Privacy policy
Effective May 1, 2026
Informly Inc. ("Informly", "we", "us") builds a customer-feedback platform. This policy explains what personal data we collect, how we use it, and the choices you have. We act as a data controller for our own marketing site and admin accounts, and as a data processor for the end-customer data our paying customers send through Informly. See our DPA for processor terms.
1. Data we collect
From visitors to informly.co: standard server logs (IP, user agent), anonymous analytics events (page views, referrer), and cookies you accept (see Cookie policy).
From customers who sign up: name, work email, company, billing details, integration credentials. Authentication via SSO where configured.
From end-customers (data our customers send us): contact identifiers (name, email, phone), survey responses, loyalty stamps, coupon redemptions, ticket content, and usage events from integrated systems.
2. How we use data
To run the platform you signed up for; to send transactional product notifications; to bill, support, and improve the service; and to detect abuse or fraud. We do not sell personal data, ever. We do not train AI models on customer or end-customer data without explicit opt-in.
3. Lawful bases (GDPR)
Performance of contract (delivering the service you signed up for), legitimate interests (security, fraud prevention, product improvement), legal obligation (tax, accounting), and consent (marketing where required).
4. Sharing + sub-processors
We use vetted infrastructure providers — listed publicly on our Sub-processors page. We require equivalent data-protection terms from every sub-processor.
5. Retention
Customer accounts are retained for the life of the contract plus 90 days. End-customer data follows the retention policy you configure (default 24 months on the free plan, configurable to a maximum of 7 years on Growth).
6. Your rights
Access, rectification, erasure, portability, restriction, objection, and the right to withdraw consent. Submit a request to privacy@informly.co — we respond within 30 days.
7. International transfers
Data residency is region-selectable (US, EU, APAC). Where data crosses regions, we use Standard Contractual Clauses (EU SCCs / UK IDTA) and supplementary technical measures.
8. Security
See our Security page for the technical and organizational measures we have in place.
9. Changes
Material changes are announced via product email and an effective-date update at the top of this page at least 30 days before they take effect.
10. Contact
Privacy questions: privacy@informly.co. EU/UK representative on request.