Privacy Policy
This policy describes what Phloem processes and why. Data requests are handled through the privacy centre — we do not publish individual inboxes.
1. Scope
This policy explains what personal data Phloem processes when you use the Service, and why.
The controller is [RIGHTS HOLDER — TO BE CONFIRMED], Zürich, Switzerland.
Where you upload or research third-party business contact data in your workspace, you act as controller for that data and we process it on your behalf as part of providing the Service.
2. Information you provide
Account data: name, work email, password credentials handled by our authentication provider, and sign-in identifiers if you use Google sign-in.
Workspace information: organisation name, members, roles, settings, budgets and plan selection.
Business details: information you give us for billing, enterprise enquiries or partnerships.
Support requests: the message, topic and contact details you submit through the support form.
3. Product usage data
We record actions taken in the product (for example missions, discovery runs, agent runs, approvals and exports), usage and credit accounting records, and technical logs such as timestamps, request metadata and error diagnostics.
This data is used to operate the product, enforce plan entitlements and budgets, bill accurately, diagnose faults and improve the Service.
4. Customer discovery data
Your ICPs, briefs, target lists and research configuration are workspace data. Companies, contacts, signals and evidence discovered or uploaded are stored in your workspace and are visible to members of that workspace according to their role and your data-access settings.
Contact records may be redacted or masked in interfaces and exports where your plan, role or extraction settings require it.
Discovery data is not sold, shared between customer workspaces, or used to build a cross-customer contact database.
5. Payments
Payments are processed by our payment providers. Card and payment-instrument details are entered with the provider and are not stored in full by Phloem.
We keep records needed for billing and accounting, such as plan, amounts, currency, status, provider reference and redacted identifiers (for example the last digits of a card).
6. Support
Support and business enquiries are processed to answer you, investigate issues and keep a record of the request. Each request is given an opaque reference.
We apply automated checks (such as rate limiting and spam scoring) to protect the form from abuse.
7. Security logging
We keep security and abuse-prevention logs, including authentication events, request metadata, extraction accounting and anomaly signals, to protect accounts and the platform.
We do not publish the thresholds or detection rules behind these controls.
8. Service providers and AI
To provide the Service we use processors and providers for cloud hosting and databases, authentication, AI model inference, web search and data enrichment, email delivery and payment processing.
Content you send to AI features (for example prompts, briefs and evidence context) is processed by the configured AI provider to generate the requested output. Sensitive values and credentials are filtered from AI payloads by the product before transmission.
[LEGAL REVIEW REQUIRED: current sub-processor list, locations and international transfer mechanisms to be published and kept current]
9. Retention
Workspace data is retained while your account is active. Financial, invoice and audit records are retained for as long as accounting and legal obligations require. Security and abuse logs are retained for a limited period appropriate to their purpose.
[LEGAL REVIEW REQUIRED: specific retention periods per data category to be confirmed against the implemented deletion behaviour and applicable law]
10. Your rights
Depending on where you are, you may have rights to access, correct, delete, restrict or object to processing, to portability, and to withdraw consent where processing relies on it. You may also have the right to complain to a supervisory authority.
Workspace members should raise requests with their workspace administrator first where the data belongs to a workspace; we will support that administrator in responding.
[LEGAL REVIEW REQUIRED: jurisdiction-specific rights wording, legal bases table and response timelines to be confirmed by counsel]
12. Contact
Privacy and data questions go through the Phloem support form, choosing the “Privacy / Data” topic; security reports should use the “Security” topic.
All legal, privacy and security contact runs through the Phloem support form — we do not publish inbox addresses.

