VOLOFO LTD ("Company," "we," "us," or "our") is the company that operates the Volofo platform. "Volofo" or the "System" means the software platform and related services accessible at volofo.com.
• This policy describes how VOLOFO LTD collects, uses, stores, shares, and protects information when the System is used.
• This policy is a notice about our handling of information; viewing or using the System does not by itself record consent to this policy, marketing, an Order, a trial, or a paid service. Any acceptance or consent that applicable law or a particular transaction requires must be requested separately through the relevant flow.
• Contact for privacy, security, and support matters: contact@volofo.com
BETA Warning
• The System is in an initial BETA phase; malfunctions, downtime, and frequent changes may occur.
• The System should not be considered a finalized solution. We recommend backing up any important information independently before entering it into the System.
Definitions
• "Personal Information": any data about an identified or identifiable individual, whether directly or indirectly (such as name, email, phone number, online identifiers, IP address, device ID, approximate location, and similar details).
• "Sensitive Information": personal data of particularly sensitive nature under applicable law (for example: health information, biometric data, sexual orientation, etc.).
• "Customer-Provided Data": any content or information that users upload to the System, including in free-form fields, files, integrations, and third-party sources.
• "Aggregated/De-Identified Data": information that does not allow for reasonable identification of a specific individual.
• "Integration Data": information accessed, received, sent, synchronized, or stored through user-authorized third-party integrations, including email, calendar, messaging, storage, CRM, payment, analytics, and workflow services.
Nature of the System and Data Entry Flexibility
• Volofo is a flexible system that enables customers to define fields, data structures, and processes freely. As a result, users may upload any type of information, including personal and/or sensitive data about themselves or third parties.
• Users are responsible for ensuring they have a proper legal basis to process the information they enter into the System, including obtaining any required consents from third parties (as applicable by law), and for complying with all applicable legal requirements (including privacy laws, regulations, and foreign laws if relevant).
Information We Collect and Process
a. Information provided directly during registration and use:
• Identifying details and contact information: full name, email, phone number, role, business/entity name, business type/industry, address, country.
• Business usage data as configured by the customer: project names, tasks, customers, vendors, work hours, statuses, uploaded documents and files, custom fields, tags, and similar data.
• Preferences: language, configuration settings, team permissions.
• Portal account holders and customer site visitors: where a customer activates a portal, protected site, or form, we may process account identifiers, authentication and session data, invitations, access roles, submissions, messages, files, and technical request data on the customer's instructions. The customer is generally responsible for its end-user notices, permissions, lawful basis, and content.
• Buyer, billing, administrative, and support contacts: we may process business contact details, authority or role, Order and billing communications, support requests, security reports, and related correspondence needed to administer the relationship.
b. Payments and billing:
• We do not store full credit card details. Payment processing, where applicable, is performed via a secure third-party payment provider subject to its policies and standards (e.g., PCI-DSS). We may retain a transaction ID, amount, currency, date, and operational metadata.
c. Telemetry and technical usage data:
• Device/browser details: device type, operating system, browser version, interface language.
• IP address and approximate geographic location based on IP.
• System logs: logins, authentication attempts, errors, crashes, key actions.
• Essential browser storage and technical logs for operation and security; optional public-site analytics data only after the applicable visitor choice.
d. Interaction and support:
• Records of support requests, emails, chats, call recordings (if any and with prior notice), feedback, and feature requests.
• We may document and retain interactions for operational purposes, security, legal compliance, and service improvement.
e. Information from third parties/integrations:
• When connecting third-party services at the user's choice (for example, Google services, Microsoft/Azure services such as Outlook or Microsoft 365, WhatsApp, Telegram, CRM systems, cloud accounts, BI tools, payment providers, and messaging providers), data may be transferred into or out of the System according to the granted permissions and the third party's policies.
Purposes and Legal Bases for Processing
We process information for the following purposes:
• Providing the service and operating the System: registration, authentication, permissions, configuration, team collaboration.
• Customization and improvement: troubleshooting, service reliability, de-identified research, and optional public-site analytics or testing when enabled and lawfully permitted.
