Privacy Policy
This policy explains how TeamOffice ("we", "us"), operated by Column Seven (8 The Green, Ste B, Dover DE 19901, USA), collects and processes personal data on teamoffice.ai, the TeamOffice application, and co-branded domains in the Agentix product family.
Contact: privacy@teamoffice.ai
1. Two roles we play
- As a data controller — for data about our own customers ("Customers"): accounts, billing, support, and service communications.
- As a data processor — for the content Customers bring into the workspace ("Workspace Content"): files, documents, drafts, voice captures, conversation history, and any personal data contained in them. The Customer is the controller of Workspace Content; we process it only to provide the service, under our Data Processing Agreement.
2. Data we collect
Customers (we are the controller)
- Account data: name, email address, authentication credentials (or OAuth identity), and workspace settings.
- Billing data: subscription tier, credit balance, and payment records. Card details are collected and stored by Stripe — we never see full card numbers.
- Support communications and service emails.
Workspace Content (we are the processor)
- Files, documents, drafts, memos, deliberations, and evidence uploaded or created in the app.
- Conversation history with AI agents.
- Voice captures and their transcripts.
- Collaboration data: names and email addresses of invited collaborators.
- Connected-app data accessed through integrations the Customer authorises (see Section 7).
Website visitors
- Server logs: IP address, user agent, requested URL — retained briefly by our hosting infrastructure for security and reliability.
- The contact form on teamoffice.ai opens your own email client (
mailto:); nothing you type is transmitted to or stored on our servers unless you choose to send the email.
3. Cookies and local storage
We use no advertising or analytics cookies and no cross-site tracking. The complete inventory:
| Name | Type | Set by | Purpose | Duration |
|---|---|---|---|---|
GAESA | Cookie | Hosting infrastructure (Google Cloud) | Load balancing. Strictly necessary. | 30 days |
| Session cookie | Cookie | TeamOffice app | Keeping you signed in. Strictly necessary. | Session (rolling) |
baseagentix_english | Cookie | TeamOffice app | Remembering your English dialect preference (en-US/en-GB). Shared across Agentix family domains so your preference follows you. Functional. | 1 year |
__stripe_mid, __stripe_sid | Cookies | Stripe (billing pages only) | Fraud prevention and payment security. Strictly necessary for payment processing. | 1 year / 30 min |
| UI preferences | localStorage | TeamOffice app | Theme, sidebar layout, accessibility settings, disclaimer acknowledgments. Never sent to our servers for tracking. | Until cleared |
Because none of these are tracking cookies, no consent banner is required and none is shown.
4. How we use data and legal bases (GDPR)
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the TeamOffice service | Account data, Workspace Content | Contract (Art. 6(1)(b)); Workspace Content processed on the Customer's behalf under our DPA |
| Billing and subscription management | Billing data | Contract (Art. 6(1)(b)) |
| Security, abuse prevention, reliability | Server logs | Legitimate interests (Art. 6(1)(f)) |
| Service announcements to Customers | Account data | Contract / legitimate interests |
| Legal compliance | Any of the above | Legal obligation (Art. 6(1)(c)) |
We do not sell personal data, do not use it for advertising, and do not use Workspace Content to train AI models.
5. AI processing — where your content travels
TeamOffice routes AI requests to large-language-model providers. What travels: the prompts, documents, and context needed to fulfil the request you make in the app. Three modes:
- Bring-your-own-key (BYOK): if you connect your own API key (e.g., OpenAI, Anthropic, OpenRouter), your content is sent to that provider under your own agreement with them. You choose the provider; their terms and data-handling commitments apply. Your API keys are stored encrypted and used only to route your requests.
- Platform credits: if you use TeamOffice credits, requests are routed through our provider accounts (currently OpenRouter and its partner networks) under agreements that prohibit training on your content. These providers appear in our sub-processor list.
- Local models: if you connect Ollama or LM Studio, content is sent to your own machine and never leaves your control.
Voice captures are transcribed by a third-party transcription provider (details to be confirmed and updated here). Audio and transcripts are stored as Workspace Content.
6. Payments
Payments are processed by Stripe, Inc. Stripe collects your card details directly; we receive only a payment reference, status, and the billing details needed for invoicing. Stripe acts as an independent controller for fraud prevention and payment processing — see Stripe's privacy policy.
7. Connected apps (integrations)
You may connect third-party apps (via Composio) to let your agents act on your behalf. When you authorise a connection, OAuth tokens are stored securely and data from that app is accessed only as needed to perform the actions you request. Disconnecting an integration revokes our access; you can also revoke from the third-party app directly.
8. Sub-processors and service providers
| Provider | Purpose | Location / safeguards |
|---|---|---|
| Replit / Google Cloud | Application hosting, server logs | US; DPA and SCCs |
| PostgreSQL (Replit managed) | Database | US; DPA |
| Stripe | Payment processing | US; independent controller, SCCs |
| Composio | Third-party app integration layer | US; DPA |
| OpenRouter and partner LLM providers | AI request processing (platform-credit mode) | US; DPA, no-training terms |
| Transactional email provider | Transactional email | To be confirmed |
Fonts are self-hosted. No font requests are made to Google or any other third party.
9. Retention
- Account data: while the account is active; deleted within 30 days of account deletion.
- Workspace Content: under the Customer's control — you can export or delete at any time; deleted within 30 days of account deletion.
- Billing records: retained as required by tax and accounting law.
- Server logs: up to 30 days. Backups purge on a rolling 30-day cycle.
10. Your rights
EU/UK residents: access, rectification, erasure, restriction, objection, portability, and complaint to a supervisory authority. Contact privacy@teamoffice.ai. For personal data inside Workspace Content, we may redirect your request to the responsible Customer (the controller), and we will assist them in fulfilling it.
11. International transfers
Where data is transferred outside the EU/UK, we rely on Standard Contractual Clauses (Module 2) incorporated by reference, and the UK Addendum for UK customers. Sub-processors are bound to equivalent safeguards.
12. Security
TLS in transit; encryption at rest; encrypted storage of API keys and OAuth tokens; per-workspace access isolation; hashed credentials; access controls and least-privilege administration. Details in our DPA's security annex.
13. Children
TeamOffice is a professional tool intended for adults. We do not knowingly collect data from anyone under 16.
14. Changes
Updates are posted here with a revised effective date. Material changes are announced to Customers by email and require re-acceptance in the app before continuing to use the service.