Privacy & Data Protection Policy
Effective date: May 22, 2026
Last reviewed: May 22, 2026
Policy owner: Security and Privacy
Entity: Pacific Apps, Inc., provider of iDialogue
Contact: support@idialogue.app
Purpose
Pacific Apps, Inc. processes personal and customer data to provide iDialogue's Salesforce, document, file-processing, AI agent, sharing, support, security, and billing services. This policy establishes requirements for lawful, limited, transparent, and secure processing.
Scope
This policy applies to personal and customer data processed through:
- iDialogue websites, APIs, and Salesforce applications;
- document generation, file processing, OCR, extraction, summarization, and document Q&A;
- AI agents, skills, tools, transcripts, memory, and knowledge;
- customer Experiences, Rooms, invitations, sharing, and publishing;
- support, security, operations, analytics, and billing; and
- infrastructure and processing providers used to deliver these services.
Principles
Pacific Apps applies the following privacy and data-protection principles, subject to the selected feature, customer agreement, and applicable law:
- Purpose limitation. Process data only for defined service, security, support, billing, contractual, or legal purposes.
- Data minimization. Configure workflows to send only the fields, files, instructions, and prior state required for the task.
- Transparency. Document material processing paths, providers, storage behavior, and private-versus-public sharing choices.
- Access control. Restrict access through authenticated application and administrative controls, tenant-aware authorization, configured Connections, and appropriately scoped Salesforce identities.
- Retention discipline. Treat Salesforce context, files, generated artifacts, transcripts, knowledge, logs, provider state, and financial records as separate data classes with appropriate lifecycle requirements.
- Provider governance. Evaluate third parties according to the data they process and capabilities they provide, with contractual and security safeguards appropriate to their role.
- Human oversight. Support human review for extracted information, consequential record changes, commercial commitments, and customer-facing outputs where appropriate to the workflow.
- Security response. Investigate suspected incidents, preserve necessary evidence, and provide notifications when required by contract or law.
AI processing
Customer data may be sent to configured AI or document-processing providers when a user or approved workflow invokes that functionality. The data processed, provider used, and applicable storage behavior depend on the configured workflow.
Model training
OpenAI states that API data is not used to train or improve its models unless the API customer explicitly opts in. Optional feedback, evaluation, fine-tuning, and service-improvement programs are governed separately by the applicable provider organization and project settings.
Application state and retention
Model training and data retention are separate issues. Current reviewed iDialogue Responses API workflows use store=true where stored application state is required for threaded conversations, background continuation, and file-processing workflows.
Provider application state, uploaded files, abuse-monitoring data, conversations, and optional sharing programs are separate data classes and may have different controls and retention behavior.
See AI & Agent Governance and the Data Retention Policy for additional information.
Individual and customer requests
Subject to applicable law, identity verification, contractual terms, and the customer's responsibility for the relevant data:
- individuals may request access, correction, deletion, restriction, or information about applicable processing;
- customers may request export or deletion assistance for in-scope customer data; and
- when the relevant data is controlled by a customer, Pacific Apps may direct an individual to that customer's designated privacy process.
Requests should be sent to support@idialogue.app.
Legal, security, backup, dispute, financial, and technical requirements may affect the timing or scope of a request.
Accountability
The policy owner reviews this policy and the underlying privacy program when material changes occur in product processing, providers, legal requirements, or incident findings.
Exceptions require a documented business need, risk assessment, responsible owner, approval, and appropriate expiration or reassessment date.