Privacy & Data Protection Policy
Effective date: May 22, 2026
Last reviewed: August 23, 2026
Policy owner: Security and Privacy
Entity: Pacific Apps, Inc., provider of iDialogue
Contact: support@idialogue.app
Purpose
Pacific Apps, Inc. processes personal and customer data to provide iDialogue's Salesforce, document, file-processing, AI agent, sharing, support, security, and billing services. This policy establishes requirements for lawful, limited, transparent, and secure processing.
Scope
This policy applies to personal and customer data processed through:
- iDialogue websites, APIs, and Salesforce applications;
- document generation, file processing, OCR, extraction, summarization, and document Q&A;
- AI agents, skills, tools, transcripts, memory, and knowledge;
- customer Experiences, Rooms, invitations, sharing, and publishing;
- support, security, operations, analytics, and billing; and
- infrastructure and processing providers used to deliver these services.
Principles
Pacific Apps applies the following privacy and data-protection principles, subject to the selected feature, customer agreement, and applicable law:
- Purpose limitation. Process data only for defined service, security, support, billing, contractual, or legal purposes.
- Data minimization. Configure workflows to send only the fields, files, instructions, and approved conversation context required for the task.
- Transparency. Document material processing paths, providers, storage behavior, and private-versus-public sharing choices.
- Access control. Restrict access through authenticated application and administrative controls, tenant-aware authorization, configured Connections, the Salesforce API connection user configured by the Salesforce Admin, and configured Experience and Room membership, invitation, and sharing controls.
- Retention discipline. Treat Salesforce context, dialogue history, task inputs, repository files, generated artifacts, indexed knowledge, provider processing, operational records, and financial records as separate data classes with appropriate lifecycle requirements.
- Provider governance. Evaluate third parties according to the data they process and capabilities they provide, with contractual and security safeguards appropriate to their role.
- Human oversight. Support human review for extracted information, consequential record changes, commercial commitments, and customer-facing outputs where appropriate to the workflow.
- Security response. Investigate suspected incidents, preserve necessary evidence, and provide notifications when required by contract or law.
AI processing
Customer data may be sent to configured AI or document-processing providers when a user or approved workflow invokes that functionality. The data processed, provider used, and applicable storage behavior depend on the configured workflow.
Model training
Under the iDialogue-managed OpenAI integration, customer data sent through the OpenAI API is not used to train OpenAI models. Customers using their own OpenAI key administer their OpenAI organization, project, and available provider settings, including optional provider programs.
Dialogue continuity
iDialogue may retain approved conversation context so users can continue an agent dialogue without re-teaching the agent or repeating earlier discussions. This intentional continuity is separate from model training.
Task-based processing and retained records
Document generation, OCR, image analysis, and transactional work are task-based and do not create conversational memory. Requested files and generated artifacts can be retained in the secure iDialogue repository. Operational, security, support, usage, billing, contractual, and legal records are separate data classes with their own purposes and lifecycles.
Provider processing records and optional provider programs are also separate and are governed by the applicable provider account, available controls, and contractual terms.
Customer-facing Experiences and Rooms
iDialogue Experiences and Document Rooms can collect form responses, checklist updates, uploads, review decisions, signatures, and other workflow inputs from invited participants. The configured workflow may write approved information or completed outcomes to Salesforce.
Access to an Experience or Document Room is not a Salesforce login and does not provide general access to the connected org. The participant receives access only to the content and actions exposed for the applicable membership and workflow.
Experience and Room content, Salesforce writeback, repository artifacts, eSignature records, and operational records are separate data classes with their own purposes and lifecycle requirements.
See AI & Agent Governance and the Data Retention Policy for additional information.
Individual and customer requests
Subject to applicable law, identity verification, contractual terms, and the customer's responsibility for the relevant data:
- individuals may request access, correction, deletion, restriction, or information about applicable processing;
- customers may request export or deletion assistance for in-scope customer data, including Experience and Room content; and
- when the relevant data is controlled by a customer, Pacific Apps may direct an individual to that customer's designated privacy process.
Requests should be sent to support@idialogue.app.
Legal, security, backup, dispute, financial, and technical requirements may affect the timing or scope of a request.
Accountability
The policy owner reviews this policy and the underlying privacy program when material changes occur in product processing, providers, legal requirements, or incident findings.
Exceptions require a documented business need, risk assessment, responsible owner, approval, and appropriate expiration or reassessment date.