• Security and fraud prevention: monitoring, detecting anomalies, preventing unauthorized access.
• Operational communications: service changes, security alerts, version updates.
• User-authorized communications: sending email, calendar, WhatsApp, Telegram, SMS, or similar messages when configured or initiated by you, your users, automations, or connected integrations.
• Marketing communications where permitted: newsletters, offers, and webinar invitations, using separate consent where required. You can unsubscribe at any time through the message link.
• Compliance with law: responding to lawful orders, handling claims, enforcing the Terms of Use.
• Research and development: using de-identified data for analysis and enhancement.
Legal bases depend on the data, role, and applicable law:
• Contract or pre-contract steps: account creation requested by you, authentication, activated service delivery, support, and administration of an accepted Order.
• Legitimate interests: proportionate security, fraud and abuse prevention, support, service reliability, troubleshooting, and product improvement where those interests are not overridden by applicable individual rights.
• Legal obligation: tax, accounting, regulatory, court-order, sanctions, and other compliance processing required by law.
• Separate consent: optional public-site analytics and marketing where consent is required; consent may be withdrawn without affecting prior lawful processing or essential service communications.
• Customer instructions: when Volofo acts as processor or service provider for Customer-Provided Data, the customer determines the applicable legal basis and Volofo processes under the customer's instructions, the activated service, applicable Governing Documents, and mandatory law.
Entering Sensitive Information and Free-Form Fields
• There is no obligation to enter sensitive information. If you choose to upload sensitive information (e.g., in free-form text fields or files), you declare that you have a proper legal basis for doing so and that you have obtained all necessary consents and notifications under applicable law.
• We recommend minimizing identifiable information in free-form fields that are not required for business purposes.
Artificial Intelligence and Machine Learning
• Volofo may integrate artificial intelligence services, including OpenAI and other AI providers or model infrastructure, as part of features such as search indexing, content generation, formula assistance, classification, summarization, and AI-powered planning.
• When you activate an AI feature, the prompts, instructions, selected Customer-Provided Data, metadata, and generated output needed for that operation may be sent to the identified AI provider. We do not treat merely creating an account as authorization to send unrelated workspace content to an AI provider.
• Where OpenAI is used, OpenAI processes data according to the applicable OpenAI business/API terms and data usage terms in effect for the relevant service. We avoid hard-coding vendor promises in this policy because provider terms, product names, and processing commitments may change over time.
• We identify material AI providers used by implemented features and apply provider terms or additional contractual protections required for the relevant activation. See our AI Subprocessors page for the current disclosure.
• For questions about AI data processing, please contact us at contact@volofo.com.
Integration Services and Channel Data
The System may allow you to connect third-party accounts and channels, including Google, Microsoft/Azure services such as Outlook and Microsoft 365, WhatsApp, Telegram, email providers, SMS providers, CRM platforms, cloud storage, payment processors, and analytics or BI services.
When you authorize an integration, we access, process, send, receive, and store only the Integration Data reasonably needed to provide the feature you configured, such as email or message metadata and content, calendar events, contact information, delivery status, files, and synchronization metadata.
Some managed connection flows use Composio as an integration intermediary to help create and operate the provider connection you select. Composio is not the destination service: the destination provider remains separate and its own permissions, terms, retention, limits, and charges continue to apply.
You are responsible for authorizing only integrations you are permitted to use, reviewing requested scopes, complying with provider terms, and disconnecting integrations that are no longer needed. Integration actions may be delayed, rejected, duplicated, or irreversible at the destination. We do not guarantee provider delivery, rate limits, retries, reversal, availability, or fees.
Disconnecting inside Volofo stops the applicable local workflow when completed, but may not revoke upstream access, undo actions already transmitted, cancel provider charges, or delete records held by the destination provider. Where necessary, use the provider's controls to revoke access or manage provider-held data.
Google API Services — User Data Disclosure
The System may allow you to connect your Google account to access Google services such as Gmail and Google Calendar. When you authorize this connection, we access and process Google user data strictly as described below.
