---
isPublished: true
template: "page.peb"
title: "Privacy & Data Protection Policy"
displayName: "Privacy & Data Protection Policy"
description: "Public privacy and data protection principles for Pacific Apps, Inc., provider of iDialogue."
category: "trust"
contentType: "policy"
audience: "end-user"
tags: "trust,policy,privacy,data-protection"
section: "trust"
effectiveDate: "2026-05-22"
lastReviewed: "2026-05-22"
owner: "Security and Privacy"
contact: "support@idialogue.app"
seoTitle: "iDialogue Privacy and Data Protection Policy"
seoDescription: "Review the privacy and data protection principles used by Pacific Apps, Inc. to provide iDialogue."
---

## Privacy & Data Protection Policy

**Effective date:** May 22, 2026  
**Last reviewed:** May 22, 2026  
**Policy owner:** Security and Privacy  
**Entity:** Pacific Apps, Inc., provider of iDialogue  
**Contact:** [support@idialogue.app](mailto:support@idialogue.app)

<div class="trust-callout trust-callout--qualified">
  This policy describes iDialogue's privacy and data-protection practices and control principles. Specific legal rights and obligations are governed by the <a href="/legal/privacy.html">Privacy Policy</a>, applicable customer agreements and Data Processing Addenda, and applicable law.
</div>

<h2 id="purpose">Purpose</h2>

Pacific Apps, Inc. processes personal and customer data to provide iDialogue's Salesforce, document, file-processing, AI agent, sharing, support, security, and billing services. This policy establishes requirements for lawful, limited, transparent, and secure processing.

<h2 id="scope">Scope</h2>

This policy applies to personal and customer data processed through:

- iDialogue websites, APIs, and Salesforce applications;
- document generation, file processing, OCR, extraction, summarization, and document Q&amp;A;
- AI agents, skills, tools, transcripts, memory, and knowledge;
- customer Experiences, Rooms, invitations, sharing, and publishing;
- support, security, operations, analytics, and billing; and
- infrastructure and processing providers used to deliver these services.

<h2 id="principles">Principles</h2>

Pacific Apps applies the following privacy and data-protection principles, subject to the selected feature, customer agreement, and applicable law:

1. **Purpose limitation.** Process data only for defined service, security, support, billing, contractual, or legal purposes.
2. **Data minimization.** Configure workflows to send only the fields, files, instructions, and prior state required for the task.
3. **Transparency.** Document material processing paths, providers, storage behavior, and private-versus-public sharing choices.
4. **Access control.** Restrict access through authenticated application and administrative controls, tenant-aware authorization, configured Connections, and appropriately scoped Salesforce identities.
5. **Retention discipline.** Treat Salesforce context, files, generated artifacts, transcripts, knowledge, logs, provider state, and financial records as separate data classes with appropriate lifecycle requirements.
6. **Provider governance.** Evaluate third parties according to the data they process and capabilities they provide, with contractual and security safeguards appropriate to their role.
7. **Human oversight.** Support human review for extracted information, consequential record changes, commercial commitments, and customer-facing outputs where appropriate to the workflow.
8. **Security response.** Investigate suspected incidents, preserve necessary evidence, and provide notifications when required by contract or law.

<h2 id="ai-processing">AI processing</h2>

Customer data may be sent to configured AI or document-processing providers when a user or approved workflow invokes that functionality. The data processed, provider used, and applicable storage behavior depend on the configured workflow.

### Model training

OpenAI states that API data is not used to train or improve its models unless the API customer explicitly opts in. Optional feedback, evaluation, fine-tuning, and service-improvement programs are governed separately by the applicable provider organization and project settings.

### Application state and retention

Model training and data retention are separate issues. Current reviewed iDialogue Responses API workflows use <code>store=true</code> where stored application state is required for threaded conversations, background continuation, and file-processing workflows.

Provider application state, uploaded files, abuse-monitoring data, conversations, and optional sharing programs are separate data classes and may have different controls and retention behavior.

See [AI &amp; Agent Governance](/trust/ai-agent-governance.html#provider-data-controls) and the [Data Retention Policy](/trust/compliance/data-retention.html) for additional information.

<h2 id="individual-requests">Individual and customer requests</h2>

Subject to applicable law, identity verification, contractual terms, and the customer's responsibility for the relevant data:

- individuals may request access, correction, deletion, restriction, or information about applicable processing;
- customers may request export or deletion assistance for in-scope customer data; and
- when the relevant data is controlled by a customer, Pacific Apps may direct an individual to that customer's designated privacy process.

Requests should be sent to [support@idialogue.app](mailto:support@idialogue.app).

Legal, security, backup, dispute, financial, and technical requirements may affect the timing or scope of a request.

<h2 id="accountability">Accountability</h2>

The policy owner reviews this policy and the underlying privacy program when material changes occur in product processing, providers, legal requirements, or incident findings.

Exceptions require a documented business need, risk assessment, responsible owner, approval, and appropriate expiration or reassessment date.

## Related information

- [Privacy Policy](/legal/privacy.html)
- [Security &amp; Data Handling](/trust/security-data-handling.html)
- [Data Retention Policy](/trust/compliance/data-retention.html)
- [Third-Party Security Policy](/trust/compliance/third-party-security.html)