    Users may manage cookie settings through their browser or any cookie-preference tool made available through the Services.

    Disabling essential cookies may affect the availability or operation of certain features.

    9. International Data Processing and Transfers

    DOO is based in the United States, and personal information may be processed and stored in the United States and in other countries where DOO or its service providers operate.

    Those countries may have privacy and data-protection laws that differ from the laws of your state, province or country of residence.

    Where required by applicable law, DOO will use reasonable contractual, technical and organizational measures designed to protect personal information transferred across national borders.

    10. Children's Privacy

    The Services are intended for business and organizational use and are not directed to children under the age of 13.

    We do not knowingly collect personal information directly from children under the age of 13 through individual user accounts.

    If we become aware that we have collected personal information directly from a child under the age of 13 without legally valid authorization, we will take reasonable steps to delete it.

    Customers must not use the Services to collect or process children's personal information unless they have all permissions, notices, safeguards and lawful authority required under applicable law.

    11. Third-Party Links and Services

    The Services may contain links to or integrations with third-party websites and services.

    DOO is not responsible for the privacy, security or data-handling practices of third parties.

    Users should review the applicable third-party privacy notices before providing information or enabling an integration.

    12. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes to:

    • the Services;
    • our data-processing practices;
    • applicable laws;
    • regulatory requirements; or
    • third-party platform requirements.

    Where changes are material, we will provide reasonable notice through the Services, by email or through another appropriate method.

    Unless otherwise stated, an updated Privacy Policy will become effective when posted.

    13. Governing Law

    This Privacy Policy and any dispute arising out of or relating to it will be governed by and construed in accordance with the laws of the State of Delaware, United States of America, without regard to its conflict-of-law principles.

    The state and federal courts located in the State of Delaware will have exclusive jurisdiction over any dispute arising out of or relating to this Privacy Policy.

    Nothing in this Section limits any non-waivable privacy or data-protection rights available under applicable law.

    14. Contact Us

    For questions, requests or complaints concerning this Privacy Policy or our handling of personal information, please contact:

    DOO Inc.

    A Delaware corporation

    United States of America

    Email: hello@doo.ooo