Data we access and why:
• Email (Gmail API): We read, send, and organize email messages and metadata on your behalf to enable email integration features within the System. We do not access email content beyond what is necessary to provide the features you initiate.
• Calendar (Google Calendar API): We read and write calendar events and metadata on your behalf to enable scheduling and calendar synchronization features within the System.
Limited Use disclosure:
Volofo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we handle Google data:
• We do not use Google API data to serve advertising, including retargeting, personalized, or interest-based advertising.
• We do not sell Google API data to third parties.
• We do not use Google API data for purposes unrelated to the features you authorized.
• Access by Volofo personnel is restricted and permitted only when you authorize support for specific data, when needed to investigate security or abuse, when required by law, or when data has been de-identified for legitimate internal operations, in each case subject to applicable access controls.
Revocation and deletion of Google data:
• You may revoke Volofo's access to your Google account at any time through your Google Account permissions settings or through the integrations settings within the System.
• After a completed disconnect or upstream revocation, we stop initiating new Google access for that connection and remove or disable the managed credential as supported by the connection flow. Transient credentials and caches follow the applicable security and provider lifecycle; we do not promise an unsupported blanket deletion period.
• Google-originated content intentionally saved into customer records may remain under the workspace's normal retention and deletion controls until the customer deletes it or submits a valid request. Security, billing, audit, backup, legal-hold, and destination-provider records follow their separate retention duties. To request deletion from Volofo systems, contact us at contact@volofo.com.
Sharing Information with Third Parties
• We may share information in the following cases:
• Service providers: cloud storage, payment processing, analytics, support, security, transactional email. Sharing is done to the extent necessary and under confidentiality and security obligations.
• Integrations at the user's choice: according to the permissions granted by the user and the policies of the third-party services.
• Structural changes: merger/acquisition/sale of assets – subject to the transferee undertaking to comply with this policy or a policy that is no less stringent.
• Legal requirements: court orders/authorized authorities; enforcement of rights; prevention of serious harm to individuals or property.
• Aggregated/de-identified data may be shared for statistical, research, and improvement purposes.
Cookies, SDKs, and Measurement Tools
• We use essential browser storage and similar technologies needed for service operation, authentication, security, language or consent state, and abuse prevention. These controls are not used as optional marketing consent.
• Optional Google Analytics on Volofo public pages loads only after a visitor selects "Allow analytics." A visitor can withdraw that choice through "Cookie settings"; essential service and security storage remains available.
• Blocking or deleting essential storage may affect authentication or service functionality. Optional analytics data, when enabled, is also handled under the applicable analytics provider terms and this policy.
Information Security
• We implement reasonable and accepted security measures, including access control, transport encryption (TLS), monitoring, and permission management.
• However, no system is completely immune. In the BETA version, risks are higher (malfunctions, bugs, availability).
• User responsibility: using strong passwords, enabling two-factor authentication if available, limiting internal access, and avoiding uploading unnecessary information.
Data Retention and Deletion
• We retain information only as long as reasonably necessary for the purposes described in this policy, to provide the Services, fulfill contractual obligations, comply with law, prevent fraud and abuse, maintain security, and resolve disputes.
Retention criteria by category:
• Account profile and workspace membership data: for the account term and as needed afterward for legal, billing, fraud, or dispute reasons.
• Billing and transaction records: retained for the period required by applicable tax, accounting, recordkeeping, audit, and dispute obligations.
• Operational and security logs: retained according to the security and risk need, including service reliability, incident response, fraud or abuse investigation, legal hold, and dispute handling.
• Backups: retained and overwritten according to the configured disaster-recovery cycle, restoration need, and infrastructure-provider constraints; backup copies are not an individual-record archive.
• Support tickets and communications: for the support lifecycle and then as needed for service quality, legal, security, or dispute reasons.
• Workspace data: active records follow customer controls and the activated product lifecycle; deletion or de-identification is then subject to valid requests, configured backup cycles, legal holds, security needs, and provider constraints.
• Integration credentials and transient caches: retained only as needed to operate and secure the authorized connection and then handled under the applicable credential, provider, and backup lifecycle. Disconnecting a local workflow, revoking upstream access, deleting customer records, and deleting destination-provider records are separate actions. Google-originated content intentionally saved as a customer record follows the workspace retention controls until deleted or a valid request is completed, subject to security, billing, audit, backup, legal-hold, and provider requirements.
• You may request deletion of eligible account data by contacting contact@volofo.com. We may require identity verification and may retain limited data where required by law, security, fraud prevention, accounting, backup cycles, or dispute enforcement obligations.
Individual Rights and Means of Contact
• Right to access, correction, and deletion: you can contact us to request access to, correction of, or deletion of your personal information, subject to law and technical/security limitations.
• Right to object/restrict processing: you can request restriction of or objection to certain processing, subject to the legal basis.
• Right to opt-out of marketing: you can unsubscribe at any time via the dedicated link in email messages.
• We require identity verification before handling requests to maintain security and confidentiality. We respond within the period required by applicable law and generally aim to respond within 30 days where that timeline is practical and legally applicable.
• Contact for privacy rights: contact@volofo.com
Changes to the Policy
• We will update this policy from time to time. Changes will take effect from the date of publication on the website/System, unless otherwise specified.
• Material legal, privacy, or pricing changes will be notified by email, in-product notice, dashboard banner, or another reasonable method before they take effect where practical. Changes required for urgent security, fraud prevention, legal, regulatory, or abuse-prevention reasons may take effect immediately.
International Transfers
• Processing locations depend on the features and providers selected. Where a cross-border transfer requires a legal mechanism, disclosure, or agreement, we will apply the requirement for that processing. A draft proposal, catalog entry, or this policy alone does not represent that a customer-specific data processing addendum or transfer arrangement has been completed.
User Obligations as Data Controllers
• For data provided by the customer about third parties (customers, employees, vendors), the user is the "data controller" under applicable law and is responsible for fulfilling obligations of notice, consent, security, data retention, and data subject rights.
• VOLOFO LTD generally acts as a "data processor" or "service provider" for Customer-Provided Data where the customer determines the purposes and means, subject to the applicable Order, any executed data processing terms, and mandatory law. This role description does not replace a customer-specific data processing addendum where one is required.
• VOLOFO LTD acts as an independent "data controller" for account administration, billing, fraud prevention, platform security, product analytics, and legal compliance data required to operate the service.
Minors
• The System is not intended for minors under the minimum age required by local law. Do not enter information about minors without a proper legal basis and required consents.
Marketing Communications
• We send marketing communications only where permitted by applicable law and on the applicable lawful basis, including separate consent where required. Agreement to Terms of Use or receipt of this policy does not by itself grant marketing permission. You can unsubscribe through the message link or by contacting us; opting out of marketing does not stop essential account, security, service, or legal notices.
• If you use the System to send or automate messages to customers, workers, website visitors, or other recipients, you are responsible for having a valid legal basis or opt-in, honoring opt-outs, avoiding spam, and complying with applicable email, SMS, WhatsApp, Telegram, and similar messaging-channel rules.
Dispute Resolution
How disputes related to this Privacy Policy are handled:
• Informal negotiations first: The parties will attempt to resolve any dispute through direct good-faith informal negotiations for at least 30 days before formal legal proceedings, unless urgent injunctive relief is required.
• Courts in Tel Aviv-Jaffa: If not resolved informally, disputes shall be brought before the competent courts in Tel Aviv-Jaffa, Israel, subject to mandatory law.
• Individual claims only: To the fullest extent permitted by law, disputes should be brought in an individual capacity and not as class, collective, or representative actions.
• This policy follows the same governing forum structure set in the Terms of Use.
Governing Law
• This Privacy Policy and any disputes related thereto shall be governed by and construed in accordance with the laws of the State of Israel, without regard to its conflict of law principles, and subject to the court jurisdiction provisions in the Terms of Use.
Summary Statement
This policy explains our current information-handling practices. Contractual acceptance, optional marketing consent, integration authorization, and any paid Order are separate events. Customers remain responsible for the legality, accuracy, permissions, notices, and instructions associated with Customer-Provided Data.